Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Windows 10 / Installation von unerwünschten Programmen hört nicht auf/Defender geht nicht (https://www.trojaner-board.de/181121-windows-10-installation-unerwuenschten-programmen-hoert-defender-geht.html)

Piristibulus 15.08.2016 20:49

Windows 10 / Installation von unerwünschten Programmen hört nicht auf/Defender geht nicht
 
Hallo,

ich habe mir heute wohl einen Trojaner gefangen.
Ich hatte versucht eine Buch herunterzuladen (Gemeinfrei - geht um was mittelalterliches, was es auch als doc-Dateien und/oder html-Format gibt/geben sollte).
Als ich die Datei mountete, ging auf einmal ein Installer los - ich dachte mir, dass etwas nicht korrekt ist und habe "cancel" geklickt.

Vermutlich hätte ich das über den Task Manager killen sollen, jedenfalls ging gleich Windows Defender los und schlug großen Alarm. Beim scannen fand er aber nur zwei Dateien. Quarantäne und Löschen half nichts - auf einmal wurden ständig weitere Programme installiert. angeblich Systemwartungssoftware und auf einmal was chinesisches.

Löschen konnte man nichts mehr (Angeblich m+uss ich dazu als Administratoren (wörtlich) eingeloggt sein, aber so ein User Account habe ich nicht, da bei mir alles auf Englisch läuft.

Habe schnell das internet ausgeschaltet (auch WiFi gekillt und de PC zugemacht. Über den Taskmanager konnte ich noch sehen, dass jede Menge komischer Sachen laufen.

Ich habe noch nie bei Windows 10 Probleme gehabt. Zum Glück habe ich noch einen alten PC. traue mich aber jetzt gar nicht, den befallenen Computer einfach wieder hochzufahren.
Wie gehe ich jetzt am besten vor? Wie kannich die empfohlenen Schritte (systemscann my FRSt, etc.) durchführen, ohne meinen Rechner wieder hochzufahren und online zu gehen? ich bin leider noch ein ziemlicher Windows 10-Newby.

Ich habe ein Lenova Yoga Pro, Windows 10, mit Anniversary Update, ursprünglich mal Windows 8.1.

ch hoffe, es kann mir jemand Helfen.

Vielen Dank im Voraus, Pirisitbulus

cosinus 16.08.2016 07:56

Zitat:

Als ich die Datei mountete
Datei mounten? :wtf:
Was genau hast du da gemacht?
mounten kann man nur Dateisysteme. Oder aber eben Dateien, die als Container dienen und ein filesystem eingebettet haben...das kennt man aber aus der Linux-Welt und nicht von Windows :kaffee:

Ich glaub du meinst: "Als ich die Datei per Doppelklick ausführte..."

Wenn ein Installer aufpoppte hast du tatsächlich kein Worddokument (*.doc) sondern irgendwas Ausfühbares heruntergeladen.


Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)




Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Piristibulus 16.08.2016 08:37

kurze Frage - FRST und online?
 
Lieber Cosinus, vielen Dank,
kurze Frage:

Muss FRSTexe Zugriff auf das Internet haben?
Danke und LG,
Pirisitbulus

cosinus 16.08.2016 08:39

ja, sollte es

Piristibulus 16.08.2016 09:09

FRST Files
 
Beim Scannen konnte ich einige der Malware-Programme erkennen, weil sie shortcuts auf dem Desktop angelegt haben:

PC Spped up
MPC Cleaner

und Max Driver Updater startete.

Außerdem ging ein Fenster auf, das behauptewte Farbar Recovery Scan Tool Nutzer hätten auch weitere Software heruntergeladen... der Defender hat auch sobald die Internetverbindung da war, Alarm geschlagen...

Aber hier die beiden Files.

Code:

Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 15-08-2016 01
durchgeführt von dbirn_000 (16-08-2016 09:44:37)
Gestartet von C:\Users\dbirn_000\Desktop
Windows 10 Home Version 1607 (X64) (2016-08-04 16:16:19)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-528608177-3768278189-544877735-500 - Administrator - Disabled)
dbirn_000 (S-1-5-21-528608177-3768278189-544877735-1001 - Administrator - Enabled) => C:\Users\dbirn_000
DefaultAccount (S-1-5-21-528608177-3768278189-544877735-503 - Limited - Disabled)
Gast (S-1-5-21-528608177-3768278189-544877735-501 - Limited - Disabled)

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Active Directory Authentication Library for SQL Server (Version: 13.0.1601.5 - Microsoft Corporation) Hidden
Active Directory Authentication Library for SQL Server (x86) (x32 Version: 13.0.1601.5 - Microsoft Corporation) Hidden
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.17 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated)
Adobe Digital Editions 4.5 (HKLM-x32\...\Adobe Digital Editions 4.5) (Version: 4.5.1 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.)
Android_Driver (HKLM-x32\...\Android_Driver) (Version: V2.5.0.1 - Android Communication Equipment Co. Ltd.)
Anki (HKLM-x32\...\Anki) (Version:  - )
Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation)
Azure AD Authentication Connected Service (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden
AzureTools.Notifications (x32 Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.)
Benutzerhandbücher (x32 Version: 3.0.0.3 - Lenovo) Hidden
Biblical Hebrew (Tiro) (HKLM\...\{E0793C01-4DBA-4B42-8145-D564303823C0}) (Version: 1.0.3.40 - Tiro Typeworks)
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Body Text Feathering (HKLM-x32\...\PopupProduct) (Version: 1.0.0.0 - Body Text Feathering) <==== ACHTUNG
calibre 64bit (HKLM\...\{32019BE2-E62F-48CF-B274-2521588B83D8}) (Version: 2.54.0 - Kovid Goyal)
Canon Generic PCL6 Driver Uninstaller (HKLM\...\Canon Generic PCL6 Driver) (Version: 6, 3, 0, 0 - Canon Inc.)
CarotDAV (HKLM-x32\...\{14332F8B-A439-4FBF-9931-F54D027141C5}) (Version: 1.12.8 - Rei Software)
CCleaner (HKLM\...\CCleaner) (Version: 5.20 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6229 - CDBurnerXP)
Citavi 5 (Beta) (HKLM-x32\...\{7EB278FB-0C3C-445E-8665-4A6CDD9B794E}) (Version: 5.3.5.1 - Swiss Academic Software)
Compress (HKLM-x32\...\ZipTool) (Version: 1.1.14.18 - ) <==== ACHTUNG
Coptic Unicode (HKLM\...\{2C35A685-D449-4BF0-8592-7CFA4E088906}) (Version: 1.0.3.40 - Center for the Tebtunis Papyri)
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Deutsch (Orientalistik) (HKLM\...\{87F25695-4C02-4CD9-89C8-29D60083E31A}) (Version: 1.0.3.40 - Institut für Iranistik)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Dotfuscator and Analytics Community Edition 5.22.0 (x32 Version: 5.22.0.3788 - PreEmptive Solutions) Hidden
Driver Booster 3.5 (HKLM-x32\...\Driver Booster_is1) (Version: 3.5 - IObit)
Driver Talent (HKLM-x32\...\{29FE44D7-BC89-4188-8B0E-F6BA073C15A5}_is1) (Version: 6.4.47.146 - OSToto Co., Ltd.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 7.4.30 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
EditPad Pro 7 DEMO 7.4.1 (HKLM\...\EditPad Pro 7) (Version: DEMO 7.4.1 - Just Great Software)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.1.51 - Lenovo)
Energy Manager (x32 Version: 1.0.1.51 - Lenovo) Hidden
Entity Framework 6.1.3 Tools  for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation)
Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.4.0 - Seiko Epson Corporation)
Epson Easy Photo Print 2 (HKLM-x32\...\{07AA1C7F-E8CA-4FDC-B975-BC9EBC22B6DE}) (Version: 2.7.0.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM-x32\...\{9F205E94-9E42-4486-A92A-DF3F6CB85444}) (Version: 3.10.0061 - Seiko Epson Corporation)
Epson E-Web Print (HKLM-x32\...\{6BF9F374-EC67-4808-A90C-F127DE6D989D}) (Version: 1.23.0000 - SEIKO EPSON CORPORATION)
Epson Print CD (HKLM-x32\...\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.43.00 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\...\{C7AA3D65-1F84-4590-AFAA-0777A04B6687}) (Version: 4.4.1 - SEIKO EPSON CORPORATION)
EPSON XP-610 Series Printer Uninstall (HKLM\...\EPSON XP-610 Series) (Version:  - SEIKO EPSON Corporation)
EPSON-Handbücher (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.52.0.0 - SEIKO EPSON CORPORATION)
Evernote v. 6.0.6 (HKLM-x32\...\{FC4A0E2E-0CD3-11E6-B80E-005056951CAD}) (Version: 6.0.6.1769 - Evernote Corp.)
Flixster Video (HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\44adf2ca8644bf21) (Version: 2.6.1.520 - Flixster Video)
FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 1.0.1 - )
GitHub (HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\5f7eb300e2ea4ebf) (Version: 3.2.0.0 - GitHub, Inc.)
Google Chrome (HKLM-x32\...\{B9A82C41-4F48-3C15-8A84-1A84582BE03E}) (Version: 52.0.2743.116 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.)
IIS 10.0 Express (HKLM\...\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}) (Version: 10.0.1736 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - )
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
InfraRecorder 0.53 (x64 edition) (HKLM\...\{2C22EA92-CB30-4932-0053-000001000000}) (Version: 0.53.00.00 - Christian Kindahl)
Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden
Intel(R) Driver Update Utility 2.6 (x32 Version: 2.6.0.32 - Intel) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 7.1.0.2103 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4474 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1419.2) (HKLM\...\{302600C1-6BDF-4FD1-1405-148929CC1385}) (Version: 17.0.1405.0464 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\...\{4F4D1244-12E7-4D6C-803D-3B16C13E8912}) (Version: 4.2.41.2633 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{3920BCB0-23AA-4D0D-93E5-404692DAF9D2}) (Version: 19.00.1621.3340 - Intel Corporation)
Intel® Driver Update Utility (HKLM-x32\...\{3e714701-b89c-4cf2-bf3b-41b2c105ffdc}) (Version: 2.6.0.32 - Intel)
Intel® PROSet/Wireless Software (HKLM-x32\...\{bc883058-299e-461f-8e52-4f1dbb355f86}) (Version: 19.0.1 - Intel Corporation)
Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Lenovo Browser Guard (HKLM-x32\...\LenovoBrowserGuard) (Version: 2.14.0.129 - ClientConnect LTD) <==== ACHTUNG
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10240 - Realtek Semiconductor Corp.)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10120.11116 - Realtek Semiconductor Corp.)
Lenovo FusionEngine  (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo Motion Control (HKLM-x32\...\InstallShield_{E9325F15-6339-45E8-9DC4-C2D44B623039}) (Version: 2.5.1.0224 - PointGrab)
Lenovo Motion Control (x32 Version: 2.5.1.0224 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited)
Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.4 - Lenovo)
Lenovo System Interface Foundation (HKLM\...\{C2E5CA37-C862-4A69-AC6D-24F450A20C16}) (Version: 1.0.062.00 - Lenovo)
Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.0.13.12271 - Lenovo)
Lenovo Yoga 2 Demo (HKLM-x32\...\{03C682A4-05CD-4D22-B50A-B9C3C5F2B137}) (Version: 1.0.7 - Lenovo)
Lenovo Yoga PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.1.9.3 - Lenovo)
Lenovo Yoga PhoneCompanion (x32 Version: 1.1.9.3 - Lenovo) Hidden
LibreOffice 5.1.3.2 (HKLM-x32\...\{5F7475A1-6240-4753-BE3E-61499621EC42}) (Version: 5.1.3.2 - The Document Foundation)
Media Go (HKLM-x32\...\{65256C0D-3FE7-4D2E-BB3E-53F1175481C8}) (Version: 3.0.403 - Sony)
Media Go Network Downloader (HKLM-x32\...\{C52148B9-19E0-433A-9422-3451B1BEE20F}) (Version: 1.6.01.0 - Sony)
Media Go Video Playback Engine 2.20.102.05220 (HKLM-x32\...\{1EBB91B3-B277-3438-6125-C1C0281E02C7}) (Version: 2.20.102.05220 - Sony)
Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation)
Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation)
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (Deutsch) (HKLM-x32\...\{529EFF09-750D-48B9-A47A-34A3B6248C3F}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (日本語) (HKLM-x32\...\{9A330858-0CD6-4FB3-8C57-0F1BB58012B0}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (日本語) (HKLM-x32\...\{903C5477-BA28-4CFC-8BE4-62E3C328D4DD}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 365 ProPlus - ar-sa (HKLM\...\O365ProPlusRetail - ar-sa) (Version: 16.0.6741.2056 - Microsoft Corporation)
Microsoft Office 365 ProPlus - de-de (HKLM\...\O365ProPlusRetail - de-de) (Version: 16.0.6741.2056 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.6741.2056 - Microsoft Corporation)
Microsoft Office 365 ProPlus - he-il (HKLM\...\O365ProPlusRetail - he-il) (Version: 16.0.6741.2056 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom  (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service  (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2016 LocalDB  (HKLM\...\{E359515A-92E6-4FA3-A2C9-E1BA02D8DE6E}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft SQL Server 2016 Management Objects  (HKLM-x32\...\{0F1C8E2F-199A-4946-B3BF-0906DACFD032}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft SQL Server 2016 Management Objects  (x64) (HKLM\...\{20EA85AA-2A1D-4F11-B09F-4BA2BF3C8989}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft SQL Server 2016 T-SQL Language Service  (HKLM-x32\...\{8BFDE775-C5B8-46DB-84EF-43FFC8A2E8AD}) (Version: 13.0.14500.10 - Microsoft Corporation)
Microsoft SQL Server 2016 T-SQL ScriptDom  (HKLM\...\{D091DE8C-EA0F-49AF-8DE3-BD6C79737C6E}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (14.0.60519.0) (HKLM-x32\...\{4E27B0EF-7BAB-432A-AF3D-3FC8F3F7353F}) (Version: 14.0.60519.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2016 (HKLM\...\{96EB5054-C775-4BEF-B7B9-AA96A295EDCD}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2016 (HKLM-x32\...\{84C23ECA-FE4D-494F-9247-3EBAD57E7F0C}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio Community 2015 with Updates (HKLM-x32\...\{79b486b9-c5f0-4096-a00c-8351f59587c2}) (Version: 14.0.25420.1 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation)
Mozilla Firefox 48.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 48.0 (x86 en-US)) (Version: 48.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 48.0 - Mozilla)
Mozilla Thunderbird 45.2.0 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 45.2.0 (x86 en-US)) (Version: 45.2.0 - Mozilla)
MSBuild/NuGet Integration 14.0 (x86) (x32 Version: 14.0.25420 - Microsoft Corporation) Hidden
Multi-Device Hybrid Apps using C# - Templates - ENU (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version:  - SEIKO EPSON Corporation)
MyEpson Portal (x32 Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.7 - F.J. Wechselberger)
MySQL Connector C++ 1.1.7 (HKLM\...\{A4310FCD-95D5-49B7-91BA-9A079F07B167}) (Version: 1.1.7 - Oracle and/or its affiliates)
MySQL Connector J (HKLM-x32\...\{BC065B80-343B-44E1-BB8B-A04950CC1284}) (Version: 5.1.39 - Oracle Corporation)
MySQL Connector Net 6.9.8 (HKLM-x32\...\{D01DF7C8-6F2D-46BC-923B-418233EB1D14}) (Version: 6.9.8 - Oracle)
MySQL Connector/C 6.1 (HKLM\...\{ABC3A516-54E3-414B-B501-762E7FB2F9D5}) (Version: 6.1.6 - Oracle Corporation)
MySQL Connector/ODBC 5.3 (HKLM\...\{17E48BE8-F0F8-42B6-82D3-7A5840694D79}) (Version: 5.3.6 - Oracle Corporation)
MySQL Documents 5.7 (HKLM-x32\...\{0644B6AB-5B66-4C4E-8E06-53A53F8C3E51}) (Version: 5.7.13 - Oracle Corporation)
MySQL Examples and Samples 5.7 (HKLM-x32\...\{027883CB-53AB-4470-AC35-B00883E5C1EF}) (Version: 5.7.13 - Oracle Corporation)
MySQL Fabric 1.5.6 & MySQL Utilities 1.5.6 (HKLM-x32\...\{C914EB85-F0E6-4150-9FA0-99B716A15EAF}) (Version: 1.5.6 - Oracle Corporation)
MySQL For Excel 1.3.6 (HKLM-x32\...\{DC8733F3-63A6-43F4-8C38-637071FB6D5F}) (Version: 1.3.6 - Oracle)
MySQL for Visual Studio 1.2.6 (HKLM-x32\...\{D885AD96-9178-4CF2-836C-33AE57A57427}) (Version: 1.2.6 - Oracle)
MySQL Installer - Community (HKLM-x32\...\{C7258570-0186-4AA6-B00E-0B0D405350A7}) (Version: 1.4.16.0 - Oracle Corporation)
MySQL Notifier 1.1.6 (HKLM-x32\...\{CB76A6E9-B184-461D-A8BE-7D0D73199545}) (Version: 1.1.6 - Oracle)
MySQL Server 5.7 (HKLM\...\{0A627D96-1AD0-497A-ACC4-D1A3BA2D328B}) (Version: 5.7.13 - Oracle Corporation)
MySQL Workbench 6.3 CE (HKLM\...\{59958BAC-A61D-4A23-8082-CC2FDF17937F}) (Version: 6.3.6 - Oracle Corporation)
Nitro Pro 9 (HKLM\...\{4C32F7E8-A65F-4D3C-9153-9F3B57CB6872}) (Version: 9.0.5.9 - Nitro)
NWZ-E580 WALKMAN Guide (HKLM-x32\...\{1D6FB94F-E8B4-4CBF-B0FD-D566506CBEF6}) (Version: 2.2.0.05230 - Sony Corporation)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6701.1034 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.6701.1034 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6701.1034 - Microsoft Corporation) Hidden
Oracle VM VirtualBox 5.0.24 (HKLM\...\{BA15D402-19CA-493E-958B-170A0C446F25}) (Version: 5.0.24 - Oracle Corporation)
Paket zur Festlegung von Zielversionen für Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM-x32\...\{4860C1E5-CE58-4D32-89DE-37951333B4C9}) (Version: 4.6.01055 - Microsoft Corporation)
PDF24 Creator 7.6.4 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Pokki (HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Pokki) (Version: 0.269.2.471 - Pokki)
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation)
Prerequisites for SSDT  (HKLM-x32\...\{B7E94916-7AE6-4F7F-A377-7A410A42BA19}) (Version: 13.0.1601.5 - Microsoft Corporation)
Python 3.5.2 (32-bit) (HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\{cf72a2ab-2f1d-49fd-a0d7-1065e6357e1e}) (Version: 3.5.2150.0 - Python Software Foundation)
Python 3.5.2 Add to Path (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Core Interpreter (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Development Libraries (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Documentation (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Executables (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 pip Bootstrap (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Standard Library (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Tcl/Tk Support (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Test Suite (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Utility Scripts (32-bit) (x32 Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{963ECCDD-F09F-4C24-9367-8B5D748AA7C8}) (Version: 3.5.2121.0 - Python Software Foundation)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7058 - Realtek Semiconductor Corp.)
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (x32 Version: 14.0.25424 - Microsoft Corporation) Hidden
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
shamela library (HKLM-x32\...\shamela library2.11) (Version:  - )
Sid Meier's Civilization V (HKLM\...\Steam App 8930) (Version:  - Firaxis Games)
Sid Meier's Civilization V (HKLM-x32\...\steam app 8930) (Version:  - 2K Games, Inc.)
Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.3 - Synaptics Incorporated)
Team Explorer for Microsoft Visual Studio 2015 Update 3 CTP1 (x32 Version: 14.98.25331 - Microsoft) Hidden
Test Tools for Microsoft Visual Studio 2015 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
The SWORD Project (HKLM-x32\...\The SWORD Project) (Version: 1.5.9 - The Crosswire Bible Society)
Thin2000 USB Display Adapter (HKLM\...\{6DB3D05C-C836-444B-8F82-4ABDB8FFC640}) (Version: 1.1.316.0 - Fresco Logic)
trotux - Uninstall (HKLM-x32\...\{76B7B400-5B55-4DF3-BF44-EC2C328A8869}) (Version:  - ) <==== ACHTUNG
TypeScript Power Tool (x32 Version: 1.8.34.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.8.35.0 - Microsoft Corporation) Hidden
UC浏览器 (HKLM-x32\...\UCBrowser) (Version: 5.6.14087.902 - 广州市动景计算机科技有限公司) <==== ACHTUNG
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN)
VS Update core components (x32 Version: 14.0.25424 - Microsoft Corporation) Hidden
vs_update3notification (x32 Version: 14.0.25424 - Microsoft Corporation) Hidden
WCF Data Services 5.6.4 Runtime (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2015 (x32 Version: 5.6.62175.4 - Microsoft Corporation) Hidden
WinDjView 2.1 (HKLM\...\WinDjView) (Version: 2.1 - Andrew Zhezherun)
Windows-Treiberpaket - Lenovo (ACPIVPC) System  (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Xiphos (HKLM-x32\...\Xiphos) (Version:  - )
XMind 7 (Update 1) (v3.6.1) (HKLM-x32\...\XMind_is1) (Version: 3.6.1.201512240104 - XMind Ltd.)
Yoga Picks (HKLM-x32\...\{267C8BA0-876B-4589-9F14-EFB84ABCEA7F}) (Version: 1.5.014.0106 - Lenovo)
Zotero Standalone 4.0.29.10 (x86 en-US) (HKLM-x32\...\Zotero Standalone 4.0.29.10 (x86 en-US)) (Version: 4.0.29.10 - Zotero)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

CustomCLSID: HKU\S-1-5-21-528608177-3768278189-544877735-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\dbirn_000\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileCoAuth.exe (Microsoft Corporation)

==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {018663A7-CC05-410C-A7E4-AD033A9991F2} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-07-22] (Microsoft Corporation)
Task: {03896D04-23AB-4F74-A27D-B1B71EE41E2C} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask => C:\Windows\system32\MDMAgent.exe [2016-07-16] (Microsoft Corporation)
Task: {041E8069-32EA-47AC-8DD8-176688803EF8} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-18] (Dropbox, Inc.)
Task: {0539D606-BE2C-49DB-9D21-91633875603D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-07-13] (Piriform Ltd)
Task: {0A5BAE61-28A6-470A-B80F-3DCEF055AA35} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Keine Datei <==== ACHTUNG
Task: {11B40DDB-CF58-490F-9F8B-FBEA6F836C24} - System32\Tasks\USER_ESRV_SVC_WILLAMETTE => Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\task.vbs"
Task: {16DEA092-FB0C-40D0-AE20-0536BECC21D9} - System32\Tasks\Microsoft\Windows\EDP\EDP App Launch Task
Task: {184784E2-6ACB-4154-BD0F-A955BE13F177} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange
Task: {1B65DD58-D16B-45E8-BEB4-94D7E4D64DF7} - System32\Tasks\Microsoft\Windows\EDP\EDP Auth Task
Task: {1C60935B-E8CD-4D42-9D91-3C8DF17FA26E} - System32\Tasks\{AC26FD83-02AC-48C9-B1EC-943F64688AE4} => Firefox.exe hxxp://ui.skype.com/ui/0/7.18.0.112/ar/abandoninstall?source=lightinstaller&amp;page=tsMain
Task: {291A1459-A3EE-4358-B13A-E4866EAB39F2} - System32\Tasks\GoogleUpdateTaskMachineUA1d0d9f35b7f3b7c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-18] (Google Inc.)
Task: {2A9D94F8-4AFD-4C85-B410-20488D9256F3} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Keine Datei <==== ACHTUNG
Task: {2E15D842-1401-48E0-A922-0CEC5D4C7E9E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-18] (Google Inc.)
Task: {3104FFA1-9D17-4B5D-B8BA-8BC8227A4C0B} - System32\Tasks\MySQLNotifierTask => C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySQLNotifier.exe [2014-09-03] (Oracle Corporation)
Task: {32E2BB15-7753-4297-99C2-7AA0E3D102D7} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => Sc.exe control iMControllerService 128
Task: {34A1438D-E7CC-4782-B0C9-289771B7036B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-07-22] (Microsoft Corporation)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe
Task: {3A873B78-91AD-43A4-AA79-AEED57F466D5} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Keine Datei <==== ACHTUNG
Task: {3BA2F199-83E2-46B0-8EE7-57BEFBF04A94} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-08-10] (Microsoft Corporation)
Task: {3DC70892-029B-44A1-954A-13A6BBBACD0D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Keine Datei <==== ACHTUNG
Task: {3F47B2DE-AC11-4DB7-AF0B-232DAAFFDABD} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-18] (Dropbox, Inc.)
Task: {453260BA-22C0-4E3C-9F39-09B4A1A43EAE} - System32\Tasks\EPSON XP-610 Series Update {FCB9B395-BD41-487E-83F4-E5EDC1023F67} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE [2015-01-18] (SEIKO EPSON CORPORATION)
Task: {477CD3D2-1B1D-46D0-A3DE-69C663A10FD2} - System32\Tasks\EPSON XP-610 Series Invitation {229C7B40-79E8-41C8-8EBE-0DE79613F010} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE [2015-01-18] (SEIKO EPSON CORPORATION)
Task: {4AF0469B-4023-450C-BF6D-D9FD343DA494} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {5BE91AA6-4313-4E4B-9C09-33DBE53D8152} - System32\Tasks\Microsoft\XblGameSave\XblGameSaveTask => C:\Windows\System32\XblGameSaveTask.exe [2016-07-16] (Microsoft Corporation)
Task: {6232090F-3BD0-4E1F-960B-78CBA797F685} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand
Task: {66CF1148-E40D-475E-A1E8-18C82B1F1C5F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Keine Datei <==== ACHTUNG
Task: {6B1AE720-1359-4B9E-9C0F-60167361EF01} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefreshTask
Task: {6E8AE752-C5D2-4B34-B351-338B4370A342} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\HandleCommand
Task: {771AE7F3-5A51-48C1-B495-467EA5FA8AF1} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe <==== ACHTUNG
Task: {79A713CA-CF8B-4660-9306-72F65FC33CB7} - System32\Tasks\MySQL\Installer\ManifestUpdate => c:\program files (x86)\mysql\mysql installer for windows\mysqlinstallerconsole.exe [2016-04-30] (Oracle Corporation)
Task: {7AC5E1E2-2FD3-40CD-8842-88CE53A3609C} - System32\Tasks\Microsoft\Windows\DiskFootprint\StorageSense
Task: {7DBFD2B0-30B0-4BFD-BB43-2CD846CC3E0C} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Keine Datei <==== ACHTUNG
Task: {7E86872C-1FAB-4B36-8352-E081A9A0B548} - System32\Tasks\{2BA78B0B-9FE5-4555-B3DA-63AF616A7EE5} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.18.0.112&amp;LastError=404
Task: {7FAB3871-06DC-4FAF-A6A6-9C8EE3F067C9} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-12] (Adobe Systems Incorporated)
Task: {8403E4CC-6C77-4C2C-A281-C704C8B6357C} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2016-07-28] (IObit)
Task: {870CCEAD-F913-4663-B183-6716D8EB2682} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-07-22] (Microsoft Corporation)
Task: {87153ED0-9FB2-40AE-B481-31FCD962651B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Keine Datei <==== ACHTUNG
Task: {88DFF413-01CA-4354-B4E9-EE2308C061D6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-03] (Microsoft Corporation)
Task: {8E45B6FF-BE20-4EA4-86FF-65D74F4B62B9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Keine Datei <==== ACHTUNG
Task: {94EE7316-F145-4A30-91FD-BA530597F52E} - System32\Tasks\{9D1D3036-8091-4543-A35F-F893AE231A6C} => pcalua.exe -a E:\Poetry.exe -d E:\
Task: {963821EF-879E-4883-8166-54D6696254BA} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo)
Task: {9851188E-AC07-4F36-BA28-6D00BB2C9C46} - System32\Tasks\Microsoft\Windows\Device Information\Device => C:\Windows\system32\devicecensus.exe [2016-07-16] (Microsoft Corporation)
Task: {9918B0E6-7054-41E0-B53B-BA5635D882BF} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_TVSUUpdateTask => reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler  /v start /t reg_dword /d 1 /f /reg:32
Task: {9A0C091B-C443-4878-A3C7-2588EF8D518D} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-06-20] (Microsoft Corporation)
Task: {A40B591A-ACCC-4055-8AEB-737BBF94E9BA} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2016-03-17] (Intel Corporation)
Task: {AE057EA2-5C7A-4DDE-B96A-248E0B024A5C} - System32\Tasks\tasklist => C:\Users\dbirn_000\AppData\Roaming\UPUpdata\service72564.exe [2016-08-15] () <==== ACHTUNG
Task: {B4620CD9-4CA0-443B-86F2-5FCBD8FED7ED} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-03] (Microsoft Corporation)
Task: {B6EE76B2-4F82-4E15-9345-C867A29CBAD0} - System32\Tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask => C:\Windows\system32\speech_onecore\common\SpeechModelDownload.exe [2016-07-16] (Microsoft Corporation)
Task: {C8EA1773-75DB-4731-AB7C-83F4902F5245} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Keine Datei <==== ACHTUNG
Task: {CC636E49-0109-402B-A40B-A37C29069A95} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession
Task: {CD19BC8A-E9FE-49ED-92A5-0E1194F69F00} - System32\Tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon => C:\Windows\System32\XblGameSaveTask.exe [2016-07-16] (Microsoft Corporation)
Task: {D394BE25-2E16-45D4-AAB2-3E8861A09351} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitorToastTask
Task: {D3C4106A-D511-42C6-9716-465644534C87} - System32\Tasks\microsoft\windows\applicationdata\appuriverifierinstall => C:\Windows\system32\AppHostRegistrationVerifier.exe [2016-07-16] (Microsoft Corporation)
Task: {D941F53F-7907-4FBE-B1E7-69EBD5B3A5D8} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange
Task: {E1F750CC-A106-492B-9992-4994AC2D89F3} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Keine Datei <==== ACHTUNG
Task: {E5082108-7C2A-49D7-BE74-290296ED9E8B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Keine Datei <==== ACHTUNG
Task: {E5607DCC-ABA7-4E24-AFC8-ABB754238F94} - System32\Tasks\UCBrowserUpdater => C:\Program Files (x86)\UCBrowser\Application\update_task.exe [2016-08-02] (UCWeb Inc) <==== ACHTUNG
Task: {E91B8136-BE82-42E5-A7D5-0CE39F0495AC} - System32\Tasks\EPSON XP-610 Series Invitation {FCB9B395-BD41-487E-83F4-E5EDC1023F67} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE [2015-01-18] (SEIKO EPSON CORPORATION)
Task: {EA9BAA00-6604-4A27-8A73-AFA65F0EE1B3} - System32\Tasks\Microsoft\Windows\SharedPC\Account Cleanup => Rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
Task: {ECCF9BF3-E2EA-4806-9660-BA462E72D398} - System32\Tasks\Driver Booster SkipUAC (dbirn_000) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2016-07-28] (IObit)
Task: {ECEDC57D-8965-4EB1-BD6F-84791D928E23} - System32\Tasks\microsoft\windows\applicationdata\appuriverifierdaily => C:\Windows\system32\AppHostRegistrationVerifier.exe [2016-07-16] (Microsoft Corporation)
Task: {F21C5111-75BF-4882-AEFA-6491528A6A0B} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Keine Datei <==== ACHTUNG
Task: {F39FE085-86A7-40C4-99F6-A01A093DCDEF} - System32\Tasks\EPSON XP-610 Series Update {229C7B40-79E8-41C8-8EBE-0DE79613F010} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE [2015-01-18] (SEIKO EPSON CORPORATION)
Task: {FD909DAD-F8E9-4B70-96A9-23F77D36402C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-18] (Google Inc.)

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\EPSON XP-610 Series Invitation {229C7B40-79E8-41C8-8EBE-0DE79613F010}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE
Task: C:\WINDOWS\Tasks\EPSON XP-610 Series Invitation {FCB9B395-BD41-487E-83F4-E5EDC1023F67}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE
Task: C:\WINDOWS\Tasks\EPSON XP-610 Series Update {229C7B40-79E8-41C8-8EBE-0DE79613F010}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE:/EXE:{229C7B40-79E8-41C8-8EBE-0DE79613F010} /F:Update WORKGROUP\PIRISTIBULUS$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON XP-610 Series Update {FCB9B395-BD41-487E-83F4-E5EDC1023F67}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_ITSLQE.EXE:/EXE:{FCB9B395-BD41-487E-83F4-E5EDC1023F67} /F:Update WORKGROUP\PIRISTIBULUS$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0d9f35b7f3b7c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\PC SpeedUp Service Deactivator.job => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe <==== ACHTUNG
Task: C:\WINDOWS\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ACHTUNG

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

ShortcutWithArgument: C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://safesurfs.net/?ssid=1471276034&a=1065788&src=sh&uuid=a1be2e46-a3e3-4b5a-93e9-cf969b3c71a6"
ShortcutWithArgument: C:\Users\dbirn_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://safesurfs.net/?ssid=1471276034&a=1065788&src=sh&uuid=a1be2e46-a3e3-4b5a-93e9-cf969b3c71a6"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://safesurfs.net/?ssid=1471276034&a=1065788&src=sh&uuid=a1be2e46-a3e3-4b5a-93e9-cf969b3c71a6"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> "hxxp://safesurfs.net/?ssid=1471276034&a=1065788&src=sh&uuid=a1be2e46-a3e3-4b5a-93e9-cf969b3c71a6"

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2014-09-18 12:06 - 2014-09-18 12:06 - 00034304 _____ () C:\WINDOWS\System32\ssm1mlm.dll
2016-06-30 16:43 - 2016-07-03 07:04 - 00173248 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
2016-08-15 17:52 - 2016-08-15 17:52 - 00244224 _____ () C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\jnsf589C.tmp
2016-05-25 09:33 - 2016-05-25 09:33 - 39702016 _____ () C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe
2016-08-15 17:52 - 2016-08-15 17:52 - 00138240 _____ () C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\hnst6DCB.tmp
2014-12-19 07:09 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2016-08-15 17:05 - 2016-08-15 17:05 - 00270848 _____ () C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\knsr42CF.tmpfs
2016-06-08 18:04 - 2016-06-08 18:04 - 00117400 _____ () C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe
2014-12-19 07:07 - 2014-01-06 16:14 - 00019440 _____ () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
2016-08-15 18:12 - 2016-08-02 08:39 - 00899984 _____ () C:\Program Files (x86)\UCBrowser\Application\UCService.exe
2014-12-19 07:09 - 2014-12-19 07:09 - 00062224 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
2016-06-12 16:50 - 2016-07-14 05:33 - 00401896 _____ () C:\WINDOWS\system32\igfxTray.exe
2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-08-04 18:26 - 2016-08-04 18:26 - 00959168 _____ () C:\Users\dbirn_000\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\ClientTelemetry.dll
2016-06-30 20:15 - 2016-07-03 16:14 - 08919232 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2016-08-15 18:17 - 2015-11-30 12:17 - 00165792 _____ () C:\Program Files\ZipTool\JZipExt.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00130048 _____ () C:\WINDOWS\SYSTEM32\CHARTV.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-08-10 13:33 - 2016-08-02 10:15 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-08-10 13:34 - 2016-08-02 10:01 - 09761280 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-08-10 13:34 - 2016-08-02 09:53 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-08-10 13:34 - 2016-08-02 09:53 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-08-10 13:34 - 2016-08-02 09:54 - 02438144 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-08-10 13:34 - 2016-08-02 09:56 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-08-13 12:54 - 2016-08-13 12:55 - 00071168 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2016-08-13 12:54 - 2016-08-13 12:55 - 00178176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2016-08-13 12:54 - 2016-08-13 12:55 - 35290624 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2016-08-15 17:57 - 2016-08-15 17:57 - 01831424 _____ () C:\Users\dbirn_000\AppData\Roaming\UPUpdata\service72564.exe
2014-12-19 07:09 - 2014-12-19 07:09 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
2014-12-19 07:09 - 2014-12-19 07:09 - 00108304 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
2015-12-07 10:15 - 2015-12-07 10:15 - 00419328 _____ () C:\Windows\System32\flvga_tray.exe
2016-07-08 17:07 - 2016-06-08 18:07 - 00458904 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv.exe
2016-07-08 17:07 - 2016-06-08 18:18 - 00709272 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_modeler.dll
2016-07-08 17:07 - 2016-06-08 18:17 - 00188568 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\foreground_window_input.dll
2016-07-08 17:07 - 2016-06-08 18:12 - 00416408 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
2016-07-08 17:07 - 2016-06-08 18:15 - 00130712 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_process_input.dll
2016-07-08 17:07 - 2016-06-08 18:16 - 00025752 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_system_power_state_input.dll
2016-07-08 17:07 - 2016-06-08 18:16 - 00059544 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_quality_and_reliability_input.dll
2016-07-08 17:07 - 2016-06-08 18:16 - 00194712 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\acpi_battery_input.dll
2016-07-08 17:07 - 2016-06-08 18:17 - 00159896 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\sema_thermal_input.dll
2016-07-08 17:07 - 2016-06-08 18:17 - 00158360 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\wifi_input.dll
2016-07-08 17:07 - 2016-06-08 18:16 - 00050840 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\devices_use_input.dll
2016-07-08 17:07 - 2016-06-08 18:15 - 00032920 _____ () C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\intel_disktrace_input.dll
2016-08-15 18:12 - 2016-08-02 08:39 - 02093968 _____ () C:\Program Files (x86)\UCBrowser\Application\5.6.14087.902\UCAgent.exe
2014-12-19 07:09 - 2014-12-19 07:09 - 00161792 _____ () C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
2016-08-15 17:06 - 2016-08-15 17:06 - 00334336 _____ () C:\Users\dbirn_000\AppData\Local\Temp\nsj79A8.tmp
2016-08-16 09:42 - 2016-08-16 09:42 - 00706048 _____ () C:\Users\dbirn_000\AppData\Local\Temp\is-RA0ET.tmp\8DBF.tmp
2016-08-16 09:42 - 2016-08-16 09:42 - 00888320 _____ () C:\Users\dbirn_000\AppData\Local\Temp\is-607HM.tmp\setup.exe
2016-08-16 09:42 - 2016-08-16 09:43 - 00080466 _____ () C:\WINDOWS\Temp\8DAE.tmp
2016-08-16 09:42 - 2016-08-16 09:43 - 01650176 _____ () C:\WINDOWS\Temp\8DC0.tmp
2015-12-26 10:59 - 2015-12-26 10:59 - 00158720 _____ () C:\Users\dbirn_000\AppData\Local\04905D8E-1471340577-11E4-B57F-68F7284155E1\qnsvAF9F.tmp
2016-07-21 09:30 - 2016-07-21 09:30 - 00239016 _____ () c:\program files (x86)\ludashi\lpi\hpsvc.dll
2016-08-05 01:08 - 2016-07-28 10:22 - 00172200 _____ () c:\program files (x86)\ostotosoft\drivertalent\ldrvsvc.dll
2016-08-05 01:08 - 2016-07-28 10:21 - 00186640 _____ () c:\program files (x86)\ostotosoft\drivertalent\CrashCatch.dll
2016-08-05 01:08 - 2016-07-28 10:22 - 00254824 _____ () c:\program files (x86)\ostotosoft\drivertalent\updater\checkupdate.dll
2016-08-05 01:08 - 2016-07-28 10:22 - 00174760 _____ () c:\program files (x86)\ostotosoft\drivertalent\substat.dll
2016-08-05 01:08 - 2016-07-28 10:22 - 00103776 _____ () c:\program files (x86)\ostotosoft\drivertalent\dstudp.dll
2016-08-05 01:08 - 2016-07-28 10:22 - 00117088 _____ () c:\program files (x86)\ostotosoft\drivertalent\udp.dll
2016-08-15 18:17 - 2015-11-30 12:16 - 00114080 _____ () c:\program files\ziptool\ziphost.dll
2016-08-15 18:17 - 2015-11-30 12:17 - 00085920 _____ () c:\program files\ziptool\ZipUpdater\ZipUpdate.dll
2016-08-15 18:16 - 2015-11-30 12:15 - 00261536 _____ () c:\program files\ziptool\CheckUpdate.dll
2016-08-15 18:17 - 2015-11-30 12:17 - 00084384 _____ () c:\program files\ziptool\ZipSubmit\ZipSubmit.dll
2016-08-15 18:17 - 2015-11-30 12:15 - 00164768 _____ () c:\program files\ziptool\substat.dll
2016-08-15 18:17 - 2015-11-30 12:16 - 00095648 _____ () c:\program files\ziptool\ZipPlug.dll
2016-08-15 18:17 - 2015-11-30 12:16 - 00164256 _____ () c:\program files\ziptool\wchsubstat.dll
2016-08-15 18:17 - 2015-11-30 12:15 - 00244640 _____ () c:\program files\ziptool\tipsdll.dll
2014-02-24 17:39 - 2014-02-24 17:39 - 00013576 _____ () C:\Program Files (x86)\Lenovo\Motion Control\PointGrabDeviceAPI.dll
2014-12-19 07:09 - 2014-12-19 07:09 - 00102672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\3200\TransitionLib.dll
2014-12-19 07:09 - 2014-12-19 07:09 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
2016-08-04 18:25 - 2016-08-04 18:25 - 00679624 _____ () C:\Users\dbirn_000\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\ClientTelemetry.dll
2016-04-27 18:48 - 2016-04-27 18:48 - 00439480 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
2016-04-27 18:48 - 2016-04-27 18:48 - 00321208 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
2015-08-18 20:46 - 2013-08-05 09:49 - 00627672 _____ () C:\Program Files (x86)\Cyberlink\Power2Go8\CLMediaLibrary.dll
2013-08-05 15:48 - 2013-08-05 15:48 - 00016856 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2016-01-14 00:40 - 2016-06-30 04:25 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2016-08-07 22:08 - 2016-06-30 04:25 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2016-08-07 22:08 - 2016-06-30 04:26 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2016-08-07 22:08 - 2016-06-30 04:25 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-01-14 00:40 - 2016-06-30 04:25 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2016-01-14 00:40 - 2016-06-30 04:25 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-01-14 00:40 - 2016-08-01 23:27 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2016-01-14 00:40 - 2016-06-30 04:25 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2016-08-07 22:08 - 2016-08-01 23:26 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2016-01-14 00:40 - 2016-06-30 04:26 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2016-08-07 22:08 - 2016-08-01 23:26 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2016-08-07 22:08 - 2016-08-01 23:26 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00021312 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-08-07 22:08 - 2016-06-30 04:25 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2016-08-07 22:08 - 2016-06-30 04:27 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-01-14 00:40 - 2016-08-01 23:27 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00025424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2016-08-07 22:08 - 2016-08-01 23:26 - 00246592 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2016-02-12 18:23 - 2016-08-01 23:27 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-02-12 18:23 - 2016-08-01 23:27 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
2016-02-12 18:23 - 2016-08-01 23:27 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
2016-01-14 00:40 - 2016-06-30 04:25 - 00144848 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
2016-08-07 22:08 - 2016-06-30 04:26 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd
2016-08-07 22:08 - 2016-08-01 23:26 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-01-14 00:40 - 2016-08-01 23:27 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-02-12 18:23 - 2016-08-01 23:27 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2016-08-07 22:08 - 2016-06-30 04:28 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2016-08-07 22:08 - 2016-08-01 23:27 - 00031568 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd
2016-08-07 22:08 - 2016-08-01 23:17 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2016-08-07 22:08 - 2016-08-01 23:27 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-08-07 22:08 - 2016-08-01 23:27 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-01-14 00:40 - 2016-06-30 04:26 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 03929392 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 01972016 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00224056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00020288 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32._winffi_user32.pyd
2016-01-14 00:40 - 2016-06-30 04:27 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2016-04-17 18:25 - 2016-08-01 23:27 - 00037192 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00168248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2016-08-07 22:08 - 2016-08-01 23:27 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2016-04-01 13:03 - 2016-02-19 10:42 - 00074272 _____ () C:\Program Files (x86)\PDF24\zlib.dll
2016-04-01 13:03 - 2016-02-19 10:42 - 00052256 _____ () C:\Program Files (x86)\PDF24\OperationUI.dll
2014-12-19 06:43 - 2013-08-08 22:25 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)


==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\sharepoint.com -> hxxps://goetheuniversitaet-files.sharepoint.com

==================== Hosts Inhalt: ==========================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2013-08-22 15:25 - 2016-08-15 17:48 - 00001006 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1      down.baidu2016.com
127.0.0.1      123.sogou.com
127.0.0.1      www.czzsyzgm.com
127.0.0.1      www.czzsyzxl.com
127.0.0.1      union.baidu2019.com

==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-528608177-3768278189-544877735-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\theme1\img1.jpg
DNS Servers: 192.168.178.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\StartupApproved\Run: => "Skype"

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [WirelessDisplay-Infra-In-TCP] => (Allow) %systemroot%\system32\CastSrv.exe
FirewallRules: [{4DB224A3-94E3-453A-A030-08D3FF9D15A8}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{80EED59F-E13A-47A1-AECF-D478587CF409}] => (Allow) LPort=3306
FirewallRules: [{DAE11010-5EA0-4A2A-A6F1-D6CB7E0D5425}] => (Allow) LPort=3306
FirewallRules: [{656A5292-5631-472E-A271-6A3A49ACC59C}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
FirewallRules: [{AA32AE9C-CE27-4C61-87B8-BB407CBDD900}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{A43FE604-02BD-4FFB-9577-66CAADDCBF19}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{840EDD12-1209-49E6-8555-844E48EE0122}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{5E1A218A-635B-4CB8-AF9B-1C6F253518E6}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{0F0123B9-6FAD-48AC-9F0E-A23833D214D1}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{A64CEE23-10F8-43F4-B227-D6809588E046}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{BCFDAC2F-B443-4D1E-AE6E-9AD1E561216B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [UDP Query User{5D4DEA57-A561-43CC-80D3-9C3E1B2154D5}C:\program files (x86)\lenovo\shareit\shareit.exe] => (Allow) C:\program files (x86)\lenovo\shareit\shareit.exe
FirewallRules: [TCP Query User{2909C1B9-AE63-4459-81D9-37A76796D390}C:\program files (x86)\lenovo\shareit\shareit.exe] => (Allow) C:\program files (x86)\lenovo\shareit\shareit.exe
FirewallRules: [{004A748F-1D35-4697-8341-1A8296E08B96}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
FirewallRules: [{0790CD0D-1A8B-4C76-AF8F-4C8ABFB56110}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
FirewallRules: [UDP Query User{A7E7B1B1-2E13-481D-9782-471C94577532}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe
FirewallRules: [TCP Query User{64BD4B83-408C-40DF-B964-9F1B71995FF4}C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe] => (Allow) C:\program files (x86)\myphoneexplorer\myphoneexplorer.exe
FirewallRules: [{086E4D84-BC53-4890-A727-E841FE7258C6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe
FirewallRules: [{1210F36E-F578-4E77-816D-1F57D96F1004}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe
FirewallRules: [{BFABB84B-D4E8-4312-8299-E2AB2DBC2610}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe
FirewallRules: [{338FF24D-830C-461C-8F8A-DED2923F2099}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe
FirewallRules: [{3EDF574D-188C-4225-B9FD-542C16808735}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
FirewallRules: [{91DC4D1B-B48B-4669-9183-D862D6D85CDB}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
FirewallRules: [UDP Query User{BB0A5AA7-F6C7-4C2B-97B4-3D9072AD36E5}C:\program files (x86)\crosswire\xiphos\bin\xiphos.exe] => (Allow) C:\program files (x86)\crosswire\xiphos\bin\xiphos.exe
FirewallRules: [TCP Query User{4AC1D5B9-AB64-41E7-947C-7B0055FF09A1}C:\program files (x86)\crosswire\xiphos\bin\xiphos.exe] => (Allow) C:\program files (x86)\crosswire\xiphos\bin\xiphos.exe
FirewallRules: [UDP Query User{5C5FEC34-6A84-4807-A11C-DDE79DDEA4DC}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{B9C5DA54-9269-4377-B07B-AE65E86213AB}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [{7F4FD72C-5F76-4CFC-A90E-F376FBB3B58D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{07A05875-430C-4432-8E83-834EACB94B03}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{34FD207F-BA00-4600-BA2F-4CA52EA73B6B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{20835D07-81A3-46D8-8443-97A89FDBAB98}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [UDP Query User{56C81FA7-6C8D-4B73-B369-16BC4677F51A}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{B61A2A74-05CD-472D-BD6A-85296E7AA534}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{65322B39-634B-4EBD-BA63-E3DA99602DBD}C:\program files (x86)\ostotosoft\drivertalent\drivertalent.exe] => (Allow) C:\program files (x86)\ostotosoft\drivertalent\drivertalent.exe
FirewallRules: [UDP Query User{9BF5EF60-7D04-4BDC-AB09-37CC1C596EB7}C:\program files (x86)\ostotosoft\drivertalent\drivertalent.exe] => (Allow) C:\program files (x86)\ostotosoft\drivertalent\drivertalent.exe
FirewallRules: [{ECE4BD84-2DE9-43AA-8D19-BEC758D272BF}] => (Allow) C:\Program Files (x86)\OSTotoSoft\DriverTalent\DriverTalent.exe
FirewallRules: [{335BEBE3-06CB-421A-AE74-ECD98C8DDE12}] => (Allow) C:\Program Files (x86)\OSTotoSoft\DriverTalent\DTLService.exe
FirewallRules: [{689C82C1-BE66-4285-B4DA-67D21CBAAA56}] => (Allow) C:\Program Files (x86)\OSTotoSoft\DriverTalent\download\MiniThunderPlatform.exe
FirewallRules: [{F7BB30B3-87F0-4883-ABD0-65DD473CF736}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{15D3B083-E3F7-4168-9CD9-968DAD58E56D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{E6356DD8-3DE7-4E83-AF20-481E8AAEFE1E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{32C62DEB-73FD-4F07-8A91-27782F3FBA40}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C29AC9C7-445B-43A6-A322-D291600B47A1}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{D364888D-ADC1-4891-9C7F-1D3DBE3D2F04}] => (Allow) C:\Users\dbirn_000\AppData\Local\Temp\30569\inst_buychannel_37.exe
FirewallRules: [{782312C8-40BD-4927-8E2A-82BC623CC77D}] => (Allow) C:\Users\dbirn_000\AppData\Local\Temp\30569\inst_buychannel_37.exe
FirewallRules: [{A4314284-1E40-4749-AED6-51DA0AB28BFD}] => (Allow) C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
FirewallRules: [{845A04E6-EF74-4B93-A4DD-31116D5A7FB8}] => (Allow) C:\Program Files (x86)\UCBrowser\Application\Downloader\download\MiniThunderPlatform.exe
FirewallRules: [{6CAA563F-16C8-4D1E-B4C7-7CBEACBD1972}] => (Allow) C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
FirewallRules: [{599935BE-E5F9-4B10-B0B6-A0F1FF94CF67}] => (Allow) C:\Program Files (x86)\LuDaShi\ComputerZTray.exe
FirewallRules: [{E1FE44A8-F718-4536-A1F0-33825635DCF6}] => (Allow) C:\Program Files (x86)\LuDaShi\ComputerZTray.exe
FirewallRules: [{8D4AD8D2-E1DF-4F40-9B29-F4E596D6F830}] => (Allow) C:\Program Files (x86)\LuDaShi\Utils\mininews.exe
FirewallRules: [{DEC0C474-86A0-49C7-BDEE-77EA13BD5F02}] => (Allow) C:\Program Files (x86)\LuDaShi\Utils\mininews.exe

==================== Wiederherstellungspunkte =========================

09-08-2016 18:39:36 Installed Evernote v. 6.0.6
11-08-2016 21:08:12 Windows Modules Installer

==================== Fehlerhafte Geräte im Gerätemanager =============


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (08/16/2016 09:37:32 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PIRISTIBULUS)
Description: Activation of application Weather.TheWeatherChannelforLenovo_t3yemqpq4kp7p!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (08/16/2016 09:22:32 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PIRISTIBULUS)
Description: Activation of application Weather.TheWeatherChannelforLenovo_t3yemqpq4kp7p!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (08/16/2016 09:09:50 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PIRISTIBULUS)
Description: Activation of application Weather.TheWeatherChannelforLenovo_t3yemqpq4kp7p!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (08/16/2016 09:07:38 AM) (Source: DptfEvent) (EventID: 1) (User: )
Description: DptfPolicyConfigTDPService
ServiceMainThread:  NotifyServiceStatusRunning() failed.

Error: (08/16/2016 09:07:38 AM) (Source: DptfEvent) (EventID: 2) (User: )
Description: DptfPolicyConfigTDPService
NotifyServiceStatusRunning:  DeviceIoControl() failed.
Last error = [0x0000001f]

Error: (08/16/2016 09:07:35 AM) (Source: DptfEvent) (EventID: 1) (User: )
Description: DptfProcessorParticipantService
ServiceMain:  ServiceStart() failed.

Error: (08/16/2016 09:07:35 AM) (Source: DptfEvent) (EventID: 1) (User: )
Description: DptfProcessorParticipantService
ServiceStart:  ConnectToDptfProcessorDriver() failed.

Error: (08/16/2016 09:07:35 AM) (Source: DptfEvent) (EventID: 2) (User: )
Description: DptfProcessorParticipantService
ConnectToDptfProcessorDriver:  SetupDiEnumDeviceInterfaces() failed.
Last error = [0x00000103]

Error: (08/15/2016 09:10:40 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PIRISTIBULUS)
Description: Activation of application Weather.TheWeatherChannelforLenovo_t3yemqpq4kp7p!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (08/15/2016 08:55:39 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PIRISTIBULUS)
Description: Activation of application Weather.TheWeatherChannelforLenovo_t3yemqpq4kp7p!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.


Systemfehler:
=============
Error: (08/16/2016 09:07:48 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

Error: (08/16/2016 09:07:48 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

Error: (08/16/2016 09:07:47 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}{F72671A9-012C-4725-9D2F-2A4D32D65169}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

Error: (08/16/2016 09:07:34 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SCService service failed to start due to the following error:
%%2 = The system cannot find the file specified.

Error: (08/16/2016 09:07:33 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The PCSUService service failed to start due to the following error:
%%2 = The system cannot find the file specified.

Error: (08/15/2016 06:20:28 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

Error: (08/15/2016 06:05:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Double Spaced Firewall service terminated unexpectedly. It has done this 1 time(s).

Error: (08/15/2016 06:02:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Document Portal service terminated unexpectedly. It has done this 1 time(s).

Error: (08/15/2016 06:01:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) HD Graphics Control Panel Service service terminated unexpectedly. It has done this 1 time(s).

Error: (08/15/2016 05:57:59 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The MPC Core Protect Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.


CodeIntegrity:
===================================
  Date: 2016-08-16 09:44:18.182
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:44:18.175
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:44:18.157
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:11:58.102
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:11:58.090
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:11:58.074
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:10:04.115
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:10:04.104
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:10:04.063
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-08-16 09:07:32.159
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\wininit.exe) attempted to load \Device\HarddiskVolume5\Windows\System32\dtsch-or.dll that did not meet the Windows signing level requirements.


==================== Speicherinformationen ===========================

Prozessor: Intel(R) Core(TM) i7-4510U CPU @ 2.00GHz
Prozentuale Nutzung des RAM: 42%
Installierter physikalischer RAM: 8104.27 MB
Verfügbarer physikalischer RAM: 4629.49 MB
Summe virtueller Speicher: 16808.27 MB
Verfügbarer virtueller Speicher: 13170.57 MB

==================== Laufwerke ================================

Drive c: (Windows8_OS) (Fixed) (Total:435.25 GB) (Free:154.63 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.56 GB) NTFS
Drive e: (RECOVERY) (Removable) (Total:0.93 GB) (Free:0.93 GB) FAT32

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: BCEDD300)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 960 MB) (Disk ID: 75CB61DA)
Partition 1: (Active) - (Size=960 MB) - (Type=0C)

==================== Ende von Addition.txt ============================

FRST.txt ist ca. 4500 Zeichen zu groß. Soll ich es aufspalten?

Piristibulus 16.08.2016 09:19

FRST.txt Teil 1:

Code:

Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 15-08-2016 01
durchgeführt von dbirn_000 (Administrator) auf PIRISTIBULUS (16-08-2016 09:43:16)
Gestartet von C:\Users\dbirn_000\Desktop
Geladene Profile: dbirn_000 (Verfügbare Profile: dbirn_000)
Platform: Windows 10 Home Version 1607 (X64) Sprache: German (Germany)
Internet Explorer Version 11 (Standard-Browser: "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe" -- "%1")
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(CANON INC.) C:\Program Files\Canon\DIAS\CnxDIAS.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(OSBASE) C:\Windows\System32\ddmgr.exe
() C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\jnsf589C.tmp
(Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Lenovo Group Limited) C:\Program Files\lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
() C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\hnst6DCB.tmp
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\knsr42CF.tmpfs
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
() C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe
() C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
() C:\Program Files (x86)\UCBrowser\Application\UCService.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON\MyEpson Portal\mep.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCTray.exe
(DotC United Inc) C:\Program Files (x86)\MPC Cleaner\MPCTray64.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c\SkypeHost.exe
() C:\Users\dbirn_000\AppData\Roaming\UPUpdata\service72564.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
() C:\Windows\System32\flvga_tray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle Corporation) C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySQLNotifier.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(CyberLink) C:\Program Files (x86)\Cyberlink\Power2Go8\CLMLSvc_P2G8.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
() C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(ClientConnect LTD) C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\CltMngSvc.exe
() C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Program Files (x86)\UCBrowser\Application\5.6.14087.902\UCAgent.exe
(Lenovo Group Limited) C:\Program Files\lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.exe
(Lenovo Group Limited) C:\Program Files\lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.exe
() C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11607.1001.32.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Users\dbirn_000\AppData\Local\Temp\nsj79A8.tmp
(                                                            ) C:\Windows\Temp\8DBF.tmp
() C:\Users\dbirn_000\AppData\Local\Temp\is-RA0ET.tmp\8DBF.tmp
() C:\Users\dbirn_000\AppData\Local\Temp\is-607HM.tmp\setup.exe
(oET3UIo) C:\Program Files (x86)\mpck\otutnetwork.exe
(mobilepcstarterkit                                          ) C:\Users\dbirn_000\AppData\Local\Temp\XDYY1Y9Z8P.exe
() C:\Users\dbirn_000\AppData\Local\Temp\is-02OPB.tmp\XDYY1Y9Z8P.tmp
() C:\Windows\Temp\8DAE.tmp
() C:\Windows\Temp\8DC0.tmp
() C:\Users\dbirn_000\AppData\Local\04905D8E-1471340577-11E4-B57F-68F7284155E1\qnsvAF9F.tmp


==================== Registry (Nicht auf der Ausnahmeliste) ===========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-08-02] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13656792 2013-10-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432 2013-09-26] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6340312 2013-07-19] (Realtek semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-12-19] (Lenovo)
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-12-19] ()
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [59923440 2014-12-19] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-12-19] (Lenovo(beijing) Limited)
HKLM\...\Run: [flvga_tray64] => C:\WINDOWS\system32\flvga_tray.exe [419328 2015-12-07] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-01-07] (Adobe Systems Incorporated)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3934720 2016-04-30] (Synaptics Incorporated)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-07-16] (Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [SpaceSoundPro] => "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe"
HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-06] (Lenovo)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Cyberlink\Power2Go8\CLMLSvc_P2G8.exe [111576 2013-08-05] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [490760 2013-10-07] (CyberLink Corp.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [23546672 2016-08-01] (Dropbox, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [213536 2016-02-19] (Geek Software GmbH)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3498720 2016-06-23] (Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM\...\RunOnce: [OTUTPRODUCT_B64AS] => C:\Program Files (x86)\mpck\otutnetwork.exe [436736 2016-08-16] (oET3UIo)
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Run: [Power2GoExpress8] => 0
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [2851408 2016-07-09] (Valve Corporation)
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8891608 2016-07-13] (Piriform Ltd)
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Run: [MySQL Notifier] => C:\Program Files (x86)\MySQL\MySQL Notifier 1.1\MySqlNotifier.exe [773120 2014-09-03] (Oracle Corporation)
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29502592 2016-07-14] (Skype Technologies S.A.)
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Run: [PCSpeedUp] => C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Run: [QGuan10in1] => C:\Users\dbirn_000\AppData\Roaming\UPUpdata\service72564.exe [1831424 2016-08-15] ()
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\Run: [ComputerZ-Tray] => C:\Program Files (x86)\LuDaShi\ComputerZTray.exe [2949032 2016-07-21] ()
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\MountPoints2: {42c56f07-5a60-11e6-82d2-28b2bde3bab5} - "F:\Auto.exe"
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\MountPoints2: {42c56f63-5a60-11e6-82d2-28b2bde3bab5} - "F:\Auto.exe"
HKU\S-1-5-21-528608177-3768278189-544877735-1001\...\MountPoints2: {71511bf0-58b1-11e6-82d1-28b2bde3bab5} - "F:\Auto.exe"
AppInit_DLLs: C:\PROGRA~2\LENOVO~1\LENOVO~1\bin\SPVC64~1.DLL => C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64Loader.dll [206152 2014-05-12] (ClientConnect LTD)
AppInit_DLLs-x32: C:\PROGRA~2\LENOVO~1\LENOVO~1\bin\SPVC32~1.DLL => C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll [173896 2014-05-12] (ClientConnect LTD)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [JzShlobj] -> {7B286609-DA97-47E1-AC6B-33B8B4732C95} => C:\Program Files\ZipTool\JZipExt.dll [2015-11-30] ()
ShellIconOverlayIdentifiers: [MyOverlayIcon] -> {B41B3408-923F-4B8B-85F2-146C509FA18C} => C:\Program Files (x86)\Wivotain\Jzidom\Arlyanafu.dll Keine Datei
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.38.dll [2016-08-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
Startup: C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2016-08-09]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2016-08-12]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

AutoConfigURL: [S-1-5-21-528608177-3768278189-544877735-1001] => hxxp://stoppblock.org/wpad.dat?207b35475f43c97b15e20097d83e76ef14487478
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{01b2b75e-ab82-46d7-a263-47201a5fd4c1}: [DhcpNameServer] 150.201.1.2
Tcpip\..\Interfaces\{64b1ba4c-1a6f-4f06-b6da-75db365bd513}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{cff56bc8-b1cc-49de-b274-e4ff70e674f4}: [NameServer] 141.2.22.74,141.2.149.10
ManualProxies: 0hxxp://stoppblock.org/wpad.dat?207b35475f43c97b15e20097d83e76ef14487478

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-528608177-3768278189-544877735-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-528608177-3768278189-544877735-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-528608177-3768278189-544877735-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-528608177-3768278189-544877735-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-04] (Microsoft Corporation)
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\system32\mscoree.dll [2016-07-16] (Microsoft Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (Seiko Epson Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2016-04-23] (Adobe Systems Incorporated)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-03] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2016-04-23] (Adobe Systems Incorporated)
BHO-x32: Kein Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> Keine Datei
BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-04] (Microsoft Corporation)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\WINDOWS\system32\mscoree.dll [2016-07-16] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-28] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2016-04-27] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2016-04-23] (Adobe Systems Incorporated)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-03] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-28] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2016-04-23] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2016-04-23] (Adobe Systems Incorporated)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (Seiko Epson Corporation)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2016-04-23] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-03] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-03] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-03] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-03] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default
FF Homepage: hxxps://wiki.de.dariah.eu/display/TextGrid/Download
hxxps://de.dariah.eu/fachwissenschaftliche-dienste
hxxps://textgrid.de/download
hxxp://www.creativebloq.com/wireframes/top-wireframing-tools-11121302
hxxps://moqups.com/
hxxps://wiki.de.dariah.eu/display/publicde/Cluster+6%3A+Annotieren%2C+analysieren%2C+visualisieren
hxxps://de.dariah.eu/fellowshipprogramm
hxxp://www.rehaverein-schwanheim.de/kurszeiten.html
hxxps://islamichumanities.org/resources/
hxxp://www.culingtec.uni-leipzig.de/ESU_C_T/node/718
hxxps://www.leihwagenversicherung.de/mietwagen-versicherungspakete.html
hxxps://www.microsoft.com/en-us/windows/features
hxxps://www.bkk-mobil-oil.de/gesundheit/gesund-leben/reisen/vor-der-reise.html
hxxp://www.iobit.com/en/install/db/?name=db&ver=3.5.0.788&lan=&to=install
hxxps://islaamiclibrary.wordpress.com/2009/03/01/thecomprehensivelibrary/
hxxp://onlinelibrary.wiley.com/doi/10.1111/1467-9809.12383/full
hxxps://evernote.com/logged-out/?var=collect&logout&uid=64732601
hxxp://search.proquest.com/docview/301390299
hxxp://www.icn.uni-hamburg.de/narrbib/wissenschaftstheorie-hermeneutik-literaturwissenschaft-anmerkungen-zu-einem-unterbliebenen
hxxps://www.zotero.org/
hxxps://www.academia.edu/
hxxp://www.nltk.org/
hxxp://nealcaren.web.unc.edu/an-introduction-to-text-analysis-with-python-part-1/
hxxps://digitalresearchtools.pbworks.com/w/page/17801682/Linguistic%20Tools
hxxp://www.nltk.org/book/ch01.html
hxxp://omz-software.com/pythonista/docs/ios/linguistictagger.html
hxxps://github.com/maximromanov/mARkdown
hxxp://iti-corpus.github.io/
hxxps://www.google.de/search?q=%22troubleshooting+history+is+taking+up+disk+space%22&ie=utf-8&oe=utf-8&client=firefox-b&gfe_rd=cr&ei=MZmvV8qaLKje8gexxJfwBQ#q=%22troubleshooting+history+is+taking+up+disk+space%22+windows+10
hxxp://www.deutschlandradiokultur.de/sein-und-streit-ganze-sendung-was-laesst-sich.2162.de.html?dram%3Aarticle_id=363052
hxxps://www.academia.edu/27712290/%D7%9E%D7%91%D7%A0%D7%94_%D7%9E%D7%A0%D7%94%D7%9C%D7%99_%D7%9E%D7%AA%D7%A7%D7%95%D7%A4%D7%AA_%D7%94%D7%91%D7%A8%D7%96%D7%9C_%D7%91_%D7%91%D7%A2%D7%99%D7%A8_%D7%93%D7%95%D7%93
hxxps://www.microsoft.com/security/scanner/en-us/default.aspx
hxxp://wikitravel.org/en/Okinawa
hxxp://www.huji.ac.il/dataj/controller/ihoker/MOP-STAFF_LINK?sno=360297&Save_t=
hxxps://www.google.de/search?q=language+bar+hotkeys+always+get+changed+windows+10&ie=utf-8&oe=utf-8&client=firefox-b&gfe_rd=cr&ei=cLmwV7-tJMGo8wfDx4yAAQ#q=%22language+hotkeys%22+keep+changing+windows+10
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-07-29] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1224194.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-03] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-07-03] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-07-29] (Adobe Systems)
FF Plugin HKU\S-1-5-21-528608177-3768278189-544877735-1001: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2015-11-20] (Sony Network Entertainment International LLC)
FF user.js: detected! => C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\user.js [2016-06-08]
FF Extension: Youtube Converter MP3 - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\extensions\{a3a5c777-f583-4fef-9380-ab4add1bc2a5}.xpi [2016-03-15]
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\extensions\2020Player_IKEA@2020Technologies.com [2016-05-24]
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2016-07-13]
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2016-08-08] [ist nicht signiert]
FF Extension: MEGA - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\Extensions\firefox@mega.co.nz.xpi [2016-08-03]
FF Extension: Alpheios Greek Tools - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\Extensions\{0f1d7e06-6ce8-40b0-83f0-9783ee65ab9b} [2016-07-10]
FF Extension: Alpheios Basic Libraries - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\Extensions\{4816253c-3208-49d8-9557-0745a5508299} [2016-07-10]
FF Extension: Yahoo! Toolbar - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2016-06-09] [ist nicht signiert]
FF Extension: Alpheios Latin Tools - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\Extensions\{7dd2b42f-3db8-4833-88c4-5a9e3788017b} [2016-07-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2016-03-21]
FF Extension: web Service Pro - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\Extensions\{c28656bf-0652-430c-86ad-2902a3fa6a79}.xpi [2016-02-25] [ist nicht signiert]
FF Extension: html5 helper - C:\Users\dbirn_000\AppData\Roaming\Mozilla\Firefox\Profiles\vdhjm1sm.default\Extensions\{d67277da-b590-4f51-9f7f-0aed4b540554}.xpi [2016-05-19] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2016-01-19] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox

Chrome:
=======
CHR StartupUrls: Default -> "hxxps://www.google.de/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=firefox%20often%20not%20responding","hxxps://support.mozilla.org/en-US/kb/warning-unresponsive-script","hxxps://support.mozilla.org/en-US/kb/firefox-uses-too-many-cpu-resources-how-fix","hxxps://support.mozilla.org/en-US/kb/firefox-uses-too-much-memory-ram","hxxp://www.technobezz.com/fix-firefox-responding-error/"
CHR Profile: C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-24]
CHR Extension: (Google Docs) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-24]
CHR Extension: (Google Drive) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-14]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2016-08-07]
CHR Extension: (YouTube) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-14]
CHR Extension: (Google Search) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-14]
CHR Extension: (Citavi Picker (Beta)) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\eaandldnbchhjimdfnaagaaidgebplgj [2016-08-08]
CHR Extension: (Google Sheets) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-24]
CHR Extension: (Google Docs Offline) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-24]
CHR Extension: (uSelect iDownload) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ileabdhfjmgaognikmjgmhhkjffggejc [2016-07-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-24]
CHR Extension: (Gmail) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-19]
CHR Extension: (Chrome Media Router) - C:\Users\dbirn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-13]
CHR HKLM-x32\...\Chrome\Extension: [eaandldnbchhjimdfnaagaaidgebplgj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2016-06-23]
CHR HKLM-x32\...\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files (x86)\Sony\Media Go\MediaGoDetector.crx" <nicht gefunden>

==================== Dienste (Nicht auf der Ausnahmeliste) ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2159832 2016-08-12] (Adobe Systems, Incorporated)
R2 Canon Driver Information Assist Service; C:\Program Files\Canon\DIAS\CnxDIAS.exe [5225312 2014-11-20] (CANON INC.)
S2 CDPUserSvc; C:\Windows\System32\CDPUserSvc.dll [337408 2016-07-16] (Microsoft Corporation)
R2 CDPUserSvc_6e768; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation)
R2 CDPUserSvc_6e768; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2854640 2016-07-03] (Microsoft Corporation)
R2 CltMngSvc; C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\CltMngSvc.exe [2535752 2014-05-12] (ClientConnect LTD)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-18] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-18] (Dropbox, Inc.)
R2 ddmgr; C:\WINDOWS\system32\ddmgr.exe [1659040 2015-12-07] (OSBASE)
R2 dowidoly; C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\jnsf589C.tmp [244224 2016-08-15] () [Datei ist nicht signiert]
S2 DptfParticipantProcessorService; C:\WINDOWS\system32\DptfParticipantProcessorService.exe [115632 2013-08-02] (Intel Corporation)
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116656 2013-08-02] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148688 2013-08-02] (Intel Corporation)
R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [124880 2013-08-02] (Intel Corporation)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-06-08] ()
S3 FrameServer; C:\Windows\system32\FrameServer.dll [803840 2016-07-16] (Microsoft Corporation)
R2 HpSvc; C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll [239016 2016-07-21] ()
S3 HvHost; C:\Windows\System32\hvhostsvc.dll [67584 2016-07-16] (Microsoft Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373736 2016-07-14] (Intel Corporation)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [59216 2016-07-01] (Lenovo Group Limited)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 LDrvSvc; C:\Program Files (x86)\OSTotoSoft\DriverTalent\LDrvSvc.dll [172200 2016-07-28] ()
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-12-19] (Lenovo(beijing) Limited)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-12-19] (Lenovo)
R2 MPCProtectService; C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe [350688 2016-08-15] (DotC United Inc)
R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [703984 2014-09-22] (SEIKO EPSON CORPORATION)
R2 MySQLpearstem; C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe [39702016 2016-05-25] () [Datei ist nicht signiert]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2016-05-03] ()
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [167176 2014-02-24] (PointGrab LTD)
R2 PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [512776 2014-02-24] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [249872 2014-12-19] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [328720 2014-12-19] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 rijufoze; C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\hnst6DCB.tmp [138240 2016-08-15] () [Datei ist nicht signiert]
R3 RmSvc; C:\Windows\System32\RMapi.dll [141312 2016-07-16] (Microsoft Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [288472 2013-09-13] (Realtek Semiconductor)
S4 shpamsvc; C:\Windows\system32\Windows.SharedPC.AccountManager.dll [161792 2016-07-16] (Microsoft Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2016-04-30] (Synaptics Incorporated)
R2 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [117400 2016-06-08] ()
R3 TimeBrokerSvc; C:\Windows\System32\TimeBrokerServer.dll [177664 2016-07-16] (Microsoft Corporation)
R2 UCBrowserSvc; C:\Program Files (x86)\UCBrowser\Application\UCService.exe [899984 2016-08-02] ()
S3 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-06-08] ()
S3 vmicrdv; C:\Windows\System32\icsvcext.dll [349696 2016-07-16] (Microsoft Corporation)
S3 vmicvss; C:\Windows\System32\icsvcext.dll [349696 2016-07-16] (Microsoft Corporation)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-07-17] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S3 wisvc; C:\Windows\system32\flightsettings.dll [614912 2016-07-16] (Microsoft Corporation)
S3 WpnUserService; C:\Windows\System32\WpnUserService.dll [74240 2016-07-16] (Microsoft Corporation)
S3 WpnUserService_6e768; C:\WINDOWS\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation)
S3 WpnUserService_6e768; C:\WINDOWS\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [34576 2014-12-19] (Lenovo)
R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2014-01-06] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3732896 2016-05-03] (Intel® Corporation)
R2 zigipyro; C:\Users\dbirn_000\AppData\Local\04905D8E-1471340577-11E4-B57F-68F7284155E1\qnsvAF9F.tmp [158720 2015-12-26] () [Datei ist nicht signiert]
R2 ziphost; c:\program files\ziptool\ziphost.dll [114080 2015-11-30] ()
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
S3 Jzidom Module; "C:\Program Files (x86)\Wivotain\Jzidom\Jzidommdlzoqerthershaviry.exe" {511AFE50-C2D8-48D5-87EB-B2BCFEC5572C} [X]
S2 PCSUService; C:\Program Files (x86)\PC Speed Up\PCSUService.exe [X]
R2 runywonezbt; C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\knsr42CF.tmpfs [X]
S2 SCService; "C:\Program Files (x86)\PC Speed Up\SpeedCheckerService.exe" [X]

===================== Treiber (Nicht auf der Ausnahmeliste) ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 AcpiDev; C:\Windows\System32\drivers\AcpiDev.sys [18432 2016-07-16] (Microsoft Corporation)
S3 applockerfltr; C:\Windows\System32\drivers\applockerfltr.sys [15360 2016-07-16] (Microsoft Corporation)
S0 b06bdrv; C:\Windows\System32\drivers\bxvbda.sys [533856 2016-07-16] (QLogic Corporation)
S3 cht4iscsi; C:\Windows\System32\drivers\cht4sx64.sys [346976 2016-07-16] (Chelsio Communications)
S3 cht4vbd; C:\Windows\System32\drivers\cht4vx64.sys [2104160 2016-07-16] (Chelsio Communications)
R2 clreg; C:\Windows\System32\drivers\registry.sys [70144 2016-07-16] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
S3 ComputerZ_x64; C:\Program Files (x86)\LuDaShi\ComputerZ_x64.sys [49152 2016-06-27] (ludashi.com)
R4 ddkmd; C:\WINDOWS\system32\drivers\ddkmd.sys [254456 2015-12-07] (OSBASE)
R0 ddkmdldr; C:\Windows\System32\drivers\ddkmdldr.sys [16888 2015-12-07] (OSBASE)
S3 DM9USB; C:\Windows\System32\drivers\dm9usb.sys [71416 2012-03-12] (DAVICOM Semiconductor, Inc.                                                    )
S3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [114680 2013-08-02] (Intel Corporation)
S3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [287160 2013-08-02] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494272 2013-08-02] (Intel Corporation)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [52200 2016-04-30] (Intel Corporation)
R3 dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [50664 2016-04-30] (Intel Corporation)
R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [31832 2016-06-12] (ELAN Microelectronic Corp.)
S3 FLxHCIv; C:\Windows\System32\Drivers\FLxHCIv.sys [194184 2015-12-07] ()
S3 hvservice; C:\Windows\System32\drivers\hvservice.sys [73568 2016-07-16] (Microsoft Corporation)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-04-30] (REALiX(tm))
S3 iagpio; C:\Windows\System32\drivers\iagpio.sys [33280 2016-07-16] (Intel(R) Corporation)
S3 iaLPSS2i_GPIO2; C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [64512 2016-07-16] (Intel Corporation)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [345872 2016-05-26] (Intel Corporation)
S3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-08] ()
S3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-08] ()
S3 IndirectKmd; C:\Windows\System32\drivers\IndirectKmd.sys [35840 2016-07-16] (Microsoft Corporation)
R0 iorate; C:\Windows\System32\drivers\iorate.sys [45920 2016-07-16] (Microsoft Corporation)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-07] ()
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185896 2016-05-05] (Intel Corporation)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [82072 2015-08-10] (McAfee, Inc.)
R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-08-15] (DotC United Inc)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3520264 2016-05-03] (Intel Corporation)
S0 percsas2i; C:\Windows\System32\drivers\percsas2i.sys [58720 2016-07-16] (Avago Technologies)
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [413912 2016-04-30] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3066072 2016-04-30] (Realtek Semiconductor Corp.)
S3 rtux64w10; C:\Windows\System32\drivers\rtux64w10.sys [350464 2016-07-21] (Realtek                                                                )
S0 scmbus; C:\Windows\System32\drivers\scmbus.sys [88416 2016-07-16] (Microsoft Corporation)
S3 scmdisk0101; C:\Windows\System32\drivers\scmdisk0101.sys [123904 2016-07-16] (Microsoft Corporation)
R3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2015-06-04] ()
R3 SensorsSimulatorDriver; C:\Windows\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-04-30] (Synaptics Incorporated)
R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [81792 2016-08-02] (Huorong Borui (Beijing) Technology Co., Ltd.)
S3 UcmTcpciCx0101; C:\Windows\System32\Drivers\UcmTcpciCx.sys [108544 2016-07-16] (Microsoft Corporation)
S1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [119712 2016-06-28] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [192864 2016-06-28] (Oracle Corporation)
S3 vmgid; C:\Windows\System32\drivers\vmgid.sys [10240 2016-07-16] (Microsoft Corporation)
R0 volume; C:\Windows\System32\drivers\volume.sys [16224 2016-07-16] (Microsoft Corporation)
R2 wcifs; C:\Windows\system32\drivers\wcifs.sys [119648 2016-07-16] (Microsoft Corporation)
R2 wcnfs; C:\Windows\system32\drivers\wcnfs.sys [66560 2016-07-16] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [149432 2015-05-20] (MBB)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
R1 ZipProtect; c:\program files\ziptool\ZipProtect64.sys [886512 2015-12-14] ()

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

NETSVC: shpamsvc -> C:\Windows\system32\Windows.SharedPC.AccountManager.dll (Microsoft Corporation)
NETSVC: wisvc -> C:\Windows\system32\flightsettings.dll (Microsoft Corporation)
NETSVC: WpnService -> C:\Windows\system32\WpnService.dll (Microsoft Corporation)
NETSVCx32: HpSvc -> C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll ()

 ============================


Piristibulus 16.08.2016 09:20

Teil 2:
Code:

==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-08-16 09:43 - 2016-08-16 09:43 - 00051246 _____ C:\Users\dbirn_000\Desktop\FRST.txt
2016-08-16 09:42 - 2016-08-16 09:43 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\04905D8E-1471340577-11E4-B57F-68F7284155E1
2016-08-16 09:42 - 2016-08-16 09:43 - 00000000 ____D C:\Program Files (x86)\mpck
2016-08-16 09:14 - 2016-08-16 09:43 - 00000000 ____D C:\FRST
2016-08-16 09:14 - 2016-08-16 09:14 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\MCorp
2016-08-16 09:14 - 2016-08-08 03:54 - 01611776 _____ C:\Users\dbirn_000\AppData\Roaming\ucdlr.exe
2016-08-16 09:08 - 2016-08-15 22:16 - 02394624 _____ (Farbar) C:\Users\dbirn_000\Desktop\FRST64.exe
2016-08-16 09:07 - 2016-08-16 09:07 - 00001809 _____ C:\Users\Public\Desktop\MPC Cleaner.lnk
2016-08-16 09:07 - 2016-08-16 09:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC
2016-08-15 18:18 - 2016-08-15 18:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Compress
2016-08-15 18:17 - 2016-08-15 18:17 - 01474568 _____ C:\Users\dbirn_000\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe
2016-08-15 18:17 - 2016-08-15 18:17 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\lockhomepage
2016-08-15 18:16 - 2016-08-15 18:19 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Ludashi
2016-08-15 18:16 - 2016-08-15 18:18 - 00000000 ____D C:\Program Files\ZipTool
2016-08-15 18:16 - 2016-08-15 18:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\鲁大师
2016-08-15 18:16 - 2016-08-15 18:16 - 00000000 ____D C:\Program Files (x86)\LDSGameCenter
2016-08-15 18:16 - 2016-02-18 10:10 - 05267952 _____ () C:\Users\dbirn_000\AppData\Roaming\ziptool_wc-9015_setup.exe
2016-08-15 18:14 - 2016-08-16 09:07 - 00000492 _____ C:\WINDOWS\Tasks\UCBrowserUpdater.job
2016-08-15 18:14 - 2016-08-15 18:15 - 00003518 _____ C:\WINDOWS\System32\Tasks\UCBrowserUpdater
2016-08-15 18:13 - 2016-08-15 19:16 - 00000000 ____D C:\Program Files (x86)\LuDaShi
2016-08-15 18:12 - 2016-08-15 18:12 - 00001606 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC浏览器.lnk
2016-08-15 18:12 - 2016-08-15 18:12 - 00001594 _____ C:\Users\Public\Desktop\UC浏览器.lnk
2016-08-15 18:12 - 2016-08-15 18:12 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\UCBrowser
2016-08-15 18:12 - 2016-08-15 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC浏览器
2016-08-15 18:12 - 2016-08-02 08:39 - 00081792 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-08-15 18:11 - 2016-08-15 18:12 - 00000000 ____D C:\Program Files (x86)\UCBrowser
2016-08-15 17:58 - 2016-08-15 18:05 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\app
2016-08-15 17:57 - 2016-08-16 09:07 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner
2016-08-15 17:57 - 2016-08-15 17:57 - 00060136 _____ (DotC United Inc) C:\WINDOWS\system32\Drivers\MPCKpt.sys
2016-08-15 17:57 - 2016-08-15 17:57 - 00003152 _____ C:\WINDOWS\System32\Tasks\tasklist
2016-08-15 17:57 - 2016-08-15 17:57 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\UPUpdata
2016-08-15 17:52 - 2016-08-15 17:52 - 00000000 ____D C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1
2016-08-15 17:52 - 2016-08-15 17:48 - 00001006 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2016-08-15 17:48 - 2016-08-16 09:07 - 00000374 _____ C:\WINDOWS\Tasks\PC SpeedUp Service Deactivator.job
2016-08-15 17:48 - 2016-08-16 09:07 - 00000000 ____D C:\Program Files\SpaceSoundPro
2016-08-15 17:48 - 2016-08-15 17:48 - 00002832 _____ C:\WINDOWS\System32\Tasks\PC SpeedUp Service Deactivator
2016-08-15 17:48 - 2016-08-15 17:48 - 00001128 _____ C:\Users\dbirn_000\Desktop\PC Speed Up.lnk
2016-08-15 17:48 - 2016-08-15 17:48 - 00000000 ____D C:\Users\dbirn_000\Documents\PCSpeedUp
2016-08-15 17:48 - 2016-08-15 17:48 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\Iwighghaceied
2016-08-15 17:48 - 2016-08-15 17:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up
2016-08-15 17:48 - 2016-08-15 17:48 - 00000000 ____D C:\Program Files\Caster
2016-08-15 15:35 - 2016-08-15 15:35 - 08119845 _____ C:\Users\dbirn_000\Downloads\PPN345203674_0058___log18.pdf
2016-08-15 14:54 - 2016-08-15 14:54 - 00001251 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zotero Standalone.lnk
2016-08-15 14:54 - 2016-08-15 14:54 - 00001239 _____ C:\Users\Public\Desktop\Zotero Standalone.lnk
2016-08-15 14:54 - 2016-08-15 14:54 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Zotero
2016-08-15 14:54 - 2016-08-15 14:54 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\Zotero
2016-08-15 14:54 - 2016-08-15 14:54 - 00000000 ____D C:\Program Files (x86)\Zotero Standalone
2016-08-15 14:29 - 2016-08-15 14:29 - 04115070 _____ C:\Users\dbirn_000\Downloads\Jacob Perkins-Python Text Processing with NLTK 2.0 Cookbook_ Use Python's NLTK suite of libraries to maximize your Natural Language Processing capabilities-Packt Publishing (2010).pdf
2016-08-15 14:25 - 2016-08-15 15:13 - 05647925 _____ C:\Users\dbirn_000\Downloads\Steven Bird, Ewan Klein, Edward Loper-Natural Language Processing with Python_ Analyzing Text with the Natural Language Toolkit-O'Reilly Media (2009).pdf
2016-08-15 14:25 - 2016-08-15 14:26 - 01969647 _____ C:\Users\dbirn_000\Downloads\Jacob Perkins-Python 3 Text Processing with NLTK 3 Cookbook_ Over 80 practical recipes on natural language processing techniques using Python's NLTK 3.0-Packt Publishing (2014).pdf
2016-08-15 13:35 - 2016-08-15 13:35 - 01110872 _____ C:\Users\dbirn_000\AppData\LocalLow\eff79D4.001
2016-08-15 13:35 - 2016-08-15 13:35 - 00095952 _____ C:\Users\dbirn_000\AppData\LocalLow\eff79D4.004
2016-08-15 13:35 - 2016-08-15 13:35 - 00055908 _____ C:\Users\dbirn_000\AppData\LocalLow\eff79D4.002
2016-08-15 13:35 - 2016-08-15 13:35 - 00054352 _____ C:\Users\dbirn_000\AppData\LocalLow\eff79D4.006
2016-08-15 13:35 - 2016-08-15 13:35 - 00050080 _____ C:\Users\dbirn_000\AppData\LocalLow\eff79D4.003
2016-08-15 13:35 - 2016-08-15 13:35 - 00044740 _____ C:\Users\dbirn_000\AppData\LocalLow\eff79D4.007
2016-08-15 13:35 - 2016-08-15 13:35 - 00042520 _____ C:\Users\dbirn_000\AppData\LocalLow\eff79D4.008
2016-08-15 13:35 - 2016-08-15 13:35 - 00014076 _____ C:\Users\dbirn_000\AppData\LocalLow\eff79D4.005
2016-08-15 13:32 - 2016-08-15 13:32 - 01787973 _____ C:\Users\dbirn_000\Downloads\mARkdown - al-Raqmiyyāt_ Digital Islamic History.pdf
2016-08-15 11:26 - 2016-08-15 11:26 - 00000000 ___HD C:\OneDriveTemp
2016-08-14 17:34 - 2016-08-14 17:36 - 05723977 _____ C:\Users\dbirn_000\Downloads\(Studies in Language Companion Series volume 12) Harm Pinkster (editor)-Latin Linguistics and Linguistic Theory (Studies in Language Companion Series, 12)-John Benjamins Publishing Company (1983).pdf.part
2016-08-13 15:21 - 2016-08-13 15:21 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\ElevatedDiagnostics
2016-08-12 13:42 - 2016-08-12 13:42 - 00000000 ____D C:\Users\dbirn_000\Documents\OneNote Notebooks
2016-08-12 12:15 - 2016-08-12 12:15 - 00000163 _____ C:\Users\dbirn_000\.gitconfig
2016-08-12 12:10 - 2016-08-12 12:10 - 00000000 ____D C:\Temp
2016-08-12 11:33 - 2016-08-12 11:34 - 00000000 ____D C:\Users\dbirn_000\.ssh
2016-08-12 11:33 - 2016-08-12 11:33 - 00001477 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EditPad Pro 7.lnk
2016-08-12 11:33 - 2016-08-12 11:33 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\JGsoft
2016-08-12 11:33 - 2016-08-12 11:33 - 00000000 ____D C:\Program Files\Just Great Software
2016-08-12 11:30 - 2016-08-12 13:37 - 00000000 ____D C:\Users\dbirn_000\Documents\GitHub
2016-08-12 11:30 - 2016-08-12 11:41 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\GitHub
2016-08-12 11:30 - 2016-08-12 11:35 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\GitHub
2016-08-12 11:30 - 2016-08-12 11:30 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc
2016-08-12 11:17 - 2016-08-12 13:41 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\Deployment
2016-08-12 11:07 - 2016-08-12 11:07 - 00849200 _____ C:\Users\dbirn_000\Desktop\SteuerIdentifikation_Birnstiel.pdf
2016-08-12 11:06 - 2016-08-12 11:06 - 00000000 ____D C:\Users\dbirn_000\Downloads\SteuerRyu
2016-08-11 11:19 - 2016-08-11 11:19 - 00915212 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.00b
2016-08-11 11:19 - 2016-08-11 11:19 - 00219524 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.009
2016-08-11 11:19 - 2016-08-11 11:19 - 00217044 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.008
2016-08-11 11:19 - 2016-08-11 11:19 - 00202180 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.006
2016-08-11 11:19 - 2016-08-11 11:19 - 00180792 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.00a
2016-08-11 11:19 - 2016-08-11 11:19 - 00176132 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.007
2016-08-11 11:19 - 2016-08-11 11:19 - 00077548 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.003
2016-08-11 11:19 - 2016-08-11 11:19 - 00051104 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.001
2016-08-11 11:19 - 2016-08-11 11:19 - 00047204 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.005
2016-08-11 11:19 - 2016-08-11 11:19 - 00045360 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.004
2016-08-11 11:19 - 2016-08-11 11:19 - 00045084 _____ C:\Users\dbirn_000\AppData\LocalLow\effA150.002
2016-08-11 11:18 - 2016-08-11 11:18 - 00077548 _____ C:\Users\dbirn_000\AppData\LocalLow\eff9B29.003
2016-08-11 11:18 - 2016-08-11 11:18 - 00059092 _____ C:\Users\dbirn_000\AppData\LocalLow\eff9B29.007
2016-08-11 11:18 - 2016-08-11 11:18 - 00055604 _____ C:\Users\dbirn_000\AppData\LocalLow\eff9B29.002
2016-08-11 11:18 - 2016-08-11 11:18 - 00052492 _____ C:\Users\dbirn_000\AppData\LocalLow\eff9B29.008
2016-08-11 11:18 - 2016-08-11 11:18 - 00051900 _____ C:\Users\dbirn_000\AppData\LocalLow\eff9B29.006
2016-08-11 11:18 - 2016-08-11 11:18 - 00045692 _____ C:\Users\dbirn_000\AppData\LocalLow\eff9B29.004
2016-08-11 11:18 - 2016-08-11 11:18 - 00039272 _____ C:\Users\dbirn_000\AppData\LocalLow\eff9B29.005
2016-08-11 10:17 - 2016-08-11 10:17 - 00059092 _____ C:\Users\dbirn_000\AppData\LocalLow\effBD18.007
2016-08-11 10:17 - 2016-08-11 10:17 - 00052492 _____ C:\Users\dbirn_000\AppData\LocalLow\effBD18.008
2016-08-11 10:17 - 2016-08-11 10:17 - 00051900 _____ C:\Users\dbirn_000\AppData\LocalLow\effBD18.006
2016-08-11 10:17 - 2016-08-11 10:17 - 00045692 _____ C:\Users\dbirn_000\AppData\LocalLow\effBD18.004
2016-08-11 10:17 - 2016-08-11 10:17 - 00039272 _____ C:\Users\dbirn_000\AppData\LocalLow\effBD18.005
2016-08-11 10:16 - 2016-08-11 10:16 - 00915212 _____ C:\Users\dbirn_000\AppData\LocalLow\eff8D80.00b
2016-08-11 10:16 - 2016-08-11 10:16 - 00219524 _____ C:\Users\dbirn_000\AppData\LocalLow\eff8D80.009
2016-08-11 10:16 - 2016-08-11 10:16 - 00217044 _____ C:\Users\dbirn_000\AppData\LocalLow\eff8D80.008
2016-08-11 10:16 - 2016-08-11 10:16 - 00202180 _____ C:\Users\dbirn_000\AppData\LocalLow\eff8D80.006
2016-08-11 10:16 - 2016-08-11 10:16 - 00180792 _____ C:\Users\dbirn_000\AppData\LocalLow\eff8D80.00a
2016-08-11 10:16 - 2016-08-11 10:16 - 00176132 _____ C:\Users\dbirn_000\AppData\LocalLow\eff8D80.007
2016-08-11 10:16 - 2016-08-11 10:16 - 00047204 _____ C:\Users\dbirn_000\AppData\LocalLow\eff8D80.005
2016-08-11 10:16 - 2016-08-11 10:16 - 00045360 _____ C:\Users\dbirn_000\AppData\LocalLow\eff8D80.004
2016-08-10 14:32 - 2016-08-10 14:32 - 00000000 ____D C:\WINDOWS\PCHEALTH
2016-08-10 13:34 - 2016-08-02 10:48 - 22219328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-08-10 13:34 - 2016-08-02 10:44 - 00151232 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-08-10 13:34 - 2016-08-02 10:44 - 00114192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2016-08-10 13:34 - 2016-08-02 10:20 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-08-10 13:34 - 2016-08-02 09:58 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-08-10 13:34 - 2016-08-02 09:55 - 03617280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-08-10 13:34 - 2016-08-02 06:51 - 20965240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-08-10 13:34 - 2016-08-02 06:37 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-08-10 13:34 - 2016-08-02 06:33 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2016-08-10 13:34 - 2016-08-02 06:27 - 07623168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-08-10 13:34 - 2016-08-02 06:25 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2016-08-10 13:34 - 2016-08-02 06:25 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-08-10 13:34 - 2016-08-02 06:23 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2016-08-10 13:34 - 2016-08-02 06:13 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2016-08-10 13:34 - 2016-08-02 06:09 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-08-10 13:33 - 2016-08-02 10:58 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-08-10 13:33 - 2016-08-02 10:53 - 02745224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-08-10 13:33 - 2016-08-02 10:52 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-08-10 13:33 - 2016-08-02 10:48 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-08-10 13:33 - 2016-08-02 10:23 - 22572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-08-10 13:33 - 2016-08-02 10:21 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-08-10 13:33 - 2016-08-02 10:21 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-08-10 13:33 - 2016-08-02 10:20 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-08-10 13:33 - 2016-08-02 10:15 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-08-10 13:33 - 2016-08-02 10:15 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-08-10 13:33 - 2016-08-02 10:14 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2016-08-10 13:33 - 2016-08-02 10:13 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-08-10 13:33 - 2016-08-02 10:12 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-08-10 13:33 - 2016-08-02 10:11 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-08-10 13:33 - 2016-08-02 10:11 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-08-10 13:33 - 2016-08-02 10:10 - 00509952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-08-10 13:33 - 2016-08-02 10:09 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-08-10 13:33 - 2016-08-02 10:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-08-10 13:33 - 2016-08-02 10:07 - 09125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-08-10 13:33 - 2016-08-02 10:03 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-08-10 13:33 - 2016-08-02 10:00 - 05511168 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-08-10 13:33 - 2016-08-02 09:59 - 08124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-08-10 13:33 - 2016-08-02 09:57 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-08-10 13:33 - 2016-08-02 09:56 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-08-10 13:33 - 2016-08-02 09:56 - 01785856 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-08-10 13:33 - 2016-08-02 09:56 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-08-10 13:33 - 2016-08-02 09:55 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-08-10 13:33 - 2016-08-02 09:52 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-08-10 13:33 - 2016-08-02 06:56 - 02251440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-08-10 13:33 - 2016-08-02 06:47 - 00079536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2016-08-10 13:33 - 2016-08-02 06:39 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-08-10 13:33 - 2016-08-02 06:37 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2016-08-10 13:33 - 2016-08-02 06:36 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2016-08-10 13:33 - 2016-08-02 06:30 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-08-10 13:33 - 2016-08-02 06:28 - 19423232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-08-10 13:33 - 2016-08-02 06:26 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-08-10 13:33 - 2016-08-02 06:26 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-08-10 13:33 - 2016-08-02 06:16 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-08-10 13:33 - 2016-08-02 06:13 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-08-10 13:33 - 2016-08-02 06:12 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-08-09 18:45 - 2016-08-09 18:47 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Skype
2016-08-09 18:45 - 2016-08-09 18:45 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-08-09 18:45 - 2016-08-09 18:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-08-09 18:43 - 2016-08-09 18:43 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\Evernote
2016-08-09 18:40 - 2016-08-09 18:40 - 00000000 ____D C:\Users\dbirn_000\AppData\LocalLow\Evernote
2016-08-09 18:40 - 2016-08-09 18:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2016-08-09 18:40 - 2016-08-09 18:40 - 00000000 ____D C:\Program Files (x86)\Evernote
2016-08-08 15:25 - 2016-08-08 15:25 - 00569425 _____ C:\Users\dbirn_000\Downloads\eLearning-Workshopprogramm_WiSe_1617.pdf
2016-08-07 22:08 - 2016-08-07 22:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-08-05 01:10 - 2016-08-05 01:10 - 00000000 ____D C:\Users\Public\Thunder Network
2016-08-05 01:10 - 2016-08-05 01:10 - 00000000 ____D C:\ProgramData\Thunder Network
2016-08-05 01:08 - 2016-08-05 01:13 - 00000000 ____D C:\ProgramData\DriverTalent
2016-08-05 01:08 - 2016-08-05 01:08 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\DriverTalent
2016-08-05 01:08 - 2016-08-05 01:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Talent
2016-08-05 01:08 - 2016-08-05 01:08 - 00000000 ____D C:\Program Files (x86)\OSTotoSoft
2016-08-05 01:08 - 2016-08-05 01:08 - 00000000 ____D C:\OSTotoFolder
2016-08-05 00:27 - 2016-08-05 00:27 - 00000568 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2016-08-04 18:51 - 2016-08-04 18:16 - 00000000 ___DC C:\WINDOWS\Panther
2016-08-04 18:48 - 2016-08-04 18:48 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-08-04 18:48 - 2016-08-04 18:48 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 01418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 01265424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 01260384 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 00843104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-08-04 18:48 - 2016-08-04 18:48 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-08-04 18:48 - 2016-08-04 18:48 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-08-04 18:48 - 2016-08-04 18:48 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-08-04 18:48 - 2016-08-04 17:59 - 00000000 ____D C:\Windows.old
2016-08-04 18:45 - 2016-07-15 20:29 - 07702016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NL7Models0011.dll
2016-08-04 18:45 - 2016-07-15 20:29 - 02454528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NL7Lexicons0011.dll
2016-08-04 18:45 - 2016-07-15 20:25 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSWB70011.dll
2016-08-04 18:45 - 2016-07-15 20:24 - 07417344 _____ (Microsoft Corporation) C:\WINDOWS\system32\NL7Data0011.dll
2016-08-04 18:45 - 2016-07-15 19:40 - 07253504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NL7Data0011.dll
2016-08-04 18:45 - 2016-07-15 19:40 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSWB70011.dll
2016-08-04 18:45 - 2016-05-25 15:39 - 00002060 _____ C:\WINDOWS\system32\noise.jpn
2016-08-04 18:45 - 2016-05-25 12:10 - 00002060 _____ C:\WINDOWS\SysWOW64\noise.jpn
2016-08-04 18:44 - 2016-07-15 20:29 - 01722880 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons000d.dll
2016-08-04 18:44 - 2016-07-15 20:27 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000d.dll
2016-08-04 18:44 - 2016-07-15 20:24 - 02295296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MLS7.dll
2016-08-04 18:44 - 2016-07-15 19:45 - 01722880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons000d.dll
2016-08-04 18:44 - 2016-07-15 19:43 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000d.dll
2016-08-04 18:44 - 2016-07-15 19:40 - 02243072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MLS7.dll
2016-08-04 18:40 - 2016-07-15 20:29 - 05739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2016-08-04 18:40 - 2016-07-15 20:29 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2016-08-04 18:40 - 2016-07-15 20:14 - 06354944 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2016-08-04 18:40 - 2016-07-15 19:45 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2016-08-04 18:40 - 2016-07-15 19:29 - 05489664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2016-08-04 18:39 - 2016-07-15 20:28 - 08229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0008.dll
2016-08-04 18:38 - 2016-07-15 20:28 - 16735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0001.dll
2016-08-04 18:37 - 2016-08-04 18:37 - 00000000 ____D C:\WINDOWS\system32\he
2016-08-04 18:37 - 2016-07-15 20:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll
2016-08-04 18:37 - 2016-07-15 20:28 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2016-08-04 18:37 - 2016-07-15 20:28 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2016-08-04 18:37 - 2016-07-15 20:26 - 00376320 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2016-08-04 18:37 - 2016-07-15 20:26 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll
2016-08-04 18:37 - 2016-07-15 20:25 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll
2016-08-04 18:37 - 2016-07-15 20:23 - 14388224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll
2016-08-04 18:37 - 2016-07-15 20:22 - 00429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll
2016-08-04 18:37 - 2016-07-15 20:22 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll
2016-08-04 18:37 - 2016-07-15 20:19 - 01323520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2016-08-04 18:37 - 2016-07-15 20:16 - 05850624 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2016-08-04 18:37 - 2016-07-15 20:16 - 04969472 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2016-08-04 18:37 - 2016-07-15 20:15 - 06582784 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12warp.dll
2016-08-04 18:37 - 2016-07-15 20:14 - 02485760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll
2016-08-04 18:37 - 2016-07-15 20:13 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2016-08-04 18:37 - 2016-07-15 20:13 - 01198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe
2016-08-04 18:37 - 2016-07-15 20:13 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll
2016-08-04 18:37 - 2016-07-15 20:12 - 00297984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll
2016-08-04 18:37 - 2016-07-15 20:12 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll
2016-08-04 18:37 - 2016-07-15 20:11 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll
2016-08-04 18:37 - 2016-07-15 19:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxToolsReportGenerator.dll
2016-08-04 18:37 - 2016-07-15 19:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsProxyStub.dll
2016-08-04 18:37 - 2016-07-15 19:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARP12Debug.dll
2016-08-04 18:37 - 2016-07-15 19:42 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARPDebug.dll
2016-08-04 18:37 - 2016-07-15 19:41 - 00355840 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2016-08-04 18:37 - 2016-07-15 19:41 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXGIDebug.dll
2016-08-04 18:37 - 2016-07-15 19:39 - 11670528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCaptureReplay.dll
2016-08-04 18:37 - 2016-07-15 19:38 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll
2016-08-04 18:37 - 2016-07-15 19:37 - 01935360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll
2016-08-04 18:37 - 2016-07-15 19:37 - 01074176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll
2016-08-04 18:37 - 2016-07-15 19:35 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perf_gputiming.dll
2016-08-04 18:37 - 2016-07-15 19:32 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2016-08-04 18:37 - 2016-07-15 19:32 - 03701248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsRemoteEngine.exe
2016-08-04 18:37 - 2016-07-15 19:31 - 04977664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12warp.dll
2016-08-04 18:37 - 2016-07-15 19:29 - 00953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCap.exe
2016-08-04 18:37 - 2016-07-15 19:29 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsExperiment.dll
2016-08-04 18:37 - 2016-07-15 19:29 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsCapture.dll
2016-08-04 18:37 - 2016-07-15 19:28 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsOfflineAnalysis.dll
2016-08-04 18:37 - 2016-07-15 19:28 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsMonitor.dll
2016-08-04 18:37 - 2016-07-15 19:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsReporting.dll
2016-08-04 18:35 - 2016-08-04 18:35 - 00000000 ____D C:\WINDOWS\system32\ar
2016-08-04 18:32 - 2016-08-16 09:13 - 00668630 _____ C:\WINDOWS\system32\perfh008.dat
2016-08-04 18:32 - 2016-08-16 09:13 - 00191042 _____ C:\WINDOWS\system32\perfc008.dat
2016-08-04 18:32 - 2016-08-04 18:32 - 00376726 _____ C:\WINDOWS\system32\perfi008.dat
2016-08-04 18:32 - 2016-08-04 18:32 - 00047288 _____ C:\WINDOWS\system32\perfd008.dat
2016-08-04 18:32 - 2016-08-04 18:32 - 00000000 ____D C:\WINDOWS\SysWOW64\el
2016-08-04 18:32 - 2016-08-04 18:32 - 00000000 ____D C:\WINDOWS\system32\el
2016-08-04 18:28 - 2016-08-16 09:13 - 00333030 _____ C:\WINDOWS\system32\perfh011.dat
2016-08-04 18:28 - 2016-08-16 09:13 - 00164772 _____ C:\WINDOWS\system32\perfc011.dat
2016-08-04 18:28 - 2016-08-04 18:28 - 00000000 ____D C:\WINDOWS\SysWOW64\ja
2016-08-04 18:28 - 2016-08-04 18:28 - 00000000 ____D C:\WINDOWS\system32\ja
2016-08-04 18:28 - 2016-08-04 18:27 - 00144476 _____ C:\WINDOWS\system32\perfi011.dat
2016-08-04 18:28 - 2016-08-04 18:27 - 00033362 _____ C:\WINDOWS\system32\perfd011.dat
2016-08-04 18:27 - 2016-08-04 18:27 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\lzhfldr2.dll
2016-08-04 18:27 - 2016-08-04 18:27 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lzhfldr2.dll
2016-08-04 18:25 - 2016-08-04 18:25 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-08-04 18:23 - 2016-08-04 18:29 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\ConnectedDevicesPlatform
2016-08-04 18:23 - 2016-08-04 18:23 - 00000020 ___SH C:\Users\dbirn_000\ntuser.ini
2016-08-04 18:22 - 2016-08-04 18:22 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-08-04 18:21 - 2016-08-04 18:37 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-08-04 18:21 - 2016-08-04 18:21 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-08-04 18:21 - 2016-08-04 18:21 - 00000000 ____D C:\Program Files\MSBuild
2016-08-04 18:21 - 2016-08-04 18:21 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-08-04 18:21 - 2016-08-04 17:59 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-08-04 18:20 - 2016-05-25 15:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-08-04 18:20 - 2016-05-25 15:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-08-04 18:20 - 2016-05-25 15:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-08-04 18:20 - 2016-05-25 12:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-08-04 18:20 - 2016-05-25 12:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-08-04 18:20 - 2016-05-25 12:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-08-04 18:16 - 2016-08-04 18:16 - 00000000 ____D C:\ProgramData\USOShared
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Vorlagen
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Startmenü
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Videos
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Videos
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2016-08-04 18:15 - 2016-08-04 18:15 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2016-08-04 18:14 - 2016-08-04 18:15 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2016-08-04 18:14 - 2016-08-04 18:15 - 00007623 _____ C:\WINDOWS\diagerr.xml
2016-08-04 18:09 - 2016-08-16 09:10 - 00003036 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (dbirn_000)
2016-08-04 18:09 - 2016-08-16 09:07 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-08-04 18:09 - 2016-08-09 18:38 - 00003384 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler
2016-08-04 18:09 - 2016-08-04 18:09 - 00003496 _____ C:\WINDOWS\System32\Tasks\EPSON XP-610 Series Update {229C7B40-79E8-41C8-8EBE-0DE79613F010}
2016-08-04 18:09 - 2016-08-04 18:09 - 00003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-08-04 18:09 - 2016-08-04 18:09 - 00003474 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0d9f35b7f3b7c
2016-08-04 18:09 - 2016-08-04 18:09 - 00003318 _____ C:\WINDOWS\System32\Tasks\EPSON XP-610 Series Invitation {229C7B40-79E8-41C8-8EBE-0DE79613F010}
2016-08-04 18:09 - 2016-08-04 18:09 - 00003308 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2016-08-04 18:09 - 2016-08-04 18:09 - 00003300 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-08-04 18:09 - 2016-08-04 18:09 - 00003272 _____ C:\WINDOWS\System32\Tasks\EPSON XP-610 Series Update {FCB9B395-BD41-487E-83F4-E5EDC1023F67}
2016-08-04 18:09 - 2016-08-04 18:09 - 00003220 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-04 18:09 - 2016-08-04 18:09 - 00003098 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-08-04 18:09 - 2016-08-04 18:09 - 00003086 _____ C:\WINDOWS\System32\Tasks\EPSON XP-610 Series Invitation {FCB9B395-BD41-487E-83F4-E5EDC1023F67}
2016-08-04 18:09 - 2016-08-04 18:09 - 00003080 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2016-08-04 18:09 - 2016-08-04 18:09 - 00002810 _____ C:\WINDOWS\System32\Tasks\MySQLNotifierTask
2016-08-04 18:09 - 2016-08-04 18:09 - 00002808 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-528608177-3768278189-544877735-1001
2016-08-04 18:09 - 2016-08-04 18:09 - 00002316 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-528608177-3768278189-544877735-500
2016-08-04 18:09 - 2016-08-04 18:09 - 00002292 _____ C:\WINDOWS\System32\Tasks\{2BA78B0B-9FE5-4555-B3DA-63AF616A7EE5}
2016-08-04 18:09 - 2016-08-04 18:09 - 00002286 _____ C:\WINDOWS\System32\Tasks\{AC26FD83-02AC-48C9-B1EC-943F64688AE4}
2016-08-04 18:09 - 2016-08-04 18:09 - 00002216 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-08-04 18:09 - 2016-08-04 18:09 - 00002180 _____ C:\WINDOWS\System32\Tasks\{9D1D3036-8091-4543-A35F-F893AE231A6C}
2016-08-04 18:09 - 2016-08-04 18:09 - 00002110 _____ C:\WINDOWS\System32\Tasks\USER_ESRV_SVC_WILLAMETTE
2016-08-04 18:09 - 2016-08-04 18:09 - 00000000 ____D C:\WINDOWS\System32\Tasks\MySQL
2016-08-04 18:09 - 2016-08-04 18:09 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2016-08-04 18:09 - 2016-08-04 18:09 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2016-08-04 18:09 - 2016-08-04 18:09 - 00000000 ____D C:\WINDOWS\System32\Tasks\Intel
2016-08-04 18:09 - 2014-04-03 20:35 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1050727674-2070356693-977449066-500
2016-08-04 18:07 - 2016-08-04 18:07 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-08-04 18:07 - 2016-08-04 18:07 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-08-04 18:07 - 2016-08-04 18:07 - 00000000 ____D C:\Users\Default\AppData\Local\Pokki
2016-08-04 18:07 - 2016-08-04 18:07 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-08-04 18:07 - 2016-08-04 18:07 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-08-04 18:07 - 2016-08-04 18:07 - 00000000 ____D C:\Users\Default User\AppData\Local\Pokki
2016-08-04 18:07 - 2016-08-04 18:07 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-08-04 17:55 - 2016-08-04 18:07 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-08-04 17:54 - 2016-08-16 09:13 - 03350822 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-08-04 17:54 - 2016-08-16 09:07 - 00000000 ____D C:\Users\dbirn_000
2016-08-04 17:54 - 2016-08-04 17:54 - 02441288 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Vorlagen
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Startmenü
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Netzwerkumgebung
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Lokale Einstellungen
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Eigene Dateien
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Druckumgebung
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Documents\Eigene Videos
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Documents\Eigene Musik
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Documents\Eigene Bilder
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\AppData\Local\Verlauf
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\AppData\Local\Anwendungsdaten
2016-08-04 17:54 - 2016-08-04 17:54 - 00000000 _SHDL C:\Users\dbirn_000\Anwendungsdaten
2016-08-04 17:53 - 2016-08-16 09:07 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-08-04 17:53 - 2016-08-05 01:23 - 00000000 ____D C:\Program Files\Intel
2016-08-04 17:53 - 2016-08-05 00:27 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-08-04 17:53 - 2016-08-04 17:53 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2016-08-04 17:53 - 2016-08-04 17:53 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2016-08-04 17:53 - 2016-08-04 17:53 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_DptfManager_01011.Wdf
2016-08-04 17:53 - 2016-08-04 17:53 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-08-04 17:53 - 2016-08-04 17:53 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-08-04 17:53 - 2016-08-04 17:53 - 00000000 ____D C:\Program Files\Synaptics
2016-08-04 17:53 - 2016-08-04 17:53 - 00000000 ____D C:\Program Files\Realtek
2016-08-04 17:53 - 2016-08-04 17:53 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2016-08-04 17:53 - 2016-07-14 05:34 - 00103960 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2016-08-04 17:53 - 2016-07-14 05:34 - 00099864 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2016-08-04 17:52 - 2016-08-16 09:33 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-08-04 17:52 - 2016-08-10 15:52 - 01397392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-08-04 17:52 - 2016-08-04 17:52 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-08-04 17:52 - 2016-07-16 13:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-07-28 19:34 - 2016-07-28 19:34 - 00000000 ____D C:\Users\dbirn_000\AppData\LocalLow\Temp
2016-07-28 19:17 - 2016-07-28 19:17 - 00000000 ____D C:\Program Files\Common Files\Intel
2016-07-28 19:17 - 2016-07-28 19:17 - 00000000 ____D C:\Program Files (x86)\Cisco
2016-07-28 18:34 - 2016-07-28 18:34 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\MySQL
2016-07-28 18:19 - 2016-07-28 18:23 - 00000000 ____D C:\Program Files\MySQL
2016-07-28 13:51 - 2016-07-28 13:51 - 00002216 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
2016-07-28 13:51 - 2016-07-28 13:51 - 00000000 ____D C:\Program Files (x86)\Belarc
2016-07-28 01:29 - 2016-07-28 18:22 - 00000469 _____ C:\WINDOWS\ODBCINST.INI
2016-07-28 00:50 - 2016-07-28 00:51 - 00000000 ____D C:\Users\dbirn_000\Documents\Visual Studio 2015
2016-07-28 00:45 - 2016-07-28 00:45 - 00000000 ____D C:\Program Files (x86)\AppInsights
2016-07-28 00:41 - 2016-08-04 18:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 11.0
2016-07-28 00:36 - 2016-07-28 00:36 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2016-07-28 00:36 - 2016-07-28 00:36 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-07-28 00:35 - 2016-07-28 00:35 - 00000000 ____D C:\ProgramData\PreEmptive Solutions
2016-07-28 00:35 - 2016-07-28 00:35 - 00000000 ____D C:\Program Files (x86)\ShellDir
2016-07-28 00:34 - 2016-07-28 00:41 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET
2016-07-28 00:32 - 2016-07-28 00:32 - 00000000 ____D C:\ProgramData\Microsoft DNX
2016-07-28 00:32 - 2016-07-28 00:32 - 00000000 ____D C:\Program Files\Microsoft DNX
2016-07-28 00:28 - 2016-07-28 00:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Web Tools
2016-07-28 00:25 - 2016-07-28 00:26 - 00000000 ____D C:\Program Files\IIS Express
2016-07-28 00:25 - 2016-07-28 00:26 - 00000000 ____D C:\Program Files (x86)\IIS Express
2016-07-28 00:24 - 2016-07-28 00:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Office365 Tools
2016-07-28 00:22 - 2016-08-04 17:59 - 00000000 ____D C:\Program Files\IIS
2016-07-28 00:22 - 2016-07-28 00:22 - 00000000 ____D C:\ProgramData\NuGet
2016-07-28 00:22 - 2016-07-28 00:22 - 00000000 ____D C:\Program Files (x86)\NuGet
2016-07-28 00:22 - 2016-07-28 00:22 - 00000000 ____D C:\Program Files (x86)\Microsoft WCF Data Services
2016-07-28 00:22 - 2016-07-28 00:22 - 00000000 ____D C:\Program Files (x86)\IIS
2016-07-28 00:21 - 2016-08-04 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression
2016-07-28 00:20 - 2016-08-04 18:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0
2016-07-28 00:20 - 2016-07-28 00:20 - 00001509 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blend for Visual Studio 2015.lnk
2016-07-28 00:20 - 2016-07-28 00:20 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 12.0
2016-07-28 00:18 - 2016-08-04 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015
2016-07-28 00:17 - 2016-07-28 00:17 - 00000000 ____D C:\WINDOWS\symbols
2016-07-28 00:17 - 2016-07-28 00:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Help Viewer
2016-07-28 00:16 - 2016-08-04 18:07 - 00000000 ____D C:\WINDOWS\SysWOW64\1033
2016-07-28 00:16 - 2016-07-28 00:43 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2016-07-28 00:16 - 2016-07-28 00:43 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2016-07-28 00:16 - 2016-07-28 00:16 - 00001518 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015.lnk
2016-07-28 00:15 - 2016-08-04 18:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 14.0
2016-07-28 00:15 - 2016-08-04 18:07 - 00000000 ____D C:\WINDOWS\system32\1033
2016-07-28 00:15 - 2016-07-28 00:15 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_SensorsSimulatorDriver_01_11_00.Wdf
2016-07-28 00:14 - 2016-07-28 00:41 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2016-07-28 00:14 - 2016-07-28 00:17 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2016-07-27 14:25 - 2016-08-04 18:07 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.5
2016-07-27 14:25 - 2016-07-27 14:25 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\Package Cache
2016-07-27 14:16 - 2016-08-04 18:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
2016-07-27 14:16 - 2016-07-28 18:29 - 00000000 ____D C:\ProgramData\MySQL
2016-07-27 14:16 - 2016-07-28 18:23 - 00000000 ____D C:\Program Files (x86)\MySQL
2016-07-27 00:27 - 2016-07-27 00:27 - 00000000 ____D C:\Users\dbirn_000\MediathekView
2016-07-25 15:39 - 2016-07-27 14:14 - 00000000 ____D C:\Users\dbirn_000\Downloads\CIDCO_CRM
2016-07-21 08:40 - 2016-07-21 08:40 - 00083200 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll
2016-07-18 00:11 - 2016-07-18 00:13 - 123576081 _____ C:\Users\dbirn_000\Downloads\eXist-db-setup-2.2.jar
2016-07-18 00:11 - 2016-07-18 00:12 - 109598839 _____ C:\Users\dbirn_000\Downloads\eXist-db-2.2.dmg
2016-07-17 01:55 - 2016-08-04 16:59 - 00000000 ___HD C:\$WINDOWS.~BT
2016-07-17 00:58 - 2016-07-17 00:58 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\quickassist.exe
2016-07-17 00:57 - 2016-07-16 13:43 - 00033498 _____ C:\WINDOWS\Core.xml
2016-07-17 00:52 - 2016-08-04 18:47 - 00000000 ____D C:\WINDOWS\OCR
2016-07-17 00:51 - 2016-08-16 09:13 - 00622244 _____ C:\WINDOWS\system32\perfh007.dat
2016-07-17 00:51 - 2016-08-16 09:13 - 00198304 _____ C:\WINDOWS\system32\perfc007.dat
2016-07-17 00:51 - 2016-07-17 00:51 - 00000000 ____D C:\WINDOWS\SKB
2016-07-17 00:51 - 2016-07-17 00:50 - 00305594 _____ C:\WINDOWS\system32\perfi007.dat
2016-07-17 00:51 - 2016-07-17 00:50 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat
2016-07-17 00:50 - 2016-08-04 18:37 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2016-07-17 00:50 - 2016-08-04 18:37 - 00000000 ____D C:\WINDOWS\system32\WCN
2016-07-17 00:50 - 2016-08-04 18:00 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2016-07-17 00:50 - 2016-08-04 18:00 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2016-07-17 00:50 - 2016-08-04 18:00 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2016-07-17 00:50 - 2016-08-04 18:00 - 00000000 ____D C:\WINDOWS\system32\winrm
2016-07-17 00:50 - 2016-08-04 18:00 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-07-17 00:50 - 2016-08-04 18:00 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\de
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\de
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\system32\0409
2016-07-17 00:50 - 2016-07-17 00:50 - 00000000 ____D C:\WINDOWS\DigitalLocker

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-08-16 09:14 - 2015-08-19 00:49 - 00000000 ___RD C:\Users\dbirn_000\Dropbox
2016-08-16 09:07 - 2015-08-18 17:28 - 00000000 __SHD C:\Users\dbirn_000\IntelGraphicsProfiles
2016-08-15 17:49 - 2016-02-12 16:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-08-15 17:49 - 2016-01-14 18:33 - 00000000 ____D C:\Users\dbirn_000\Documents\Anki
2016-08-15 17:48 - 2015-08-20 13:42 - 00000000 ___HD C:\Users\dbirn_000\AppData\Roaming\Nitro PDF
2016-08-15 17:47 - 2015-08-18 22:15 - 00002481 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-15 17:47 - 2015-08-18 21:58 - 00001437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-08-15 17:39 - 2016-01-14 11:38 - 00000000 ____D C:\Users\dbirn_000\Documents\Citavi 5
2016-08-15 13:15 - 2016-04-07 00:54 - 00000000 ____D C:\Users\dbirn_000\Downloads\DowloadsAcademia
2016-08-15 11:26 - 2015-08-18 17:35 - 00000000 ___RD C:\Users\dbirn_000\OneDrive
2016-08-15 11:14 - 2016-07-16 08:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-08-14 20:52 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
2016-08-14 20:13 - 2016-04-07 00:54 - 00000000 ____D C:\Users\dbirn_000\Downloads\DownloadsLibGen
2016-08-14 16:38 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-08-13 12:55 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2016-08-12 11:00 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2016-08-11 21:08 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-08-10 21:41 - 2015-08-18 17:28 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\Packages
2016-08-10 17:45 - 2015-08-19 00:24 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-08-10 15:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-08-10 14:32 - 2016-01-14 01:19 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-08-10 14:20 - 2016-01-14 01:19 - 147640136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-08-10 13:20 - 2015-08-18 21:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-09 18:45 - 2016-03-18 16:22 - 00000000 ____D C:\ProgramData\Skype
2016-08-09 18:38 - 2016-04-30 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 3
2016-08-09 17:37 - 2016-05-05 18:40 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\MyPhoneExplorer
2016-08-08 18:14 - 2016-01-14 11:37 - 00000000 ____D C:\ProgramData\Swiss Academic Software
2016-08-08 18:14 - 2016-01-14 11:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citavi 5
2016-08-08 18:13 - 2016-01-14 11:36 - 00000000 ____D C:\Users\dbirn_000\AppData\Local\Downloaded Installations
2016-08-07 22:08 - 2015-08-18 22:42 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-08-05 01:23 - 2014-12-19 06:47 - 00000000 ____D C:\ProgramData\Package Cache
2016-08-05 00:07 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\appcompat
2016-08-04 23:11 - 2016-05-20 00:40 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-08-04 19:58 - 2016-04-30 21:04 - 00000000 ____D C:\ProgramData\ProductData
2016-08-04 18:51 - 2016-07-16 13:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ___RD C:\Program Files\Windows Defender
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Help
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\System
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-08-04 18:37 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-08-04 18:37 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\servicing
2016-08-04 18:32 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2016-08-04 18:32 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-08-04 18:32 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2016-08-04 18:32 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Com
2016-08-04 18:26 - 2016-02-29 00:36 - 00002386 _____ C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-08-04 18:16 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\USOPrivate
2016-08-04 18:15 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows NT
2016-08-04 18:15 - 2016-07-16 08:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-08-04 18:14 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-08-04 18:14 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Registration
2016-08-04 18:14 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-08-04 18:09 - 2016-02-28 18:41 - 00023056 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-08-04 18:08 - 2016-07-16 13:47 - 00000000 __RHD C:\Users\Public\Libraries
2016-08-04 18:07 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-08-04 18:07 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2016-08-04 18:07 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-08-04 18:07 - 2016-07-08 17:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility
2016-08-04 18:07 - 2016-07-03 01:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2016-08-04 18:07 - 2016-07-03 01:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\כלי Office 2016
2016-08-04 18:07 - 2016-06-18 21:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeMind
2016-08-04 18:07 - 2016-06-11 02:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.1
2016-08-04 18:07 - 2016-05-05 18:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2016-08-04 18:07 - 2016-04-09 02:10 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flixster Video
2016-08-04 18:07 - 2016-04-05 14:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\المكتبة الشاملة
2016-08-04 18:07 - 2016-04-04 09:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xiphos
2016-08-04 18:07 - 2016-04-03 18:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The SWORD Project
2016-08-04 18:07 - 2016-03-28 16:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WALKMAN Guide
2016-08-04 18:07 - 2016-03-27 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-08-04 18:07 - 2016-03-27 16:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-08-04 18:07 - 2016-03-12 23:44 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-08-04 18:07 - 2016-03-12 23:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2016-08-04 18:07 - 2016-02-27 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XMind
2016-08-04 18:07 - 2016-02-27 13:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2016-08-04 18:07 - 2016-02-02 13:20 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InfraRecorder
2016-08-04 18:07 - 2016-02-02 12:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
2016-08-04 18:07 - 2016-01-19 12:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2016-08-04 18:07 - 2016-01-19 12:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
2016-08-04 18:07 - 2016-01-16 16:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-08-04 18:07 - 2016-01-14 18:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDjView
2016-08-04 18:07 - 2016-01-14 11:25 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2016-08-04 18:07 - 2016-01-14 03:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2016-08-04 18:07 - 2015-10-30 20:44 - 00000000 ____D C:\WINDOWS\ShellNew
2016-08-04 18:07 - 2015-10-30 08:28 - 00000000 ____D C:\Users\Default.migrated
2016-08-04 18:07 - 2015-08-18 22:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-08-04 18:07 - 2015-08-18 22:15 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-08-04 18:07 - 2015-08-18 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-08-04 18:07 - 2015-08-18 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-08-04 18:07 - 2015-08-18 21:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-08-04 18:07 - 2015-08-18 20:51 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PhotoDirector 4
2016-08-04 18:07 - 2015-08-18 20:44 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite
2016-08-04 18:07 - 2014-12-19 07:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Photo Master
2016-08-04 18:07 - 2014-12-19 07:09 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector 10
2016-08-04 18:07 - 2014-12-19 07:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2016-08-04 18:07 - 2014-12-19 06:47 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-08-04 18:07 - 2014-12-19 06:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\spool
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\InputMethod
2016-08-04 18:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\IME
2016-08-04 18:00 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-08-04 18:00 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-08-04 18:00 - 2016-05-24 13:27 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2016-08-04 18:00 - 2016-05-23 01:21 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2016-08-04 18:00 - 2016-03-23 14:38 - 00000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2016-08-04 18:00 - 2016-02-27 13:14 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe
2016-08-04 18:00 - 2014-12-19 06:51 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
2016-08-04 18:00 - 2014-12-19 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2016-08-04 18:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2016-08-04 18:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2016-08-04 17:59 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-08-04 17:59 - 2016-04-01 13:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
2016-08-04 17:59 - 2016-03-28 17:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2016-08-04 17:59 - 2016-02-27 13:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2016-08-04 17:59 - 2014-12-19 07:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hightail
2016-08-04 17:55 - 2016-04-11 17:48 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Android
2016-08-04 17:54 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-08-04 17:53 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-08-04 17:53 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-08-04 17:17 - 2016-02-22 18:13 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-08-04 16:47 - 2015-08-18 22:42 - 00000940 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-08-04 16:42 - 2015-08-18 17:42 - 00000945 _____ C:\WINDOWS\Tasks\EPSON XP-610 Series Update {FCB9B395-BD41-487E-83F4-E5EDC1023F67}.job
2016-08-04 16:42 - 2015-08-18 17:42 - 00000759 _____ C:\WINDOWS\Tasks\EPSON XP-610 Series Invitation {FCB9B395-BD41-487E-83F4-E5EDC1023F67}.job
2016-08-04 16:30 - 2015-08-18 22:20 - 00000932 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0d9f35b7f3b7c.job
2016-08-04 16:25 - 2015-08-18 22:15 - 00000932 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-04 16:20 - 2016-05-04 00:20 - 00000945 _____ C:\WINDOWS\Tasks\EPSON XP-610 Series Update {229C7B40-79E8-41C8-8EBE-0DE79613F010}.job
2016-08-04 16:20 - 2016-05-04 00:20 - 00000759 _____ C:\WINDOWS\Tasks\EPSON XP-610 Series Invitation {229C7B40-79E8-41C8-8EBE-0DE79613F010}.job
2016-08-04 12:30 - 2015-08-18 22:15 - 00000928 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-03 22:47 - 2015-08-18 22:42 - 00000936 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-08-03 15:08 - 2016-06-16 10:08 - 00000000 ____D C:\Users\dbirn_000\Documents\Custom Office Templates
2016-08-03 11:03 - 2016-04-05 00:02 - 00464000 _____ C:\WINDOWS\system32\perfh001.dat
2016-08-03 11:03 - 2016-04-05 00:02 - 00078708 _____ C:\WINDOWS\system32\perfc001.dat
2016-08-03 11:03 - 2016-02-28 18:10 - 00435280 _____ C:\WINDOWS\system32\perfh00D.dat
2016-08-03 11:03 - 2016-02-28 18:10 - 00078450 _____ C:\WINDOWS\system32\perfc00D.dat
2016-08-02 15:27 - 2016-01-22 13:59 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\vlc
2016-07-30 14:32 - 2016-07-03 01:28 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Oracle
2016-07-28 19:36 - 2016-01-19 12:50 - 00000000 ____D C:\Users\dbirn_000\AppData\Roaming\Epson
2016-07-28 19:17 - 2014-12-19 06:44 - 00000000 ____D C:\ProgramData\Intel
2016-07-28 19:17 - 2014-12-19 06:43 - 00000000 ____D C:\Program Files (x86)\Intel
2016-07-28 18:57 - 2016-03-27 16:41 - 00000000 ____D C:\ProgramData\Oracle
2016-07-28 18:55 - 2016-03-27 16:41 - 00000000 ____D C:\Program Files (x86)\Java
2016-07-28 18:54 - 2016-02-27 13:44 - 00000000 ___HD C:\Users\dbirn_000\.oracle_jre_usage
2016-07-28 18:53 - 2016-03-27 16:41 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-07-27 21:25 - 2016-01-14 19:00 - 00504488 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-07-27 14:16 - 2016-07-03 01:38 - 00000000 ____D C:\Users\dbirn_000\Software
2016-07-27 00:27 - 2016-03-27 16:50 - 00000000 ___HD C:\Users\dbirn_000\.mediathek3
2016-07-26 18:55 - 2016-05-28 18:50 - 00000000 ____D C:\Users\dbirn_000\Downloads\OtherDownloads
2016-07-23 17:56 - 2016-02-02 12:09 - 00000000 ____D C:\Users\dbirn_000\Downloads\NewBookScan
2016-07-22 15:17 - 2015-08-18 17:31 - 00000000 ___HD C:\Users\dbirn_000\AppData\Local\Lenovo
2016-07-22 12:13 - 2014-12-19 07:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-07-21 08:40 - 2016-05-05 18:42 - 00350464 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rtux64w10.sys
2016-07-19 18:16 - 2016-03-12 23:29 - 00000000 ____D C:\Program Files (x86)\Steam
2016-07-19 13:06 - 2016-07-03 02:00 - 00000000 ____D C:\Users\dbirn_000\.VirtualBox
2016-07-17 00:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SystemApps
2016-07-17 00:56 - 2016-07-16 13:44 - 02549760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkAnalysisLegacyCom.dll
2016-07-17 00:56 - 2016-07-16 13:44 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll
2016-07-17 00:56 - 2016-07-16 13:44 - 00268552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpendp.dll
2016-07-17 00:56 - 2016-07-16 13:44 - 00177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2016-07-17 00:56 - 2016-07-16 13:44 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfdts.dll
2016-07-17 00:56 - 2016-07-16 13:44 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rfxvmt.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 03584000 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkAnalysisLegacyCom.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsCpl.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsCpl.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mblctr.exe
2016-07-17 00:56 - 2016-07-16 13:43 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00571904 _____ (Microsoft Corporation) C:\WINDOWS\system32\msTextPrediction.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SnippingTool.exe
2016-07-17 00:56 - 2016-07-16 13:43 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2016-07-17 00:56 - 2016-07-16 13:43 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00298536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpendp.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\hwrreg.exe
2016-07-17 00:56 - 2016-07-16 13:43 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinput.exe
2016-07-17 00:56 - 2016-07-16 13:43 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsClassExtension.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DFDWiz.exe
2016-07-17 00:56 - 2016-07-16 13:43 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RotMgr.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hwrcomp.exe
2016-07-17 00:56 - 2016-07-16 13:43 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetppui.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00029536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2016-07-17 00:56 - 2016-07-16 13:43 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorPerformanceEvents.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorCustomAdbAlgorithm.dll
2016-07-17 00:56 - 2016-07-16 13:43 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnpinst.exe
2016-07-17 00:56 - 2016-07-16 13:41 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\terminpt.sys
2016-07-17 00:56 - 2016-07-16 13:41 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpbus.sys
2016-07-17 00:51 - 2016-07-16 13:44 - 12039168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0007.dll
2016-07-17 00:51 - 2016-07-16 13:44 - 12039168 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0007.dll
2016-07-17 00:51 - 2016-07-16 13:44 - 02083328 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0007.dll
2016-07-17 00:51 - 2016-07-16 13:44 - 01997312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0007.dll
2016-07-17 00:51 - 2016-07-16 13:43 - 11602432 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0007.dll
2016-07-17 00:50 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2016-07-17 00:50 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-07-17 00:50 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\setup

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2016-08-16 09:14 - 2016-08-08 03:54 - 1611776 _____ () C:\Users\dbirn_000\AppData\Roaming\ucdlr.exe
2016-08-15 18:16 - 2016-02-18 10:10 - 5267952 _____ () C:\Users\dbirn_000\AppData\Roaming\ziptool_wc-9015_setup.exe
2016-04-21 12:34 - 2016-04-21 12:34 - 0003584 _____ () C:\Users\dbirn_000\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-06-15 21:20 - 2016-06-15 21:20 - 0000017 _____ () C:\Users\dbirn_000\AppData\Local\resmon.resmoncfg
2016-08-04 17:53 - 2016-08-04 17:53 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Einige Dateien in TEMP:
====================
C:\Users\dbirn_000\AppData\Local\Temp\2UJUgehsRH.exe
C:\Users\dbirn_000\AppData\Local\Temp\4PbGHxNmSi.exe
C:\Users\dbirn_000\AppData\Local\Temp\B1B.tmp.exe
C:\Users\dbirn_000\AppData\Local\Temp\BI5R6F2ELP.exe
C:\Users\dbirn_000\AppData\Local\Temp\fL4dYHfHaS.exe
C:\Users\dbirn_000\AppData\Local\Temp\ludashisetup.exe
C:\Users\dbirn_000\AppData\Local\Temp\nsf212F.tmp.exe
C:\Users\dbirn_000\AppData\Local\Temp\PqY4Go5L1S.exe
C:\Users\dbirn_000\AppData\Local\Temp\sdf8CA8.exe
C:\Users\dbirn_000\AppData\Local\Temp\sdfFBD2.exe
C:\Users\dbirn_000\AppData\Local\Temp\X8ON6CB31V.exe
C:\Users\dbirn_000\AppData\Local\Temp\XDYY1Y9Z8P.exe


==================== Bamital & volsnap =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-08-14 21:16

==================== Ende von FRST.txt


cosinus 16.08.2016 09:37

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    Body Text Feathering

    Compress

    Lenovo Browser Guard

    trotux - Uninstall

    UC浏览器

  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 


Piristibulus 16.08.2016 09:44

Vielen Dank,
auch hier wieder meine Frage: muss das Programm online?

Ich sehe, dass der befallene Rechner ständig versucht weitere Sachen zu unternehmen (z.B. Fenster geht auf, gibt sich als Lenovo Energy Manager aus, etc.).

Da würde ich es lieber über einem USB Stick installieren.

cosinus 16.08.2016 09:46

unsere tools brauchen idR einen Zugang ins Internet

Piristibulus 16.08.2016 10:41

OK, vielen Dank!
Ich habe Revo Uninstaller laufen lassen. keine Reste
Body Text Feathering keine Reste

Compress Reste gefunden, mehrmals alle ausgewählt und gelöscht, + Meldung „ausgewählte aber nicht entfernte Dateien werden beim nächsten Systemstart entfernt“
Lenovo Browser Guard keine Reste
trotux - Uninstall Reste gefunden, alle ausgewählt und gelöscht
UC浏览器hier musste ich zunächst neu starten, weil sich das Programm aufgehängt hatte und über Task Manager geschlossen werden musste. Reste gefunden, mehrfach alle ausgewählt und gelöscht, + Meldung „ausgewählte aber nicht entfernte Dateien werden beim nächsten Systemstart entfernt“. (Ein Shortcut in der Taskleiste ist immer noch da).

cosinus 16.08.2016 10:49

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Piristibulus 16.08.2016 16:25

So, ich habe das Tool laufen lassen.

Ich habe es normal und nicht als Admin ausgeführt.
Beim ersten Durchlauf erschienen immer noch pop-ups wie "„Energy Manager User“ verwendeten noch weitere Apps , installieren", habe es immer weggeklickt.

Nach dem Neustart hatte ich war arabisches auf dem Desktop, der chinesische Link im Task Bar war weg, es gab und gibt weiterhin Shortcuts auf dem Desktop zu PC Spee Up und MPC Cleaner.

Beim zweiten Durchlauf von MBAR war ich nach dem ich die Datenbank aktualisiert und Scan geklickt hatte, kurz draussen, als ich wieder reinkam, hatte der PC neugestartet. Danach habe ich es erneut probiert.

Ein Installationsfenster für "Threadapp" ging auf, hab es weggeklickt, kurz nach dem Start von MBAR (nach dem Aktualisieren der Datenbank/bei Scan) trat ein Blue Screen Error auf.

Dann Neustart - Threadapp wegklicken - MBAR starten - blue screen

Danach Neustart - Threadapp - weggeklickt -> gewartet bluescreen.

Es kamen dabei immer Meldungen über resets der default apps für Bilder, MP3, MP4 etc.

Die Blue Screen Message ist PAGE_FAULT_IN_NON_PAGED_AREA

Daher habe ich keine Ahnung, ob der zweite Durchlauf erfolgt war, aber ich denke eher nicht.

Hier ist einstweilen das Logfile, vermutlich des ersten Durchlaufs:

Code:

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2016.08.16.06
  rootkit: v2016.08.15.01

Windows 10 x64 NTFS
Internet Explorer 11.51.14393.0
dbirn_000 :: PIRISTIBULUS [administrator]

16/08/2016 13:37:43
mbar-log-2016-08-16 (13-37-43).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 695393
Time elapsed: 1 hour(s), 43 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 3
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IPHLPSVC\PARAMETERS\PROXYMGR\{F6368126-6E4B-4323-BB0C-56C3CB44D005}|AutoConfigUrl (Hijack.AutoConfigURL.PrxySvrRST) -> Data: hxxp://stoppblock.org/wpad.dat?207b35475f43c97b15e20097d83e76ef14487478 -> Delete on reboot. [c7ff94b703971c1a9c681f9530d413ed]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES| (Hijack.AutoConfigURL.PrxySvrRST) -> Data: 0hxxp://stoppblock.org/wpad.dat?207b35475f43c97b15e20097d83e76ef14487478 -> Delete on reboot. [facc8cbf5c3e41f558a9456fc53f31cf]
HKU\S-1-5-21-528608177-3768278189-544877735-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|AutoConfigUrl (Hijack.AutoConfigURL.PrxySvrRST) -> Data: hxxp://stoppblock.org/wpad.dat?207b35475f43c97b15e20097d83e76ef14487478 -> Delete on reboot. [ac1a69e2059566d0fc064e6621e3639d]

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 13
C:\WINDOWS\SYSTEM32\drivers\MPCKpt.sys (PUP.Optional.MorePowerfulCleaner) -> Delete on reboot. [b66a551d00e41d5416f4cb5497926238]
C:\$Recycle.Bin\S-1-5-21-528608177-3768278189-544877735-1001\$RWZYZ9V\uninstall.exe (Adware.Agent) -> Delete on reboot. [f7cf99b246543105bc1794d769996799]
C:\Users\dbirn_000\AppData\Local\Temp\fL4dYHfHaS.exe (Trojan.Agent) -> Delete on reboot. [1caa0645039734028dc23e8f8b79c33d]
C:\Windows\Temp\8DC1.tmp (Adware.ConvertAd) -> Delete on reboot. [61650b40d4c604322fa571fa1ee4f30d]
C:\Users\dbirn_000\AppData\Local\Temp\1.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [f1d594b71e7cc175934116a910f3be42]
C:\Users\dbirn_000\AppData\Local\Temp\2.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [8244a2a9544683b32ea66e51d92a48b8]
C:\Users\dbirn_000\AppData\Local\Temp\3.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [14b2fe4d3e5c2c0a0ec607b8a75c01ff]
C:\Users\dbirn_000\AppData\Local\Temp\4.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [794da1aa89117cba587c3f8028db7987]
C:\Users\dbirn_000\AppData\Local\Temp\5.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [7c4a91ba2c6ede58b22286399a6940c0]
C:\Users\dbirn_000\AppData\Local\Temp\6.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [8a3c16352971c27474608936b1523bc5]
C:\Users\dbirn_000\AppData\Local\Temp\7.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [854197b41e7cde58ddf74a75ff047c84]
C:\Users\dbirn_000\AppData\Local\Temp\8.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [b5114704ebaf51e52ca84e71a65d08f8]
C:\Users\dbirn_000\AppData\Local\Temp\9.tmp.exe (Trojan.Agent.E) -> Delete on reboot. [53737dce1486e65006cee2ddcc37758b]

Physical Sectors Detected: 0
(No malicious items detected)

(end)


cosinus 16.08.2016 21:10

MBAR wiederholen

Piristibulus 16.08.2016 21:35

Habe es mehrfach versucht ...
Aber immer bekomme ich nach ein paar Sekungen einen Blue Scree und der PC stürzt ab.
:-(

cosinus 16.08.2016 21:38

Dann bitte das hier:

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Piristibulus 16.08.2016 22:13

Nach mehreren Versuchen, mit Absturz wegen Blue Screen Error hat es geklappt.

Hier das Log in zwei Teilen, da zu lang:
Teil 1:

Code:

22:57:18.0685 0x25c0  TDSS rootkit removing tool 3.1.0.11 Aug  5 2016 12:13:31
22:57:18.0685 0x25c0  UEFI system
22:57:24.0665 0x25c0  ============================================================
22:57:24.0665 0x25c0  Current date / time: 2016/08/16 22:57:24.0665
22:57:24.0665 0x25c0  SystemInfo:
22:57:24.0665 0x25c0 
22:57:24.0665 0x25c0  OS Version: 10.0.14393 ServicePack: 0.0
22:57:24.0665 0x25c0  Product type: Workstation
22:57:24.0665 0x25c0  ComputerName: PIRISTIBULUS
22:57:24.0665 0x25c0  UserName: dbirn_000
22:57:24.0665 0x25c0  Windows directory: C:\WINDOWS
22:57:24.0665 0x25c0  System windows directory: C:\WINDOWS
22:57:24.0665 0x25c0  Running under WOW64
22:57:24.0665 0x25c0  Processor architecture: Intel x64
22:57:24.0665 0x25c0  Number of processors: 4
22:57:24.0665 0x25c0  Page size: 0x1000
22:57:24.0665 0x25c0  Boot type: Normal boot
22:57:24.0665 0x25c0  CodeIntegrityOptions = 0x00000001
22:57:24.0665 0x25c0  ============================================================
22:57:24.0887 0x25c0  KLMD registered as C:\WINDOWS\system32\drivers\73693984.sys
22:57:24.0887 0x25c0  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.0, osProperties = 0x19
22:57:26.0120 0x25c0  System UUID: {AB828E4B-EBEB-47F5-2012-287CB0E5DAFF}
22:57:26.0803 0x25c0  Drive \Device\Harddisk0\DR0 - Size: 0x773C256000 ( 476.94 Gb ), SectorSize: 0x200, Cylinders: 0xF334, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:57:27.0621 0x25c0  Drive \Device\Harddisk1\DR1 - Size: 0x3C000000 ( 0.94 Gb ), SectorSize: 0x200, Cylinders: 0x7A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
22:57:27.0624 0x25c0  ============================================================
22:57:27.0624 0x25c0  \Device\Harddisk0\DR0:
22:57:27.0627 0x25c0  GPT partitions:
22:57:27.0629 0x25c0  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {E6872534-D39F-4D51-8C56-5F8712CF9DA8}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x1F4000
22:57:27.0629 0x25c0  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {5C79513C-CE8A-40B2-86C8-9FA5F40CD90A}, Name: EFI system partition, StartLBA 0x1F4800, BlocksNum 0x82000
22:57:27.0629 0x25c0  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {C0D64BCB-BDF7-4415-A319-1D596DBF4079}, Name: Basic data partition, StartLBA 0x276800, BlocksNum 0x1F4000
22:57:27.0629 0x25c0  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {FD746D6F-AD8C-45A7-991E-733D5D5E8104}, Name: Microsoft reserved partition, StartLBA 0x46A800, BlocksNum 0x40000
22:57:27.0629 0x25c0  \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {7A4D5883-94A9-4C84-849E-B3024501E368}, Name: Basic data partition, StartLBA 0x4AA800, BlocksNum 0x36680000
22:57:27.0629 0x25c0  \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {15ACFF03-364A-4884-8546-CCDA62724C1B}, Name: Basic data partition, StartLBA 0x36B2A800, BlocksNum 0x3200000
22:57:27.0629 0x25c0  \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {EE765799-E795-4301-A97C-831049B7F01E}, Name: Basic data partition, StartLBA 0x39D2A800, BlocksNum 0x1CB6800
22:57:27.0630 0x25c0  MBR partitions:
22:57:27.0630 0x25c0  \Device\Harddisk1\DR1:
22:57:27.0630 0x25c0  MBR partitions:
22:57:27.0630 0x25c0  \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x80, BlocksNum 0x1DFF80
22:57:27.0630 0x25c0  ============================================================
22:57:27.0631 0x25c0  C: <-> \Device\Harddisk0\DR0\Partition5
22:57:27.0632 0x25c0  D: <-> \Device\Harddisk0\DR0\Partition6
22:57:27.0632 0x25c0  ============================================================
22:57:27.0632 0x25c0  Initialize success
22:57:27.0632 0x25c0  ============================================================
22:57:33.0226 0x28a0  ============================================================
22:57:33.0226 0x28a0  Scan started
22:57:33.0226 0x28a0  Mode: Manual; SigCheck; TDLFS;
22:57:33.0226 0x28a0  ============================================================
22:57:33.0226 0x28a0  KSN ping started
22:57:33.0337 0x28a0  KSN ping finished: true
22:57:33.0876 0x28a0  ================ Scan system memory ========================
22:57:33.0876 0x28a0  System memory - ok
22:57:33.0876 0x28a0  ================ Scan services =============================
22:57:33.0945 0x28a0  [ A7901875F89D011C38CF52C98ACF5B29, 782141AB1DD7ACDE6EA08B5BAFDE8BADD05B81D38C18E097D6D9C46102056EB1 ] 1394ohci        C:\WINDOWS\System32\drivers\1394ohci.sys
22:57:34.0061 0x28a0  1394ohci - ok
22:57:34.0077 0x28a0  [ EE1CCC54F75C24727A218F98FC5349DA, 0B0D26640BFA0F551B7087027E572D0BF2C5EAF50A4187C5A7D839180B7FF589 ] 3ware          C:\WINDOWS\system32\drivers\3ware.sys
22:57:34.0108 0x28a0  3ware - ok
22:57:34.0141 0x28a0  [ 73C73E1AA0D4D727A04AAAB120B7F56A, 5D311F11022994410DF5C67914D38B1F0D813EFD181EA234750286A272D67A1A ] ACPI            C:\WINDOWS\system32\drivers\ACPI.sys
22:57:34.0177 0x28a0  ACPI - ok
22:57:34.0177 0x28a0  [ 0935496EF9624B46B935CB35ECE1F205, A22A2A29195505A65E8626D60B00C86C23E0CABC1EB8345EA5ED523516CC21C0 ] AcpiDev        C:\WINDOWS\System32\drivers\AcpiDev.sys
22:57:34.0208 0x28a0  AcpiDev - ok
22:57:34.0208 0x28a0  [ D6794C31F4077B71433988787BAA926E, F16365C2F195AAE94D4740E6C3DF4C0CECEC6393CAD65425DCCD28CDBA6EC51A ] acpiex          C:\WINDOWS\system32\Drivers\acpiex.sys
22:57:34.0244 0x28a0  acpiex - ok
22:57:34.0246 0x28a0  [ FE5F656D6B35089DA39112E74EC6A85A, 5D81EE63998232A5B36DE47FE15B9D04D5BD02234CA133A2462AECA8C60A22ED ] acpipagr        C:\WINDOWS\System32\drivers\acpipagr.sys
22:57:34.0261 0x28a0  acpipagr - ok
22:57:34.0277 0x28a0  [ 2F242941E4DFF69B883D77A16F039557, 45C388365317C720654A659A9326B2BC0E9D84929C704654985597D5D620101C ] AcpiPmi        C:\WINDOWS\System32\drivers\acpipmi.sys
22:57:34.0308 0x28a0  AcpiPmi - ok
22:57:34.0308 0x28a0  [ C247E35A21682DA8D0DC3AF9F025FCC5, 455415EE3166B3043AD8A4DD50B688DB74242267FB555642441251EFA823E971 ] acpitime        C:\WINDOWS\System32\drivers\acpitime.sys
22:57:34.0344 0x28a0  acpitime - ok
22:57:34.0377 0x28a0  [ AF7A18603B0B82DFA5B420456FAF2201, 64AD831433778BB0B0B1615EEA7682960ED5815A091A9EFEE95A862EFBDE6D69 ] ACPIVPC        C:\WINDOWS\System32\drivers\AcpiVpc.sys
22:57:34.0409 0x28a0  ACPIVPC - ok
22:57:34.0424 0x28a0  [ 68E7DEA59FDEF410BAF29FDB5B7A6EEF, B808FCF0C30B465A1330E47947B84FC722A3B4C46260E261C54B1EED725A288F ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:57:34.0443 0x28a0  AdobeARMservice - ok
22:57:34.0462 0x28a0  [ 32B31B696CB8E8F380831DFEB80A67E4, 8C8F6E16F2FB3E8F10569261B7712BBC931A2924B6C27D561E7F828041C4F3E6 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:57:34.0493 0x28a0  AdobeFlashPlayerUpdateSvc - ok
22:57:34.0542 0x28a0  [ 49B9DB97AFC85DCCBDACDAB2E90085B7, 2A6C2A09F74EA15044F442CCFB54A0F24F105ADB915E5C78F02F59652DC29152 ] ADP80XX        C:\WINDOWS\system32\drivers\ADP80XX.SYS
22:57:34.0609 0x28a0  ADP80XX - ok
22:57:34.0625 0x28a0  [ 983266DA83FFF73DBDDD3730A4712228, 433A2731DAC687C52FB7E23093B8E11D92CCCF4C35B493D73AC30C6A4A6D2A6C ] AFD            C:\WINDOWS\system32\drivers\afd.sys
22:57:34.0663 0x28a0  AFD - ok
22:57:34.0744 0x28a0  [ 9A53CCE5A15CFB948CD9D3D1A79282DC, 1FC8422C43400E550414448F64290DA6DB0E0A0C03D88BCBDA0EDA5FD7B2EFBB ] AGSService      C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
22:57:34.0825 0x28a0  AGSService - ok
22:57:34.0825 0x28a0  [ E44DB3F7225EC3E119560738B3619972, 32946FBC2BD74072F22E48D769A034183F6C3728FCCC3CF0DD561602511E39B2 ] ahcache        C:\WINDOWS\system32\DRIVERS\ahcache.sys
22:57:34.0863 0x28a0  ahcache - ok
22:57:34.0863 0x28a0  [ D0905D4A945D01D4B28DB9E1BD5985F7, CF389CBCD3B99D1BAE34A42F723F1005C32213A394F691978076D3DF1727715C ] AJRouter        C:\WINDOWS\System32\AJRouter.dll
22:57:34.0894 0x28a0  AJRouter - ok
22:57:34.0894 0x28a0  [ 8FD51B3B35707A66080D7C8CB05E792D, FE52F3DC280D208FDDC75F6E3294B8D601E0D86F9BD3DB1ACC8FC296AC74C23B ] ALG            C:\WINDOWS\System32\alg.exe
22:57:34.0926 0x28a0  ALG - ok
22:57:34.0947 0x28a0  [ DF21E05E41E5AC3F13F304D91457649A, 7F48F2AD1DBE89A261113C76D7C23AD7D87D5599BCC31F8A558A8A10B81BF521 ] AmdK8          C:\WINDOWS\System32\drivers\amdk8.sys
22:57:34.0963 0x28a0  AmdK8 - ok
22:57:34.0979 0x28a0  [ 45D0AA4BB90B821DF92E8F19ABED0C5E, EA87A6E98DB3C5A88A844C04C6934E870B7004E783AA5211722115382A211B90 ] AmdPPM          C:\WINDOWS\System32\drivers\amdppm.sys
22:57:34.0994 0x28a0  AmdPPM - ok
22:57:35.0010 0x28a0  [ 74FFBC43B4B899C9A8CA06A892F2CE73, 8D599363C7F3D373F1859BAA4D06DD0F40BE78B56BE52B74DE6EA6EF99452004 ] amdsata        C:\WINDOWS\system32\drivers\amdsata.sys
22:57:35.0026 0x28a0  amdsata - ok
22:57:35.0026 0x28a0  [ AAB0F1D8D7E54761ABAB13AF161F1680, CF847990EFFA2828F5B1DB1A68F08A6C2C918E9612EDFFCF95C36BCABBBEA272 ] amdsbs          C:\WINDOWS\system32\drivers\amdsbs.sys
22:57:35.0063 0x28a0  amdsbs - ok
22:57:35.0063 0x28a0  [ F91BAAC4237C40352A807000F3B716F9, F7EFA08E5067C3D419C9D21EDB880BA08883A80DDF35F8B42EC3AB293FE5E03E ] amdxata        C:\WINDOWS\system32\drivers\amdxata.sys
22:57:35.0079 0x28a0  amdxata - ok
22:57:35.0095 0x28a0  [ BC121C099C6C659126AD2102AFDFF8CF, 42B5EE293BDD7ADCE48173A01B30D8452564B9DA225EAF25E9292FE77C0FCF3E ] AppID          C:\WINDOWS\system32\drivers\appid.sys
22:57:35.0110 0x28a0  AppID - ok
22:57:35.0126 0x28a0  [ 74A24CF946279111D7F203B36569EC02, FD67D36804744B4FE3E20BA891852575E6C2DA6515643B2F4B4210118B0FCCDA ] AppIDSvc        C:\WINDOWS\System32\appidsvc.dll
22:57:35.0148 0x28a0  AppIDSvc - ok
22:57:35.0148 0x28a0  [ 008E4CCA7A4B33042276061E0A5B8244, DAD980540B564EFA06760435AF1B3213056E6DE8B2A55DF98E7D871625D4B080 ] Appinfo        C:\WINDOWS\System32\appinfo.dll
22:57:35.0179 0x28a0  Appinfo - ok
22:57:35.0195 0x28a0  [ 68190E2BADF23BD782344970E5B5DE9E, 95D30EC12C7FDF5822CED8BC2F17669A6687A2FB262B4F0D15C8DCFF4E9AB33D ] applockerfltr  C:\WINDOWS\system32\drivers\applockerfltr.sys
22:57:35.0211 0x28a0  applockerfltr - ok
22:57:35.0245 0x28a0  [ 41BF82B41BD24BAC9D9890DAC3212007, 0644BEE740244188B3D39F875D313B560D288B7FC33064E352C2A5F09073E361 ] AppReadiness    C:\WINDOWS\system32\AppReadiness.dll
22:57:35.0295 0x28a0  AppReadiness - ok
22:57:35.0364 0x28a0  [ 757646A22C2E9BC21E6A50842FE79139, 6AEBD3486F79C55154D677204D0CCB8179DAFC90941A743D277B44C1EED9DB12 ] AppXSvc        C:\WINDOWS\system32\appxdeploymentserver.dll
22:57:35.0480 0x28a0  AppXSvc - ok
22:57:35.0496 0x28a0  [ E6AB1F0B4C3D4E0D2A88332D76FECD03, 0D3003EB979DA4546DCDD055011E24F13E34F683F02C9801CAC564D1809F11D2 ] arcsas          C:\WINDOWS\system32\drivers\arcsas.sys
22:57:35.0511 0x28a0  arcsas - ok
22:57:35.0546 0x28a0  [ 5EE26734A882478AF6696092E2E0F352, 6CACFF521B3B839F73EBEB6EFBFDCCA8A8BC319DDB254BE3EFE29A39040B2C26 ] aspnet_state    C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
22:57:35.0549 0x28a0  aspnet_state - ok
22:57:35.0565 0x28a0  [ 61C5A480C43E7E8E49C42869F49D0D3E, E610F0E4315ABA1D90AD4A1D7A68ABA2ACBB7FCA89E9D1798470365D52592D55 ] AsyncMac        C:\WINDOWS\System32\drivers\asyncmac.sys
22:57:35.0596 0x28a0  AsyncMac - ok
22:57:35.0596 0x28a0  [ A10F989A812B57B9695F6C305907C9C6, E2B292610079AA1A10696138DE8130905A8A834B75A8DED7EBF8B6732B77A0F4 ] atapi          C:\WINDOWS\system32\drivers\atapi.sys
22:57:35.0627 0x28a0  atapi - ok
22:57:35.0648 0x28a0  [ 5D637DF654D6386487876ADF5AF301B3, 7B53356237369D892F5BBEA9C967B20DCA40FA2B6B3C5AF7A4304FFD00DF1BFC ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
22:57:35.0680 0x28a0  AudioEndpointBuilder - ok
22:57:35.0712 0x28a0  [ 57CEE51D9D84870F93D404302705A054, 14364B9798E9FE3F8A42109D749804795FA507C1A7D535DC17876ECCD47644E9 ] Audiosrv        C:\WINDOWS\System32\Audiosrv.dll
22:57:35.0782 0x28a0  Audiosrv - ok
22:57:35.0791 0x28a0  [ 6D90FDA2DC364B8EA1420F2F81585CC3, 10E6F23A213CFE49BE04BB7D366ADD4028D61D7114FEC67C30B5467DF6B36D4F ] AxInstSV        C:\WINDOWS\System32\AxInstSV.dll
22:57:35.0815 0x28a0  AxInstSV - ok
22:57:35.0831 0x28a0  [ 61BAC67048CA5C1D08C48FCC8012B613, 71B2A466FC38DA1029B471FBD2541D8FE359751A7B212AE0F420DB3645916450 ] b06bdrv        C:\WINDOWS\system32\drivers\bxvbda.sys
22:57:35.0894 0x28a0  b06bdrv - ok
22:57:35.0899 0x28a0  [ 68F72B05EBC6D1779C0D60A147C7CA0B, AA1C857BEE34865C6B901157FC22570D4CF45D950708BAD7AA333F120F2B474C ] BasicDisplay    C:\WINDOWS\System32\drivers\BasicDisplay.sys
22:57:35.0931 0x28a0  BasicDisplay - ok
22:57:35.0931 0x28a0  [ 23156E7EDAF613D839E2839746B168D3, CAEF8F9C7D3A338BD747AC9D5BFBE730D77B911E87BCF532EBB75E1F80916AFA ] BasicRender    C:\WINDOWS\System32\drivers\BasicRender.sys
22:57:35.0947 0x28a0  BasicRender - ok
22:57:35.0962 0x28a0  [ 3F5523DCEFE42B385659C5CB46A6B810, CA24A3DF002B19E7BDEDE9B5EB60623F299D0E78B2E4F58DCFC028D76DEFE52D ] bcmfn          C:\WINDOWS\System32\drivers\bcmfn.sys
22:57:35.0995 0x28a0  bcmfn - ok
22:57:36.0000 0x28a0  [ 0B750A6A6D847E73CA48ADD7A0F5A393, 6A43020F23846EFB1AFA3C070465B0059E9DF60DEB16899E09559462DF30939F ] bcmfn2          C:\WINDOWS\System32\drivers\bcmfn2.sys
22:57:36.0016 0x28a0  bcmfn2 - ok
22:57:36.0031 0x28a0  [ D4EFDA0D56429018281F8F3188E6F86C, 020B861338BAF8E2A861CA1D2D22640CCD39BA84F18260F9862F7E3AC5014985 ] BDESVC          C:\WINDOWS\System32\bdesvc.dll
22:57:36.0078 0x28a0  BDESVC - ok
22:57:36.0078 0x28a0  [ 0A508274355745EEF01C6BE3198D02C4, E2DB08AEE2368FA95FDB357BB31EA4EBF31679C3E72E109DB3D7CD1B5F7B828E ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
22:57:36.0100 0x28a0  Beep - ok
22:57:36.0131 0x28a0  [ 5125CBB61AC81168366BEB290399CB8E, B2A3095D45E2114DE2BD0E5A3AE20B3CE95EE517A35B9E1EAD05E231F38DBDCF ] BFE            C:\WINDOWS\System32\bfe.dll
22:57:36.0200 0x28a0  BFE - ok
22:57:36.0232 0x28a0  [ D99CD8421A546B5AC727CD947C61DC83, E5DD081CB7D8FB6891277D4DEB34B003C04EEF236462E2FCAE35D131F580C10D ] BITS            C:\WINDOWS\System32\qmgr.dll
22:57:36.0316 0x28a0  BITS - ok
22:57:36.0332 0x28a0  [ EEBFAEB4702E1049ECD44B10485E6C0C, 8F4D31E36717101B6172D7346E86EBC77B9CDAA5CC14AA1379661C16A7FF05E2 ] bowser          C:\WINDOWS\system32\DRIVERS\bowser.sys
22:57:36.0363 0x28a0  bowser - ok
22:57:36.0399 0x28a0  [ 78C35DD7CF780428650B1EE9B0F8D41E, C5A3111383CD9813A4ED33E244E20E2E0607CDEFC5BF00A760F63DAD019EE90E ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
22:57:36.0479 0x28a0  BrokerInfrastructure - ok
22:57:36.0501 0x28a0  [ B3F32C630DD3F2F6A6091B89CFF13641, 7A9C53EF9AB9FF1DC392FD711B194A101DB36CA5BC799E817BEB446741089B76 ] Browser        C:\WINDOWS\System32\browser.dll
22:57:36.0533 0x28a0  Browser - ok
22:57:36.0533 0x28a0  [ 722036C26D2C4E50EC2A2EC5FD678846, 999468038AE01F0FF6881F4B2A2CB67BC636641188E95F10729E08ADBC3CB3DE ] BthAvrcpTg      C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
22:57:36.0564 0x28a0  BthAvrcpTg - ok
22:57:36.0564 0x28a0  [ FF218FBB511B733F8A6829FB17CA972D, 05BB1C3BFE189549E78A02C5C0C0C832C248680668D821F92FE7B6B39DC111A0 ] BthEnum        C:\WINDOWS\System32\drivers\BthEnum.sys
22:57:36.0601 0x28a0  BthEnum - ok
22:57:36.0601 0x28a0  [ C2E31BE025D46D189E38DD1EDF07837A, 656528DCAAAF485EC57EE5C3021E96736634DE3B9C39CBCD2728E055ABD4C0A5 ] BthHFEnum      C:\WINDOWS\System32\drivers\bthhfenum.sys
22:57:36.0648 0x28a0  BthHFEnum - ok
22:57:36.0648 0x28a0  [ F7CD605FC0B0B22F3F6F247595E3A655, 1CD9140DE5415DDBEACD8667E63E5C95FD64D693B56302A0474E693E578BEAB0 ] bthhfhid        C:\WINDOWS\System32\drivers\BthHFHid.sys
22:57:36.0699 0x28a0  bthhfhid - ok
22:57:36.0717 0x28a0  [ B157D72BDA6A6DD6E9DC6BF338CD0CF8, B2AC26AE214151E5AD93DED78256BC0295DBF0133C854E7DEE4CD776D9C9A349 ] BthHFSrv        C:\WINDOWS\System32\BthHFSrv.dll
22:57:36.0749 0x28a0  BthHFSrv - ok
22:57:36.0764 0x28a0  [ 8EDA0733FF6266C2FB26BCE0B4AA8B15, F60BE5630EE714B718233933DC6101130DF672A01F99C7389D0708BC00E8D5DF ] BthLEEnum      C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
22:57:36.0801 0x28a0  BthLEEnum - ok
22:57:36.0802 0x28a0  [ 535DC41A33630AE4C262406F9E981C03, 599332589AA28D04189E19B87A4AE6FEEB60B40A7BC6E3B11240DA363A981C29 ] BTHMODEM        C:\WINDOWS\System32\drivers\bthmodem.sys
22:57:36.0818 0x28a0  BTHMODEM - ok
22:57:36.0833 0x28a0  [ D2A121586B660311B09964D2A6DDF864, 539953D953D40014366918BB38FADD3F21417EF8ADA532E1ABD1824949B952D4 ] BthPan          C:\WINDOWS\System32\drivers\bthpan.sys
22:57:36.0849 0x28a0  BthPan - ok
22:57:36.0880 0x28a0  [ E465D7F6F3E4CA9F0E5FB6FD346F2F3D, 8F01051202903E8E16A6AE42B3F5F900C4D0B021311AE44225E8D11BE48DB129 ] BTHPORT        C:\WINDOWS\system32\DRIVERS\BTHport.sys
22:57:36.0949 0x28a0  BTHPORT - ok
22:57:36.0965 0x28a0  [ 96932F631F5CB9F5D1C8F99A71568EF3, 5E4C8955A2EE9DC76B4EBC383653EB753D76D6B017E1A5DD553AC16094D7F12A ] bthserv        C:\WINDOWS\system32\bthserv.dll
22:57:37.0014 0x28a0  bthserv - ok
22:57:37.0022 0x28a0  [ 7E844E3B520CA7873674D36286BC380F, 8B2A079B59625754D4CDFC486FC606B036B063DB382F6449A0CB69C5675F7A8A ] BTHUSB          C:\WINDOWS\system32\DRIVERS\BTHUSB.sys
22:57:37.0055 0x28a0  BTHUSB - ok
22:57:37.0061 0x28a0  [ 23F9EF739F685E07482116425E7879AA, 0EBDF96A49A319C0BCF6F51FB6C8C392C017E1738B950C19C91FF43E14D73143 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys
22:57:37.0101 0x28a0  buttonconverter - ok
22:57:37.0263 0x28a0  [ 072F43B6B6F8824B971FE503F9E7CB83, 9CDF5127C656A9A94402DE69497F5E5101C5BBEA087C364D47A3322462955E64 ] Canon Driver Information Assist Service C:\Program Files\Canon\DIAS\CnxDIAS.exe
22:57:37.0662 0x28a0  Canon Driver Information Assist Service - ok
22:57:37.0676 0x28a0  [ 4C61113687EB66035A70A55EE9B7DB4A, 3339821A3853B90F3B468470493A813053D82014E2677E726C16E19AABE2A440 ] CapImg          C:\WINDOWS\System32\drivers\capimg.sys
22:57:37.0713 0x28a0  CapImg - ok
22:57:37.0720 0x28a0  [ F8FB51B9EF6372610E9B31A1D86B62FC, 7461584A8B39AC549AD7BAFFA509D4CD81EEE542808BC8EFC285863A0AE6432D ] cdfs            C:\WINDOWS\system32\DRIVERS\cdfs.sys
22:57:37.0748 0x28a0  cdfs - ok
22:57:37.0762 0x28a0  [ 7AD576CF28F1E7AEFC3D6E8279DF84F6, 1F7E26F9354B543881E940F5183086AC00684CDC0AB7A797E1F0AB21C4AD8716 ] CDPSvc          C:\WINDOWS\System32\CDPSvc.dll
22:57:37.0812 0x28a0  CDPSvc - ok
22:57:37.0825 0x28a0  [ 0415CA08674F64D63329CB51D4004685, 12F3AB9A263F2E131F4969E6CED2AE6DD7AF06C10AF02923256FF4C9E34698BF ] CDPUserSvc      C:\WINDOWS\System32\CDPUserSvc.dll
22:57:37.0880 0x28a0  CDPUserSvc - ok
22:57:37.0893 0x28a0  [ 613D0137C269187FA298A157E3D14A18, 84BC268525F14BB27202CE242BF94D9E83BC91B50A0335908574F31B29A2F04D ] cdrom          C:\WINDOWS\System32\drivers\cdrom.sys
22:57:37.0938 0x28a0  cdrom - ok
22:57:37.0948 0x28a0  [ 9450FA11E9DE6715FCB71A519A8FF90B, B7E341C6E4CE967FCDD0D17A497C07E8A1C6B0AACE8A6E8E5D6C21EF73F13E16 ] CertPropSvc    C:\WINDOWS\System32\certprop.dll
22:57:37.0993 0x28a0  CertPropSvc - ok
22:57:38.0006 0x28a0  [ 0AED948DA8D5F08B3D6F12E4E2089736, 95E538E81DDBC83492C5F3820C82C78F050B4D74ACF12D7970EC84F93581AE29 ] cht4iscsi      C:\WINDOWS\system32\drivers\cht4sx64.sys
22:57:38.0049 0x28a0  cht4iscsi - ok
22:57:38.0121 0x28a0  [ 0002A0FDE087C1657AB31CE73077539C, 4DD6210B67E9633AB3240371590869DC833A4C986C74FC12A5D4FFFFD361848A ] cht4vbd        C:\WINDOWS\System32\drivers\cht4vx64.sys
22:57:38.0213 0x28a0  cht4vbd - ok
22:57:38.0236 0x28a0  [ 6B4F90A287D75CCD78694F6790C911B2, 73D7C31E9F475FA3FD568FCA9A953F968729AA114F63C06F38BF5198DAD67BD8 ] circlass        C:\WINDOWS\System32\drivers\circlass.sys
22:57:38.0265 0x28a0  circlass - ok
22:57:38.0279 0x28a0  [ 09D0B94D3A06EFD1EB70189EC4B26DF7, 47E73C536C63F4C21E4ADBB122A152D3A291CF4EDD4CB4D07D09D14E1A9961F1 ] CLFS            C:\WINDOWS\system32\drivers\CLFS.sys
22:57:38.0309 0x28a0  CLFS - ok
22:57:38.0383 0x28a0  [ F6541F3D7FAF912F52AAE4398757084E, 1C573949C115B0A371236B791BB748FFFC4E7B12CA4D4ACD23110AF6082625FA ] ClickToRunSvc  C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
22:57:38.0503 0x28a0  ClickToRunSvc - ok
22:57:38.0530 0x28a0  [ E133CFCBFABB3CB517BE9F42FEA5887C, DA699CDD5F3CC427354540C907BD24CCA7BAC3112C53918EB611CB4EEC7611DA ] ClipSVC        C:\WINDOWS\System32\ClipSVC.dll
22:57:38.0574 0x28a0  ClipSVC - ok
22:57:38.0581 0x28a0  [ EEC3A4A98AE1A337E3CD1483AD6F2E15, 764DA329984A95E092F5C15116DA34FA7FC27216C0862365D4BF10ADC97EC5C5 ] clreg          C:\WINDOWS\System32\drivers\registry.sys
22:57:38.0609 0x28a0  clreg - ok
22:57:38.0625 0x28a0  [ 3E76A1547F2448BCEE3D2F4AE3931AB5, 31B41723FAA4210A86B1AE02D6C052BD8B738C4B89FB0177C1AE997D24BA5B8C ] CLVirtualDrive  C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys
22:57:38.0640 0x28a0  CLVirtualDrive - ok
22:57:38.0646 0x28a0  [ 429623E266EF067A44E8CF148E9DFB9B, A48AA85ACC52C7AD73DB2D6148B3F9FB5EAC33C8F8C5BB6D7D0A9D84B7C08E11 ] CmBatt          C:\WINDOWS\System32\drivers\CmBatt.sys
22:57:38.0680 0x28a0  CmBatt - ok
22:57:38.0700 0x28a0  [ E09C3E2CD29727AAC0977E1A7CE0425E, 86BC9C4306861D104A0F87E9C6E3E7A972488C80DD399A983397FF0312292DA3 ] CNG            C:\WINDOWS\system32\Drivers\cng.sys
22:57:38.0740 0x28a0  CNG - ok
22:57:38.0746 0x28a0  [ 3DB10C59405931E2C72EFB82C1AF97D1, 100B5450A70988DB1C1F8A5FDBB3553AF1A0D47B42A5AC71460DB92E26010CE6 ] cnghwassist    C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
22:57:38.0764 0x28a0  cnghwassist - ok
22:57:38.0779 0x28a0  [ 34C935AF2A414572B412B3556586D783, 912981B88B0796576ECCD5EBE0C4728EC02D5D6A96B039447DCBA59B2583F25E ] CompositeBus    C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys
22:57:38.0804 0x28a0  CompositeBus - ok
22:57:38.0810 0x28a0  [ 5FADE7137C14A94B323F3B7886FBA2A9, 66F851B309BADA6D3E4B211BAA23B534165B29BA16B5CBF5E8F44EAEB3CA86EA ] ComputerZ_x64  C:\Program Files (x86)\LuDaShi\ComputerZ_x64.sys
22:57:38.0825 0x28a0  ComputerZ_x64 - ok
22:57:38.0830 0x28a0  COMSysApp - ok
22:57:38.0836 0x28a0  [ 44EEEB2382F566999287E13F2067693C, 53A4A0C85EAD38030FF2078C67465E3710ECD03A08FF34E1E67B2E3E1CC70043 ] condrv          C:\WINDOWS\system32\drivers\condrv.sys
22:57:38.0854 0x28a0  condrv - ok
22:57:38.0878 0x28a0  [ 9CE94A05A5BA6A92013CAD1B924B1EC2, 19ECE2C607BAE5DCE7ED4AB46722E63EF834B219716F3A90AF661C02B58088C4 ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll
22:57:38.0922 0x28a0  CoreMessagingRegistrar - ok
22:57:38.0952 0x28a0  [ C46BAFE2828011F51B57E59DE4D4FECA, 14BAC9D350EBF95867455F36260C8E644A863CC1BC8A2A6CACA9D519091695FE ] cphs            C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
22:57:39.0050 0x28a0  cphs - ok
22:57:39.0050 0x28a0  [ 5F06CAC4B09250CDDDD0180A08162924, A2EB0A57225E65FC264CFC9FAD858D8B54A015CDAE3DC904B1C4E9AAB40B1F06 ] CryptSvc        C:\WINDOWS\system32\cryptsvc.dll
22:57:39.0065 0x28a0  CryptSvc - ok
22:57:39.0081 0x28a0  [ 68B1E0DA1BB1680494227E88CE821E2F, DE9AFCE4CC28F3484180D6A63FBBDA5B89F208E056BD17870C074094159ED6AF ] dam            C:\WINDOWS\system32\drivers\dam.sys
22:57:39.0081 0x28a0  dam - ok
22:57:39.0096 0x28a0  dbupdate - ok
22:57:39.0096 0x28a0  dbupdatem - ok
22:57:39.0112 0x28a0  [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
22:57:39.0166 0x28a0  DcomLaunch - ok
22:57:39.0181 0x28a0  [ AE9F09F87755C18904656CB4F59F351D, B352A43B3B68B497D87B49C302AF3F37F36D56D49878AE3785C3D43597E5DC57 ] DcpSvc          C:\WINDOWS\system32\dcpsvc.dll
22:57:39.0212 0x28a0  DcpSvc - ok
22:57:39.0234 0x28a0  [ EB493F82365D3E1CD21379268BAFA3A2, 27FCDFE37D7AF8E046F99BA9AA1F6EDE8F4E08689EB3B5DC9731C3DB4CAADA2D ] ddkmd          C:\WINDOWS\system32\drivers\ddkmd.sys
22:57:39.0312 0x28a0  ddkmd - ok
22:57:39.0312 0x28a0  [ FC89D0D4F589DD3A9E2FDC5F0E0273A5, 85F338F6BE4F63AD37B19A5059DD7449C80A7639C880A1E6BF55DAC5D7243158 ] ddkmdldr        C:\WINDOWS\system32\drivers\ddkmdldr.sys
22:57:39.0397 0x28a0  ddkmdldr - ok
22:57:39.0435 0x28a0  [ 64E8BD4FEDF726C2D6054FA5838F3831, 4F74BAC2D66FC56F1F0DB573F7FE8EDFC36A608100B01CEEC40502D1B838DD8C ] ddmgr          C:\WINDOWS\system32\ddmgr.exe
22:57:39.0535 0x28a0  ddmgr - ok
22:57:39.0551 0x28a0  [ 361A95B67CB826E644A72377033C8CD2, 303A5BB8CE4855B25E4F16ADD7F0531B66E8C00B26404E036FE5D438DB112760 ] deciqyguzbt    C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\knsd9A99.tmp
22:57:39.0598 0x28a0  deciqyguzbt - detected UnsignedFile.Multi.Generic ( 1 )
22:57:39.0797 0x28a0  deciqyguzbt ( UnsignedFile.Multi.Generic ) - warning
22:57:39.0797 0x28a0  Force sending object to P2P due to detect: deciqyguzbt
22:57:40.0082 0x28a0  Object send P2P result: true
22:57:40.0347 0x28a0  [ ABBD3EE724117242E28D31F19FBCFF03, 68EA91A969DD80A5DE28B0A8EAEB308837183713559C2C2FAEF991858C971393 ] defragsvc      C:\WINDOWS\System32\defragsvc.dll
22:57:40.0401 0x28a0  defragsvc - ok
22:57:40.0417 0x28a0  [ 78658EBDAD59E17ACC3569C8451F07B3, 629A014AF4E306C167B4D5C8DAFEE145472691CDCBBBB616D1435B67AA6FF20B ] DeviceAssociationService C:\WINDOWS\system32\das.dll
22:57:40.0446 0x28a0  DeviceAssociationService - ok
22:57:40.0453 0x28a0  [ FEA494AC3A1BAE63C1F2AF267D49F1DB, 0722FEA2481740B53EF26B1CA59166C63C157A5C708AC93DF3FBB74A27266C9C ] DeviceInstall  C:\WINDOWS\system32\umpnpmgr.dll
22:57:40.0490 0x28a0  DeviceInstall - ok
22:57:40.0500 0x28a0  [ CDF1B1B5C5951111791C236B2696C7F8, BF6C4BA545C8827B40DB69890DB4D2B2F9C583C5E3CFBDFD370B05891141458D ] DevQueryBroker  C:\WINDOWS\system32\DevQueryBroker.dll
22:57:40.0524 0x28a0  DevQueryBroker - ok
22:57:40.0535 0x28a0  [ 7EAFDEF51136E8F2452CEBD8D084F108, 88609DCB578D14BEBF7CF3C4D300FE2440BA0CF95189969247AB516059E9C284 ] Dfsc            C:\WINDOWS\system32\Drivers\dfsc.sys
22:57:40.0562 0x28a0  Dfsc - ok
22:57:40.0562 0x28a0  [ F0D4400BA0F08610D9A551B15BF10B76, 83EB8FB272FC2DD2CC0659C2FB90AD0DAE88A88AB3951E03BCD933A25B601E10 ] Dhcp            C:\WINDOWS\system32\dhcpcore.dll
22:57:40.0593 0x28a0  Dhcp - ok
22:57:40.0609 0x28a0  [ CA7FEDDFCF61EF15A09C54DA2C07C49F, 346EF7709BA9E6BD48592B86FA46F9D956C847EF91F4980EEAD98269D0F0EF67 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
22:57:40.0645 0x28a0  diagnosticshub.standardcollector.service - ok
22:57:40.0678 0x28a0  [ 6079A6F6406C4FFB552F66384F25F919, 8B38645F1F4A8F72DF18373EDCD3828DDF8D4E2A406E42E654F21C0C1A5EB661 ] DiagTrack      C:\WINDOWS\system32\diagtrack.dll
22:57:40.0778 0x28a0  DiagTrack - ok
22:57:40.0794 0x28a0  [ 35B9D46560339A5A7F0CAC6ED702C817, F70480B01533B7029F90E2DE297E9E829660300DDE7A7D009B0AC2684E7691A7 ] disk            C:\WINDOWS\system32\drivers\disk.sys
22:57:40.0809 0x28a0  disk - ok
22:57:40.0809 0x28a0  [ 6CF67B5720DFBF28BCDDC37307369A74, C3347722FBB65F303A889B71E5B3453388C5076194B5A58962940021B05BCB28 ] DM9USB          C:\WINDOWS\System32\drivers\dm9usb.sys
22:57:40.0847 0x28a0  DM9USB - ok
22:57:40.0847 0x28a0  [ 53757B27986CDC970725FAE35F45CA11, 3B332C2FBD502BAD959DDD65C86FEAFA78DFDDF6405F130F2F26A8AF9424E21B ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll
22:57:40.0894 0x28a0  DmEnrollmentSvc - ok
22:57:40.0894 0x28a0  [ 815F45161A4571C2C44491564F3D5968, 32E7AE8414A178CE429C0CDFCF718E3C11C705FB3155EA5CA0EAD48AAE507B01 ] dmvsc          C:\WINDOWS\System32\drivers\dmvsc.sys
22:57:40.0910 0x28a0  dmvsc - ok
22:57:40.0925 0x28a0  [ 6E5EE6E420FECD64DE463C5F01CBFE71, F173C56895E80AA03D70CD78B3AB659C2EEAACFF43BE3B6EF3939D6F4AD4F62D ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll
22:57:40.0947 0x28a0  dmwappushservice - ok
22:57:40.0947 0x28a0  [ 7F8A3ABF7750326E18CE953CCE262670, 5DBD159E8A455A42764FC73CF7DCAC849B5896848C5589B00BD36697804C0A3B ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
22:57:40.0963 0x28a0  Dnscache - ok
22:57:40.0979 0x28a0  [ 8F46B4C3F9BA19C26A26D0A11137B20B, BA0A66DBA98D77FD85A7CD2D4593F2B2A1A3B4D32BBECBCFFBEB5A54DCB0D8ED ] dot3svc        C:\WINDOWS\System32\dot3svc.dll
22:57:40.0994 0x28a0  dot3svc - ok
22:57:41.0010 0x28a0  [ AB798F6DF51BCCB31E1E42E5F77ACB4F, 656E2AC9E6FAA2F5AC306D4A0AAC05010C21459AA4F06B9C494174A1730B4D64 ] dowidoly        C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\jnsf589C.tmp
22:57:41.0048 0x28a0  dowidoly - detected UnsignedFile.Multi.Generic ( 1 )
22:57:41.0411 0x28a0  dowidoly ( UnsignedFile.Multi.Generic ) - warning
22:57:41.0411 0x28a0  Force sending object to P2P due to detect: dowidoly
22:57:41.0595 0x28a0  Object send P2P result: true
22:57:41.0711 0x28a0  [ CA09EAEE92C6FDDC6B05057F11A0372D, 14DB5C186B69644AA93C445BF31CC9670204F95A47B77B6EACB19B4A316378AD ] DPS            C:\WINDOWS\system32\dps.dll
22:57:41.0746 0x28a0  DPS - ok
22:57:41.0749 0x28a0  [ E87CD3E4F9AC0A2C181990CB781DD4BA, 693F30DF8D4AE732BBB36D250D89DEC05C291B0A0998CBE87677E4F019253432 ] DptfDevPch      C:\WINDOWS\system32\DRIVERS\DptfDevPch.sys
22:57:41.0764 0x28a0  DptfDevPch - ok
22:57:41.0764 0x28a0  [ 1C3C798B4150F7A047853838EBE2A95B, 8A44147DAB1FCBD5F23B5D427D12D0D5CA4A8260216ECE155CD849D09328069A ] DptfDevProc    C:\WINDOWS\system32\DRIVERS\DptfDevProc.sys
22:57:41.0780 0x28a0  DptfDevProc - ok
22:57:41.0796 0x28a0  [ 133C04EDB13A8A7740FFA3D7DD397C80, 56A28AF194354A6AA48A9204F13C845A4B3FE4E3139BBDE31DDDE318F3FB20C9 ] DptfManager    C:\WINDOWS\system32\DRIVERS\DptfManager.sys
22:57:41.0827 0x28a0  DptfManager - ok
22:57:41.0827 0x28a0  [ 8A18176B5108C2FBB23ADA9D548BDD3A, 204E39EE27B6FEDB75E97950B1608DEB0641248857FF0FDD2B66168929967043 ] DptfParticipantProcessorService C:\WINDOWS\system32\DptfParticipantProcessorService.exe
22:57:41.0849 0x28a0  DptfParticipantProcessorService - ok
22:57:41.0849 0x28a0  [ 82239362B0C3CDA6C2E69EAB73FA8A97, 73ADB64C365E5C1F2DF92B91982E65577ADC58DE84ECF0399F0C1C380602E630 ] DptfPolicyConfigTDPService C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe
22:57:41.0865 0x28a0  DptfPolicyConfigTDPService - ok
22:57:41.0865 0x28a0  [ FAFA22CD7FD7B0A195239E738F7B7030, 9DF3810F814ACD4A694F25482E57ADEA01F1072CEAA4AC14ED5D383A4D2DE385 ] DptfPolicyCriticalService C:\WINDOWS\system32\DptfPolicyCriticalService.exe
22:57:41.0880 0x28a0  DptfPolicyCriticalService - ok
22:57:41.0896 0x28a0  [ 06B40DF90D494E2242C63DCACB354B8E, A10EB3EF74EDA33CF710B74E52D97A2B3B7874F3C5212016ED1FB89F8070D6A9 ] DptfPolicyLpmService C:\WINDOWS\system32\DptfPolicyLpmService.exe
22:57:41.0896 0x28a0  DptfPolicyLpmService - ok
22:57:41.0912 0x28a0  [ 4DD17AA07FA0A75E79B47E5B7F18964D, 157983BEAD4C8F7218E46392F8672E7052C8E81CF842A9E82DAA8AE8CC4020C9 ] dptf_cpu        C:\WINDOWS\System32\drivers\dptf_cpu.sys
22:57:41.0927 0x28a0  dptf_cpu - ok
22:57:41.0965 0x28a0  [ 285C138043A4DE3A5E11FCE19FD75914, DB64D8A97BFE1D381920C739A4E90392823AF88609C59F5226EFAF5BEB5CC5A5 ] dptf_pch        C:\WINDOWS\System32\drivers\dptf_pch.sys
22:57:41.0996 0x28a0  dptf_pch - ok
22:57:41.0996 0x28a0  [ AE6BD4C879A8C849E53947C92DF3B3A0, 8C29774CB2D30D901C54AAC0C8ACE709351EE40E5C8FB9951B2A18B4A03F28B7 ] drmkaud        C:\WINDOWS\system32\DRIVERS\drmkaud.sys
22:57:42.0012 0x28a0  drmkaud - ok
22:57:42.0012 0x28a0  [ 7433474BE77F065D2FA628671FE31A3E, 063ADDC68F48036749E6EC7B2F66284DB29F90F62E9468D16B4EF5A0FDC45E35 ] DsmSvc          C:\WINDOWS\System32\DeviceSetupManager.dll
22:57:42.0027 0x28a0  DsmSvc - ok
22:57:42.0050 0x28a0  [ 5FCA45C24501DA7390065D3706A9FC3F, 093FD840F1502ECC6F05B9723CA523B3F15CF39A5D2B9106E1267739B3F2C52C ] DsSvc          C:\WINDOWS\System32\DsSvc.dll
22:57:42.0065 0x28a0  DsSvc - ok
22:57:42.0128 0x28a0  [ A90C76FB62526DEB5A5557A8839841AB, 939BDA8A4F73E834A319D45C97B0892B0A44886A9191BA20D1121622BAE413FA ] DXGKrnl        C:\WINDOWS\System32\drivers\dxgkrnl.sys
22:57:42.0197 0x28a0  DXGKrnl - ok
22:57:42.0212 0x28a0  [ 9FCE4EF7D5E274F862D9A2526B5F4779, 81D42D5475C2801C8E0C233A0BA827569D8A70590017C91C665C8B232D9BFAA9 ] EapHost        C:\WINDOWS\System32\eapsvc.dll
22:57:42.0228 0x28a0  EapHost - ok
22:57:42.0312 0x28a0  [ 7EC6FC0266D74BD47ABB130A328B70EC, 3856790AF967AB03B1A89F97328DC4D5A6854ACDA6169681A9AFB03D7CF791F9 ] ebdrv          C:\WINDOWS\system32\drivers\evbda.sys
22:57:42.0412 0x28a0  ebdrv - ok
22:57:42.0428 0x28a0  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] EFS            C:\WINDOWS\System32\lsass.exe
22:57:42.0450 0x28a0  EFS - ok
22:57:42.0450 0x28a0  [ 8D74B8B5D6F7C5BC4C525BAF2B083FF1, DA5656F745B3911F96871887FDFDC40F4D9C820622A0AA27EFE4BA93662833CA ] EhStorClass    C:\WINDOWS\system32\drivers\EhStorClass.sys
22:57:42.0466 0x28a0  EhStorClass - ok
22:57:42.0466 0x28a0  [ 4D49B99DCACA1FC782A94DB596246504, 878B27A128093640830AB4C78973E1D896CF3AA918FA24FAB1029F0C9D1CB98B ] EhStorTcgDrv    C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
22:57:42.0481 0x28a0  EhStorTcgDrv - ok
22:57:42.0497 0x28a0  [ 80A7999DE02CE678B865832E1CE78CD6, 2576EBB6E4D630A906DE724F125099E52A962B5B68B9F9BCA849A7B29D8C8689 ] embeddedmode    C:\WINDOWS\System32\embeddedmodesvc.dll
22:57:42.0513 0x28a0  embeddedmode - ok
22:57:42.0528 0x28a0  [ B4264DEF962801CDB83C008DE30758D1, 57886688102BE727450BA45932044A5A389B5822A0C1C08C2AFFBA380F70C3F3 ] EntAppSvc      C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
22:57:42.0566 0x28a0  EntAppSvc - ok
22:57:42.0566 0x28a0  [ D315FF43E23DF424ECEC2F6C930203E4, 68940EDA34DC4945CDD0D8018D96A0DA8F99F16A930946D14E4FECEE033FCB80 ] EpsonScanSvc    C:\WINDOWS\system32\EscSvc64.exe
22:57:42.0582 0x28a0  EpsonScanSvc - ok
22:57:42.0582 0x28a0  [ 77B60DEC7DCB4233E4A69D3F52E5DB24, 3A5C905E37A93899051497C90E5BA8E1D003B56C6906CADFD2F1CDF52052D248 ] ErrDev          C:\WINDOWS\System32\drivers\errdev.sys
22:57:42.0613 0x28a0  ErrDev - ok
22:57:42.0629 0x28a0  [ B5BB7C38E9EEC3FB462861E8E9ED1912, 0EC736EF2CE9D34581FB7BDE6C185EC03B763F5088142E458D07CC602ED9CB2B ] ETDSMBus        C:\WINDOWS\System32\drivers\ETDSMBus.sys
22:57:42.0651 0x28a0  ETDSMBus - ok
22:57:42.0666 0x28a0  [ F89083AB8B9F51C0031C1CBD0A9A7E35, 9EE973A25134960E62D1A6A1E34AD9B3F7690E71C1AD31A23FA2081A73438754 ] EventSystem    C:\WINDOWS\system32\es.dll
22:57:42.0698 0x28a0  EventSystem - ok
22:57:42.0713 0x28a0  [ 27E9D2103887F6D52367F5D07352B07A, 75D5EF634FF5BE68408C01B7DB28904B1AE7D6DBEBB5C5396F79CB46348CC3C4 ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
22:57:42.0751 0x28a0  EvtEng - ok
22:57:42.0767 0x28a0  [ FCD2C63754C2E739A8EEAD9BC63F9DDC, C57A72ABA4C0BD71F914B9C8FF965DCFF585A205498F19A4584A4BAF7674839D ] exfat          C:\WINDOWS\system32\drivers\exfat.sys
22:57:42.0798 0x28a0  exfat - ok
22:57:42.0814 0x28a0  [ C077AA74EDDAF69985EB27597BCB342A, 8CE48D37E39A6DFA3C8E959CA92A49029100446DC40044EE009D55FB9CDE378A ] fastfat        C:\WINDOWS\system32\drivers\fastfat.sys
22:57:42.0846 0x28a0  fastfat - ok
22:57:42.0867 0x28a0  [ 77CE56471AF984800F318F3734D768C7, 72D540072374A56C2C497F0532A50705D3F0637F2C0C96B1D715F2EDFCA3AA2D ] Fax            C:\WINDOWS\system32\fxssvc.exe
22:57:42.0898 0x28a0  Fax - ok
22:57:42.0914 0x28a0  [ 99598ECA5E41996E005D5B9D9FF1EFA2, 91345CD50EF02431B69093505C1C5F5DC6A1AA6BF192EE9392ED4D5626B60462 ] fdc            C:\WINDOWS\System32\drivers\fdc.sys
22:57:42.0929 0x28a0  fdc - ok
22:57:42.0929 0x28a0  [ EF0DD43A4CBAB367BCA1AFBDC9971E4F, 73E161C45D63FDDE71EE2438137913724DC513860539D1E7F6BD861F5D1B33F3 ] fdPHost        C:\WINDOWS\system32\fdPHost.dll
22:57:42.0952 0x28a0  fdPHost - ok
22:57:42.0967 0x28a0  [ 34DAC585994CD3B4E910DE11C584EF3D, A6C6A4CB5413EA61F1A54E2D3AD71A311CEA2C26218544D2D2D4A5CFEC52DE8C ] FDResPub        C:\WINDOWS\system32\fdrespub.dll
22:57:42.0983 0x28a0  FDResPub - ok
22:57:42.0998 0x28a0  [ B68DA1FE3CA2311AFD38DD6905CA7F71, 4B395DFB1B47D2507CA4D9DC996A70D0A3BDB1A245CD6DA6C42B2A299AFCCF37 ] fhsvc          C:\WINDOWS\system32\fhsvc.dll
22:57:43.0014 0x28a0  fhsvc - ok
22:57:43.0030 0x28a0  [ F44F666B0EACC3181544FFCF8CA0FFC7, 83F771CF9DAE1C504B30731EEC55355EA1253174252DA2192ADF1D228B3735C3 ] FileCrypt      C:\WINDOWS\system32\drivers\filecrypt.sys
22:57:43.0052 0x28a0  FileCrypt - ok
22:57:43.0052 0x28a0  [ 78A210DDFDF2C9EC884631D2DAA573F0, 5D39C6EF4AC690A9749EEDBE2478FFF15A22877A2861EDA103C7BF1607B0C1BD ] FileInfo        C:\WINDOWS\system32\drivers\fileinfo.sys
22:57:43.0083 0x28a0  FileInfo - ok
22:57:43.0083 0x28a0  [ 1A97DB5E701A186989F3795223C3BE39, F7982220D4DF7E104955E63CACE352394E2577DEF49506EA126127F820EB62DF ] Filetrace      C:\WINDOWS\system32\drivers\filetrace.sys
22:57:43.0114 0x28a0  Filetrace - ok
22:57:43.0130 0x28a0  [ 46626665F0E5906E45619B4EFD6186B8, 37FDD3B8AD49FD29E54DA5567EA77F28A53498AE56348F7A2628E5E5549D638B ] flpydisk        C:\WINDOWS\System32\drivers\flpydisk.sys
22:57:43.0152 0x28a0  flpydisk - ok
22:57:43.0152 0x28a0  [ FDA72ACA14D516D18C33AFCD0FD9260F, 6509612DEC82EA74614B5C9A7B432305A1A468C97B88BED9E141DF2929B621B1 ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
22:57:43.0183 0x28a0  FltMgr - ok
22:57:43.0183 0x28a0  [ 7F8A3219F3110ACF8B67CFAB09433F9C, 0DA9DC021847D512F5829487BFC3820A91C5DD9C32624CC0ACF12735E35A8D34 ] FLxHCIv        C:\WINDOWS\System32\Drivers\FLxHCIv.sys
22:57:43.0215 0x28a0  FLxHCIv - ok
22:57:43.0268 0x28a0  [ 289EFA0470B308F01BAF955DE81E0682, F88081AD427BD90B3085A07439D1BDBB4966A898D49B0ABEFF7829D68BE532A5 ] FontCache      C:\WINDOWS\system32\FntCache.dll
22:57:43.0352 0x28a0  FontCache - ok
22:57:43.0368 0x28a0  [ 59241194DBDF30A2B4029E402F377900, 47A92E9CD8494C403B377799D395670A393766647E24CD83B15338CE2AA50266 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:57:43.0383 0x28a0  FontCache3.0.0.0 - ok
22:57:43.0399 0x28a0  [ B6848AE7BF5BD5182075D948DF7588DC, 0245D35CA48451D0743347338EE2E8E8AB6C6FD8ABE0B91E7FE2830714D30BE0 ] FrameServer    C:\WINDOWS\system32\FrameServer.dll
22:57:43.0452 0x28a0  FrameServer - ok
22:57:43.0452 0x28a0  [ D152CCBFC8251670BF0AAFE00D6BC782, 9DE82D8FC4E1DAF8FF23EE08C0B7CB5051A9224E64544D262CFA4996A41B04E1 ] FsDepends      C:\WINDOWS\system32\drivers\FsDepends.sys
22:57:43.0468 0x28a0  FsDepends - ok
22:57:43.0468 0x28a0  [ 6D6BB5C7363CD35FA715E826F3D029EE, C214F791EB39E8B25CE57ED9D6C1D56EE1AF6021BCB380980BD42A6338A6C9F7 ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:57:43.0484 0x28a0  Fs_Rec - ok
22:57:43.0515 0x28a0  [ B719EAA1EC93586955B013BD7DD61356, 0D0D94CF33322EEC0AD08835D0314E578F9687F361CD436A2073A4D2C0D56C86 ] fvevol          C:\WINDOWS\system32\DRIVERS\fvevol.sys
22:57:43.0553 0x28a0  fvevol - ok
22:57:43.0553 0x28a0  [ EF78034773CE506323655A868C949144, DF195BEEE6704FBCC6D2D9E1BF6723E52ED502A1459F495B7D18481E6A79B5BC ] gencounter      C:\WINDOWS\System32\drivers\vmgencounter.sys
22:57:43.0584 0x28a0  gencounter - ok
22:57:43.0584 0x28a0  [ B55FEBC6A00DAA1FE074F020B6907516, 67071FBAC2ABA47AB71358A5F08E92E034A55343878F00137E90B3B1F7362976 ] genericusbfn    C:\WINDOWS\System32\drivers\genericusbfn.sys
22:57:43.0615 0x28a0  genericusbfn - ok
22:57:43.0615 0x28a0  [ DDD8A8CDDC7F13EF57D1DAAE71865936, 9D472A8689F72F24D40D5B94849690F53C67849FDF6162A94EF4FB330A3DA566 ] GPIOClx0101    C:\WINDOWS\system32\Drivers\msgpioclx.sys
22:57:43.0653 0x28a0  GPIOClx0101 - ok
22:57:43.0690 0x28a0  [ C9316C91895057669386E620C89580E5, 5C7BF2C890E77AE3D401BB1F9F76B42D8A0ECD98118F17929FCD4097C768D90A ] gpsvc          C:\WINDOWS\System32\gpsvc.dll
22:57:43.0767 0x28a0  gpsvc - ok
22:57:43.0773 0x28a0  [ 7ACD8F69B5D6EC97E6D2C006E19BED88, FC69214C9308EA64B88EF4C3C95800586DDBB44C8540846B79A161BAD8203B6E ] GpuEnergyDrv    C:\WINDOWS\system32\drivers\gpuenergydrv.sys
22:57:43.0789 0x28a0  GpuEnergyDrv - ok
22:57:43.0789 0x28a0  [ E1B44A75947137F4143308D566889837, EC7E883E7AF38BF3AC0AC513CFDE0186038443E9ACC7AD616EE6BD0EC09AACB9 ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:57:43.0804 0x28a0  gupdate - ok
22:57:43.0820 0x28a0  [ E1B44A75947137F4143308D566889837, EC7E883E7AF38BF3AC0AC513CFDE0186038443E9ACC7AD616EE6BD0EC09AACB9 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:57:43.0836 0x28a0  gupdatem - ok
22:57:43.0836 0x28a0  [ 10E3515FE5DBA6656FA62C29342EC4A1, 2051F10F74ED712B1766EB61E87FADE25AB3D0970BABFD320600D1B0D6377F26 ] HDAudBus        C:\WINDOWS\System32\drivers\HDAudBus.sys
22:57:43.0873 0x28a0  HDAudBus - ok
22:57:43.0873 0x28a0  [ B90D284B97CD4CA9DE7430AAAD887A56, 2F14F985C39B7801ED64590979CF2114924E9547F5B11D2B37A74DBFFDD9E7C5 ] HidBatt        C:\WINDOWS\System32\drivers\HidBatt.sys
22:57:43.0905 0x28a0  HidBatt - ok
22:57:43.0920 0x28a0  [ B2FE11643CC6ACDEE6C247DD36018FDB, 5796613C7DBF8B2A9E860E006FF1A245B6BE7D10E3F6685AD142B48E5C237B8C ] HidBth          C:\WINDOWS\System32\drivers\hidbth.sys
22:57:43.0952 0x28a0  HidBth - ok
22:57:43.0973 0x28a0  [ D24355488A2D4D2323518EC1AC7A6D9E, ED2176A2093726087EDDA25B86E9CDD4BA35F4E748E3A6DE0B15C4C97646B5C7 ] hidi2c          C:\WINDOWS\System32\drivers\hidi2c.sys
22:57:44.0005 0x28a0  hidi2c - ok
22:57:44.0005 0x28a0  [ 0AF9ABBA4F3F55C6C803890D64BC3C29, D3DE6FA308F8E7CD4F16387F46AE4B2F7EC9BBA07BF87652B660A0D645710571 ] hidinterrupt    C:\WINDOWS\System32\drivers\hidinterrupt.sys
22:57:44.0036 0x28a0  hidinterrupt - ok
22:57:44.0052 0x28a0  [ CDBCF8E9AB06D88A1E1191D32F320C5D, F76963AB7CF2BAB3A220013879AECD3976BFD851CFB66B5A69A9EA2541048861 ] HidIr          C:\WINDOWS\System32\drivers\hidir.sys
22:57:44.0093 0x28a0  HidIr - ok
22:57:44.0103 0x28a0  [ C900FE0DD6A1E2220084B8F1C427790C, 802194EBEDA1A50EDA300078B0888AAC1F17A42E67147B7B3B9C50AD8D4E5C89 ] hidserv        C:\WINDOWS\system32\hidserv.dll
22:57:44.0149 0x28a0  hidserv - ok
22:57:44.0160 0x28a0  [ 2B7002EEACFC2687788A34ADB204293D, 040B5FC43459E80AD56CEBB26EC7676F449310537ADCD3272C2064241E328834 ] HidUsb          C:\WINDOWS\System32\drivers\hidusb.sys
22:57:44.0197 0x28a0  HidUsb - ok
22:57:44.0215 0x28a0  [ 44D54C8356588525D7AD0FDCFDDA0811, 46963ADBF14FA8A9B0E6564106ADEA49BBD4EBD9E43DF389CCD31F9B9BD080D9 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
22:57:44.0281 0x28a0  HomeGroupListener - ok
22:57:44.0305 0x28a0  [ 86161A89F16851728802590EC7C92608, 3A3B05BB4E115410D27063B30C0EF3F18295F542050F329F1E466C81A9E23A46 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
22:57:44.0370 0x28a0  HomeGroupProvider - ok
22:57:44.0380 0x28a0  [ F5CA18197B4646E04DB9EB2D6642CC4D, 5BA3342DDF1BCB67E4156169FE9A33E7BC2641C729E9F1A80C0E80953C6AB114 ] HpSAMD          C:\WINDOWS\system32\drivers\HpSAMD.sys
22:57:44.0407 0x28a0  HpSAMD - ok
22:57:44.0423 0x28a0  [ 83198A09E62B7DEBDA394F5D1516D74C, CBF8E4EC18048FD4308FF23A7C7DE3FCAFFCD777105DFC468B8D2C1B205431BE ] HpSvc          C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll
22:57:44.0447 0x28a0  HpSvc - ok
22:57:44.0491 0x28a0  [ 65E358D604267CBAACB74A2598BBE22B, A645E48641D638A58789B7948FC3DD5072179C0919B546A6DB08094FA9321A30 ] HTTP            C:\WINDOWS\system32\drivers\HTTP.sys
22:57:44.0569 0x28a0  HTTP - ok
22:57:44.0585 0x28a0  [ 0C84C250F80EAEC2C9768464CC1A9626, 212E1003B78F9B98FEB084FD1FDB59B26A9DE4C9120F24D4361FBBF0F3C035E7 ] HvHost          C:\WINDOWS\System32\hvhostsvc.dll
22:57:44.0632 0x28a0  HvHost - ok
22:57:44.0642 0x28a0  [ 3756E15BB86689412775DF22A442FC46, AD9DF5B542B30C89F9904CB574E75BD2D18A31F67032F0E2453290E912FC5DE3 ] hvservice      C:\WINDOWS\system32\drivers\hvservice.sys
22:57:44.0674 0x28a0  hvservice - ok
22:57:44.0702 0x28a0  [ EF558A02D734A1403583E95CCEEC2487, F0D052DAF48A62E4A90D067BFCB5EE9563804DE68D0EA82E0E11C8D16AD19D29 ] HWiNFO32        C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS
22:57:44.0722 0x28a0  HWiNFO32 - ok
22:57:44.0733 0x28a0  [ 771EDDA9830A3079F996F34D681FB6E5, F452AD656872A1C8B2D6DCE232CE01EBD456C46F4934A7601E78470F2A2CBF38 ] hwpolicy        C:\WINDOWS\system32\drivers\hwpolicy.sys
22:57:44.0757 0x28a0  hwpolicy - ok
22:57:44.0768 0x28a0  [ 3B9F315E7FA72CC25228EB097DD9C694, B26F1E494428EF197A0C97645C05BB3CA093827A005D35C987F1D6778BC4E52C ] hyperkbd        C:\WINDOWS\System32\drivers\hyperkbd.sys
22:57:44.0813 0x28a0  hyperkbd - ok
22:57:44.0826 0x28a0  [ B54B30992620C97230013A74461C8517, CAF09BDCDD6DE2A39CB8AE2C65E6F8FE12D8E93D84BBEF6C6A98F872BF54A4E3 ] i8042prt        C:\WINDOWS\System32\drivers\i8042prt.sys
22:57:44.0870 0x28a0  i8042prt - ok
22:57:44.0880 0x28a0  [ C6B8743B213F06AA60943D8366FE968F, 758954F70B810063914B243115B2C753B2BCE40190F95C30ACBA0BF04EBD5B33 ] iagpio          C:\WINDOWS\System32\drivers\iagpio.sys
22:57:44.0919 0x28a0  iagpio - ok
22:57:44.0933 0x28a0  [ 9A2A2F3C69B9A30B6E78536F6D258BAD, 5E28E132A7300E6F5E0C6439D6BA00F1AEF66D729FF671FDA91274A25A921463 ] iai2c          C:\WINDOWS\System32\drivers\iai2c.sys
22:57:44.0969 0x28a0  iai2c - ok
22:57:44.0988 0x28a0  [ 5A0E850F8CD17791A3E6A3CF81D0CA28, 10A965A49D53360DD250E0758B6BB142872298A21C732EB026ACB93492C5C6CF ] iaLPSS2i_GPIO2  C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys
22:57:45.0023 0x28a0  iaLPSS2i_GPIO2 - ok
22:57:45.0039 0x28a0  [ 7508F1096803385D6376BFD0BD473AC4, 1F32EC23CDC94DCB9710E6663B5C3BD83568545DDC2C741CFC13550A4E4DD2BE ] iaLPSS2i_I2C    C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys
22:57:45.0065 0x28a0  iaLPSS2i_I2C - ok
22:57:45.0076 0x28a0  [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO    C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
22:57:45.0096 0x28a0  iaLPSSi_GPIO - ok
22:57:45.0109 0x28a0  [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C    C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
22:57:45.0150 0x28a0  iaLPSSi_I2C - ok
22:57:45.0208 0x28a0  [ 0609694A9C4D6C71319732FA82C6E5C5, 5507D20AB9C86B11564C953C6F535976A0D201295C642EA0CABF435DAD908251 ] iaStorA        C:\WINDOWS\system32\drivers\iaStorA.sys
22:57:45.0285 0x28a0  iaStorA - ok
22:57:45.0318 0x28a0  [ 97E553D03219D3D51705C7235D9EAEBD, 5D4578C8804AF32D1DC0868E34D6538138DC15F9568CA7E21051B1C82C0D8D55 ] iaStorAV        C:\WINDOWS\system32\drivers\iaStorAV.sys
22:57:45.0375 0x28a0  iaStorAV - ok
22:57:45.0391 0x28a0  [ 20E83F4632E15A5E9E716FF2E8AC7FAE, 7CA1A4924F432AD30ED7FA6247C6513DA173EE31132AE115E85C0ED7E5971029 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
22:57:45.0410 0x28a0  IAStorDataMgrSvc - ok
22:57:45.0433 0x28a0  [ 8350FE3BCDE3428BC040877BB7E9EAEB, 77F9456351CA640C6B7862907C0580627E761EC807B551976A95657EB4D6CC20 ] iaStorV        C:\WINDOWS\system32\drivers\iaStorV.sys
22:57:45.0477 0x28a0  iaStorV - ok
22:57:45.0503 0x28a0  [ 3BA03F7C7700DDF4C383DDE9252F5817, 3E90F69D0010E7764349D9AE865D577E431FEBC67DA554B400BC808DD286E203 ] ibbus          C:\WINDOWS\System32\drivers\ibbus.sys
22:57:45.0572 0x28a0  ibbus - ok
22:57:45.0582 0x28a0  ibtsiva - ok
22:57:45.0602 0x28a0  [ 445E2B8B742D430CDD979FF8551B97BA, C9DA1B2FAD3875ECAF6360D844204266C986F917B5272699BE00A1D5F99839EB ] ibtusb          C:\WINDOWS\system32\DRIVERS\ibtusb.sys
22:57:45.0635 0x28a0  ibtusb - ok
22:57:45.0651 0x28a0  [ 937AC47F7356554DA05D9722C356EB55, 9EABC9F19B4E1193B669D2674967F5C6F03FAD348EDF0615E3F78554FF9A83CC ] icssvc          C:\WINDOWS\System32\tetheringservice.dll
22:57:45.0696 0x28a0  icssvc - ok
22:57:45.0974 0x28a0  [ D12E20EA9F42FACE950E05FE4700A4B7, 2D78B042274A6DA5A44B3B23FB17D590858E352712962A7B90C476664BB5A221 ] igfx            C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
22:57:46.0346 0x28a0  igfx - ok
22:57:46.0379 0x28a0  [ AB747396F38F96A7A182FA8A9E95D0DA, 461431FD5197878E0BEC94BB7EB1D5A31CE9FE8A80357AEED110064E881C8CBE ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
22:57:46.0471 0x28a0  igfxCUIService2.0.0.0 - ok
22:57:46.0482 0x28a0  [ E71AC94964ED675B3ED0727059B7F97B, 5468B5E9B75B10EA0BFBD81827FFC9CABFC69A4065CC5A5792DBC289D4DA27EE ] ikbevent        C:\WINDOWS\system32\DRIVERS\ikbevent.sys
22:57:46.0530 0x28a0  ikbevent - ok
22:57:46.0568 0x28a0  [ F2934208C0E50C0B971A7981AB90BED2, B936BFBBD71E731CC2CDB8B47D262F2EF09726FF921C2DA0841910CA2401423D ] IKEEXT          C:\WINDOWS\System32\ikeext.dll
22:57:46.0674 0x28a0  IKEEXT - ok
22:57:46.0686 0x28a0  [ D073054784FBD418735BECF4588C14D7, DFA1D42063EAF3107B9BFD67F0BB3E83F5CFCFDD7825BC8C367C3D008E5465FD ] ImControllerService C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
22:57:46.0868 0x28a0  ImControllerService - ok
22:57:46.0878 0x28a0  [ 2FDB67F5B9F4E96B40FDC9D1AA0B686F, B556328D54F886792A89588F3FEFE38F7129E3D7A417CDC012778FA4EF37A8C1 ] imsevent        C:\WINDOWS\system32\DRIVERS\imsevent.sys
22:57:46.0920 0x28a0  imsevent - ok
22:57:46.0928 0x28a0  [ 2A01C96DF5802D3434634E55C91232D8, A3ABEF36E2FD2CF5C371ADBF92566A09669A1D990ABE4677370F57F2EEAF8121 ] IndirectKmd    C:\WINDOWS\System32\drivers\IndirectKmd.sys
22:57:46.0952 0x28a0  IndirectKmd - ok
22:57:46.0964 0x28a0  [ F0F581A2299CB2BAB1DF2597BCDDB80F, EE485AF3049C87666BC6D6BFFC8A0EB4B95831D9061EB81848ECEE29C4232BF4 ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
22:57:46.0976 0x28a0  intaud_WaveExtensible - ok
22:57:47.0074 0x28a0  [ 4C60B08DFC8E2543075FF13C9E68DD55, C8314F957102DD843763C9CC9A2356AB390FC79E4E636CC43AC80BA6431D2F76 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
22:57:47.0191 0x28a0  IntcAzAudAddService - ok
22:57:47.0212 0x28a0  [ E300D1E37B737ED14F7A08CD5604E5D9, 5C1135081E29D7F4A97D5CAA2C8FBE1DD04EC7A3D8E648E69F2AA9EBDD88EBBB ] IntcDAud        C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
22:57:47.0232 0x28a0  IntcDAud - ok
22:57:47.0264 0x28a0  [ 0DB1E3F6189C628675F855C0EB510419, 989F539E82105019D2D81255369B96DC65826CD2A421DA09809155B26F69C555 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
22:57:48.0419 0x28a0  Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
22:57:48.0584 0x28a0  Detect skipped due to KSN trusted
22:57:48.0585 0x28a0  Intel(R) Capability Licensing Service Interface - ok
22:57:48.0620 0x28a0  [ 492AAF2FF66F437F0E796574B116EFC3, 6BF21C61ED05705DD58203952A750D1AB4D4B62F3A2B640BBBD9B85D1ECC3E5C ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
22:57:50.0267 0x28a0  Intel(R) Capability Licensing Service TCP IP Interface - ok
22:57:50.0282 0x28a0  [ 9F7E87F6595D065A8A200A291043045E, 6944F72F73EADC6C9B7691F2C1C6DF1898F22C88EFA78EC0BA8CB5FFD9CE057B ] intelide        C:\WINDOWS\system32\drivers\intelide.sys
22:57:50.0314 0x28a0  intelide - ok
22:57:50.0325 0x28a0  [ A6BD2E20AE1BC5CB2776C87C28E4F4CA, BD8BE67CED9A4982D785CE9ECBEFE868C3A2E37DF7F9592B9F9049B807A1554B ] intelpep        C:\WINDOWS\system32\drivers\intelpep.sys
22:57:50.0352 0x28a0  intelpep - ok
22:57:50.0367 0x28a0  [ 2A48DA39542636DB0FA3BA915385D1B3, 6CA0916F5F4B1E81AE6A6233276320599BFA7C129267177703E3BB6468FB4683 ] intelppm        C:\WINDOWS\System32\drivers\intelppm.sys
22:57:50.0404 0x28a0  intelppm - ok
22:57:50.0414 0x28a0  [ 4A922CAB4AB5F29F1BECC9D95B4B7F05, 7C1006799E26A0B4DF49373A4D0509748C602588CFB3C1CBB409E335F5DF9593 ] iorate          C:\WINDOWS\system32\drivers\iorate.sys
22:57:50.0441 0x28a0  iorate - ok
22:57:50.0454 0x28a0  [ FE85D0A86CA7A5A99CF8CD04DE7F80AE, 544C01FC01EE728EB5667158207E5F4418FE77A88BA318192A834722DB766F4E ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:57:50.0488 0x28a0  IpFilterDriver - ok
22:57:50.0529 0x28a0  [ 89548E57FD0A7BC703541C69C0286B13, 261698B302DF5B80C57FC4257E0A0AABC8DEFFED16D8CD142AD8E7CB51AF2007 ] iphlpsvc        C:\WINDOWS\System32\iphlpsvc.dll
22:57:50.0630 0x28a0  iphlpsvc - ok
22:57:50.0652 0x28a0  [ 450DBDD716C7911F83E05F78EE18BFA2, 43C0DA172F632131898F315A53DEDD1AE99FB0620AB32B3A5B99FEC498C9AAE5 ] IPMIDRV        C:\WINDOWS\System32\drivers\IPMIDrv.sys
22:57:50.0685 0x28a0  IPMIDRV - ok
22:57:50.0701 0x28a0  [ F1DAECC3B3D6399875D4F10529D6A77C, 6533D2F858816BE6570C998510919FCA2904EC6EF806F61C1FD325E88133111B ] IPNAT          C:\WINDOWS\system32\drivers\ipnat.sys
22:57:50.0745 0x28a0  IPNAT - ok
22:57:50.0758 0x28a0  [ 7475A2903BB704B446AA6309E34D3362, C94643A1626A9716015EBA7041A1224098501EB7DAA704CBFCAD3DC6F3CFC6AF ] irda            C:\WINDOWS\system32\drivers\irda.sys
22:57:50.0798 0x28a0  irda - ok
22:57:50.0808 0x28a0  [ 9725E7F0C64CE9916A5CDABE8D6E13C3, 04AF9E48FEF208A2850DF28352E8FDCBF4018982C72C0F67EE12C048C4070116 ] IRENUM          C:\WINDOWS\system32\drivers\irenum.sys
22:57:50.0842 0x28a0  IRENUM - ok
22:57:50.0852 0x28a0  [ 8C604213A2E73088BFFE6CD2E6F1AE53, B4C4FEE4D398A29F72EC27D5668071D7E68CD943FFFC38624DD5DF5BEBDF46D3 ] irmon          C:\WINDOWS\System32\irmon.dll
22:57:50.0885 0x28a0  irmon - ok
22:57:50.0895 0x28a0  [ 58040898883A96160D41739C80328BBF, 7F85C91C905811416E266A263DDEFCDCB0B45376AAE51B551AB636C16577DB9F ] isapnp          C:\WINDOWS\system32\drivers\isapnp.sys
22:57:50.0918 0x28a0  isapnp - ok
22:57:50.0935 0x28a0  [ C9FD02D62E09337B67B0C61EC8CA38CC, DC77E935ECC8474BE9018F0937CB11C137073582B20A0EE107CE247FD9E1F9C1 ] iScsiPrt        C:\WINDOWS\System32\drivers\msiscsi.sys
22:57:50.0971 0x28a0  iScsiPrt - ok
22:57:50.0982 0x28a0  [ 4EE2423C38F43D37F8497A672FD10BDC, 031C5272DD28809255CF4FA8E6DE45DBFBD9A363BBD5156D0AEE0787C4297980 ] ISCT            C:\WINDOWS\System32\drivers\ISCTD64.sys
22:57:51.0029 0x28a0  ISCT - ok
22:57:51.0049 0x28a0  [ 52069AEB42D3D0F97CBCA1085EBF55E6, ADB2EFFF563B3FE113FCD156FD1E469BC24FC1D68AFEDCA21306F76592C9FF88 ] jhi_service    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
22:57:51.0075 0x28a0  jhi_service - ok
22:57:51.0082 0x28a0  Jzidom Module - ok
22:57:51.0096 0x28a0  [ 210808437570BDDEE71A43535E3A2D30, EF5DE6EE4FF58F44CDE4D4E7F298ABBC9086EC05CC3AE4903060DA878115AC1E ] kbdclass        C:\WINDOWS\System32\drivers\kbdclass.sys
22:57:51.0122 0x28a0  kbdclass - ok
22:57:51.0132 0x28a0  [ 2D05785B0C58D90A34EA15032EADBBA9, 3E1238FF7F6ECA522761830FE7EA7587B704FCB3ECE8C6BF94CC17A640B678ED ] kbdhid          C:\WINDOWS\System32\drivers\kbdhid.sys
22:57:51.0185 0x28a0  kbdhid - ok
22:57:51.0197 0x28a0  [ 813BA3EB2CE038F2A5382DDD75CAD60B, 99FA444027CAC247B54317730D54AB0C4C000AE076B97E47470FDA9834594312 ] kdnic          C:\WINDOWS\System32\drivers\kdnic.sys
22:57:51.0278 0x28a0  kdnic - ok
22:57:51.0290 0x28a0  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] KeyIso          C:\WINDOWS\system32\lsass.exe
22:57:51.0317 0x28a0  KeyIso - ok
22:57:51.0331 0x28a0  [ 9FA1B5D84F596F0664F0465F302044DC, 47B41D3D6119B5B20C83AF84D315C4AB40B5534D687736A8B67BD985A3B232C1 ] KSecDD          C:\WINDOWS\system32\Drivers\ksecdd.sys
22:57:51.0361 0x28a0  KSecDD - ok
22:57:51.0377 0x28a0  [ 3B342AD20A76FAEC4851A38774B99AB4, 5003427A1BA8AFA2273C623BCF1A9CC5D60654A346FE4A2FB43CDAD2732E8BB3 ] KSecPkg        C:\WINDOWS\system32\Drivers\ksecpkg.sys
22:57:51.0408 0x28a0  KSecPkg - ok
22:57:51.0419 0x28a0  [ 4ED115CD1A1099705F56B5E0FFF97CC6, 9CC49DF2CD6AAAE405BA661D13EFC1E05111D1DE3D1E50C39C425AF1F075610B ] ksthunk        C:\WINDOWS\system32\drivers\ksthunk.sys
22:57:51.0468 0x28a0  ksthunk - ok
22:57:51.0491 0x28a0  [ 8125BDF7ADC261F75EF0CAD92456E350, 184797AA1D58C4FF743BA60D48590B88B781EE7779205E45E0679DEC79F3E185 ] KtmRm          C:\WINDOWS\system32\msdtckrm.dll
22:57:51.0547 0x28a0  KtmRm - ok
22:57:51.0560 0x28a0  [ 31CBF3DB2E83C988728F792EC27F51ED, E20FF15A2D51B2015F5426952FB7E0C9FCBB4E0933B1A095A2F49845FDD16F22 ] KuaiZipDrive    C:\WINDOWS\system32\drivers\KuaiZipDrive.sys
22:57:51.0624 0x28a0  KuaiZipDrive - ok
22:57:51.0641 0x28a0  [ D3B57404176A89A75E1DDCE287FB670B, 364C6DD9166243D0CA47DE4D05D22CE000D2B52845D56FA0EF2C894BD34DFF87 ] KuaizipUpdateChecker C:\Program Files\؟ىر¹\X86\kuaizipUpdateChecker.dll
22:57:51.0721 0x28a0  KuaizipUpdateChecker - ok
22:57:51.0743 0x28a0  [ 8CCAB08815B50AD78B823DB3F96C8604, 265E6D582EB7207B5CC577D61CB7BC3646F613047F168CD69BB776C37780EBF5 ] LanmanServer    C:\WINDOWS\system32\srvsvc.dll
22:57:51.0808 0x28a0  LanmanServer - ok
22:57:51.0827 0x28a0  [ 752FE77F22592016A5EBBF399EC12E14, 231CF3E069FF64A4E8C81D0799A73924D864585B25382EFF8D1707F87747AC9E ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
22:57:51.0891 0x28a0  LanmanWorkstation - ok
22:57:51.0913 0x28a0  [ 3CDD29A1A62BBFC7F9EE31F31E322A69, 61F657041A9F537001A39745D953FC9B77EE4DDFC2F32A1C58965827840BF268 ] LDrvSvc        C:\Program Files (x86)\OSTotoSoft\DriverTalent\LDrvSvc.dll
22:57:52.0012 0x28a0  LDrvSvc - ok
22:57:52.0041 0x28a0  [ DA297A7BAB4E3889CFF60C02AE7BFB5D, 9E533D6FE2C9777A298F1E09C6E74F4135CC32D406382655EA9C0B7B2C533F3E ] Lenovo EasyPlus Hotspot C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe
22:57:52.0080 0x28a0  Lenovo EasyPlus Hotspot - ok
22:57:52.0102 0x28a0  [ 031199B929009F268A478F0283E1CE32, B7BFB848A03535C16798085D489AB294935955F2982330B39190B2074BF9122B ] LenovoWiFiHotspotSvr C:\Windows\System32\LenovoWiFiHotspotSvr.exe
22:57:52.0184 0x28a0  LenovoWiFiHotspotSvr - ok
22:57:52.0195 0x28a0  [ F8EBAA1FE6D3BF84752931DE1BFA0E2A, 2F3C512712BA709BBBBD779D9E792DBE324876C402CDCEF0345B8B7ABE1D232A ] lfsvc          C:\WINDOWS\System32\lfsvc.dll
22:57:52.0231 0x28a0  lfsvc - ok
22:57:52.0243 0x28a0  [ F2E1302599E445F3E1A305123A92A8BC, 162D5C8045463931E8465544144F11567AA0F246AEAC3828A13284C283F01633 ] LicenseManager  C:\WINDOWS\system32\LicenseManagerSvc.dll
22:57:52.0275 0x28a0  LicenseManager - ok
22:57:52.0287 0x28a0  [ 5933A6673F00D8255C52957E40C2D601, 0AA1281F8B3F97E360592D1B35EE7D3D614F1AB46007F9884CFFB1C5E647575E ] lltdio          C:\WINDOWS\system32\drivers\lltdio.sys
22:57:52.0322 0x28a0  lltdio - ok
22:57:52.0342 0x28a0  [ 88A3C935725FA6EA1A228DCC26CF9C6F, 9B1F70644EEFA1EE7CE151A8A970430087339B7A6345F2E0252370929D4AFAC6 ] lltdsvc        C:\WINDOWS\System32\lltdsvc.dll
22:57:52.0391 0x28a0  lltdsvc - ok
22:57:52.0402 0x28a0  [ 3F858E28AEE6545FA1B64134DFD5C2CE, FFD7B4FB0A7B61BC6B76A172134673842F2CF00E96FA3ED4A8273DC525B6BB92 ] lmhosts        C:\WINDOWS\System32\lmhsvc.dll
22:57:52.0437 0x28a0  lmhosts - ok
22:57:52.0466 0x28a0  [ B16F2A40E738277AB75515D4B024305E, 38F48CCD72FA2B32DFD3123C0864AB724AC673414EEE09C6F582754177CD4B98 ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:57:52.0504 0x28a0  LMS - ok
22:57:52.0525 0x28a0  [ 8E1B0946948CCC0BC1FA3CB70374A795, 0B894C129A35E223FF9594725AC90916CBD597FAD2211A18FC2AE03EA8679597 ] LSI_SAS        C:\WINDOWS\system32\drivers\lsi_sas.sys
22:57:52.0554 0x28a0  LSI_SAS - ok
22:57:52.0567 0x28a0  [ 4F68163FC04C973500DC4DA0946917B0, DF060C29109EB3978CEDFE781999B0C4C1E8C0FDB133428058D8400C53315EEC ] LSI_SAS2i      C:\WINDOWS\system32\drivers\lsi_sas2i.sys
22:57:52.0596 0x28a0  LSI_SAS2i - ok
22:57:52.0609 0x28a0  [ E5AC5F2815938651CDCC27F425474673, 3AF0598982153C36A766506FA088F7B84333CC96FEBB050402547AFC613AF9F7 ] LSI_SAS3i      C:\WINDOWS\system32\drivers\lsi_sas3i.sys
22:57:52.0638 0x28a0  LSI_SAS3i - ok
22:57:52.0651 0x28a0  [ CCF6EC9FB9B8F18E05B4253E81013E48, EBE8D77FEE8B99BD8C29702404774D554673C96DF3FDF3DCEA9C99E22C2709FC ] LSI_SSS        C:\WINDOWS\system32\drivers\lsi_sss.sys
22:57:52.0678 0x28a0  LSI_SSS - ok
22:57:52.0714 0x28a0  [ 5570D03E2048AC7961BEF6FFEE3A2CA5, FD0232312D87015FA0B8062FA175A44410F8C1C9778145CCDD57BA1C23929C87 ] LSM            C:\WINDOWS\System32\lsm.dll
22:57:52.0784 0x28a0  LSM - ok
22:57:52.0801 0x28a0  [ B9D6F27D06565CEFF51FD012B74822CB, D6526314DC2F58745969B7132722C60DB33442CB55ADAB28E7EF64EB088E32DF ] LsvUIService    C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
22:57:52.0872 0x28a0  LsvUIService - ok
22:57:52.0886 0x28a0  [ C9579D32219E5B936AC3A48D470117EC, E61A77191B6BA25D29B1221FEBBE826BBC11F825C0E35A72B4CEFFF8B7FE59A8 ] luafv          C:\WINDOWS\system32\drivers\luafv.sys
22:57:52.0926 0x28a0  luafv - ok
22:57:52.0963 0x28a0  [ 96C2218301EAE9AD23A69E0DA1E5D6EB, BA33A4635DE6E5F53E82C376446252DBB514064928B4944A5E3142EF7CC1DEC1 ] MaohaWifiNetPro C:\Program Files (x86)\GreatMaker\MaohaWiFi\MaoHaWiFiNet64.sys
22:57:53.0010 0x28a0  MaohaWifiNetPro - ok
22:57:53.0020 0x28a0  [ 710C517D863BDBD036B72BF94D4F8517, 39CF433D19DCDCCE082D805534F07BDA0840D8BEFC37293DC1486E86153A874D ] MaohaWifiSvr    C:\Program Files (x86)\GreatMaker\MaohaWiFi\MaohaWifiSvr.exe
22:57:53.0101 0x28a0  MaohaWifiSvr - ok
22:57:53.0111 0x28a0  [ 6D4111E1852A9F0BFC07BB69F3141841, 9BFF4517F26F1E9DF4DA6633B542EAA20A698B9397D2ED73134E7AEF306FBB15 ] MapsBroker      C:\WINDOWS\System32\moshost.dll
22:57:53.0136 0x28a0  MapsBroker - ok
22:57:53.0145 0x28a0  [ 47701ECA633574E122687693B5C5D35C, 1DB12767462347504956450FAD0D90B6E682E2E8959A6C5DF3792C3C3DA289B1 ] mbamchameleon  C:\WINDOWS\system32\drivers\mbamchameleon.sys
22:57:53.0253 0x28a0  mbamchameleon - ok
22:57:53.0270 0x28a0  [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy  C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
22:57:53.0314 0x28a0  MBAMSwissArmy - ok
22:57:53.0325 0x28a0  [ C3CDCCF07486BD2616A7B82946E07AC0, 1EF95DAB2DA856BC7D7573B2EB2D9006DF337F827F0B56A161D0C97F45DB755E ] megasas        C:\WINDOWS\system32\drivers\megasas.sys
22:57:53.0340 0x28a0  megasas - ok
22:57:53.0357 0x28a0  [ FADB2FE017E69EECE0E1BA78661C2E8C, BE99B49031D8B4B670B6F6B6E829E54406779CF6F1D8AFE8AB79A73E6764AB2F ] megasr          C:\WINDOWS\system32\drivers\megasr.sys
22:57:53.0395 0x28a0  megasr - ok
22:57:53.0408 0x28a0  [ 84178491109A97D0A0CFF0840A644CD9, B822A9F7C9623764430435DBCE1380386D0A0D9784779DDD3A7A2E59FC29AFF6 ] MEIx64          C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
22:57:53.0459 0x28a0  MEIx64 - ok
22:57:53.0468 0x28a0  [ 55A417C3E41F2A98666CF929EC19108E, A38C262B2863C87E4151525BF26D6AC16E7982D370E2C6998EB15C88C4BC8254 ] MessagingService C:\WINDOWS\System32\MessagingService.dll
22:57:53.0483 0x28a0  MessagingService - ok
22:57:53.0499 0x28a0  [ 573CE2135CA79AAB6EFB110EEB998F75, 225C81228C1261BA562DCC08C97A37754A8472A4C9A4C5BE5C19A40C15B93F62 ] mfeelamk        C:\WINDOWS\system32\drivers\mfeelamk.sys
22:57:53.0515 0x28a0  mfeelamk - ok
22:57:53.0530 0x28a0  [ FD60818B66B2E8A5415EA840E99A9D8F, 5D2F22909354534B821D958FBEF6A40EB4F642F53C7B509D00949096EF716F36 ] mlx4_bus        C:\WINDOWS\System32\drivers\mlx4_bus.sys
22:57:53.0562 0x28a0  mlx4_bus - ok
22:57:53.0579 0x28a0  [ 68F6977F1CFBAAC770D940A8C0326FA1, 90EE1E7DAC680EAA5AD50E9B0B9FD8FCE8DD6A02D5EF941B5AA5084CBD40BB80 ] MMCSS          C:\WINDOWS\system32\drivers\mmcss.sys
22:57:53.0583 0x28a0  MMCSS - ok
22:57:53.0599 0x28a0  [ D842ADDB5911945D51F61A0B1C8F36E3, 5EB93A1FD2D2D9FAB6121356E1AB18F2ADE9550D3033274AF7CA8F7FD51E59ED ] Modem          C:\WINDOWS\system32\drivers\modem.sys
22:57:53.0614 0x28a0  Modem - ok
22:57:53.0614 0x28a0  [ 9CCCB7FC3EDADEBA461D78615A6011A6, C120B58F25E8CCFD971EB78645C0682F367AD56DC15F2D8C1980CE75B04719DF ] monitor        C:\WINDOWS\System32\drivers\monitor.sys
22:57:53.0630 0x28a0  monitor - ok
22:57:53.0630 0x28a0  [ 27A07B2FB2E3057DA8DAEA4F25D843C7, 09D2B39E6B9AAEC879E5871DD6BCFF2AEF0B894F3B44649665A685F8B3CA6F27 ] mouclass        C:\WINDOWS\System32\drivers\mouclass.sys
22:57:53.0646 0x28a0  mouclass - ok
22:57:53.0646 0x28a0  [ 7BD6E7F7C9001AB21B8362CFFEE80B25, C470C3363EEF3A60409A5934988BFB9B72AE7C2BB63CC2C2D006D7EB1C797F6A ] mouhid          C:\WINDOWS\System32\drivers\mouhid.sys
22:57:53.0661 0x28a0  mouhid - ok
22:57:53.0681 0x28a0  [ F5BDAEE4B7D369D4C74668DCFBA3FF10, 100F39288E56AFE0D39D1CC235BDC9F3727C873CD3114E092DA7A08810BD3EB2 ] mountmgr        C:\WINDOWS\system32\drivers\mountmgr.sys
22:57:53.0684 0x28a0  mountmgr - ok
22:57:53.0700 0x28a0  [ C01441BA6F99890B7FF6CD0260B7750A, E02FFB1E8A3E423C9392ADAA9DF5FECF800DFAB3E09B74A029106DC337995539 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:57:53.0700 0x28a0  MozillaMaintenance - ok
22:57:53.0715 0x28a0  MPCKpt - ok
22:57:53.0731 0x28a0  [ E5F8E0143A8B64F2ED68674909B14075, 86518EFC5E832ABF153C266C7AC52128C90A741EFD074F593EC4F4BE8DEDAE95 ] MPCProtectService C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe
22:57:53.0747 0x28a0  MPCProtectService - ok


Piristibulus 16.08.2016 22:14

Teil 2:
Code:

22:57:53.0747 0x28a0  [ 30844BD376F9D01E62C820BEF446F1F8, 910D672EDB544A20AEB4450B4D89830F46EDD28CE0021156176315C5D068A1B4 ] mpsdrv          C:\WINDOWS\system32\drivers\mpsdrv.sys
22:57:53.0762 0x28a0  mpsdrv - ok
22:57:53.0800 0x28a0  [ 779CFDB17EA07A6D26FEBBAC95B65772, 74D9542E8DCCD07396A45A45D2F500AA6F9DCC1DB785A6153EB3067E42F576A4 ] MpsSvc          C:\WINDOWS\system32\mpssvc.dll
22:57:53.0847 0x28a0  MpsSvc - ok
22:57:53.0862 0x28a0  [ 50C2389CD04C5B8632E3DC2D733EF15D, 0F83A8A5F405BC6F401B5A75D45F6D07C61C0CA692D2A77C63E742622F5BF921 ] MRxDAV          C:\WINDOWS\system32\drivers\mrxdav.sys
22:57:53.0884 0x28a0  MRxDAV - ok
22:57:53.0900 0x28a0  [ C9BB4E2FCAB693FEB00CF940060D94F4, DBE5DACBAB0CF803EBBDC414FD4D2A159B9062892DE923E22E56CBCDB80F13A7 ] mrxsmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:57:53.0916 0x28a0  mrxsmb - ok
22:57:53.0931 0x28a0  [ 8F58AEAE00B39AC9AD93755E777B19D8, 335E4D9E9E81609BEAFA08376EE29C35DA6A1839FAFC37399B9066F03BFFFBC1 ] mrxsmb10        C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
22:57:53.0947 0x28a0  mrxsmb10 - ok
22:57:53.0963 0x28a0  [ 6C83C4A8278E48455DA13E554CEB45F1, 9389EF464F242861FCE8C22D2EB19E8574BF3E56C1A4FB064DE9E7480631E7F6 ] mrxsmb20        C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
22:57:53.0980 0x28a0  mrxsmb20 - ok
22:57:53.0984 0x28a0  [ 74C9D21523DAE0C18F413C196DF0058A, 3DB4B8CA368D9DD82FAE2C2BC828A21142C8D29780A7C8667188C447519FF702 ] MsBridge        C:\WINDOWS\system32\drivers\bridge.sys
22:57:54.0000 0x28a0  MsBridge - ok
22:57:54.0000 0x28a0  [ 308F08347923DEEDE7BC03EC7D485841, 72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0 ] MSDTC          C:\WINDOWS\System32\msdtc.exe
22:57:54.0015 0x28a0  MSDTC - ok
22:57:54.0031 0x28a0  [ F01B849D9D4A8CEAF32D4FDBD0B83C92, D2473AC4C6E6C03DEF13EA73EC78FB878BDC95C047651BF79A16C9DEA82AD046 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
22:57:54.0047 0x28a0  Msfs - ok
22:57:54.0047 0x28a0  [ 22ECD8F5D1DFADF2011BBB1700CB871D, 8F9EFF51137394EFA5471B8A29C541710063B65806B075B4925A84D5B6BC3BBB ] msgpiowin32    C:\WINDOWS\System32\drivers\msgpiowin32.sys
22:57:54.0062 0x28a0  msgpiowin32 - ok
22:57:54.0062 0x28a0  [ FD870F6968A145E4D2BA8A8842686B03, 34B8F601F3B5E42B4D0A41E2AF7DB4EB4E5B627DA8DA9A2A2D46B153AF23AEB1 ] mshidkmdf      C:\WINDOWS\System32\drivers\mshidkmdf.sys
22:57:54.0085 0x28a0  mshidkmdf - ok
22:57:54.0085 0x28a0  [ 30364757963A028CE5DF0FBAAC270173, C72588A6A52FF8E418A15D2C407A4DB7EA768585423720145F8253D5CA519DC2 ] mshidumdf      C:\WINDOWS\System32\drivers\mshidumdf.sys
22:57:54.0100 0x28a0  mshidumdf - ok
22:57:54.0100 0x28a0  [ 6BB0FEDDAE7135FA37FFAFF4D9E0E876, B41A3C0FFDFC493D6325ED493445AFCED04EC9DFF2B38125616FC5419AD1ACC4 ] msisadrv        C:\WINDOWS\system32\drivers\msisadrv.sys
22:57:54.0116 0x28a0  msisadrv - ok
22:57:54.0116 0x28a0  [ 07E3E54734B14F43A4A95A849C0A0DE2, 314AA02EA84D267B32DBAEBEA6C1AC1A266DED1E8D35A17B41D1D2AC75E8049E ] MSiSCSI        C:\WINDOWS\system32\iscsiexe.dll
22:57:54.0147 0x28a0  MSiSCSI - ok
22:57:54.0147 0x28a0  msiserver - ok
22:57:54.0163 0x28a0  [ 13D614E6B51ECF36746C48CE829FA7F6, CAD63C0A4F7110093F84C58252C5803F14E3FC46584B79DA17EC86D49FEAEA64 ] MSKSSRV        C:\WINDOWS\system32\DRIVERS\MSKSSRV.sys
22:57:54.0184 0x28a0  MSKSSRV - ok
22:57:54.0185 0x28a0  [ 642CDE46351D5D2D90311E77072AB46D, B2D3033E607BA2F6E6B9CFB1CBF154CD0CE910EA473C56343EC81B9B94044CCA ] MsLldp          C:\WINDOWS\system32\drivers\mslldp.sys
22:57:54.0200 0x28a0  MsLldp - ok
22:57:54.0200 0x28a0  [ F2302A5CE63CA7673200FAFCEEEDB6AF, B8C44FC2DC0332183DE325CDBF511101F3307225295EDD428CE575A8DE15C223 ] MSPCLOCK        C:\WINDOWS\system32\DRIVERS\MSPCLOCK.sys
22:57:54.0216 0x28a0  MSPCLOCK - ok
22:57:54.0232 0x28a0  [ 6114512EA26E835BA522C63635429DB5, 0F91CE41B4555316A79AEF3047C152D538CC9C7C329987C9FD0E3D961AFC87C8 ] MSPQM          C:\WINDOWS\system32\DRIVERS\MSPQM.sys
22:57:54.0247 0x28a0  MSPQM - ok
22:57:54.0247 0x28a0  [ AA538E16E644D00E3BA5349BBA9598EC, 64A68B06883FE7ED34E04AB119BA819753F1222923EDD4E802C35D402B89D075 ] MsRPC          C:\WINDOWS\system32\drivers\MsRPC.sys
22:57:54.0280 0x28a0  MsRPC - ok
22:57:54.0285 0x28a0  [ 0543BEFD41EC4D25C7F7CF36409CEC7D, 631622CFEC49952C0470531B23FFFFF483DC0EFFEF7A97B1179A600392C05DDD ] mssmbios        C:\WINDOWS\System32\drivers\mssmbios.sys
22:57:54.0301 0x28a0  mssmbios - ok
22:57:54.0301 0x28a0  [ C1569E4DB8EFE3617847BF041A3C842F, 99ADE5E7F50E04CAEC737F7F90741CCA8EE628996BA5EB6C6BC62184884429B6 ] MSTEE          C:\WINDOWS\system32\DRIVERS\MSTEE.sys
22:57:54.0316 0x28a0  MSTEE - ok
22:57:54.0332 0x28a0  [ 130B16970154BA9876B09E5C4BAC63BE, BE3AF8FC5A26AB9C9DBA9C015C2E1FD3C4CD9CB423A2BBDABA91428BF8620553 ] MTConfig        C:\WINDOWS\System32\drivers\MTConfig.sys
22:57:54.0348 0x28a0  MTConfig - ok
22:57:54.0348 0x28a0  [ 15D987C8F6CCD4AC94E070C5986762CB, 452FB0C48B86C7F8F53794CC2DDBF2B900B03A0383B2DE8F6A830F8CB0AFBAD8 ] Mup            C:\WINDOWS\system32\Drivers\mup.sys
22:57:54.0363 0x28a0  Mup - ok
22:57:54.0363 0x28a0  [ 3D2C5B4995CA0751D32DEA0DE9FDFE44, A26958785FD9E05E2CA97078C9BB277CD44222BF5F7D9E8DC2F3F6AAAFFC6483 ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
22:57:54.0385 0x28a0  mvumis - ok
22:57:54.0401 0x28a0  [ E605F35F03C881DC46902E0E2F5985B3, C97F0C733377E35B463EF7F6A5B879DA21AB512719899160C09278615FE39A21 ] MyEpson Portal Service C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
22:57:54.0432 0x28a0  MyEpson Portal Service - ok
22:57:54.0432 0x28a0  MySQLpearstem - ok
22:57:54.0448 0x28a0  [ AB6031419C320BBDF456102ADD011D7E, 3308C30CA5C50F08D6FCF662980C9B8ED04B744F65B0D77E60EFC655BC1F310B ] MyWiFiDHCPDNS  C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
22:57:54.0463 0x28a0  MyWiFiDHCPDNS - ok
22:57:54.0486 0x28a0  [ DB31EBB04C871F422C36A0962DA7D38B, B1BC2344744F537FB2C7D07B415F860195B7795E185253F05C0817A3764FEC10 ] NativeWifiP    C:\WINDOWS\system32\DRIVERS\nwifi.sys
22:57:54.0517 0x28a0  NativeWifiP - ok
22:57:54.0532 0x28a0  [ C3D9870E680D9D843B18F4626C3858FE, 43596CAC9FB488F810FBA954C52BC4D13F7D32028C40ACFE33DFD7EE36A65C17 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
22:57:54.0548 0x28a0  NcaSvc - ok
22:57:54.0564 0x28a0  [ 04CE2C0F0759EACD886BA4B658B60D5D, E34D0976FC5936C8629800D826DB127072D1DFC3D350EFACA3AA1B8119551762 ] NcbService      C:\WINDOWS\System32\ncbservice.dll
22:57:54.0586 0x28a0  NcbService - ok
22:57:54.0586 0x28a0  [ E6094065008FE423377294050E7CEA2D, 86E200227256407530E2C28243DEFBC3CB6E9497644404D9AD79DA242286DF7B ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
22:57:54.0617 0x28a0  NcdAutoSetup - ok
22:57:54.0617 0x28a0  [ 629CB21AC49C8867E0F29DF1C16DB7B4, 20663E68C69D0A1A2FE99A0C2A9DEFABF49786A1DC8F7F4E1699458AF57D7E79 ] ndfltr          C:\WINDOWS\System32\drivers\ndfltr.sys
22:57:54.0633 0x28a0  ndfltr - ok
22:57:54.0664 0x28a0  [ 36DD2C614720EC2970CB5E870BA69D8D, 692BDA4201119E0561E17E7E1A72320DBECDE3F8E4E65FBEA1B2C1128E16508B ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
22:57:54.0702 0x28a0  NDIS - ok
22:57:54.0717 0x28a0  [ 6DD605338FAAF6BA17662AA874E0D162, 636607829F5D7C3B7A4683C0A2DD594360D72F2AA3F8710153BE32575AE34A15 ] NdisCap        C:\WINDOWS\system32\drivers\ndiscap.sys
22:57:54.0733 0x28a0  NdisCap - ok
22:57:54.0749 0x28a0  [ E34196F285F8B8879E1FF36C31F7179E, 77A4F24F995D4C0689C43F9956E08DCEC62517E4F8B1B9EAA1852B5293DB5B9A ] NdisImPlatform  C:\WINDOWS\system32\drivers\NdisImPlatform.sys
22:57:54.0764 0x28a0  NdisImPlatform - ok
22:57:54.0782 0x28a0  [ 1FAD2398673F30CEC616B89C46B7DCBA, 70302049E6AE2BC6B3A7A9DE54D3F940AD6A9771CC2EBCCEC65994E67A25ECB5 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:57:54.0786 0x28a0  NdisTapi - ok
22:57:54.0802 0x28a0  [ AEB8ECBE66CC46854066CB1F5623E179, 2F650A85A9DAE38887610C0B876621035616CEDB65D4BBBD7F1405616D218AAF ] Ndisuio        C:\WINDOWS\system32\drivers\ndisuio.sys
22:57:54.0818 0x28a0  Ndisuio - ok
22:57:54.0818 0x28a0  [ 7340104C2BF2F126714F7CDE85E63610, 45B64EC6F3A4C43F7D74806789067658C6EF0D44D36B841F4D26E1EBC95AF66C ] NdisVirtualBus  C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
22:57:54.0833 0x28a0  NdisVirtualBus - ok
22:57:54.0849 0x28a0  [ 07ADC1F8DCBEB8104D75129B11584B8C, CB51A294D9FD4E210DBEEF05A1E60A96CE52D6D138EF62A54E1F608F90FED300 ] NdisWan        C:\WINDOWS\System32\drivers\ndiswan.sys
22:57:54.0865 0x28a0  NdisWan - ok
22:57:54.0887 0x28a0  [ 07ADC1F8DCBEB8104D75129B11584B8C, CB51A294D9FD4E210DBEEF05A1E60A96CE52D6D138EF62A54E1F608F90FED300 ] ndiswanlegacy  C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:57:54.0902 0x28a0  ndiswanlegacy - ok
22:57:54.0918 0x28a0  [ 78A12E3DF035B5D054986949B19BE43C, AD9B34F89B9F27D473BD5FCE6694A40FCCB808B61ABEDD6F70F1AF6C7E73ABF8 ] ndproxy        C:\WINDOWS\system32\DRIVERS\NDProxy.sys
22:57:54.0934 0x28a0  ndproxy - ok
22:57:54.0949 0x28a0  [ 04C8859355C1DC9C0FA198D1894D71C2, E7C67E73009341B5D402470C686781B3C7BBE2531CE26665E08E711B990B1A77 ] Ndu            C:\WINDOWS\system32\drivers\Ndu.sys
22:57:54.0986 0x28a0  Ndu - ok
22:57:54.0987 0x28a0  [ 6C76780A01FC2B885BD6E957B5C36B02, DB7834F03A765F65C773E772D8051AFADB22CA4B5074180AA397857A0C47A068 ] NetAdapterCx    C:\WINDOWS\system32\drivers\NetAdapterCx.sys
22:57:55.0003 0x28a0  NetAdapterCx - ok
22:57:55.0003 0x28a0  [ 5D1513BD6430307C9DB86C6E351372ED, D2AB709CF7CFA5B857B084AFC821914A975B7DDDCE154229981F19448973BD6D ] NetBIOS        C:\WINDOWS\system32\drivers\netbios.sys
22:57:55.0018 0x28a0  NetBIOS - ok
22:57:55.0034 0x28a0  [ 6FEBB0A847FFD5F057B9AC8889F1B9A7, 558BCC64C59079E6569F61CCE1219A124B3313FC4E6CB5CBCC94124D202FF19D ] NetBT          C:\WINDOWS\system32\DRIVERS\netbt.sys
22:57:55.0049 0x28a0  NetBT - ok
22:57:55.0065 0x28a0  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] Netlogon        C:\WINDOWS\system32\lsass.exe
22:57:55.0065 0x28a0  Netlogon - ok
22:57:55.0087 0x28a0  [ D3BF2DA9216A4CF22A97820A50A67EFF, D00CBE0A7ECFB449D9B48967A01EE56141404EBE229893D5A1710781AD5F2551 ] Netman          C:\WINDOWS\System32\netman.dll
22:57:55.0103 0x28a0  Netman - ok
22:57:55.0118 0x28a0  [ F2645D51DD8AABC8BC72358409410437, 8CB97628923D6CEA6EFAD7E666BE92C154060BD108C28D46287A520A14B18ADA ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
22:57:55.0149 0x28a0  netprofm - ok
22:57:55.0165 0x28a0  [ 724EA060EF56BAB4DED8F731FA56279B, E07FFE11D7B5C94D6B56940C6423ACB85910F6E8789E788EC91EEEE1C02B247F ] NetSetupSvc    C:\WINDOWS\System32\NetSetupSvc.dll
22:57:55.0187 0x28a0  NetSetupSvc - ok
22:57:55.0203 0x28a0  [ EFA857E2B0CC7C9DFEF48A2187B910F7, 424475568CD70237F056838388A5F7BDCD1B09349085498644C75940B12E8EAF ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:57:55.0250 0x28a0  NetTcpPortSharing - ok
22:57:55.0488 0x28a0  [ AC754EB741173D97931947D834F1FE94, 1DC03E5561B4CAFF126038D56AEC43C39642920B1EA1EEC23E2BFCEB644BC94A ] NETwNb64        C:\WINDOWS\System32\drivers\Netwbw02.sys
22:57:55.0797 0x28a0  NETwNb64 - ok
22:57:55.0858 0x28a0  [ B996DE26A2E16053C9485F5905B05320, 30EB2CEB466A4F05A44F7CBFCDFD8CC3C27B5FCF1269C1B9410C48AB362D2A75 ] NgcCtnrSvc      C:\WINDOWS\System32\NgcCtnrSvc.dll
22:57:55.0975 0x28a0  NgcCtnrSvc - ok
22:57:56.0057 0x28a0  [ 2EC2F2E4C88BA9B72D1F6B92234BCD53, 4DC98EBE5A3B34ED654017F076F457970D3FBF749DC54A6533DAABDE85A7C4FE ] NgcSvc          C:\WINDOWS\system32\ngcsvc.dll
22:57:56.0214 0x28a0  NgcSvc - ok
22:57:56.0260 0x28a0  [ 02E736F9861F1A6134736CF7473C513F, 7C574A50980885B213EFC0C394AFE613879B669246A4EA5EA6B5F791F7F6F32E ] NitroDriverReadSpool9 C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
22:57:56.0316 0x28a0  NitroDriverReadSpool9 - ok
22:57:56.0370 0x28a0  [ 0B5083278F195C26FE9E0140AEAEDCBE, B4D505963D5EBA14EC80E6D0BB8B862D96D1D1C3A57F4744AEBA3FF4BFB1997A ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
22:57:56.0509 0x28a0  NlaSvc - ok
22:57:56.0573 0x28a0  [ CD2C0C25ECFCF816306126D3C208614B, C0C8B59BDDB349A593DFF5107841EB76618631C867D7C8F234C9ECBD76713CB0 ] nlsX86cc        C:\WINDOWS\SysWOW64\NLSSRV32.EXE
22:57:56.0611 0x28a0  nlsX86cc - ok
22:57:56.0642 0x28a0  [ 001CBD7A2CD45C4EB39C01C3C677EF73, F4AAF4D60DB1232921C7811A62287B55C7C098B7A1FF9A40D88AF58A5ABECBA2 ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
22:57:56.0708 0x28a0  Npfs - ok
22:57:56.0735 0x28a0  [ 90F5DC9802AAA00CD0B6E2AD9E7FFADC, 71C0777829299DECA6ACD42F38802DBE3C29A42CFBD8A396F39DFA44D1F55B6C ] npsvctrig      C:\WINDOWS\System32\drivers\npsvctrig.sys
22:57:56.0796 0x28a0  npsvctrig - ok
22:57:56.0826 0x28a0  [ 1993C85962692EF7024501E7FE92D466, F5BCAA8308495EBF8BB061C2015E07C202A779668D171364D7E312975BC18B10 ] nsi            C:\WINDOWS\system32\nsisvc.dll
22:57:56.0917 0x28a0  nsi - ok
22:57:56.0945 0x28a0  [ 0C6218321A09A7B51BA7FFAFBA4CCB21, 330B3FA793A78410B28DFC8250BBF24442E3BB80434A7938BB96F02337614E0D ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
22:57:57.0021 0x28a0  nsiproxy - ok
22:57:57.0219 0x28a0  [ D1AF837A1555990602A51A3ED238EC80, 37F25AAC4431C665F014FF7EB2FBB395621581200CB5029D4C3F5040E9181F52 ] NTFS            C:\WINDOWS\system32\drivers\NTFS.sys
22:57:57.0477 0x28a0  NTFS - ok
22:57:57.0509 0x28a0  [ 6E6DD6F9DD2A034CF85E94047DBDB992, 63D0A0756F551B7668D1CBAB24B29FD462C706E8A81690BC248D6C92061FE215 ] Null            C:\WINDOWS\system32\drivers\Null.sys
22:57:57.0603 0x28a0  Null - ok
22:57:57.0636 0x28a0  [ D261DF41F0840F734856A2B4F5E072C7, 2E703556D0C919375D0B7770513456844B13362190643D5524663EC8546E0FF5 ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
22:57:57.0704 0x28a0  nvraid - ok
22:57:57.0740 0x28a0  [ 23B702B555EB0436B9DAA0BC63DA65CE, D454F80D9657CFEC852F022C12D7B2C1A2D7D247ECC591EDB07B9369DFD8C99E ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
22:57:57.0801 0x28a0  nvstor - ok
22:57:57.0854 0x28a0  [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:57:57.0925 0x28a0  odserv - ok
22:57:57.0972 0x28a0  [ 17997DC2441F7E29CDFC6458E0392764, 636CCE2DA1EF8195B33F8D6D5C8CC151D58EBF08DC9AD8ACCCE7ABD41A69639F ] OneSyncSvc      C:\WINDOWS\System32\APHostService.dll
22:57:58.0073 0x28a0  OneSyncSvc - ok
22:57:58.0124 0x28a0  [ E6D14F57D20E1C70482BA3ABAC367E4B, 9C0C5337F38EBC446FBC968098C55DF7FF101CF2291FD3A98EC7055F36964BC8 ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:57:58.0175 0x28a0  ose - ok
22:57:58.0214 0x28a0  [ 4578ECA1FCEF4E7C787D84F78625143B, F5FE84D6D7412A4C037772593C434253D590E476B0B7498987A1697BED86A510 ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
22:57:58.0299 0x28a0  p2pimsvc - ok
22:57:58.0345 0x28a0  [ 2BBCED66D7AFC968BDBB0E4D8524DF0A, 762D916390F9DE69B3EA1D31244224F910645F8E5CEF4C505B76B215BFDFCD9A ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
22:57:58.0441 0x28a0  p2psvc - ok
22:57:58.0474 0x28a0  [ 6B81BF7853D161DB8AC62CD8B9C2DE6B, B2DC06D135FD2501217DDA7349556EB873309E02188D4C3901807BA24FAB30C7 ] Parport        C:\WINDOWS\System32\drivers\parport.sys
22:57:58.0533 0x28a0  Parport - ok
22:57:58.0558 0x28a0  [ F9C32E5ECA5D29852A93C3888A4CC4B2, D52FFB5B85962D5C8FF8016627CBAE69472DDBA559261B6C7FD6DC4C677BB7C0 ] partmgr        C:\WINDOWS\system32\drivers\partmgr.sys
22:57:58.0605 0x28a0  partmgr - ok
22:57:58.0655 0x28a0  [ CE515B2C6E2EA50053A8862398646B38, C85D370E5250AFCF44796CE274B5A100C6829DC28BF1D4C6991EF61DE46FD10A ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
22:57:58.0738 0x28a0  PcaSvc - ok
22:57:58.0779 0x28a0  [ 55E45E0A89429AE9C62D728B9C4891C0, 729922C3488866C8D67F00E82C082F2E8E6F05180F4767AD30FC7E1FFE4946C5 ] pci            C:\WINDOWS\system32\drivers\pci.sys
22:57:58.0836 0x28a0  pci - ok
22:57:58.0857 0x28a0  [ 214DCC87E3898F738075D1341252A552, E721FBBC3510DDB848A8CAEA3B6031EE988F42252DBC3BF7BDB6ABD9A0D9FABD ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
22:57:58.0891 0x28a0  pciide - ok
22:57:58.0913 0x28a0  [ AED76A3333B3A31536E430020E0226FC, EC255B79B0908E3C142D92E35B79D90A3F2594BA012CA2B1B04A6A8745153430 ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
22:57:58.0954 0x28a0  pcmcia - ok
22:57:58.0969 0x28a0  PCSUService - ok
22:57:58.0990 0x28a0  [ E63FB38B6E75B39467492FBAD2CD512A, DB406C92BA2460C833A49B98EB5BD58348E868F643A0123B0C9B5315FFC6A124 ] pcw            C:\WINDOWS\system32\drivers\pcw.sys
22:57:59.0025 0x28a0  pcw - ok
22:57:59.0047 0x28a0  [ 2CCD68D8A6BBFF2DE0EC54F086C5F3BC, D3D5A56F0C1BEBA9A05CE82F4BBD011E40A15358C00A668F9614F7E002A65A08 ] pdc            C:\WINDOWS\system32\drivers\pdc.sys
22:57:59.0114 0x28a0  pdc - ok
22:57:59.0166 0x28a0  [ 1509A77F840AA9E72CF8247D0CF2FBDE, 2D47AD4D8F5C2D871E603FB6D72D25EFD0E63FA3A542DAADAB9D82ED074C0E0B ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
22:57:59.0300 0x28a0  PEAUTH - ok
22:57:59.0323 0x28a0  [ 540116170E2135FCD5DDE77702166B67, CBEC51C2D47532F1781B3255040F303263420B204C2F8BB2B5D1EC342F57B285 ] percsas2i      C:\WINDOWS\system32\drivers\percsas2i.sys
22:57:59.0360 0x28a0  percsas2i - ok
22:57:59.0381 0x28a0  [ 8356F87553BF49C703CF382033815898, 245EB941566D848F134629690BF271B1CBEAB6440771D3D8D7AED3756835354E ] percsas3i      C:\WINDOWS\system32\drivers\percsas3i.sys
22:57:59.0415 0x28a0  percsas3i - ok
22:57:59.0441 0x28a0  [ CB5343FF52A702A9ACFAAE6BE972FE09, EAA5362D91D05D382DF4EBBAA3FD575456F23CAD531CC6F1270F8254892DBF02 ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
22:57:59.0491 0x28a0  PerfHost - ok
22:57:59.0550 0x28a0  [ AC8BC4D8BD937897EA765C1ACCF1BDE4, 0AC36AE36644AD728F9C46208F43F4A9A6323E8C28A7A0EE0A10A536D8FA175F ] PGService      C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
22:57:59.0659 0x28a0  PGService - ok
22:57:59.0698 0x28a0  [ 33CB582342A8FC574EE439D583495137, D8F087C42DA05E5584C8C124452B4A5CE7F2D56D7DA4AB733D7492A8D7D87BC2 ] PG_Service_Launcher C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
22:57:59.0923 0x28a0  PG_Service_Launcher - ok
22:57:59.0949 0x28a0  [ 3A6D56E0E072AB0F022FE03ED8C2693A, 8AA5823F68FEDEDB5E8916BD35832BC438A781142CF1672983D593B903083A68 ] PhoneCompanionPusher C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
22:58:00.0032 0x28a0  PhoneCompanionPusher - ok
22:58:00.0057 0x28a0  [ 0B2E100645AFAB3204313148DFE42322, C28FA6EF4FD8001E8F3367A7CB32E44F5D6A3E1EFBEC3C947A2FD3C3B0AF3568 ] PhoneCompanionVap C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe
22:58:00.0154 0x28a0  PhoneCompanionVap - ok
22:58:00.0198 0x28a0  [ CFA4868B2932396D47BCC8E7350907C1, C757910212982F54CF9B2CFFCB632D58E3A07E468A2DA42CDF97BFB6A05823DE ] PhoneSvc        C:\WINDOWS\System32\PhoneService.dll
22:58:00.0313 0x28a0  PhoneSvc - ok
22:58:00.0336 0x28a0  [ 06A31E2C90347128A1A25290568E152C, 7F0BC96C116A5C6B9796233CA975B1F6A73D554A533191F38295D60221E503C4 ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll
22:58:00.0394 0x28a0  PimIndexMaintenanceSvc - ok
22:58:00.0472 0x28a0  [ F931F21E4287FE3ECCF09B54A232BBA2, CEB7AB3236E5F30214027092B7B695ED35F7A1E007DF4046797D1E4DFEF49EC8 ] pla            C:\WINDOWS\system32\pla.dll
22:58:00.0603 0x28a0  pla - ok
22:58:00.0615 0x28a0  [ FEA494AC3A1BAE63C1F2AF267D49F1DB, 0722FEA2481740B53EF26B1CA59166C63C157A5C708AC93DF3FBB74A27266C9C ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
22:58:00.0651 0x28a0  PlugPlay - ok
22:58:00.0681 0x28a0  [ 56D7A89423325121C4A9BD5C326414F3, 649048C23D1973C3504E26B35362AC99DFE9BF31FFE73F45B43306A212AEA34C ] PNRPAutoReg    C:\WINDOWS\system32\pnrpauto.dll
22:58:00.0706 0x28a0  PNRPAutoReg - ok
22:58:00.0724 0x28a0  [ 4578ECA1FCEF4E7C787D84F78625143B, F5FE84D6D7412A4C037772593C434253D590E476B0B7498987A1697BED86A510 ] PNRPsvc        C:\WINDOWS\system32\pnrpsvc.dll
22:58:00.0761 0x28a0  PNRPsvc - ok
22:58:00.0779 0x28a0  [ F70CAC34B455D05EAA04B2F8FB58E1CB, 295BFFB3DA03C5CE5462C11D3240024B68AC06E8DEA9062A739BE2CCEE19EB5D ] PolicyAgent    C:\WINDOWS\System32\ipsecsvc.dll
22:58:00.0821 0x28a0  PolicyAgent - ok
22:58:00.0840 0x28a0  [ 60C8376B48BA96F07AEA536527433D44, EB988C119C3E71169B91ED2A744C71933DD35447DC4A8249E80EC24E9E7077D4 ] Power          C:\WINDOWS\system32\umpo.dll
22:58:00.0870 0x28a0  Power - ok
22:58:00.0882 0x28a0  [ 5645B9D9788CCA2C88B9534996ED2D6D, 4988942DF163DB5B9B1A08CE6B628D2C47C2E2EAA30AEAE4EFE21C8CF4C8DC5D ] PptpMiniport    C:\WINDOWS\System32\drivers\raspptp.sys
22:58:00.0913 0x28a0  PptpMiniport - ok
22:58:00.0996 0x28a0  [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify    C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
22:58:01.0194 0x28a0  PrintNotify - ok
22:58:01.0209 0x28a0  [ 372913E12677A8CBBBABDD8311894F9D, A5233D95A0D22D2A9DB214E7CB79A99D389B67189FF6A87D0AD4610A333A637F ] Processor      C:\WINDOWS\System32\drivers\processr.sys
22:58:01.0233 0x28a0  Processor - ok
22:58:01.0249 0x28a0  [ B2DC3BA675F95343D55EC989FE303561, C53FCA036358B0B11BBE5348074FA24831CF67C9FEE31A3DC9CF88B6178CFBC8 ] ProfSvc        C:\WINDOWS\system32\profsvc.dll
22:58:01.0290 0x28a0  ProfSvc - ok
22:58:01.0302 0x28a0  [ FC98407B85A31161851FDE245517574F, 2CCD706CF243934FCDA32B24CE0C385EA2E67F206E0306FA584496F583A20CD1 ] Psched          C:\WINDOWS\system32\drivers\pacer.sys
22:58:01.0323 0x28a0  Psched - ok
22:58:01.0335 0x28a0  [ 7A68710BAC9B6809314B86C0CB1CBC4A, C02D97993D1F6FE6EFBA5B1366B3A4FE8CE1136A95F3A2DA07BA59554C163501 ] QWAVE          C:\WINDOWS\system32\qwave.dll
22:58:01.0364 0x28a0  QWAVE - ok
22:58:01.0373 0x28a0  [ 819602BBBFDB0BD46DEA3715BF0DD452, D4007FF1E5296316B53436CA3598D6B1CF4F60AB77D5B02F3E595081EDD5D879 ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
22:58:01.0395 0x28a0  QWAVEdrv - ok
22:58:01.0418 0x28a0  [ CDF47037A0939F56D11F699629C276AD, A63F2A3FE80FB8084E3870E907505694B79EE1D9E56E292C01D481FEFD2534B0 ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:58:01.0438 0x28a0  RasAcd - ok
22:58:01.0449 0x28a0  [ 28C2EA278070EE12701D0EDF8CB0EC36, F10288C1C6835840026DB30285345EF892DE989F43C948E7F4760B8895FF675F ] RasAgileVpn    C:\WINDOWS\System32\drivers\AgileVpn.sys
22:58:01.0477 0x28a0  RasAgileVpn - ok
22:58:01.0486 0x28a0  [ 7B82197BF35CC3BE59AEF8B706AB8A16, AB0216164A548A48CD21F5F035E57E867584A96890B9887EC08F8DABDD89F990 ] RasAuto        C:\WINDOWS\System32\rasauto.dll
22:58:01.0511 0x28a0  RasAuto - ok
22:58:01.0522 0x28a0  [ 17E565710172ED71B8531D8822E1C5D1, 0CA39ABD9E544DDAD9D9D7D1FC50444274C31E18F9BF73069051D9F62833698F ] Rasl2tp        C:\WINDOWS\System32\drivers\rasl2tp.sys
22:58:01.0549 0x28a0  Rasl2tp - ok
22:58:01.0568 0x28a0  [ DF0702D6A190452E1BFA52F36E58640A, 37B7B8220CDE965F1232D883CEEEDDDB309ABA0ACBE38486E69B9052D39187C4 ] RasMan          C:\WINDOWS\System32\rasmans.dll
22:58:01.0619 0x28a0  RasMan - ok
22:58:01.0630 0x28a0  [ 9387DF155233D45D4E010F4F2FB52A57, CABC25DA4E512809AED0085767BDD94BF3C1DA792BFF8A009B5465D9110E7060 ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:58:01.0655 0x28a0  RasPppoe - ok
22:58:01.0665 0x28a0  [ F0F4EEDEEBEE7A4244FAFB96A16B5712, F64717E601BD5EB674003009507B8CDD6F69F00E8670D6895EC64786166A0E8D ] RasSstp        C:\WINDOWS\System32\drivers\rassstp.sys
22:58:01.0691 0x28a0  RasSstp - ok
22:58:01.0705 0x28a0  [ BBE0FC9C9E7C556DA6E6E6904739DF7E, E6F0C48371EEB92B796DA0AE49DA575AC0B4403146F75A1040DC2C1A44CAB0F6 ] rdbss          C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:58:01.0737 0x28a0  rdbss - ok
22:58:01.0752 0x28a0  [ 79A415E6FA915EFC00297DAB16EC2635, 47BB49F6D756214193D38A4AB182B541AAC180381C3111FF7F9B0AD4C44D8733 ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
22:58:01.0772 0x28a0  rdpbus - ok
22:58:01.0774 0x28a0  [ 7135785C21CA79D270D11037C43D3F19, 654A3C65CF891ED8C82A740D10CF607FC7D709185E664DE03288CEB5B25F03A6 ] RDPDR          C:\WINDOWS\system32\drivers\rdpdr.sys
22:58:01.0805 0x28a0  RDPDR - ok
22:58:01.0821 0x28a0  [ 97A61A3CB2B5CB4FC32B3224EF333448, E4F2E8BCEE3639BE57BBC8A8E67FDE42C3A5158F1204684B0ECD216F4AA044A3 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
22:58:01.0836 0x28a0  RdpVideoMiniport - ok
22:58:01.0852 0x28a0  [ 69BB204AE07EE84ECFAB1BF13C4BD04B, 1CA832CBF4AE4821EEA2A19F9519C2D1D00406B8CCE2A86FE3B33A5F293DB218 ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
22:58:01.0874 0x28a0  rdyboost - ok
22:58:01.0905 0x28a0  [ 940D6F5A2B0A61EE4170DF84F6C95C20, F8EE846DC8015EDFE7CB5BEEDC977EAA9C586BAC2216DE69D8ECCBDBC7408649 ] ReFSv1          C:\WINDOWS\system32\drivers\ReFSv1.sys
22:58:01.0952 0x28a0  ReFSv1 - ok
22:58:01.0968 0x28a0  [ 6242A806ED208E80BB788CCA967F672E, B960DAB695BE43665B1F9E433BE5E774E2831012AE2E9C8404CECBCE496A3022 ] RegSrvc        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
22:58:01.0974 0x28a0  RegSrvc - ok
22:58:01.0990 0x28a0  [ FD2B3A645798A2EFB7FB61AC42AAA611, 8A121D361A73CA19AA87B1AD33B8020A99444BF4C8904944AD5913C5083859B8 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
22:58:02.0037 0x28a0  RemoteAccess - ok
22:58:02.0052 0x28a0  [ 3183B161B1F05333F6C325577FEF3596, D6A89B2A021377B6F371E5B9EFC36FF018822B28F0ED41F8CD2F00C5C8605707 ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
22:58:02.0090 0x28a0  RemoteRegistry - ok
22:58:02.0106 0x28a0  [ 94DCF20DF6170B557AFD386E37C128BC, 70FB7C7A7D2BFA95EACEEE38B39E1DCA93DA63AE1898C4F54956B9413C60EB88 ] RetailDemo      C:\WINDOWS\system32\RDXService.dll
22:58:02.0153 0x28a0  RetailDemo - ok
22:58:02.0175 0x28a0  [ E82F3B1918C6A5FE6EB761CDF1E772AF, 0C993FCB7BFD6E01B70A1821E0DEAFA2CB241AF8C2E6D4CC120F59C1B5F6FF5F ] RFCOMM          C:\WINDOWS\System32\drivers\rfcomm.sys
22:58:02.0206 0x28a0  RFCOMM - ok
22:58:02.0222 0x28a0  [ FBA61BB4C484A01A655AFB18FF86C417, D53B2110CB09D0A909C4E330C468351BFE076BB056CCDDCB8ADA2FB91E96352E ] RichVideo64    C:\Program Files\CyberLink\Shared files\RichVideo64.exe
22:58:02.0237 0x28a0  RichVideo64 - ok
22:58:02.0253 0x28a0  [ 237AAA173D673B77740BE6AE3359AE47, E9683DBF594522A6C7331EB3F6EE33920B3E232689E814F0063871D6540479C7 ] rijufoze        C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\hnst6DCB.tmp
22:58:02.0291 0x28a0  rijufoze - detected UnsignedFile.Multi.Generic ( 1 )
22:58:02.0375 0x28a0  rijufoze ( UnsignedFile.Multi.Generic ) - warning
22:58:02.0491 0x28a0  [ 068220E1B417556F4226E6A3CA0A1C24, 381DD82EF6EAEE83B5B3FA123D04A4D1EEB3407737683C22BBA787C39DCAFFE3 ] RmSvc          C:\WINDOWS\System32\RMapi.dll
22:58:02.0538 0x28a0  RmSvc - ok
22:58:02.0538 0x28a0  [ 672724C8B21B7DC56646045DE4D5B860, 79986E80A92C949C543959F1E35647A9788DAB2892AC20B6DEA5C0BBC0CEDE9E ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
22:58:02.0554 0x28a0  RpcEptMapper - ok
22:58:02.0575 0x28a0  [ 109C1D609951E886D3643B15C1EDD1C2, 347D8E7C50EC7F96217C7421D9BC8A42C9DF50B94169CB58DCF857A63C33C2EA ] RpcLocator      C:\WINDOWS\system32\locator.exe
22:58:02.0591 0x28a0  RpcLocator - ok
22:58:02.0623 0x28a0  [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] RpcSs          C:\WINDOWS\system32\rpcss.dll
22:58:02.0674 0x28a0  RpcSs - ok
22:58:02.0676 0x28a0  [ 5FF28F097C9699097B473F8FC7C1AA7D, 695560F1DBD85073F3D6CB1FF16F16504CA044EA62E940E463A16BBA8B86E2FA ] rspndr          C:\WINDOWS\system32\drivers\rspndr.sys
22:58:02.0692 0x28a0  rspndr - ok
22:58:02.0723 0x28a0  [ 6CBF283C7EBD07B7BB01D3E33B11BB28, 90B7AF25EFDBC71FDDD48D668BF410DB828ABD512FC02146E76962A8FF053DE9 ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
22:58:02.0739 0x28a0  RtkAudioService - ok
22:58:02.0754 0x28a0  [ AE4607D7C7AA83A863BFA214483E8EE4, 828CC9F40BAB2F65AF75608D37ED17EF608E73E911132DD085F0685F163EFEC6 ] RTSUER          C:\WINDOWS\system32\Drivers\RtsUer.sys
22:58:02.0776 0x28a0  RTSUER - ok
22:58:02.0839 0x28a0  [ 11FB11B89D7889506F1DF51AD31A7E6C, F58735A6FEC79B6C19B5B23F310D4836AA8A7EA033B56E74D5AF58BE1FFF05D1 ] rtsuvc          C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
22:58:02.0923 0x28a0  rtsuvc - ok
22:58:02.0939 0x28a0  [ 82F73415998B255CA3137E66FABDABEF, 34021170DB62274A01A7ACB7BECA688EEB8A9CE0E02916721FA1CAA8C349E24D ] rtux64w10      C:\WINDOWS\System32\drivers\rtux64w10.sys
22:58:02.0976 0x28a0  rtux64w10 - ok
22:58:02.0977 0x28a0  [ B5DAEE69BACA64D2BB004568E22D8756, C0072CF6B438ED756435A182D55AC55F3AD356ACBD483DE06A94893D3CA8CCC5 ] s3cap          C:\WINDOWS\System32\drivers\vms3cap.sys
22:58:02.0992 0x28a0  s3cap - ok
22:58:03.0008 0x28a0  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] SamSs          C:\WINDOWS\system32\lsass.exe
22:58:03.0024 0x28a0  SamSs - ok
22:58:03.0039 0x28a0  [ 5E73FB63E2DBC75FE0C17DEB0010CE0E, 9DAC47486262397D03BC01F7438CAB62CF33BD7B5283F5B9548C770A3D6D0ADC ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
22:58:03.0055 0x28a0  sbp2port - ok
22:58:03.0081 0x28a0  [ 3CD0130FFDEAEACF0905B482F3934EA3, 1EC355B63135FD2563093EBB206741C0C4CCE0551A662F6DC86C875146A88B06 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
22:58:03.0117 0x28a0  SCardSvr - ok
22:58:03.0131 0x28a0  [ 9EE060D6560FFBFBDB2ED5D6ED192294, 14387B69CD26D12BE31A23251B6AA8EDFC4D6CDE4FA558F0950DE91D2DD03946 ] ScDeviceEnum    C:\WINDOWS\System32\ScDeviceEnum.dll
22:58:03.0165 0x28a0  ScDeviceEnum - ok
22:58:03.0175 0x28a0  [ 3D9A82B03C92D1FEC42CB171D6F57778, DC027F02F5EB5F1D10DB6F405FB0C15D4D5C922445F5F3C916624113278AF072 ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
22:58:03.0192 0x28a0  scfilter - ok
22:58:03.0217 0x28a0  [ D4DB6B318A0A0C74A90260725A228C0B, 57BA2EF9D880488C785C806ABF9EE753A48E589129442D72F815CD6EFFA07B22 ] Schedule        C:\WINDOWS\system32\schedsvc.dll
22:58:03.0290 0x28a0  Schedule - ok
22:58:03.0305 0x28a0  [ 9055ADDFBA4C8B914C914CE693B55C0A, DB213AC36E14D856B81D2AFE46815402537A2ABEEA15032A9FF436F953129441 ] scmbus          C:\WINDOWS\system32\drivers\scmbus.sys
22:58:03.0317 0x28a0  scmbus - ok
22:58:03.0329 0x28a0  [ B6F2363584E62960846F7C3F00124A4F, 252189FF9D623CF69BF415FF7C7FE74B0BBF756B632420578BFAFF6595616CF7 ] scmdisk0101    C:\WINDOWS\System32\drivers\scmdisk0101.sys
22:58:03.0354 0x28a0  scmdisk0101 - ok
22:58:03.0367 0x28a0  [ 9450FA11E9DE6715FCB71A519A8FF90B, B7E341C6E4CE967FCDD0D17A497C07E8A1C6B0AACE8A6E8E5D6C21EF73F13E16 ] SCPolicySvc    C:\WINDOWS\System32\certprop.dll
22:58:03.0391 0x28a0  SCPolicySvc - ok
22:58:03.0399 0x28a0  SCService - ok
22:58:03.0414 0x28a0  [ FCBB8A17B4437B2CA8CC8DA8CB1D306E, 5FA762B1B6C8A45ED6F304A45B500038537ABD3DF6328F3C8E2BD43CBDEAB835 ] sdbus          C:\WINDOWS\System32\drivers\sdbus.sys
22:58:03.0441 0x28a0  sdbus - ok
22:58:03.0453 0x28a0  [ F3714DBAA42C15F78FFCDFE4273214EB, 2D018970B92C5F0744FAE10A2FC298F3DCEA5C2EDEB760F4F0651337B9878ABF ] SDRSVC          C:\WINDOWS\System32\SDRSVC.dll
22:58:03.0477 0x28a0  SDRSVC - ok
22:58:03.0477 0x28a0  [ 120DFCB71D6C502613A9E2D50E16850C, 2C294010AD1C9C380CD5221A37720544178B7358C8C8553AF44055E4CEE5DAF5 ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
22:58:03.0493 0x28a0  sdstor - ok
22:58:03.0509 0x28a0  [ EFD644DD091E1D94555FC3BBC95EA66D, FBDDA6680BEC378CCF12A32D9186020E884DA15A1E789D1531B1E687FC7B54B1 ] seclogon        C:\WINDOWS\system32\seclogon.dll
22:58:03.0524 0x28a0  seclogon - ok
22:58:03.0540 0x28a0  [ 07F83829E7429E60298440CD1E601A6A, 9F1229CD8DD9092C27A01F5D56E3C0D59C2BB9F0139ABF042E56F343637FDA33 ] semav6msr64    C:\WINDOWS\system32\drivers\semav6msr64.sys
22:58:03.0578 0x28a0  semav6msr64 - ok
22:58:03.0578 0x28a0  [ B605A44ACA1FCFF736235A4D7AEDA548, 48D8B5BC027CFE91AF7402C463327572181D4C1B1E2942F4D05792EED070B2DC ] SENS            C:\WINDOWS\System32\sens.dll
22:58:03.0609 0x28a0  SENS - ok
22:58:03.0656 0x28a0  [ 1CC993A041899B48D5DF4D3F4A4425FC, 8D138B3A92C0E181C865A37AD55EE2D55CC352ED9B60BF60BE0AC610F13F8FA1 ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe
22:58:03.0740 0x28a0  SensorDataService - ok
22:58:03.0773 0x28a0  [ 7BFD114F0F308CE29AEB8F16056D0658, 0CD3B3C69DCB3EAD8F8EF5C633911DD4F2C1167DC6FE28107EE38713A35A1F5C ] SensorService  C:\WINDOWS\system32\SensorService.dll
22:58:03.0816 0x28a0  SensorService - ok
22:58:03.0830 0x28a0  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] SensorsHIDClassDriver C:\WINDOWS\System32\drivers\WUDFRd.sys
22:58:03.0848 0x28a0  SensorsHIDClassDriver - ok
22:58:03.0864 0x28a0  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] SensorsSimulatorDriver C:\WINDOWS\System32\drivers\WUDFRd.sys
22:58:03.0879 0x28a0  SensorsSimulatorDriver - ok
22:58:03.0895 0x28a0  [ E6F00415DADCEEC860E7AB42BFD19A65, 274CAF22F93D43B6DB6953730E3DF8DA94776B24EEE74B80AB4CD780BC1366A9 ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
22:58:03.0926 0x28a0  SensrSvc - ok
22:58:03.0926 0x28a0  [ 401D706DDC0A7AF18C3DD228ADF74551, 27C0B38D7C2E3F6FF06201124E63483931F6071954B2B99EC0143C464238C0B7 ] SerCx          C:\WINDOWS\system32\drivers\SerCx.sys
22:58:03.0949 0x28a0  SerCx - ok
22:58:03.0949 0x28a0  [ 7084D11083F0CDCA8B5C76F9846ABF5D, F639920882B0E784D8CFAF0D4C0F0C411937B6831E5DD99B0ABFBFE06BA4742F ] SerCx2          C:\WINDOWS\system32\drivers\SerCx2.sys
22:58:03.0964 0x28a0  SerCx2 - ok
22:58:03.0980 0x28a0  [ 3FF478A8ED32A83C36581425F6282B6C, 787646A17098EA7CF36064D0A950C1D470D4A280C8C5AC40023D566E53860EAE ] Serenum        C:\WINDOWS\System32\drivers\serenum.sys
22:58:03.0995 0x28a0  Serenum - ok
22:58:04.0011 0x28a0  [ 92509187AA171A80521528B36F753E1D, FE0DA272B8A155ECC161E99586C4AE7EE17B1C84BC330DA1566C83B8E03FA825 ] Serial          C:\WINDOWS\System32\drivers\serial.sys
22:58:04.0027 0x28a0  Serial - ok
22:58:04.0043 0x28a0  [ 433D38FF6D08B993847EA2A10EB8CB52, 29BA75DB6D1AC761BBDFB5AC8874FC7D763E1CD10D290E369063B34CE951270F ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
22:58:04.0049 0x28a0  sermouse - ok
22:58:04.0080 0x28a0  [ D525D273BE5691BDACE72B07AB0D1E02, 9231BD2137E71B3D555CEBBA8811297F239FDA08BF573CA4741D03D76718B5B1 ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
22:58:04.0127 0x28a0  SessionEnv - ok
22:58:04.0127 0x28a0  [ 697D3EE0740AEAB62B66ABCA1C83D13B, FCF54A0071ED04AD3FC8551C67FE5FD49089DC0510F753052CAC5972A65C9E3D ] sfloppy        C:\WINDOWS\System32\drivers\sfloppy.sys
22:58:04.0149 0x28a0  sfloppy - ok
22:58:04.0165 0x28a0  [ 3D0069B8F0C2FB1B0F13DBDB57593DAD, 4CEC91BC45A51C4E445D2DD8A13AC97719D5AAC1DBA8EA9166D2A354E7857378 ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
22:58:04.0196 0x28a0  SharedAccess - ok
22:58:04.0227 0x28a0  [ 482E6BE8A07832E824080D352075ACA1, 4123A76C8E805AF4FE229C53E9C174095C0937913BA81A63FE9B45C44AA5B15F ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:58:04.0280 0x28a0  ShellHWDetection - ok
22:58:04.0296 0x28a0  [ CF3BDF9EAD8D3EF671E9339B44B185BA, C17EC6D5B00F49D9C8B5B6C262A85F34ED71C58450659F006B3632AA84F68E23 ] shpamsvc        C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
22:58:04.0311 0x28a0  shpamsvc - ok
22:58:04.0327 0x28a0  [ A34CE1830E45DA98932295FDE4B7908A, FC553ECF4D64B4B10B7FDE5352707785517A18D487A80665BAFC7261E3F35CDC ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
22:58:04.0347 0x28a0  SiSRaid2 - ok
22:58:04.0349 0x28a0  [ A7B5C670770E908DA5FEF5BF1136E933, 8D3BB6FF65E631C34BE8EA766481B2FDB2E1E916A4FD67F86705A8975A136E6C ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
22:58:04.0365 0x28a0  SiSRaid4 - ok
22:58:04.0365 0x28a0  [ 6749AD471D1D44CBD1F30257C861F77B, D5A554F35E380948F13BFE0673B49F8FD8AE5A438BF3645857522E2560A58685 ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
22:58:04.0380 0x28a0  SkypeUpdate - ok
22:58:04.0396 0x28a0  [ 1B96814008B0D75F0050C21E9B0D0C6F, AD3E606D546C432F494C14DE49B845EEC4D3EC039418F005F782E37BC4E14502 ] SmbDrvI        C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
22:58:04.0412 0x28a0  SmbDrvI - ok
22:58:04.0412 0x28a0  [ 3CF50AFD283566573E0412E5D512184A, 382825D5592F13088FB82A0452F9FAC917767A808B521F1BDACB78B70797FB5A ] smphost        C:\WINDOWS\System32\smphost.dll
22:58:04.0427 0x28a0  smphost - ok
22:58:04.0449 0x28a0  [ 0B217141AC1283655402CDB356577735, 6EFA4CA46CFC8B7156CE7E5CA89B7F7073E16D66C2FC13F4DB95FEB78CCF698F ] SmsRouter      C:\WINDOWS\system32\SmsRouterSvc.dll
22:58:04.0481 0x28a0  SmsRouter - ok
22:58:04.0512 0x28a0  [ 6F4CE07D420FB657B5936F71101ABD41, CEC52984C56E578E0FFE12BE1B8148335F788B7D1751F2D0E79B944A41113C20 ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
22:58:04.0528 0x28a0  SNMPTRAP - ok
22:58:04.0549 0x28a0  [ 3DB9C2950439B61A038BF83E697C7A14, 6BF5EA5D4A251CB982F336840A60EF4241A3FC7442E7CD4D7C82199F5BF8D4D2 ] spaceport      C:\WINDOWS\system32\drivers\spaceport.sys
22:58:04.0581 0x28a0  spaceport - ok
22:58:04.0597 0x28a0  [ E03264C4C25B568F92ED1656AD541E64, D42942BFFBC7213D204FAF84F4FE015FC23A6ACB29B5E752834EDBC17A3AC20D ] SpbCx          C:\WINDOWS\system32\drivers\SpbCx.sys
22:58:04.0612 0x28a0  SpbCx - ok
22:58:04.0628 0x28a0  [ DA5A9752A702E86AFC10F06115A8AF4C, 1EBF973AAEE0D851934CFD99BF6FC3B33D6EF5EDE95F81450D2EA18117172FC9 ] Spooler        C:\WINDOWS\System32\spoolsv.exe
22:58:04.0681 0x28a0  Spooler - ok
22:58:04.0813 0x28a0  [ D9B2C0D75F4463EE117F56D59D3CD670, 6E43BCF9388BCA58E2BDF64B71022334542727B0CDDE5F8DAF2AA8CFEA5F619F ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
22:58:05.0013 0x28a0  sppsvc - ok
22:58:05.0028 0x28a0  [ E8276BE984738AA44070CFDE6EFC9300, F0B09D3E08BDB1B8AEBA97A700271E97AB2506793B42D96415B23DB68DA99FA8 ] SQLWriter      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
22:58:05.0051 0x28a0  SQLWriter - ok
22:58:05.0051 0x28a0  [ EDCDCD95B916DB156A903AC6256F0CCF, 4158EFE298235EDE2C34CE9F3978A4F3690379F14B21F917647EEAA0A8C1DE4A ] srv            C:\WINDOWS\system32\DRIVERS\srv.sys
22:58:05.0082 0x28a0  srv - ok
22:58:05.0113 0x28a0  [ DF7147DE10921DBAAE9F9EEF94590E10, 2222BA441227056DA17194648B3AF49655650F7BBA9E4A9ACEF519E392099C6D ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
22:58:05.0151 0x28a0  srv2 - ok
22:58:05.0166 0x28a0  [ 416D224AF7481A4179F018FB1F9A5B6B, 38159D7957A8091DFC5C32DCAC4DB07FDE14BBE4E75B4E61B4FBB332E3F9259D ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
22:58:05.0182 0x28a0  srvnet - ok
22:58:05.0198 0x28a0  [ 44758105AB3EA34E815D4B6CA1153311, 7F223A20D2538C123BAC6F75BE0E126876A116F09502FD980C05B8916E26E1B7 ] SSDPSRV        C:\WINDOWS\System32\ssdpsrv.dll
22:58:05.0213 0x28a0  SSDPSRV - ok
22:58:05.0229 0x28a0  [ B97C7EC07218A8002323718202BF5E77, 39D3254383E3F49FD3E2DFF8212F4B5744D8D5E0A6BB320516C5EE525AD211EB ] SstpSvc        C:\WINDOWS\system32\sstpsvc.dll
22:58:05.0251 0x28a0  SstpSvc - ok
22:58:05.0350 0x28a0  [ DF762D30EF0EE10E569C507BE75EAA6B, C23BA05E778CF1A547E7D3FE2226E0E68917570C56D5E703E599CAF2FD10BD17 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll
22:58:05.0554 0x28a0  StateRepository - ok
22:58:05.0605 0x28a0  [ 345C39599C3D4940D12F5F9F42A79229, B5D6C716D374E453940C2A23772B9E063CBCB06DA74574F0F19F813AE65F4A78 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
22:58:06.0199 0x28a0  Steam Client Service - ok
22:58:06.0214 0x28a0  [ 29D26E1347AE1BBD4201014E19880B2C, 9E2153AD96CE4F189EEE43BB02515532C619FB1CA02D8F6DEF517AC3347AAA14 ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
22:58:06.0231 0x28a0  stexstor - ok
22:58:06.0259 0x28a0  [ 91CB95B35481155BFE29C217CD237F27, CA66957DF1441D991453BEF02D768D44E5D9A484BC23C8874E8A7AC20904CB06 ] stisvc          C:\WINDOWS\System32\wiaservc.dll
22:58:06.0313 0x28a0  stisvc - ok
22:58:06.0327 0x28a0  [ 0FE3B9A9E40DE1029B0AC2368A3F765D, AB06795E456DB9CE4E5A91DD1C2638B4D474CE1C5DB4819D5EE17A337D74A231 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
22:58:06.0333 0x28a0  storahci - ok
22:58:06.0348 0x28a0  [ C5E0ACE4771F5575D9D5B457ABF3AD03, 365880BC5AC313F25C313EFB7758301F98D9B2BF4C5FC9499F98C2B7F8407D96 ] storflt        C:\WINDOWS\system32\drivers\vmstorfl.sys
22:58:06.0364 0x28a0  storflt - ok
22:58:06.0379 0x28a0  [ C1CFB9C19BF1134D8B9A7CF89BEC0AD1, 60DDF10777B30F3F70E4D52AFEABE71C7B509D0F2E3829106ED42ED330F8BCF4 ] stornvme        C:\WINDOWS\system32\drivers\stornvme.sys
22:58:06.0395 0x28a0  stornvme - ok
22:58:06.0411 0x28a0  [ BEBF85EB4D90E6996047DA027D0ED26E, DF109CF0F07CDD1B9B702C2A076D4DD5366DAAD971CC9359AF0358E79981706F ] storqosflt      C:\WINDOWS\system32\drivers\storqosflt.sys
22:58:06.0448 0x28a0  storqosflt - ok
22:58:06.0464 0x28a0  [ EAB902EB8DCF9436354C7CF71A41C223, BB855A7C296AE60C025C7D488EB24BB7AB72FC716A12BE0BBE14B95DFCD290ED ] StorSvc        C:\WINDOWS\system32\storsvc.dll
22:58:06.0511 0x28a0  StorSvc - ok
22:58:06.0527 0x28a0  [ 8E73037A6F8938475692FFCC26EBF385, F78C5CD1A3CD17AA831EEC82426B14006B4DDBC9085A4814E04E8C37FD6B05F7 ] storufs        C:\WINDOWS\system32\drivers\storufs.sys
22:58:06.0533 0x28a0  storufs - ok
22:58:06.0549 0x28a0  [ 9D9DED47DA10E845EFF2DD57C94C809B, 520D0CE7A867051B80C8141E351FE5A5BCE3C99776093F234DB77D3407B1F104 ] storvsc        C:\WINDOWS\system32\drivers\storvsc.sys
22:58:06.0564 0x28a0  storvsc - ok
22:58:06.0580 0x28a0  [ 224C92E442B1B8C20C274332F1ACF00D, CDE5DCFB7A21089464A6E2ABB29BBE08B184C3433C218756AA5902A8F67C0B2C ] svsvc          C:\WINDOWS\system32\svsvc.dll
22:58:06.0611 0x28a0  svsvc - ok
22:58:06.0630 0x28a0  [ 505E0C40B5D0ADDCBB414640F59BD2E0, DF4B5E65FE6FF2224F298A2A2FAC9B648C082DFF8463148633647580A9FAD34D ] swenum          C:\WINDOWS\System32\drivers\swenum.sys
22:58:06.0633 0x28a0  swenum - ok
22:58:06.0664 0x28a0  [ 2EE27411B5904C63D723BEA391819F58, C88C11D460E90398E16011B8A2CED5EE5626084F24790EA6115532F8F70060C6 ] swprv          C:\WINDOWS\System32\swprv.dll
22:58:06.0711 0x28a0  swprv - ok
22:58:06.0730 0x28a0  [ 32F46FB0F290D16DAA452B289C985795, 73F88AAAA6026DB4C27F1D054145216DCC3F1960946FB2A7A90518DD1D5737CB ] Synth3dVsc      C:\WINDOWS\System32\drivers\Synth3dVsc.sys
22:58:06.0749 0x28a0  Synth3dVsc - ok
22:58:06.0765 0x28a0  [ 6954AF16E100598A724B164EEE7D7AC1, 0B9811282D1B9C3FFEEA4807FC7E90D19C37C6C703F5BC3EA08A2CFCCFC1C5BF ] SynTP          C:\WINDOWS\system32\DRIVERS\SynTP.sys
22:58:06.0780 0x28a0  SynTP - ok
22:58:06.0796 0x28a0  [ 5AE7713E95B16B00370952031CD36927, 0AEB9C95C3461ABFCB41594E46FEF9C2845ABF4D3FE238750E6AFD037BD8E057 ] SynTPEnhService C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
22:58:06.0812 0x28a0  SynTPEnhService - ok
22:58:06.0834 0x28a0  [ FED48B19D6F55D7A3AB498D85729D1BA, FA5E0E02BC2E2DE108C55991E3B063CC947072228B53539F42F922661510DE7C ] SysMain        C:\WINDOWS\system32\sysmain.dll
22:58:06.0881 0x28a0  SysMain - ok
22:58:06.0896 0x28a0  [ D9FEA79BF6AF136F8E656AE045C2FEC8, E6F08A93348E035185F0F1C6B6277E636F4F25D1136E3ACCA63488DAEEC7114B ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
22:58:06.0933 0x28a0  SystemEventsBroker - ok
22:58:06.0934 0x28a0  [ 2BE3A44B764D6C43CBF4650E862CB807, 78920DA47F3A0C26503FB62EF159455A860E57A9A39C72AEE23A9324168EC1D2 ] SystemUsageReportSvc_WILLAMETTE C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe
22:58:06.0981 0x28a0  SystemUsageReportSvc_WILLAMETTE - ok
22:58:06.0996 0x28a0  [ 86E7FD5C8DBEC1EB51C4368561402B75, 86EE61414CD5854E39E33F67BF5DA4377B569B3ED4D18882C470BC6784891DA1 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
22:58:07.0012 0x28a0  TabletInputService - ok
22:58:07.0034 0x28a0  [ 3929C8FC134AC672C4F3F85160956257, CD3195CA58BA6F55EA0DDA2BE6AB58280AD1CA488D7AAA1539DD05FB99374F36 ] TapiSrv        C:\WINDOWS\System32\tapisrv.dll
22:58:07.0050 0x28a0  TapiSrv - ok
22:58:07.0112 0x28a0  [ 172B5A199F917B4BACB38F13BCAA11CB, 8491C9E284658920544F5EFED7125D50135C43360BD50B78F962578D9716C719 ] Tcpip          C:\WINDOWS\system32\drivers\tcpip.sys
22:58:07.0197 0x28a0  Tcpip - ok
22:58:07.0250 0x28a0  [ 172B5A199F917B4BACB38F13BCAA11CB, 8491C9E284658920544F5EFED7125D50135C43360BD50B78F962578D9716C719 ] Tcpip6          C:\WINDOWS\system32\drivers\tcpip.sys
22:58:07.0313 0x28a0  Tcpip6 - ok
22:58:07.0335 0x28a0  [ 8DBB1BE20C36E6D19BCC89EEA00B953C, 8B97A7E53E1D77363AFF6A5AAEAD89EBAE28DCB8D82753C804FD7CD5646500AF ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
22:58:07.0351 0x28a0  tcpipreg - ok
22:58:07.0382 0x28a0  [ 9D2DD64A0B51C56285512DC9454340F6, ABB90CE6A55269F71AFB08E04969CF9A4EFD93F7A7189AF920EEE3E005214DDD ] tdx            C:\WINDOWS\system32\DRIVERS\tdx.sys
22:58:07.0397 0x28a0  tdx - ok
22:58:07.0397 0x28a0  [ 06130AFFECEB94525FC2352936576B70, 10EBE2C8FDC087D29E2FFB328F0F7905A5374AB8CC9FAE8699E7676DBC8CBF91 ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
22:58:07.0413 0x28a0  terminpt - ok
22:58:07.0451 0x28a0  [ FB68E5F02316C42BE7282DA492351C6F, AC31D841FEA58B776127E138DB20F8D48E26FD8C00CE2FA9695EA14EBF159A0A ] TermService    C:\WINDOWS\System32\termsrv.dll
22:58:07.0498 0x28a0  TermService - ok
22:58:07.0513 0x28a0  [ 2AF438EC0D361A7BBB70E604A686602C, 4BE6A0461EB2CB94288614434A1CEC81C2ED46241721FD5BBD8ABE0680F7C804 ] Themes          C:\WINDOWS\system32\themeservice.dll
22:58:07.0535 0x28a0  Themes - ok
22:58:07.0551 0x28a0  [ 1482B8ED5CACA87992A882B853B83CEE, 613247F0E362A109090E8563D977DECC50C64D45D6962905FA84A2D59329045C ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe
22:58:07.0582 0x28a0  TieringEngineService - ok
22:58:07.0613 0x28a0  [ 3B3C607C3C62DFBEF61938DA2CAB94DF, E5EEA7F45A7BBFDF6F0003CD77E39958C451DD1B4B401876B5619A3C20F5C370 ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll
22:58:07.0651 0x28a0  tiledatamodelsvc - ok
22:58:07.0666 0x28a0  [ C1F8CBE2D4843E0CCC3EFEA2EC60D4AB, 9D07527D982066922318C77AECE99280DE55034C375ACE145E827A6BEB5C3B70 ] TimeBrokerSvc  C:\WINDOWS\System32\TimeBrokerServer.dll
22:58:07.0682 0x28a0  TimeBrokerSvc - ok
22:58:07.0698 0x28a0  [ 798C8CB861EB09C5AFB77468E5449BBB, F6631E779159B99B097A59792D11713809CA493618B6A210A4BC905F16782094 ] TPM            C:\WINDOWS\System32\drivers\tpm.sys
22:58:07.0713 0x28a0  TPM - ok
22:58:07.0734 0x28a0  [ 3B91F35089240F6187AD681A5EC28BDE, 3D035CB73BC8E7831DCD0FB7D9DAD91CE51D3D0F9D9C8B866A0009BD508B6702 ] TrkWks          C:\WINDOWS\System32\trkwks.dll
22:58:07.0751 0x28a0  TrkWks - ok
22:58:07.0751 0x28a0  [ AF343840E793BE63A9C646760BE8F2CD, 483FE55873A01DB7ACEC99B6823DAACC9EA7C67D36C6F12698113B31A7D5B8BE ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
22:58:07.0782 0x28a0  TrustedInstaller - ok
22:58:07.0798 0x28a0  [ A6F4025664C9D4BC2A9EDAB4092706D7, 89808A1679C0E716F86F06EE7701DCC289200894F0FA1F120DA2AC3A45FDB312 ] tsusbflt        C:\WINDOWS\system32\drivers\TsUsbFlt.sys
22:58:07.0814 0x28a0  tsusbflt - ok
22:58:07.0814 0x28a0  [ 37A96AD493E110C0BF1EE0AC0F9E7DBD, F2A6894A4AEE18DF2B92222CDB0801A13AEEB7212071F0431430788339B30E23 ] TsUsbGD        C:\WINDOWS\System32\drivers\TsUsbGD.sys
22:58:07.0836 0x28a0  TsUsbGD - ok
22:58:07.0836 0x28a0  [ 79E264287F17D56D768440B0270466DE, ABF9DC95C5E939B30BFD9BF9EDFDB3BD78A9DFCB055B945965303B6A60E6D7A7 ] tunnel          C:\WINDOWS\System32\drivers\tunnel.sys
22:58:07.0851 0x28a0  tunnel - ok
22:58:07.0867 0x28a0  [ 0F38FCE8C61CC14DE3718FAB5FFC0D3A, 527071956BDC0F2863DCDFEDD314DB5265A6AE525F810186F508E0D58A97D767 ] tzautoupdate    C:\WINDOWS\system32\tzautoupdate.dll
22:58:07.0883 0x28a0  tzautoupdate - ok
22:58:07.0898 0x28a0  [ AA65954F512BA097DD190790876DD991, C1BB2B8F54F064D01190327B5E7949EBBDA21D6FC6F94D9FCD20F685C2F855FA ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
22:58:07.0914 0x28a0  UASPStor - ok
22:58:07.0914 0x28a0  UCBrowserSvc - ok
22:58:07.0935 0x28a0  [ EB482DBC9786F1A9E3ED5AB6864794FA, 4154B259587D743612830F67800450DD04031C215A8459CC26E11D3498640BA0 ] UCGuard        C:\WINDOWS\system32\DRIVERS\ucguard.sys
22:58:07.0951 0x28a0  UCGuard - ok
22:58:07.0967 0x28a0  [ AB6268022C3A5B529075A39C33904DA6, 2717F1704640201F2681711543EA39A74C3E89C7DB232EC5DD89FD8AA6F07846 ] UcmCx0101      C:\WINDOWS\system32\Drivers\UcmCx.sys
22:58:07.0982 0x28a0  UcmCx0101 - ok
22:58:07.0998 0x28a0  [ 7ED2EDA43D21C7A5F589A7960E265C52, 7DB8A595236FBB8A264D7AB155201357212855050ABB5B1036EF32F1223FDCC2 ] UcmTcpciCx0101  C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
22:58:08.0014 0x28a0  UcmTcpciCx0101 - ok
22:58:08.0014 0x28a0  [ 169351463039B45F5CDED9768879F712, 990C8C4AEF9ED7FF6BCEAE67F7BDAA037777B142B8D96A74F8715C941A5C63C6 ] UcmUcsi        C:\WINDOWS\System32\drivers\UcmUcsi.sys
22:58:08.0036 0x28a0  UcmUcsi - ok
22:58:08.0051 0x28a0  [ 08A9E3AD29B215484FBB68CDC175DF3A, 3EFFF99C3BC4A1454E3D2B5177AE587ED3041AB4CE2A95BA7E28A2124E38E1E5 ] Ucx01000        C:\WINDOWS\system32\drivers\ucx01000.sys
22:58:08.0067 0x28a0  Ucx01000 - ok
22:58:08.0067 0x28a0  [ DA70AEE267491AA56BC63AA0C0C96CA2, 0A0AADB27607F9292BB3CE000CFDDB19BD4CA09EAAD926C4925CB43B17817AD9 ] UdeCx          C:\WINDOWS\system32\drivers\udecx.sys
22:58:08.0083 0x28a0  UdeCx - ok
22:58:08.0098 0x28a0  [ FBC5ECF6D5A868D0B116C2DBB02B8168, 945AA76C60ABAD6075B5C8F9172C018F75BCF393A1CB8B329F5E68E664627775 ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
22:58:08.0133 0x28a0  udfs - ok
22:58:08.0136 0x28a0  [ B918E40FAA9CD118CCA4AD388B748C98, 4B539B7B656F02C5E5BAEE52A677757B05CC11C5500D619850A564C28FAB8115 ] UEFI            C:\WINDOWS\System32\drivers\UEFI.sys
22:58:08.0152 0x28a0  UEFI - ok
22:58:08.0152 0x28a0  [ 0FD75222C1AD2687AB365BEBEA400DD4, AD10DBCA59EB7D34FD8F963CE267F36774A9BC613F8D637903B12AC88C328E8A ] Ufx01000        C:\WINDOWS\system32\drivers\ufx01000.sys
22:58:08.0167 0x28a0  Ufx01000 - ok
22:58:08.0183 0x28a0  [ C1A78C53E01C641AE41BFA65797819F5, 0B9FE1BD724B3315199A1B1DA2F03255E4FE744DA3CE6CD0F77699A8E42E9359 ] UfxChipidea    C:\WINDOWS\System32\drivers\UfxChipidea.sys
22:58:08.0199 0x28a0  UfxChipidea - ok
22:58:08.0214 0x28a0  [ 767307212110EBEFB93EC9A5BE9E85B9, 368797400FE54802CE74F34B773CE2AF09EB8DEA6C035B55419A52F0B5A6FAD0 ] ufxsynopsys    C:\WINDOWS\System32\drivers\ufxsynopsys.sys
22:58:08.0230 0x28a0  ufxsynopsys - ok
22:58:08.0252 0x28a0  [ 8578F83EC5175920F2D8586FFF9DCE47, 049A16AC87F93E761150C8286633FFCA62EE85F5645DDE77D36BD0EB6481FF83 ] UI0Detect      C:\WINDOWS\system32\UI0Detect.exe
22:58:08.0268 0x28a0  UI0Detect - ok
22:58:08.0283 0x28a0  [ DC460AAA18CA2342FBBFB2DF9B044472, 14D45E059C596AE97506D26705F248CA1C2269160B31A60341060E8A93146CBD ] umbus          C:\WINDOWS\System32\drivers\umbus.sys
22:58:08.0299 0x28a0  umbus - ok
22:58:08.0315 0x28a0  [ C3CF0377917ECE6D65D7623E1E61568F, 4909695E04CBC86BFCFFBC15F332C367521054B7B4D3C141C7CA6B2E40E090B9 ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
22:58:08.0334 0x28a0  UmPass - ok
22:58:08.0337 0x28a0  [ 640CF093C1CF16D5FD317616CA348F31, BEC34D1AACA83BF5A84CE01F6A668E3CA5A33C56A446DC42EFFF7C43D22E1AE6 ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
22:58:08.0368 0x28a0  UmRdpService - ok
22:58:08.0399 0x28a0  [ B8272BB8D4982C496FDC704809C38E02, F93855D932FB1DBBCC86E82C0FE0DC9ECF93BBD629D2CA9D0BE7E075E114B7FF ] UnistoreSvc    C:\WINDOWS\System32\unistore.dll
22:58:08.0453 0x28a0  UnistoreSvc - ok
22:58:08.0484 0x28a0  [ 6CDA3536F6BAB7896A57EAB7DC07F379, 8FBE6457ECD1ABB518D9800EBA8A017774FFAA8EABD2EDC0825181A12FE9AEF6 ] upnphost        C:\WINDOWS\System32\upnphost.dll
22:58:08.0534 0x28a0  upnphost - ok
22:58:08.0537 0x28a0  [ 6B46FC140C9AF68E6E7697D66D59CB4D, F018B4784D65F1A8140A6EA69C35D6A7ECE01738694052FD54AFD2B81A8F2FF8 ] UrsChipidea    C:\WINDOWS\System32\drivers\urschipidea.sys
22:58:08.0553 0x28a0  UrsChipidea - ok
22:58:08.0553 0x28a0  [ B4402E7F0923F660270442CE76877ABE, 1C2DD26EAB71F75EA576E8DAABAF71FD7DC3DF807CF025617C774CEF33C0B718 ] UrsCx01000      C:\WINDOWS\system32\drivers\urscx01000.sys
22:58:08.0568 0x28a0  UrsCx01000 - ok
22:58:08.0584 0x28a0  [ 9DD431F1B94789CFB527E5D19261F124, 8F5A249A97C5B14B282E3147DD21951D2AD34B651E762814C12F4C26D74EC70C ] UrsSynopsys    C:\WINDOWS\System32\drivers\urssynopsys.sys
22:58:08.0584 0x28a0  UrsSynopsys - ok
22:58:08.0600 0x28a0  [ 93F169DE94DBAC5DAF4755AFF10193DD, 381E6751EB97426B9BF30929E4B82A665D1ED985DA60BE18D3C17CF2BB41F848 ] usbaudio        C:\WINDOWS\system32\drivers\usbaudio.sys
22:58:08.0615 0x28a0  usbaudio - ok
22:58:08.0637 0x28a0  [ C87E32B90F085970D9637FBAD45EF6FE, C180EACD2EE479277DA5DBF39E43B428BD7945141B2451CB3946B0C1E495E76F ] usbccgp        C:\WINDOWS\System32\drivers\usbccgp.sys
22:58:08.0637 0x28a0  usbccgp - ok
22:58:08.0653 0x28a0  [ 0B663856474AC41924D9E9112203858F, 9E09F2A6279B48CAC09F8C7AA1F1BE02864D540C2ED1460CBA9FABCF0A546A1E ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
22:58:08.0669 0x28a0  usbcir - ok
22:58:08.0684 0x28a0  [ F83D2250256203AC5DA5E8601C1AFDD7, AC0D90E2DB3051798B9D287CF3D0E92FED4000822E65A82775A29CF896B76F04 ] usbehci        C:\WINDOWS\System32\drivers\usbehci.sys
22:58:08.0700 0x28a0  usbehci - ok
22:58:08.0716 0x28a0  [ 7FFD26742321919590ED77FCA556D65F, F7FAB63C36F8519F5A7B9091C507F3CB580C390322FAF9155CCE7F66C965B968 ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
22:58:08.0738 0x28a0  usbhub - ok
22:58:08.0753 0x28a0  [ 7A749B2863B5561BE34B39E8E249AD8F, E5B67DFAF5407007FD0CC408D6B4BA19DF59584819FC715E9F9E0FBF3EA00AAB ] USBHUB3        C:\WINDOWS\System32\drivers\UsbHub3.sys
22:58:08.0769 0x28a0  USBHUB3 - ok
22:58:08.0785 0x28a0  [ D2109F1F4FEBF1DAC415CDC5DE876479, C8A871EBD0E5EF004BA622A73DAC36C03608CD317FDCD0A6A98608DF4CC10D55 ] usbohci        C:\WINDOWS\System32\drivers\usbohci.sys
22:58:08.0800 0x28a0  usbohci - ok
22:58:08.0800 0x28a0  [ 29C9572F2D061CFC3C0BD48A3163E343, 2527DCC9E6D421F5DC40051C787A5270EB077746785465C9AA2A2AEEF47307D5 ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
22:58:08.0816 0x28a0  usbprint - ok
22:58:08.0833 0x28a0  [ 429477D6DEF3321FF7D3EF23CAAADA00, BB7D2AFE99736AAFFA8B0B2DABF7D6A6D5CB9563B1DE6A7E86CE7DC9D27F31C0 ] usbser          C:\WINDOWS\System32\drivers\usbser.sys
22:58:08.0838 0x28a0  usbser - ok
22:58:08.0854 0x28a0  [ 0CC16F7B91C57AE9A4E44425A295FDAA, 7CEE11955E5742DA390601F565412C14A7481B8747C495CCD246696C56B426DC ] USBSTOR        C:\WINDOWS\System32\drivers\USBSTOR.SYS
22:58:08.0854 0x28a0  USBSTOR - ok
22:58:08.0869 0x28a0  [ C917D09064CDBD18F75ADC9B2C48F847, A7F6223346CCD7E84186CD0C0715014F8E3A4398298925A43290224678620D23 ] usbuhci        C:\WINDOWS\System32\drivers\usbuhci.sys
22:58:08.0885 0x28a0  usbuhci - ok
22:58:08.0900 0x28a0  [ 95BCCEFBC40D06484CF16144FE79B8A5, 8ABA73C5FFEDD319FB96B807AD08716698E557522478DF1A2C5D662675636AE0 ] USBXHCI        C:\WINDOWS\System32\drivers\USBXHCI.SYS
22:58:08.0916 0x28a0  USBXHCI - ok
22:58:08.0953 0x28a0  [ 4CC81AB9D380A6264FF4C0C1512CF965, 76C33053D1C9155B0F3F8392FF982AD4EABEE2BBBEE89EA41DBFE8E436973EB0 ] UserDataSvc    C:\WINDOWS\System32\userdataservice.dll
22:58:09.0015 0x28a0  UserDataSvc - ok
22:58:09.0053 0x28a0  [ 8F6DAAFDDDA27D83ACC8C7FF1536CAF6, 5E1B67A5B388CBB3B193C238546BAD4DC5F5DF54859E16607A60681E6D38FA73 ] UserManager    C:\WINDOWS\System32\usermgr.dll
22:58:09.0100 0x28a0  UserManager - ok
22:58:09.0115 0x28a0  [ F4D8F67474DDA4FEF3935393AAA0173F, 5EB1700895E33972816DE4C2B920769CCE5580B83CAB8B2D7A8A6264F3A42B80 ] USER_ESRV_SVC_WILLAMETTE C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
22:58:09.0136 0x28a0  USER_ESRV_SVC_WILLAMETTE - ok
22:58:09.0153 0x28a0  [ C7CC4F8EA7FC1DE4221103B39360ABA0, 00B12186D731C3869022DCE763B243123D4E0B9BD0EA52AD9C95F9416F13FFD1 ] UsoSvc          C:\WINDOWS\system32\usocore.dll
22:58:09.0184 0x28a0  UsoSvc - ok
22:58:09.0184 0x28a0  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] VaultSvc        C:\WINDOWS\system32\lsass.exe
22:58:09.0200 0x28a0  VaultSvc - ok
22:58:09.0237 0x28a0  [ 87640B7EDD84E7F6D3C68A7BD2EB067B, 70AE7AAC17216C771908A1CFC0581F9C7DDC2D9C547A8D5203CFE73BF6216F09 ] VBoxDrv        C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys
22:58:09.0253 0x28a0  VBoxDrv - ok
22:58:09.0269 0x28a0  [ C42E4C5200CCDF94954215910A92ADD6, 3AE0BD3B7DEEAAD2411E87829ED931B7EC365534C141F688EB92FE8351AFC9F3 ] VBoxNetAdp      C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys
22:58:09.0285 0x28a0  VBoxNetAdp - ok
22:58:09.0285 0x28a0  [ 88DC4343B07D0CA1248D4F598ACD850C, 15BC2B76227ABA62F6CB3C76ADD576D8AA87FCF20F4555EA333FD1458EDB5AF9 ] VBoxNetLwf      C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys
22:58:09.0300 0x28a0  VBoxNetLwf - ok
22:58:09.0316 0x28a0  [ 5379DB8F681E7A91B3A454AA5153C31D, D935475CAA37374F8990B4F197300A379B2A931F3852C1DB61E7DF8332719520 ] VBoxUSBMon      C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys
22:58:09.0316 0x28a0  VBoxUSBMon - ok
22:58:09.0335 0x28a0  [ 0CBDE344FB48E42D78E29469F202ADBC, A1C3FBA5409DD3BBEAF1D3CE2583D6C8A621C0E4F534155EC540AFD67BC9E8CA ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
22:58:09.0338 0x28a0  vdrvroot - ok
22:58:09.0354 0x28a0  [ 0783EDE1FA94649ED7F3CEF6A734041A, 1A13A613EF6B67459031C7994FFC6F32F73E02E0F123A171618E4F011C635684 ] vds            C:\WINDOWS\System32\vds.exe
22:58:09.0385 0x28a0  vds - ok
22:58:09.0401 0x28a0  [ 723195568C8755CAD57F7933C5F2C5C2, 5C403799F67223605F825BC16D217C1EF5E1A0DDF00AC6380FE8976339B67D9B ] VerifierExt    C:\WINDOWS\system32\drivers\VerifierExt.sys
22:58:09.0416 0x28a0  VerifierExt - ok
22:58:09.0438 0x28a0  [ C12B4859FC255AA6B3021CF8BB14A11F, E95922351825D23ABCADD173E9256FC9AFFF28555DD1971CFF5666A2055958C5 ] vhdmp          C:\WINDOWS\System32\drivers\vhdmp.sys
22:58:09.0470 0x28a0  vhdmp - ok
22:58:09.0485 0x28a0  [ 7929228F0E8B0C2FA0495A17A4FC27F6, 1F1667B10A96B1D85ED165F62A5C0EF28C37F828B8280EA08BFCC1BAC03F2C90 ] vhf            C:\WINDOWS\System32\drivers\vhf.sys
22:58:09.0501 0x28a0  vhf - ok
22:58:09.0516 0x28a0  [ AEE432ED868831B1F068E373598F6D93, BAE91F47B0CB94B826CA010B490AD924D7B715911DF3FCE62F9165F3B571105C ] vmbus          C:\WINDOWS\system32\drivers\vmbus.sys
22:58:09.0539 0x28a0  vmbus - ok
22:58:09.0539 0x28a0  [ 9444B23FC694B5F90F21B0FC7F10D8DD, 86F92856F5C985DD8E5993B51E85E1F47EF8C9B2FB37468998C94266963BB4BD ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
22:58:09.0554 0x28a0  VMBusHID - ok
22:58:09.0554 0x28a0  [ 4D0287F566B36536DD812A54C015FC4A, 01D6508CA59CF04A47902B1F7C202FD14A81240E0B447588D919DD1072B040CF ] vmgid          C:\WINDOWS\System32\drivers\vmgid.sys
22:58:09.0570 0x28a0  vmgid - ok
22:58:09.0585 0x28a0  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll
22:58:09.0601 0x28a0  vmicguestinterface - ok
22:58:09.0617 0x28a0  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmicheartbeat  C:\WINDOWS\System32\icsvc.dll
22:58:09.0638 0x28a0  vmicheartbeat - ok
22:58:09.0654 0x28a0  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll
22:58:09.0670 0x28a0  vmickvpexchange - ok
22:58:09.0685 0x28a0  [ DC3172A6EB5DDB5EF94CB734CB7D4E63, 812971E0C2C18C876FFC9A46F1563801894C2EE9DD01CE1A641A0C68C0C1C6E2 ] vmicrdv        C:\WINDOWS\System32\icsvcext.dll
22:58:09.0717 0x28a0  vmicrdv - ok
22:58:09.0733 0x28a0  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmicshutdown    C:\WINDOWS\System32\icsvc.dll
22:58:09.0754 0x28a0  vmicshutdown - ok
22:58:09.0754 0x28a0  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmictimesync    C:\WINDOWS\System32\icsvc.dll
22:58:09.0786 0x28a0  vmictimesync - ok
22:58:09.0801 0x28a0  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmicvmsession  C:\WINDOWS\System32\icsvc.dll
22:58:09.0817 0x28a0  vmicvmsession - ok
22:58:09.0839 0x28a0  [ DC3172A6EB5DDB5EF94CB734CB7D4E63, 812971E0C2C18C876FFC9A46F1563801894C2EE9DD01CE1A641A0C68C0C1C6E2 ] vmicvss        C:\WINDOWS\System32\icsvcext.dll
22:58:09.0855 0x28a0  vmicvss - ok
22:58:09.0870 0x28a0  [ 29075915F9BDC3437F8BED71C067D399, 2C7718080C11DFDD4C9A2085537F78F5633369B4A27D9C64168F0249594A4AA2 ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
22:58:09.0870 0x28a0  volmgr - ok
22:58:09.0886 0x28a0  [ 6BDB6CE6D2D9E3D3F28F1C97E12B62E2, 5E77D7AF858D7B90FF395F39B86D6F96413D1DDEA28BC9FB40C5524A4DF6DAD0 ] volmgrx        C:\WINDOWS\system32\drivers\volmgrx.sys
22:58:09.0902 0x28a0  volmgrx - ok
22:58:09.0917 0x28a0  [ BF2546583BB75F01DDA60A7921DFB230, 579BD0BC55F4F03CD8D1FCDAC3975A1649C688820F2F7FC1AD354132D9E3BEE9 ] volsnap        C:\WINDOWS\system32\drivers\volsnap.sys
22:58:09.0939 0x28a0  volsnap - ok
22:58:09.0955 0x28a0  [ AC2E20A74D09D24485BE8396CE04F07B, 23FCE8BEE01B89E5CDCA536D75DBA6DCE3E92E13178A66836CEB7829310A89D1 ] volume          C:\WINDOWS\system32\drivers\volume.sys
22:58:09.0955 0x28a0  volume - ok
22:58:09.0971 0x28a0  [ 04BEC879AD7B3FDDD0339B19FECB0160, 8C92755DDB41AD7DDA1643D7F32FAA0FCA7E2C65C69611EB5EC1B3276EA8DBC7 ] vpci            C:\WINDOWS\System32\drivers\vpci.sys
22:58:09.0971 0x28a0  vpci - ok
22:58:09.0986 0x28a0  [ FD9BCB8920973CEAD4D49DC7A6D8A618, 34AB4A485FB40DF737600006D8323BE927FB0BDA2BC170F4C123BE775EAE7CC8 ] vsmraid        C:\WINDOWS\system32\drivers\vsmraid.sys
22:58:10.0002 0x28a0  vsmraid - ok
22:58:10.0040 0x28a0  [ 01FFD5AF533F2CFDF26DDDC9313731C1, BFF0F2E57CD2358AC8F519F6F5692A46D97EC4E9B763D47101CEF31712FD4738 ] VSS            C:\WINDOWS\system32\vssvc.exe
22:58:10.0102 0x28a0  VSS - ok
22:58:10.0102 0x28a0  [ 99030F89DE0CFA7428A38D498CE5DDD7, 64E64962BC19047FC55EB73F007D25953E86D8DF0D6EA6D28E0BB47D5A50E8AF ] VSStandardCollectorService140 C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe
22:58:10.0118 0x28a0  VSStandardCollectorService140 - ok
22:58:10.0138 0x28a0  [ 0C111F220798CCE80484026E06822379, B98A5E44D3ABA67E6DE99E18BF3C2C606923E6269E262665C721F672ACBBED2A ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
22:58:10.0139 0x28a0  VSTXRAID - ok
22:58:10.0155 0x28a0  [ 607639716E9DB1CEF4E18B5B229293B4, 1D997177093F907EFE8A04AD10443BB9C355C0D7657DBD449E7EE7FCABC3ECBC ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
22:58:10.0171 0x28a0  vwifibus - ok
22:58:10.0171 0x28a0  [ B1ED64E628763148BF84FBE23F2AD711, 6182A39675E6049BC3DD353694720795A8E3D0331509AA8ABA4883D5C569AD5E ] vwififlt        C:\WINDOWS\system32\drivers\vwififlt.sys
22:58:10.0202 0x28a0  vwififlt - ok
22:58:10.0202 0x28a0  [ 59920894C38A827091A06AF559834E47, 8B40FE0B1BA3B2A79BFF70803D039DB921F85C978724722E5E5AFF188FA75471 ] vwifimp        C:\WINDOWS\System32\drivers\vwifimp.sys
22:58:10.0218 0x28a0  vwifimp - ok
22:58:10.0239 0x28a0  [ E7DE2794DF35F02868513D9594BF10FD, 89CB88814A5F7ACCFAC6FB5E3388B6922E1F8DCBB275531826DD04419BF74A7A ] W32Time        C:\WINDOWS\system32\w32time.dll
22:58:10.0271 0x28a0  W32Time - ok
22:58:10.0271 0x28a0  [ 55D00B785A7587F4263D125817871283, B92400B229099C1E243F2B149881A1423A2E9C8CA2D77D868B9B923BFDEC7FF2 ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
22:58:10.0287 0x28a0  WacomPen - ok
22:58:10.0302 0x28a0  [ 1483BE4D0135C378CB61D3CD73AB3E03, B7309C9E4F370860C507BF52D17234CDF4A7FAE95D2D822714E07EF5DEC0249B ] WalletService  C:\WINDOWS\system32\WalletService.dll
22:58:10.0335 0x28a0  WalletService - ok
22:58:10.0340 0x28a0  [ CEF3D306C09BEC1A800E9B4A06F859F6, 75D21F97E9F94FA97024F945AF512FEC94F88DD8073F3FAD92A6E0A9FDC586DB ] wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:58:10.0355 0x28a0  wanarp - ok
22:58:10.0355 0x28a0  [ CEF3D306C09BEC1A800E9B4A06F859F6, 75D21F97E9F94FA97024F945AF512FEC94F88DD8073F3FAD92A6E0A9FDC586DB ] wanarpv6        C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:58:10.0387 0x28a0  wanarpv6 - ok
22:58:10.0418 0x28a0  [ 30B8286F8FE1AE90A583100D45E02247, 3C86A4A5E21F9A1267EA231B20914E0A162BA4C25FE8917AD3AB6D504DA5BE0C ] wbengine        C:\WINDOWS\system32\wbengine.exe
22:58:10.0471 0x28a0  wbengine - ok
22:58:10.0503 0x28a0  [ 6BE945D6DE02713BAD8627205CDF9F48, F6548EAF5D67DA4682D8B31E5B565606DEAAB9276B44F25F1A4203AB61B9400B ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
22:58:10.0540 0x28a0  WbioSrvc - ok
22:58:10.0540 0x28a0  [ CD24DEEA22152524CCFE859591D12A57, C60ACF77647E5D6EDC10BBBCF974DF264145123C8EDB6506AFA9C949EBA53D7F ] wcifs          C:\WINDOWS\system32\drivers\wcifs.sys
22:58:10.0556 0x28a0  wcifs - ok
22:58:10.0587 0x28a0  [ 32960EA9CF836D7DD77767DCB68CE230, 679446A4FAB0331C181D2716CAEA225267C6164BB9867E360C5B3D6AB1083195 ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
22:58:10.0618 0x28a0  Wcmsvc - ok
22:58:10.0641 0x28a0  [ D50645235A507B0546B1B5CF7D0B8849, 19F5FE10C953B8EE8EEDA9A9F7F2E97AA193BB085E7FC364066686089ADD1C9F ] wcncsvc        C:\WINDOWS\System32\wcncsvc.dll
22:58:10.0656 0x28a0  wcncsvc - ok
22:58:10.0672 0x28a0  [ AEA1093B751339267D8C8C1EF3D669CF, 8F3325E7FB16BD856A0593C36F2E3E018909038C52CD5F92E116E0C1366F31CB ] wcnfs          C:\WINDOWS\system32\drivers\wcnfs.sys
22:58:10.0687 0x28a0  wcnfs - ok
22:58:10.0687 0x28a0  [ D520B1B849B6D4D707AB31722B952C2D, 149BABB7BD63C1F212ADD9306C84FFB2A5CE6DC435BD3213EAB787E9B222C61F ] WdBoot          C:\WINDOWS\system32\drivers\WdBoot.sys
22:58:10.0703 0x28a0  WdBoot - ok
22:58:10.0740 0x28a0  [ 5030C76047D756263093A47B82970868, E772F15973F6DE36851DD230F1F4190746CD81CA1E7284DC074711C4BF45CAF0 ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
22:58:10.0756 0x28a0  Wdf01000 - ok
22:58:10.0772 0x28a0  [ 29FF9199EDEB4F5470BB134D1A2563D2, 94713F98A6EA6042203D5DD0DE6758F5F0F331F7D4BB05E91EF20CEEEBD6780F ] WdFilter        C:\WINDOWS\system32\drivers\WdFilter.sys
22:58:10.0788 0x28a0  WdFilter - ok
22:58:10.0803 0x28a0  [ E7A7E8803E66B7CCED95D327A4DBC135, 401ECD953D4014A95C9022822D9ACEC1A68C917281DBA2365503A473FC6D9507 ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
22:58:10.0819 0x28a0  WdiServiceHost - ok
22:58:10.0838 0x28a0  [ E7A7E8803E66B7CCED95D327A4DBC135, 401ECD953D4014A95C9022822D9ACEC1A68C917281DBA2365503A473FC6D9507 ] WdiSystemHost  C:\WINDOWS\system32\wdi.dll
22:58:10.0857 0x28a0  WdiSystemHost - ok
22:58:10.0872 0x28a0  [ 373DF27CD5D5E50FFA2A90FEE0C0D994, 09E6C6C690AEE1C1A9A84BBA87A934040B2A20F677E5F5B2D24F8433B61BD81E ] wdiwifi        C:\WINDOWS\system32\DRIVERS\wdiwifi.sys
22:58:10.0904 0x28a0  wdiwifi - ok
22:58:10.0919 0x28a0  [ EFCC801981E66DBF5193149817569FF4, 4FCDC89EB38A0AB349C403678BEC07383CC7C942955468827CCAC462F6BA2AE9 ] wdm_usb        C:\WINDOWS\system32\DRIVERS\usb2ser.sys
22:58:10.0936 0x28a0  wdm_usb - ok
22:58:10.0941 0x28a0  [ 17CF416CFF408190F5A4CBD79AB12E55, E376C8865C7EA633AE20D2CF940E4C7584AC783BAAF7941780FB6C4C84802F33 ] WdNisDrv        C:\WINDOWS\system32\Drivers\WdNisDrv.sys
22:58:10.0957 0x28a0  WdNisDrv - ok
22:58:10.0957 0x28a0  WdNisSvc - ok
22:58:10.0973 0x28a0  [ 3570C4E14F85CE0B537D126727ACA91C, A474C9E6B6E4E5945C63367C1D3D24D4782C4A4FEB00FAE15DFED099D8283078 ] WebClient      C:\WINDOWS\System32\webclnt.dll
22:58:10.0988 0x28a0  WebClient - ok
22:58:11.0004 0x28a0  [ 1785F9C96A0BDEC1F6E0C79EF412F342, D6D4EDA69457BEDDA69C2F60FC4C2FAC97D46CD8E9C1804CCD68F169383583E3 ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
22:58:11.0019 0x28a0  Wecsvc - ok
22:58:11.0041 0x28a0  [ B9175D63527B05131F2FA504CF0265F2, 1E43A17788F1B6A29E2889C81E0BE100D64BD3A9DEE7C154D9581F01D2D7D05F ] WEPHOSTSVC      C:\WINDOWS\system32\wephostsvc.dll
22:58:11.0042 0x28a0  WEPHOSTSVC - ok
22:58:11.0057 0x28a0  [ 5C58EC0C9D4DE04DCDE56F6DCEA62080, 8ED386EDF4C39C339CE0BB2AC7E199C38705E5A6B3F56A4987B9A8ABD19BB59F ] wercplsupport  C:\WINDOWS\System32\wercplsupport.dll
22:58:11.0073 0x28a0  wercplsupport - ok
22:58:11.0088 0x28a0  [ F899B355CC95AF26AB36E84E8A0DD685, C400F2F80FFF6473FEF066943C4A2AFF0FFE988A4F755757A2E5005C2A10DAD8 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
22:58:11.0104 0x28a0  WerSvc - ok
22:58:11.0120 0x28a0  [ E1785942AC51FEE6826CDF02075C5AA9, 56FE7017684086F4F9C3A2C0D3AC00369BA0938BA3987EEBEE9A75B8E3CA0AE1 ] WFPLWFS        C:\WINDOWS\system32\drivers\wfplwfs.sys
22:58:11.0138 0x28a0  WFPLWFS - ok
22:58:11.0142 0x28a0  [ B154618505A6A9026EFA6AB8C4123BF1, 713648D71AA027B4472E7E75B942630DBE7383687984B02A5E99C9E4192C95EB ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
22:58:11.0158 0x28a0  WiaRpc - ok
22:58:11.0158 0x28a0  [ 0CF79A0EACFFBB75A50A469A27696D02, E112BF7B5A8D0B0AD2EA0E7B9FD4E8CFEC9371C8E94A60248292D688AFE715C4 ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
22:58:11.0173 0x28a0  WIMMount - ok
22:58:11.0173 0x28a0  WinDefend - ok
22:58:11.0204 0x28a0  [ 0DE131733317EB4BE67028366B0CAAC6, AC7DADBF03A3752B4D33CA19F03DBCEDD6F56893C2DA25C98B0AB07063D990E3 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
22:58:11.0220 0x28a0  WindowsTrustedRT - ok
22:58:11.0220 0x28a0  [ 92EB5D38BDF10C790450F3E46BF93A0E, 0FC027398DBD43EDC1F7D703C0B6DB20294DF34E67C9288442039B1A5663CE1B ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
22:58:11.0239 0x28a0  WindowsTrustedRTProxy - ok
22:58:11.0258 0x28a0  [ C9E7D91A044B77CBCB4121C06610A86C, 9FF039D67A5CE4732920EA4F1F5CFD9DE0AAADC34829A007EA697030D42D3623 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
22:58:11.0289 0x28a0  WinHttpAutoProxySvc - ok
22:58:11.0305 0x28a0  [ F95DE20312ACCA7761446DE152BD1F7C, F6C5ACA500C2182437F4A7402BD81C3A2B77C0BBD78BA31FB574DC1997FCBFE6 ] WinMad          C:\WINDOWS\System32\drivers\winmad.sys
22:58:11.0320 0x28a0  WinMad - ok
22:58:11.0337 0x28a0  [ CD49CA8E3280ACEEC5ECF431A59F5EFD, 75F48EFC6DEE9E06B490703EE47602AFDEA51505285B02D2CF884601E71857CC ] Winmgmt        C:\WINDOWS\system32\wbem\WMIsvc.dll
22:58:11.0342 0x28a0  Winmgmt - ok
22:58:11.0405 0x28a0  [ F86E9029774478D276E0AAB7D169896D, EDCB96F745E1F16BDFF70B140B38412096FA29A407157183223AE6111CBB4B38 ] WinRM          C:\WINDOWS\system32\WsmSvc.dll
22:58:11.0505 0x28a0  WinRM - ok
22:58:11.0538 0x28a0  [ 4EFB346BFDAEEB29316AA52BBB9852B1, 4BC5554F44BD9549D0A929D77BD410FA3EB502A7D0170303D369268672505494 ] WINUSB          C:\WINDOWS\System32\drivers\WinUSB.SYS
22:58:11.0542 0x28a0  WINUSB - ok
22:58:11.0558 0x28a0  [ 8B9AFF5F08E66A6F1F1063DEC9457FB6, 98F2AF6988D125521FD34CAA48B9652922F0C8ECFAE9B0C1DF4B3CE6B9CF500F ] WinVerbs        C:\WINDOWS\System32\drivers\winverbs.sys
22:58:11.0558 0x28a0  WinVerbs - ok
22:58:11.0589 0x28a0  [ 4D694EDF85F1BFC463B15846D4E00A9B, 4ED44C0E22D2843121E4C8A58F97B526BB7D85C0D7A0BB4B1158A970258C791E ] wisvc          C:\WINDOWS\system32\flightsettings.dll
22:58:11.0620 0x28a0  wisvc - ok
22:58:11.0658 0x28a0  [ B155B02AFF09DEFBC7FC8B359747B2C3, 6F759629305B4BDF08FC9C99C8EE3F328D87E8703819D98E1452D6A9F5D9896C ] WlanSvc        C:\WINDOWS\System32\wlansvc.dll
22:58:11.0789 0x28a0  WlanSvc - ok
22:58:11.0858 0x28a0  [ 7A98AF088E0B1A5EB98863B14F493716, 8B2F8D02AC0637C72859AF29C05C01D7D1C81C6A15CBE2D579F27F3254E66076 ] wlidsvc        C:\WINDOWS\system32\wlidsvc.dll
22:58:11.0958 0x28a0  wlidsvc - ok
22:58:11.0974 0x28a0  [ 6F4F4F5A007D1710BD76FB311DA97C07, FC0FEA4364F6BA4E31DBC82735D09D429CA3BE9AFCFF5D5E1263D8B27FC2CE3E ] WmiAcpi        C:\WINDOWS\System32\drivers\wmiacpi.sys
22:58:12.0005 0x28a0  WmiAcpi - ok
22:58:12.0021 0x28a0  [ 3CDDFF6CAD962C5EF1C52FD667C358B6, F6F09145E9461EB17172988D26749FCF36920A1A683459334D04A6D072B31A92 ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
22:58:12.0043 0x28a0  wmiApSrv - ok
22:58:12.0059 0x28a0  WMPNetworkSvc - ok
22:58:12.0074 0x28a0  [ EDADABA8665AB5C51BF59C4E2566BA7E, C85337881856B466F61DFA1E69FC2FD8250085D299A5DE052BFA80C83FD5EFD0 ] Wof            C:\WINDOWS\system32\drivers\Wof.sys
22:58:12.0090 0x28a0  Wof - ok
22:58:12.0159 0x28a0  [ 909CB4BBF7B08E78C363000E09E79A6F, 217205D1B5EE03274AFF9405AED6D2A5665CBA4C3876E84B53DA44920CDF9CB1 ] workfolderssvc  C:\WINDOWS\system32\workfolderssvc.dll
22:58:12.0275 0x28a0  workfolderssvc - ok
22:58:12.0290 0x28a0  [ F02930EB91596042F2221397D60AFCE5, 10E2AB0993B67CBAA9E11C68280608965064EC9F7E0C570F5B453FACADB8AB5D ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
22:58:12.0321 0x28a0  WPDBusEnum - ok
22:58:12.0338 0x28a0  [ 75A9284F01FE7CB1A7D5EAE5C1EB4F33, 390EF23AEA06D8711555F7979FF8BE0620B53C1A551638C4EC6FB7C6678965B3 ] WpdUpFltr      C:\WINDOWS\system32\drivers\WpdUpFltr.sys
22:58:12.0344 0x28a0  WpdUpFltr - ok
22:58:12.0359 0x28a0  [ 60E2EB3E7B7F15C25E02462159F90707, D8344B529EEC0D4922CAC3E6897CC9F191ACF1376017BE38ED6BF6019F1ED181 ] WpnService      C:\WINDOWS\system32\WpnService.dll
22:58:12.0406 0x28a0  WpnService - ok
22:58:12.0422 0x28a0  [ C7C91FB86A3C6CD7619725A88ED1884C, 132C43C518F37BF303D768BD5FB0AB835F693C43FE693937D804A34E940D770F ] WpnUserService  C:\WINDOWS\System32\WpnUserService.dll
22:58:12.0444 0x28a0  WpnUserService - ok
22:58:12.0475 0x28a0  [ 36D7B73ADC3E10607ED6EC874AFB5D1E, 1737B3E4D2CA76BB27903BF460E4960E6A0BC32D35069AC7C5E4B07F625F3282 ] ws2ifsl        C:\WINDOWS\system32\drivers\ws2ifsl.sys
22:58:12.0491 0x28a0  ws2ifsl - ok
22:58:12.0522 0x28a0  [ 519806FBCF00A0B17B8E03297DB0F551, 1911EA7168B06DBF3D36833120E4731437BF1ACC294C289B132C50280A40F548 ] wscsvc          C:\WINDOWS\System32\wscsvc.dll
22:58:12.0544 0x28a0  wscsvc - ok
22:58:12.0560 0x28a0  [ 696EC2EAA2A42A137CCBB9A84D6917C0, 424089F4F373962AF8357C5D4D43F35948989BE3F58EAD3690F565F4C1BBC66F ] WSDPrintDevice  C:\WINDOWS\System32\drivers\WSDPrint.sys
22:58:12.0575 0x28a0  WSDPrintDevice - ok
22:58:12.0591 0x28a0  [ 46E4A69825A7554A5DB784A55F8AD203, 7F347054FCDD5DEF93083D420E56EBE5EEBBAE2BD2FED9B2E75E85149DE52780 ] WSDScan        C:\WINDOWS\system32\DRIVERS\WSDScan.sys
22:58:12.0622 0x28a0  WSDScan - ok
22:58:12.0639 0x28a0  WSearch - ok
22:58:12.0660 0x28a0  [ 72B4E9DF6456C43C42A1419B09486045, 536BA7377B5BEA7EA46864453933111DB88DB8FB689C68915ACD7261A996E61D ] wsvd            C:\WINDOWS\system32\DRIVERS\wsvd.sys
22:58:12.0676 0x28a0  wsvd - ok
22:58:12.0745 0x28a0  [ DB38A10568D01CCCDA442C8F52EDF657, C48AE43F8AE22B1A68E73E452C09CE8913885A549DCD33D017A16350AEA5EAB5 ] wuauserv        C:\WINDOWS\system32\wuaueng.dll
22:58:12.0876 0x28a0  wuauserv - ok
22:58:12.0876 0x28a0  [ AED7FE551E8672B824A56324076183EB, FFE543AAEFDEFFE6B20C244DB141A9425BDA88ED36F4870F0B70FEC433BDF0C1 ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
22:58:12.0907 0x28a0  WudfPf - ok
22:58:12.0907 0x28a0  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFRd          C:\WINDOWS\System32\drivers\WUDFRd.sys
22:58:12.0941 0x28a0  WUDFRd - ok
22:58:12.0945 0x28a0  [ 47F6450F28BAA32B2AB0D6BE00996249, C8A47D6ADF89AD613AB685C6224B9099DCEFDCD8ABCF703542AFDC356404116E ] wudfsvc        C:\WINDOWS\System32\WUDFSvc.dll
22:58:12.0961 0x28a0  wudfsvc - ok
22:58:12.0976 0x28a0  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFWpdFs      C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
22:58:12.0992 0x28a0  WUDFWpdFs - ok
22:58:13.0008 0x28a0  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFWpdMtp      C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
22:58:13.0023 0x28a0  WUDFWpdMtp - ok
22:58:13.0045 0x28a0  [ 42DF36725C1B28EF40F94363BA9213ED, 87F7355FEF000326BFFC9ED24D6E32D05F36A549779A1D319603F94E6D8223FD ] WwanSvc        C:\WINDOWS\System32\wwansvc.dll
22:58:13.0108 0x28a0  WwanSvc - ok
22:58:13.0124 0x28a0  [ 38DDEB2AFE7D72B43DB116DACBFB97CD, 516368980793E22034298CA9C800D1AAD5B89979771182B74EB6E5FBC8BA1016 ] XblAuthManager  C:\WINDOWS\System32\XblAuthManager.dll
22:58:13.0177 0x28a0  XblAuthManager - ok
22:58:13.0208 0x28a0  [ 765FF96467A26C4C03281ECA426EC2D9, 2526B03C518D72F429C29BA4D4F11707AF277BF71520A1A92238A932950AE161 ] XblGameSave    C:\WINDOWS\System32\XblGameSave.dll
22:58:13.0262 0x28a0  XblGameSave - ok
22:58:13.0277 0x28a0  [ 59335CEA021FB89E07AD5DB5D17F09D0, 33FEFD5798BFA306FBEDCC8F2D0D984B6546A61B5026E921A8AC0466ADF2B698 ] xboxgip        C:\WINDOWS\System32\drivers\xboxgip.sys
22:58:13.0293 0x28a0  xboxgip - ok
22:58:13.0324 0x28a0  [ 335E6F2BE58523B295945C840C185B00, 94ED7E2CB212A3D55B8A2CB90CD1D02A6AF92DC0DDD487CB5B7CAC9883343460 ] XboxNetApiSvc  C:\WINDOWS\system32\XboxNetApiSvc.dll
22:58:13.0362 0x28a0  XboxNetApiSvc - ok
22:58:13.0378 0x28a0  [ 864F4209B03BE4267DDE09B067A165CA, C6751CB80940F320A742C38295E4FEEC85F99BE7D6C564AC5F5068E85A82421D ] xinputhid      C:\WINDOWS\System32\drivers\xinputhid.sys
22:58:13.0393 0x28a0  xinputhid - ok
22:58:13.0409 0x28a0  [ 17BFB2EE1B300127071ED386E9B8F47D, E485768AD6B356DAF565A958BB8E4DCFD6C2BF69D7938EFE065A99E81993F36F ] ymc            C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
22:58:13.0424 0x28a0  ymc - ok
22:58:13.0447 0x28a0  [ D4518D2080B3D29FCCDFAEC61529F537, 4941F4835283BD7F7A66F7C19501D7A6BB38C54C90EF59437681D7F02AAA385D ] YogaPicks.AppService C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
22:58:13.0462 0x28a0  YogaPicks.AppService - ok
22:58:13.0546 0x28a0  [ B429532039BAFD4A68AF0E7BC4CED6F8, 7CE6191793D3F58655F58CC2B0D201429AD883272E6565314B3F7B015B042076 ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
22:58:13.0625 0x28a0  ZeroConfigService - ok
22:58:13.0643 0x28a0  [ DA4878DF031FE6009D79BA758D4D5BAC, E1805A1657BD57CBDA2F5262B14710A39920D7FE481A6A2A546BCD15E8D68AAE ] ziphost        c:\program files\ziptool\ziphost.dll
22:58:13.0662 0x28a0  ziphost - ok
22:58:13.0694 0x28a0  [ D607CAF42E620BB80BFAE4D8D0644AD6, 8E203F0257773DB3EC30A45BEF707399E96A7AA80B97AEF25EFE91F61F707668 ] ZipProtect      c:\program files\ziptool\ZipProtect64.sys
22:58:13.0725 0x28a0  ZipProtect - ok
22:58:13.0725 0x28a0  ================ Scan global ===============================
22:58:13.0725 0x28a0  [ 0C710DB449712EE13ACE733695DB7780, BBC7875B38D318CE4E88979D083AC72E8993254A466A8A6882DDE9E0C3B687A3 ] C:\WINDOWS\system32\basesrv.dll
22:58:13.0725 0x28a0  [ 1FEF9536BA2779E2F3CB524E34BAC715, 6387C7E2FD538EFD9AC19B622AEC81F6F924576FDAB6F003AF5B6CBD33F6A379 ] C:\WINDOWS\system32\winsrv.dll
22:58:13.0747 0x28a0  [ 1EE06E957B0B2CA52D26DA7861E160EF, 4B743A1C7010138F5F6684BBCF7CAD6FD05F49920BDD3FDB776347AA6B44AB94 ] C:\WINDOWS\system32\sxssrv.dll
22:58:13.0747 0x28a0  [ 133390D061D94917125DC666DA67ECD0, 69D6FFF3E0A0C4D77A62B4D71E1E3A8D10D93C46782A1B05F0EC4B8919C384B9 ] C:\WINDOWS\system32\services.exe
22:58:13.0763 0x28a0  [ Global ] - ok
22:58:13.0763 0x28a0  ================ Scan MBR ==================================
22:58:13.0763 0x28a0  [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
22:58:13.0847 0x28a0  \Device\Harddisk0\DR0 - ok
22:58:13.0863 0x28a0  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
22:58:13.0925 0x28a0  \Device\Harddisk1\DR1 - ok
22:58:13.0925 0x28a0  ================ Scan VBR ==================================
22:58:13.0925 0x28a0  [ 99C094ABF141497EF8D991DB057D58BC ] \Device\Harddisk0\DR0\Partition1
22:58:13.0925 0x28a0  \Device\Harddisk0\DR0\Partition1 - ok
22:58:13.0942 0x28a0  [ E9E0A1205F3060EAA0D1BCD47064CF63 ] \Device\Harddisk0\DR0\Partition2
22:58:13.0943 0x28a0  \Device\Harddisk0\DR0\Partition2 - ok
22:58:13.0945 0x28a0  [ DE5C1ABFDD2E9EB44970C5365B48273E ] \Device\Harddisk0\DR0\Partition3
22:58:13.0946 0x28a0  \Device\Harddisk0\DR0\Partition3 - ok
22:58:13.0947 0x28a0  [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition4
22:58:13.0947 0x28a0  \Device\Harddisk0\DR0\Partition4 - ok
22:58:13.0947 0x28a0  [ FEC425992E95F49203BECF108296B085 ] \Device\Harddisk0\DR0\Partition5
22:58:13.0947 0x28a0  \Device\Harddisk0\DR0\Partition5 - ok
22:58:13.0947 0x28a0  [ FDC4821B62D9AD53B052C7820DC8FFAA ] \Device\Harddisk0\DR0\Partition6
22:58:13.0947 0x28a0  \Device\Harddisk0\DR0\Partition6 - ok
22:58:13.0947 0x28a0  [ FA84D1E11286E87CEE878879AAC377A1 ] \Device\Harddisk0\DR0\Partition7
22:58:13.0947 0x28a0  \Device\Harddisk0\DR0\Partition7 - ok
22:58:13.0963 0x28a0  [ B5024BE9436B35BF1D470F244CF2E15D ] \Device\Harddisk1\DR1\Partition1
22:58:13.0963 0x28a0  \Device\Harddisk1\DR1\Partition1 - ok
22:58:13.0963 0x28a0  ================ Scan generic autorun ======================
22:58:13.0963 0x28a0  [ 92BED6F62FBAC9E327A3BF599CE9AB32, 6ED9BB1B97AB0BDC64CE07FB8757651A83C918320320B84AB823933B8ACFDEB6 ] C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe
22:58:13.0979 0x28a0  DptfPolicyLpmServiceHelper - ok
22:58:14.0799 0x28a0  [ 2A7EAF9A5DCC6DF4DFA1162AE69A2AA7, DA2BEC60E08748774B38B727FF83850B64F8C39A17FD7559EE8318683C2E672E ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
22:58:15.0768 0x28a0  RtHDVCpl - ok
22:58:15.0892 0x28a0  [ 2BFBD5FB7B6EFFF59AD79BB8A8796926, BBD0BC11B9BAA0691BAAE7C7960F51183A6D5ACD322B7092E436900FA495FBDB ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
22:58:16.0015 0x28a0  RtHDVBg_Dolby - ok
22:58:16.0544 0x28a0  [ 6546BB9B4B32BE17C66479EBCF6F34BF, 79FF9DD229C8218499FE10ECE258CCAFF3FF258790840769948E4D05B017E9B8 ] C:\WINDOWS\RTFTrack.exe
22:58:17.0186 0x28a0  RtsFT - ok
22:58:17.0218 0x28a0  [ 4A0477ADCD07EC9D21257A2E456B16C5, CEF9C81730C12283A7600C3D921D89A62B14D1C46544B493F3AF7520DD2D1F79 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
22:58:17.0253 0x28a0  IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
22:58:17.0437 0x28a0  Detect skipped due to KSN trusted
22:58:17.0437 0x28a0  IAStorIcon - ok
22:58:17.0521 0x28a0  [ 5689BB0DB40DC712CC87A4F27925F939, 57164AEC7101BBB1E1321B1BD8CF91453F4A9AC549851885087B42E23D777DB2 ] C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe
22:58:17.0634 0x28a0  Yoga PhoneCompanion - ok
22:58:17.0664 0x28a0  [ 7ECEA25EAF0AE3333FF5B4449FBDB6D4, 2C35D9F85A968F4305B945D66B234955BA7F9D4A8FCBEAF085313E3413CC1C0F ] C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
22:58:17.0717 0x28a0  AutoStartTransition - ok
22:58:17.0726 0x28a0  Energy Manager - ok
22:58:17.0745 0x28a0  [ ACFA436C851BC9204A6E2B8EBC8B888D, F895E7A77C2C04E61FD8D09909E08172FFEBF039D6DCF7C3D84FF1992D5FFFD3 ] C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe
22:58:17.0778 0x28a0  Lenovo Utility - ok
22:58:17.0813 0x28a0  [ 9602CE3F53844065AD38CC5F355E19DF, EA3109B8C733462E2F097C8582E299864ADC9904EF17CBA417006006E8E1D14E ] C:\WINDOWS\system32\flvga_tray.exe
22:58:17.0900 0x28a0  flvga_tray64 - detected UnsignedFile.Multi.Generic ( 1 )
22:58:18.0838 0x28a0  flvga_tray64 ( UnsignedFile.Multi.Generic ) - warning
22:58:19.0017 0x28a0  [ 20C08CA080F650B730B1E3FDEA9AD532, 1D2B0914412378E0B5834A95BDD86F8927B6A8D37F4E044C904CE381F1C19A75 ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
22:58:19.0065 0x28a0  AdobeAAMUpdater-1.0 - ok
22:58:19.0068 0x28a0  SynTPEnh - ok
22:58:19.0072 0x28a0  WindowsDefender - ok
22:58:19.0088 0x28a0  [ C7645D43451C6D94D87F4D07BDE59C89, 495BBA47FC43EE23054FCD419F2F00457162D1C04296900C6AEA551102A810F3 ] C:\Windows\system32\rundll32.exe
22:58:19.0180 0x28a0  Logitech Download Assistant - ok
22:58:19.0184 0x28a0  SpaceSoundPro - ok
22:58:19.0211 0x28a0  [ 6867EC437947A1DA443A1068B82FB8CD, 2428AA0ED8939346EBFB1C744BCA1064E4A429737C04B226C4264F24716E4856 ] C:\Program Files (x86)\mpck\otutnetwork.exe
22:58:19.0297 0x28a0  OTUTPRODUCT_VB7ZI - detected UnsignedFile.Multi.Generic ( 1 )
22:58:21.0963 0x28a0  Detect turned to UDS exact due to KSN untrusted
22:58:21.0963 0x28a0  OTUTPRODUCT_VB7ZI ( UDS:DangerousObject.Multi.Generic ) - infected
22:58:21.0963 0x28a0  Force sending object to P2P due to detect: C:\Program Files (x86)\mpck\otutnetwork.exe
22:58:22.0248 0x28a0  Object send P2P result: true
22:58:22.0395 0x28a0  [ 58D4F708D35E07139D62F32A31FAE7AE, 45C6E4ED441B655BB0185689CEB57EFCFF0F00970C074534BC05A4B43448F17F ] C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe
22:58:22.0433 0x28a0  Yoga Picks - ok
22:58:22.0464 0x28a0  [ 4E9AF25BA5E8219310E384AEA5B0EED8, 743062F755E7A88BA394E96CA26A988CCFDF73B441B779B3149D54A769CBC411 ] C:\Program Files (x86)\Cyberlink\Power2Go8\CLMLSvc_P2G8.exe
22:58:22.0511 0x28a0  CLMLServer_For_P2G8 - ok
22:58:22.0569 0x28a0  [ DD68093E7697D02FD019EC7FD4DBC1B1, 17D873A48F443DBA91956747ED76E4E12EDB2C569345A8DC28EAF4FDB1CF1E34 ] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe
22:58:22.0630 0x28a0  CLVirtualDrive - ok
22:58:22.0645 0x28a0  Dropbox - ok
22:58:23.0266 0x28a0  [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe
22:58:23.0966 0x28a0  OneDriveSetup - ok
22:58:24.0539 0x28a0  [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe
22:58:25.0196 0x28a0  OneDriveSetup - ok
22:58:25.0217 0x28a0  Waiting for KSN requests completion. In queue: 5
22:58:26.0257 0x28a0  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.0 ), 0x61100 ( enabled : updated )
22:58:26.0272 0x28a0  Win FW state via NFP2: enabled ( trusted )
22:58:26.0451 0x28a0  ============================================================
22:58:26.0451 0x28a0  Scan finished
22:58:26.0451 0x28a0  ============================================================
22:58:26.0473 0x2898  Detected object count: 5
22:58:26.0473 0x2898  Actual detected object count: 5
22:58:33.0195 0x2898  deciqyguzbt ( UnsignedFile.Multi.Generic ) - skipped by user
22:58:33.0195 0x2898  deciqyguzbt ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:58:33.0195 0x2898  dowidoly ( UnsignedFile.Multi.Generic ) - skipped by user
22:58:33.0195 0x2898  dowidoly ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:58:33.0195 0x2898  rijufoze ( UnsignedFile.Multi.Generic ) - skipped by user
22:58:33.0195 0x2898  rijufoze ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:58:33.0210 0x2898  flvga_tray64 ( UnsignedFile.Multi.Generic ) - skipped by user
22:58:33.0210 0x2898  flvga_tray64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:58:33.0210 0x2898  OTUTPRODUCT_VB7ZI ( UDS:DangerousObject.Multi.Generic ) - skipped by user
22:58:33.0210 0x2898  OTUTPRODUCT_VB7ZI ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip


cosinus 16.08.2016 22:31

TDSS-Killer erneut starten. Diesmal aber bitte nach dem Fund folgende entfernen:

deciqyguzbt
dowidoly
rijufoze
OTUTPRODUCT_VB7ZI

Piristibulus 16.08.2016 22:52

gemacht ... und als die Meldung über reboot zum Abschluss kam, ist er wieder mit Blue Screen abgestürzt

Hier das log, was er noch vorher angelegt hatte:

Teil 1:
Code:

23:44:01.0648 0x22d4  TDSS rootkit removing tool 3.1.0.11 Aug  5 2016 12:13:31
23:44:01.0649 0x22d4  UEFI system
23:44:04.0360 0x22d4  ============================================================
23:44:04.0361 0x22d4  Current date / time: 2016/08/16 23:44:04.0360
23:44:04.0361 0x22d4  SystemInfo:
23:44:04.0361 0x22d4 
23:44:04.0361 0x22d4  OS Version: 10.0.14393 ServicePack: 0.0
23:44:04.0361 0x22d4  Product type: Workstation
23:44:04.0361 0x22d4  ComputerName: PIRISTIBULUS
23:44:04.0361 0x22d4  UserName: dbirn_000
23:44:04.0361 0x22d4  Windows directory: C:\WINDOWS
23:44:04.0361 0x22d4  System windows directory: C:\WINDOWS
23:44:04.0361 0x22d4  Running under WOW64
23:44:04.0361 0x22d4  Processor architecture: Intel x64
23:44:04.0362 0x22d4  Number of processors: 4
23:44:04.0362 0x22d4  Page size: 0x1000
23:44:04.0362 0x22d4  Boot type: Normal boot
23:44:04.0362 0x22d4  CodeIntegrityOptions = 0x00000001
23:44:04.0362 0x22d4  ============================================================
23:44:04.0524 0x22d4  KLMD registered as C:\WINDOWS\system32\drivers\33158120.sys
23:44:04.0524 0x22d4  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.0, osProperties = 0x19
23:44:05.0418 0x22d4  System UUID: {AB828E4B-EBEB-47F5-2012-287CB0E5DAFF}
23:44:06.0106 0x22d4  Drive \Device\Harddisk0\DR0 - Size: 0x773C256000 ( 476.94 Gb ), SectorSize: 0x200, Cylinders: 0xF334, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:44:06.0115 0x22d4  ============================================================
23:44:06.0115 0x22d4  \Device\Harddisk0\DR0:
23:44:06.0115 0x22d4  GPT partitions:
23:44:06.0117 0x22d4  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {E6872534-D39F-4D51-8C56-5F8712CF9DA8}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x1F4000
23:44:06.0117 0x22d4  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {5C79513C-CE8A-40B2-86C8-9FA5F40CD90A}, Name: EFI system partition, StartLBA 0x1F4800, BlocksNum 0x82000
23:44:06.0117 0x22d4  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {C0D64BCB-BDF7-4415-A319-1D596DBF4079}, Name: Basic data partition, StartLBA 0x276800, BlocksNum 0x1F4000
23:44:06.0117 0x22d4  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {FD746D6F-AD8C-45A7-991E-733D5D5E8104}, Name: Microsoft reserved partition, StartLBA 0x46A800, BlocksNum 0x40000
23:44:06.0117 0x22d4  \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {7A4D5883-94A9-4C84-849E-B3024501E368}, Name: Basic data partition, StartLBA 0x4AA800, BlocksNum 0x36680000
23:44:06.0117 0x22d4  \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {15ACFF03-364A-4884-8546-CCDA62724C1B}, Name: Basic data partition, StartLBA 0x36B2A800, BlocksNum 0x3200000
23:44:06.0117 0x22d4  \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {EE765799-E795-4301-A97C-831049B7F01E}, Name: Basic data partition, StartLBA 0x39D2A800, BlocksNum 0x1CB6800
23:44:06.0117 0x22d4  MBR partitions:
23:44:06.0117 0x22d4  ============================================================
23:44:06.0118 0x22d4  C: <-> \Device\Harddisk0\DR0\Partition5
23:44:06.0119 0x22d4  D: <-> \Device\Harddisk0\DR0\Partition6
23:44:06.0119 0x22d4  ============================================================
23:44:06.0119 0x22d4  Initialize success
23:44:06.0119 0x22d4  ============================================================
23:44:12.0502 0x1f2c  ============================================================
23:44:12.0502 0x1f2c  Scan started
23:44:12.0502 0x1f2c  Mode: Manual; SigCheck; TDLFS;
23:44:12.0502 0x1f2c  ============================================================
23:44:12.0502 0x1f2c  KSN ping started
23:44:12.0800 0x1f2c  KSN ping finished: true
23:44:13.0325 0x1f2c  ================ Scan system memory ========================
23:44:13.0325 0x1f2c  System memory - ok
23:44:13.0326 0x1f2c  ================ Scan services =============================
23:44:13.0377 0x1f2c  [ A7901875F89D011C38CF52C98ACF5B29, 782141AB1DD7ACDE6EA08B5BAFDE8BADD05B81D38C18E097D6D9C46102056EB1 ] 1394ohci        C:\WINDOWS\System32\drivers\1394ohci.sys
23:44:13.0464 0x1f2c  1394ohci - ok
23:44:13.0476 0x1f2c  [ EE1CCC54F75C24727A218F98FC5349DA, 0B0D26640BFA0F551B7087027E572D0BF2C5EAF50A4187C5A7D839180B7FF589 ] 3ware          C:\WINDOWS\system32\drivers\3ware.sys
23:44:13.0497 0x1f2c  3ware - ok
23:44:13.0513 0x1f2c  [ 73C73E1AA0D4D727A04AAAB120B7F56A, 5D311F11022994410DF5C67914D38B1F0D813EFD181EA234750286A272D67A1A ] ACPI            C:\WINDOWS\system32\drivers\ACPI.sys
23:44:13.0560 0x1f2c  ACPI - ok
23:44:13.0560 0x1f2c  [ 0935496EF9624B46B935CB35ECE1F205, A22A2A29195505A65E8626D60B00C86C23E0CABC1EB8345EA5ED523516CC21C0 ] AcpiDev        C:\WINDOWS\System32\drivers\AcpiDev.sys
23:44:13.0582 0x1f2c  AcpiDev - ok
23:44:13.0582 0x1f2c  [ D6794C31F4077B71433988787BAA926E, F16365C2F195AAE94D4740E6C3DF4C0CECEC6393CAD65425DCCD28CDBA6EC51A ] acpiex          C:\WINDOWS\system32\Drivers\acpiex.sys
23:44:13.0613 0x1f2c  acpiex - ok
23:44:13.0613 0x1f2c  [ FE5F656D6B35089DA39112E74EC6A85A, 5D81EE63998232A5B36DE47FE15B9D04D5BD02234CA133A2462AECA8C60A22ED ] acpipagr        C:\WINDOWS\System32\drivers\acpipagr.sys
23:44:13.0629 0x1f2c  acpipagr - ok
23:44:13.0645 0x1f2c  [ 2F242941E4DFF69B883D77A16F039557, 45C388365317C720654A659A9326B2BC0E9D84929C704654985597D5D620101C ] AcpiPmi        C:\WINDOWS\System32\drivers\acpipmi.sys
23:44:13.0660 0x1f2c  AcpiPmi - ok
23:44:13.0660 0x1f2c  [ C247E35A21682DA8D0DC3AF9F025FCC5, 455415EE3166B3043AD8A4DD50B688DB74242267FB555642441251EFA823E971 ] acpitime        C:\WINDOWS\System32\drivers\acpitime.sys
23:44:13.0683 0x1f2c  acpitime - ok
23:44:13.0683 0x1f2c  [ AF7A18603B0B82DFA5B420456FAF2201, 64AD831433778BB0B0B1615EEA7682960ED5815A091A9EFEE95A862EFBDE6D69 ] ACPIVPC        C:\WINDOWS\System32\drivers\AcpiVpc.sys
23:44:13.0729 0x1f2c  ACPIVPC - ok
23:44:13.0745 0x1f2c  [ 68E7DEA59FDEF410BAF29FDB5B7A6EEF, B808FCF0C30B465A1330E47947B84FC722A3B4C46260E261C54B1EED725A288F ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
23:44:13.0745 0x1f2c  AdobeARMservice - ok
23:44:13.0783 0x1f2c  [ 32B31B696CB8E8F380831DFEB80A67E4, 8C8F6E16F2FB3E8F10569261B7712BBC931A2924B6C27D561E7F828041C4F3E6 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
23:44:13.0798 0x1f2c  AdobeFlashPlayerUpdateSvc - ok
23:44:13.0845 0x1f2c  [ 49B9DB97AFC85DCCBDACDAB2E90085B7, 2A6C2A09F74EA15044F442CCFB54A0F24F105ADB915E5C78F02F59652DC29152 ] ADP80XX        C:\WINDOWS\system32\drivers\ADP80XX.SYS
23:44:13.0907 0x1f2c  ADP80XX - ok
23:44:13.0929 0x1f2c  [ 983266DA83FFF73DBDDD3730A4712228, 433A2731DAC687C52FB7E23093B8E11D92CCCF4C35B493D73AC30C6A4A6D2A6C ] AFD            C:\WINDOWS\system32\drivers\afd.sys
23:44:13.0964 0x1f2c  AFD - ok
23:44:14.0022 0x1f2c  [ 9A53CCE5A15CFB948CD9D3D1A79282DC, 1FC8422C43400E550414448F64290DA6DB0E0A0C03D88BCBDA0EDA5FD7B2EFBB ] AGSService      C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
23:44:14.0099 0x1f2c  AGSService - ok
23:44:14.0112 0x1f2c  [ E44DB3F7225EC3E119560738B3619972, 32946FBC2BD74072F22E48D769A034183F6C3728FCCC3CF0DD561602511E39B2 ] ahcache        C:\WINDOWS\system32\DRIVERS\ahcache.sys
23:44:14.0146 0x1f2c  ahcache - ok
23:44:14.0151 0x1f2c  [ D0905D4A945D01D4B28DB9E1BD5985F7, CF389CBCD3B99D1BAE34A42F723F1005C32213A394F691978076D3DF1727715C ] AJRouter        C:\WINDOWS\System32\AJRouter.dll
23:44:14.0173 0x1f2c  AJRouter - ok
23:44:14.0180 0x1f2c  [ 8FD51B3B35707A66080D7C8CB05E792D, FE52F3DC280D208FDDC75F6E3294B8D601E0D86F9BD3DB1ACC8FC296AC74C23B ] ALG            C:\WINDOWS\System32\alg.exe
23:44:14.0217 0x1f2c  ALG - ok
23:44:14.0225 0x1f2c  [ DF21E05E41E5AC3F13F304D91457649A, 7F48F2AD1DBE89A261113C76D7C23AD7D87D5599BCC31F8A558A8A10B81BF521 ] AmdK8          C:\WINDOWS\System32\drivers\amdk8.sys
23:44:14.0251 0x1f2c  AmdK8 - ok
23:44:14.0258 0x1f2c  [ 45D0AA4BB90B821DF92E8F19ABED0C5E, EA87A6E98DB3C5A88A844C04C6934E870B7004E783AA5211722115382A211B90 ] AmdPPM          C:\WINDOWS\System32\drivers\amdppm.sys
23:44:14.0284 0x1f2c  AmdPPM - ok
23:44:14.0290 0x1f2c  [ 74FFBC43B4B899C9A8CA06A892F2CE73, 8D599363C7F3D373F1859BAA4D06DD0F40BE78B56BE52B74DE6EA6EF99452004 ] amdsata        C:\WINDOWS\system32\drivers\amdsata.sys
23:44:14.0309 0x1f2c  amdsata - ok
23:44:14.0320 0x1f2c  [ AAB0F1D8D7E54761ABAB13AF161F1680, CF847990EFFA2828F5B1DB1A68F08A6C2C918E9612EDFFCF95C36BCABBBEA272 ] amdsbs          C:\WINDOWS\system32\drivers\amdsbs.sys
23:44:14.0347 0x1f2c  amdsbs - ok
23:44:14.0352 0x1f2c  [ F91BAAC4237C40352A807000F3B716F9, F7EFA08E5067C3D419C9D21EDB880BA08883A80DDF35F8B42EC3AB293FE5E03E ] amdxata        C:\WINDOWS\system32\drivers\amdxata.sys
23:44:14.0369 0x1f2c  amdxata - ok
23:44:14.0377 0x1f2c  [ BC121C099C6C659126AD2102AFDFF8CF, 42B5EE293BDD7ADCE48173A01B30D8452564B9DA225EAF25E9292FE77C0FCF3E ] AppID          C:\WINDOWS\system32\drivers\appid.sys
23:44:14.0399 0x1f2c  AppID - ok
23:44:14.0407 0x1f2c  [ 74A24CF946279111D7F203B36569EC02, FD67D36804744B4FE3E20BA891852575E6C2DA6515643B2F4B4210118B0FCCDA ] AppIDSvc        C:\WINDOWS\System32\appidsvc.dll
23:44:14.0440 0x1f2c  AppIDSvc - ok
23:44:14.0447 0x1f2c  [ 008E4CCA7A4B33042276061E0A5B8244, DAD980540B564EFA06760435AF1B3213056E6DE8B2A55DF98E7D871625D4B080 ] Appinfo        C:\WINDOWS\System32\appinfo.dll
23:44:14.0477 0x1f2c  Appinfo - ok
23:44:14.0482 0x1f2c  [ 68190E2BADF23BD782344970E5B5DE9E, 95D30EC12C7FDF5822CED8BC2F17669A6687A2FB262B4F0D15C8DCFF4E9AB33D ] applockerfltr  C:\WINDOWS\system32\drivers\applockerfltr.sys
23:44:14.0519 0x1f2c  applockerfltr - ok
23:44:14.0544 0x1f2c  [ 41BF82B41BD24BAC9D9890DAC3212007, 0644BEE740244188B3D39F875D313B560D288B7FC33064E352C2A5F09073E361 ] AppReadiness    C:\WINDOWS\system32\AppReadiness.dll
23:44:14.0609 0x1f2c  AppReadiness - ok
23:44:14.0672 0x1f2c  [ 757646A22C2E9BC21E6A50842FE79139, 6AEBD3486F79C55154D677204D0CCB8179DAFC90941A743D277B44C1EED9DB12 ] AppXSvc        C:\WINDOWS\system32\appxdeploymentserver.dll
23:44:14.0829 0x1f2c  AppXSvc - ok
23:44:14.0841 0x1f2c  [ E6AB1F0B4C3D4E0D2A88332D76FECD03, 0D3003EB979DA4546DCDD055011E24F13E34F683F02C9801CAC564D1809F11D2 ] arcsas          C:\WINDOWS\system32\drivers\arcsas.sys
23:44:14.0868 0x1f2c  arcsas - ok
23:44:14.0897 0x1f2c  [ 5EE26734A882478AF6696092E2E0F352, 6CACFF521B3B839F73EBEB6EFBFDCCA8A8BC319DDB254BE3EFE29A39040B2C26 ] aspnet_state    C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
23:44:14.0920 0x1f2c  aspnet_state - ok
23:44:14.0925 0x1f2c  [ 61C5A480C43E7E8E49C42869F49D0D3E, E610F0E4315ABA1D90AD4A1D7A68ABA2ACBB7FCA89E9D1798470365D52592D55 ] AsyncMac        C:\WINDOWS\System32\drivers\asyncmac.sys
23:44:15.0028 0x1f2c  AsyncMac - ok
23:44:15.0034 0x1f2c  [ A10F989A812B57B9695F6C305907C9C6, E2B292610079AA1A10696138DE8130905A8A834B75A8DED7EBF8B6732B77A0F4 ] atapi          C:\WINDOWS\system32\drivers\atapi.sys
23:44:15.0047 0x1f2c  atapi - ok
23:44:15.0064 0x1f2c  [ 5D637DF654D6386487876ADF5AF301B3, 7B53356237369D892F5BBEA9C967B20DCA40FA2B6B3C5AF7A4304FFD00DF1BFC ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
23:44:15.0105 0x1f2c  AudioEndpointBuilder - ok
23:44:15.0121 0x1f2c  [ 57CEE51D9D84870F93D404302705A054, 14364B9798E9FE3F8A42109D749804795FA507C1A7D535DC17876ECCD47644E9 ] Audiosrv        C:\WINDOWS\System32\Audiosrv.dll
23:44:15.0174 0x1f2c  Audiosrv - ok
23:44:15.0190 0x1f2c  [ 6D90FDA2DC364B8EA1420F2F81585CC3, 10E6F23A213CFE49BE04BB7D366ADD4028D61D7114FEC67C30B5467DF6B36D4F ] AxInstSV        C:\WINDOWS\System32\AxInstSV.dll
23:44:15.0221 0x1f2c  AxInstSV - ok
23:44:15.0236 0x1f2c  [ 61BAC67048CA5C1D08C48FCC8012B613, 71B2A466FC38DA1029B471FBD2541D8FE359751A7B212AE0F420DB3645916450 ] b06bdrv        C:\WINDOWS\system32\drivers\bxvbda.sys
23:44:15.0270 0x1f2c  b06bdrv - ok
23:44:15.0274 0x1f2c  [ 68F72B05EBC6D1779C0D60A147C7CA0B, AA1C857BEE34865C6B901157FC22570D4CF45D950708BAD7AA333F120F2B474C ] BasicDisplay    C:\WINDOWS\System32\drivers\BasicDisplay.sys
23:44:15.0305 0x1f2c  BasicDisplay - ok
23:44:15.0305 0x1f2c  [ 23156E7EDAF613D839E2839746B168D3, CAEF8F9C7D3A338BD747AC9D5BFBE730D77B911E87BCF532EBB75E1F80916AFA ] BasicRender    C:\WINDOWS\System32\drivers\BasicRender.sys
23:44:15.0321 0x1f2c  BasicRender - ok
23:44:15.0337 0x1f2c  [ 3F5523DCEFE42B385659C5CB46A6B810, CA24A3DF002B19E7BDEDE9B5EB60623F299D0E78B2E4F58DCFC028D76DEFE52D ] bcmfn          C:\WINDOWS\System32\drivers\bcmfn.sys
23:44:15.0352 0x1f2c  bcmfn - ok
23:44:15.0369 0x1f2c  [ 0B750A6A6D847E73CA48ADD7A0F5A393, 6A43020F23846EFB1AFA3C070465B0059E9DF60DEB16899E09559462DF30939F ] bcmfn2          C:\WINDOWS\System32\drivers\bcmfn2.sys
23:44:15.0390 0x1f2c  bcmfn2 - ok
23:44:15.0406 0x1f2c  [ D4EFDA0D56429018281F8F3188E6F86C, 020B861338BAF8E2A861CA1D2D22640CCD39BA84F18260F9862F7E3AC5014985 ] BDESVC          C:\WINDOWS\System32\bdesvc.dll
23:44:15.0437 0x1f2c  BDESVC - ok
23:44:15.0453 0x1f2c  [ 0A508274355745EEF01C6BE3198D02C4, E2DB08AEE2368FA95FDB357BB31EA4EBF31679C3E72E109DB3D7CD1B5F7B828E ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
23:44:15.0474 0x1f2c  Beep - ok
23:44:15.0490 0x1f2c  [ 5125CBB61AC81168366BEB290399CB8E, B2A3095D45E2114DE2BD0E5A3AE20B3CE95EE517A35B9E1EAD05E231F38DBDCF ] BFE            C:\WINDOWS\System32\bfe.dll
23:44:15.0537 0x1f2c  BFE - ok
23:44:15.0553 0x1f2c  [ D99CD8421A546B5AC727CD947C61DC83, E5DD081CB7D8FB6891277D4DEB34B003C04EEF236462E2FCAE35D131F580C10D ] BITS            C:\WINDOWS\System32\qmgr.dll
23:44:15.0622 0x1f2c  BITS - ok
23:44:15.0622 0x1f2c  [ EEBFAEB4702E1049ECD44B10485E6C0C, 8F4D31E36717101B6172D7346E86EBC77B9CDAA5CC14AA1379661C16A7FF05E2 ] bowser          C:\WINDOWS\system32\DRIVERS\bowser.sys
23:44:15.0637 0x1f2c  bowser - ok
23:44:15.0670 0x1f2c  [ 78C35DD7CF780428650B1EE9B0F8D41E, C5A3111383CD9813A4ED33E244E20E2E0607CDEFC5BF00A760F63DAD019EE90E ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
23:44:15.0722 0x1f2c  BrokerInfrastructure - ok
23:44:15.0722 0x1f2c  [ B3F32C630DD3F2F6A6091B89CFF13641, 7A9C53EF9AB9FF1DC392FD711B194A101DB36CA5BC799E817BEB446741089B76 ] Browser        C:\WINDOWS\System32\browser.dll
23:44:15.0753 0x1f2c  Browser - ok
23:44:15.0753 0x1f2c  [ 722036C26D2C4E50EC2A2EC5FD678846, 999468038AE01F0FF6881F4B2A2CB67BC636641188E95F10729E08ADBC3CB3DE ] BthAvrcpTg      C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
23:44:15.0775 0x1f2c  BthAvrcpTg - ok
23:44:15.0775 0x1f2c  [ FF218FBB511B733F8A6829FB17CA972D, 05BB1C3BFE189549E78A02C5C0C0C832C248680668D821F92FE7B6B39DC111A0 ] BthEnum        C:\WINDOWS\System32\drivers\BthEnum.sys
23:44:15.0791 0x1f2c  BthEnum - ok
23:44:15.0791 0x1f2c  [ C2E31BE025D46D189E38DD1EDF07837A, 656528DCAAAF485EC57EE5C3021E96736634DE3B9C39CBCD2728E055ABD4C0A5 ] BthHFEnum      C:\WINDOWS\System32\drivers\bthhfenum.sys
23:44:15.0807 0x1f2c  BthHFEnum - ok
23:44:15.0822 0x1f2c  [ F7CD605FC0B0B22F3F6F247595E3A655, 1CD9140DE5415DDBEACD8667E63E5C95FD64D693B56302A0474E693E578BEAB0 ] bthhfhid        C:\WINDOWS\System32\drivers\BthHFHid.sys
23:44:15.0838 0x1f2c  bthhfhid - ok
23:44:15.0838 0x1f2c  [ B157D72BDA6A6DD6E9DC6BF338CD0CF8, B2AC26AE214151E5AD93DED78256BC0295DBF0133C854E7DEE4CD776D9C9A349 ] BthHFSrv        C:\WINDOWS\System32\BthHFSrv.dll
23:44:15.0876 0x1f2c  BthHFSrv - ok
23:44:15.0891 0x1f2c  [ 8EDA0733FF6266C2FB26BCE0B4AA8B15, F60BE5630EE714B718233933DC6101130DF672A01F99C7389D0708BC00E8D5DF ] BthLEEnum      C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
23:44:15.0922 0x1f2c  BthLEEnum - ok
23:44:15.0922 0x1f2c  [ 535DC41A33630AE4C262406F9E981C03, 599332589AA28D04189E19B87A4AE6FEEB60B40A7BC6E3B11240DA363A981C29 ] BTHMODEM        C:\WINDOWS\System32\drivers\bthmodem.sys
23:44:15.0954 0x1f2c  BTHMODEM - ok
23:44:15.0971 0x1f2c  [ D2A121586B660311B09964D2A6DDF864, 539953D953D40014366918BB38FADD3F21417EF8ADA532E1ABD1824949B952D4 ] BthPan          C:\WINDOWS\System32\drivers\bthpan.sys
23:44:16.0004 0x1f2c  BthPan - ok
23:44:16.0032 0x1f2c  [ E465D7F6F3E4CA9F0E5FB6FD346F2F3D, 8F01051202903E8E16A6AE42B3F5F900C4D0B021311AE44225E8D11BE48DB129 ] BTHPORT        C:\WINDOWS\system32\DRIVERS\BTHport.sys
23:44:16.0099 0x1f2c  BTHPORT - ok
23:44:16.0108 0x1f2c  [ 96932F631F5CB9F5D1C8F99A71568EF3, 5E4C8955A2EE9DC76B4EBC383653EB753D76D6B017E1A5DD553AC16094D7F12A ] bthserv        C:\WINDOWS\system32\bthserv.dll
23:44:16.0136 0x1f2c  bthserv - ok
23:44:16.0142 0x1f2c  [ 7E844E3B520CA7873674D36286BC380F, 8B2A079B59625754D4CDFC486FC606B036B063DB382F6449A0CB69C5675F7A8A ] BTHUSB          C:\WINDOWS\system32\DRIVERS\BTHUSB.sys
23:44:16.0163 0x1f2c  BTHUSB - ok
23:44:16.0166 0x1f2c  [ 23F9EF739F685E07482116425E7879AA, 0EBDF96A49A319C0BCF6F51FB6C8C392C017E1738B950C19C91FF43E14D73143 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys
23:44:16.0182 0x1f2c  buttonconverter - ok
23:44:16.0329 0x1f2c  [ 072F43B6B6F8824B971FE503F9E7CB83, 9CDF5127C656A9A94402DE69497F5E5101C5BBEA087C364D47A3322462955E64 ] Canon Driver Information Assist Service C:\Program Files\Canon\DIAS\CnxDIAS.exe
23:44:16.0749 0x1f2c  Canon Driver Information Assist Service - ok
23:44:16.0764 0x1f2c  [ 4C61113687EB66035A70A55EE9B7DB4A, 3339821A3853B90F3B468470493A813053D82014E2677E726C16E19AABE2A440 ] CapImg          C:\WINDOWS\System32\drivers\capimg.sys
23:44:16.0807 0x1f2c  CapImg - ok
23:44:16.0814 0x1f2c  [ F8FB51B9EF6372610E9B31A1D86B62FC, 7461584A8B39AC549AD7BAFFA509D4CD81EEE542808BC8EFC285863A0AE6432D ] cdfs            C:\WINDOWS\system32\DRIVERS\cdfs.sys
23:44:16.0849 0x1f2c  cdfs - ok
23:44:16.0864 0x1f2c  [ 7AD576CF28F1E7AEFC3D6E8279DF84F6, 1F7E26F9354B543881E940F5183086AC00684CDC0AB7A797E1F0AB21C4AD8716 ] CDPSvc          C:\WINDOWS\System32\CDPSvc.dll
23:44:16.0918 0x1f2c  CDPSvc - ok
23:44:16.0931 0x1f2c  [ 0415CA08674F64D63329CB51D4004685, 12F3AB9A263F2E131F4969E6CED2AE6DD7AF06C10AF02923256FF4C9E34698BF ] CDPUserSvc      C:\WINDOWS\System32\CDPUserSvc.dll
23:44:16.0987 0x1f2c  CDPUserSvc - ok
23:44:16.0999 0x1f2c  [ 613D0137C269187FA298A157E3D14A18, 84BC268525F14BB27202CE242BF94D9E83BC91B50A0335908574F31B29A2F04D ] cdrom          C:\WINDOWS\System32\drivers\cdrom.sys
23:44:17.0038 0x1f2c  cdrom - ok
23:44:17.0048 0x1f2c  [ 9450FA11E9DE6715FCB71A519A8FF90B, B7E341C6E4CE967FCDD0D17A497C07E8A1C6B0AACE8A6E8E5D6C21EF73F13E16 ] CertPropSvc    C:\WINDOWS\System32\certprop.dll
23:44:17.0097 0x1f2c  CertPropSvc - ok
23:44:17.0109 0x1f2c  [ 0AED948DA8D5F08B3D6F12E4E2089736, 95E538E81DDBC83492C5F3820C82C78F050B4D74ACF12D7970EC84F93581AE29 ] cht4iscsi      C:\WINDOWS\system32\drivers\cht4sx64.sys
23:44:17.0138 0x1f2c  cht4iscsi - ok
23:44:17.0193 0x1f2c  [ 0002A0FDE087C1657AB31CE73077539C, 4DD6210B67E9633AB3240371590869DC833A4C986C74FC12A5D4FFFFD361848A ] cht4vbd        C:\WINDOWS\System32\drivers\cht4vx64.sys
23:44:17.0283 0x1f2c  cht4vbd - ok
23:44:17.0292 0x1f2c  [ 6B4F90A287D75CCD78694F6790C911B2, 73D7C31E9F475FA3FD568FCA9A953F968729AA114F63C06F38BF5198DAD67BD8 ] circlass        C:\WINDOWS\System32\drivers\circlass.sys
23:44:17.0315 0x1f2c  circlass - ok
23:44:17.0317 0x1f2c  [ 09D0B94D3A06EFD1EB70189EC4B26DF7, 47E73C536C63F4C21E4ADBB122A152D3A291CF4EDD4CB4D07D09D14E1A9961F1 ] CLFS            C:\WINDOWS\system32\drivers\CLFS.sys
23:44:17.0333 0x1f2c  CLFS - ok
23:44:17.0412 0x1f2c  [ F6541F3D7FAF912F52AAE4398757084E, 1C573949C115B0A371236B791BB748FFFC4E7B12CA4D4ACD23110AF6082625FA ] ClickToRunSvc  C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
23:44:17.0480 0x1f2c  ClickToRunSvc - ok
23:44:17.0518 0x1f2c  [ E133CFCBFABB3CB517BE9F42FEA5887C, DA699CDD5F3CC427354540C907BD24CCA7BAC3112C53918EB611CB4EEC7611DA ] ClipSVC        C:\WINDOWS\System32\ClipSVC.dll
23:44:17.0549 0x1f2c  ClipSVC - ok
23:44:17.0565 0x1f2c  [ EEC3A4A98AE1A337E3CD1483AD6F2E15, 764DA329984A95E092F5C15116DA34FA7FC27216C0862365D4BF10ADC97EC5C5 ] clreg          C:\WINDOWS\System32\drivers\registry.sys
23:44:17.0580 0x1f2c  clreg - ok
23:44:17.0596 0x1f2c  [ 3E76A1547F2448BCEE3D2F4AE3931AB5, 31B41723FAA4210A86B1AE02D6C052BD8B738C4B89FB0177C1AE997D24BA5B8C ] CLVirtualDrive  C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys
23:44:17.0612 0x1f2c  CLVirtualDrive - ok
23:44:17.0617 0x1f2c  [ 429623E266EF067A44E8CF148E9DFB9B, A48AA85ACC52C7AD73DB2D6148B3F9FB5EAC33C8F8C5BB6D7D0A9D84B7C08E11 ] CmBatt          C:\WINDOWS\System32\drivers\CmBatt.sys
23:44:17.0618 0x1f2c  CmBatt - ok
23:44:17.0633 0x1f2c  [ E09C3E2CD29727AAC0977E1A7CE0425E, 86BC9C4306861D104A0F87E9C6E3E7A972488C80DD399A983397FF0312292DA3 ] CNG            C:\WINDOWS\system32\Drivers\cng.sys
23:44:17.0665 0x1f2c  CNG - ok
23:44:17.0665 0x1f2c  [ 3DB10C59405931E2C72EFB82C1AF97D1, 100B5450A70988DB1C1F8A5FDBB3553AF1A0D47B42A5AC71460DB92E26010CE6 ] cnghwassist    C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
23:44:17.0680 0x1f2c  cnghwassist - ok
23:44:17.0717 0x1f2c  [ 34C935AF2A414572B412B3556586D783, 912981B88B0796576ECCD5EBE0C4728EC02D5D6A96B039447DCBA59B2583F25E ] CompositeBus    C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys
23:44:17.0718 0x1f2c  CompositeBus - ok
23:44:17.0734 0x1f2c  [ 5FADE7137C14A94B323F3B7886FBA2A9, 66F851B309BADA6D3E4B211BAA23B534165B29BA16B5CBF5E8F44EAEB3CA86EA ] ComputerZ_x64  C:\Program Files (x86)\LuDaShi\ComputerZ_x64.sys
23:44:17.0734 0x1f2c  ComputerZ_x64 - ok
23:44:17.0749 0x1f2c  COMSysApp - ok
23:44:17.0749 0x1f2c  [ 44EEEB2382F566999287E13F2067693C, 53A4A0C85EAD38030FF2078C67465E3710ECD03A08FF34E1E67B2E3E1CC70043 ] condrv          C:\WINDOWS\system32\drivers\condrv.sys
23:44:17.0765 0x1f2c  condrv - ok
23:44:17.0781 0x1f2c  [ 9CE94A05A5BA6A92013CAD1B924B1EC2, 19ECE2C607BAE5DCE7ED4AB46722E63EF834B219716F3A90AF661C02B58088C4 ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll
23:44:17.0818 0x1f2c  CoreMessagingRegistrar - ok
23:44:17.0833 0x1f2c  [ C46BAFE2828011F51B57E59DE4D4FECA, 14BAC9D350EBF95867455F36260C8E644A863CC1BC8A2A6CACA9D519091695FE ] cphs            C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
23:44:17.0918 0x1f2c  cphs - ok
23:44:17.0934 0x1f2c  [ 5F06CAC4B09250CDDDD0180A08162924, A2EB0A57225E65FC264CFC9FAD858D8B54A015CDAE3DC904B1C4E9AAB40B1F06 ] CryptSvc        C:\WINDOWS\system32\cryptsvc.dll
23:44:17.0949 0x1f2c  CryptSvc - ok
23:44:17.0949 0x1f2c  [ 68B1E0DA1BB1680494227E88CE821E2F, DE9AFCE4CC28F3484180D6A63FBBDA5B89F208E056BD17870C074094159ED6AF ] dam            C:\WINDOWS\system32\drivers\dam.sys
23:44:17.0965 0x1f2c  dam - ok
23:44:17.0965 0x1f2c  dbupdate - ok
23:44:17.0965 0x1f2c  dbupdatem - ok
23:44:17.0996 0x1f2c  [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
23:44:18.0034 0x1f2c  DcomLaunch - ok
23:44:18.0034 0x1f2c  [ AE9F09F87755C18904656CB4F59F351D, B352A43B3B68B497D87B49C302AF3F37F36D56D49878AE3785C3D43597E5DC57 ] DcpSvc          C:\WINDOWS\system32\dcpsvc.dll
23:44:18.0065 0x1f2c  DcpSvc - ok
23:44:18.0065 0x1f2c  [ EB493F82365D3E1CD21379268BAFA3A2, 27FCDFE37D7AF8E046F99BA9AA1F6EDE8F4E08689EB3B5DC9731C3DB4CAADA2D ] ddkmd          C:\WINDOWS\system32\drivers\ddkmd.sys
23:44:18.0119 0x1f2c  ddkmd - ok
23:44:18.0119 0x1f2c  [ FC89D0D4F589DD3A9E2FDC5F0E0273A5, 85F338F6BE4F63AD37B19A5059DD7449C80A7639C880A1E6BF55DAC5D7243158 ] ddkmdldr        C:\WINDOWS\system32\drivers\ddkmdldr.sys
23:44:18.0134 0x1f2c  ddkmdldr - ok
23:44:18.0165 0x1f2c  [ 64E8BD4FEDF726C2D6054FA5838F3831, 4F74BAC2D66FC56F1F0DB573F7FE8EDFC36A608100B01CEEC40502D1B838DD8C ] ddmgr          C:\WINDOWS\system32\ddmgr.exe
23:44:18.0250 0x1f2c  ddmgr - ok
23:44:18.0266 0x1f2c  [ 361A95B67CB826E644A72377033C8CD2, 303A5BB8CE4855B25E4F16ADD7F0531B66E8C00B26404E036FE5D438DB112760 ] deciqyguzbt    C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\knsd9A99.tmp
23:44:18.0318 0x1f2c  deciqyguzbt - detected UnsignedFile.Multi.Generic ( 1 )
23:44:19.0704 0x1f2c  deciqyguzbt ( UnsignedFile.Multi.Generic ) - warning
23:44:20.0320 0x1f2c  [ ABBD3EE724117242E28D31F19FBCFF03, 68EA91A969DD80A5DE28B0A8EAEB308837183713559C2C2FAEF991858C971393 ] defragsvc      C:\WINDOWS\System32\defragsvc.dll
23:44:20.0468 0x1f2c  defragsvc - ok
23:44:20.0521 0x1f2c  [ 78658EBDAD59E17ACC3569C8451F07B3, 629A014AF4E306C167B4D5C8DAFEE145472691CDCBBBB616D1435B67AA6FF20B ] DeviceAssociationService C:\WINDOWS\system32\das.dll
23:44:20.0662 0x1f2c  DeviceAssociationService - ok
23:44:20.0688 0x1f2c  [ FEA494AC3A1BAE63C1F2AF267D49F1DB, 0722FEA2481740B53EF26B1CA59166C63C157A5C708AC93DF3FBB74A27266C9C ] DeviceInstall  C:\WINDOWS\system32\umpnpmgr.dll
23:44:20.0787 0x1f2c  DeviceInstall - ok
23:44:20.0805 0x1f2c  [ CDF1B1B5C5951111791C236B2696C7F8, BF6C4BA545C8827B40DB69890DB4D2B2F9C583C5E3CFBDFD370B05891141458D ] DevQueryBroker  C:\WINDOWS\system32\DevQueryBroker.dll
23:44:20.0856 0x1f2c  DevQueryBroker - ok
23:44:20.0884 0x1f2c  [ 7EAFDEF51136E8F2452CEBD8D084F108, 88609DCB578D14BEBF7CF3C4D300FE2440BA0CF95189969247AB516059E9C284 ] Dfsc            C:\WINDOWS\system32\Drivers\dfsc.sys
23:44:20.0951 0x1f2c  Dfsc - ok
23:44:20.0987 0x1f2c  [ F0D4400BA0F08610D9A551B15BF10B76, 83EB8FB272FC2DD2CC0659C2FB90AD0DAE88A88AB3951E03BCD933A25B601E10 ] Dhcp            C:\WINDOWS\system32\dhcpcore.dll
23:44:21.0083 0x1f2c  Dhcp - ok
23:44:21.0104 0x1f2c  [ CA7FEDDFCF61EF15A09C54DA2C07C49F, 346EF7709BA9E6BD48592B86FA46F9D956C847EF91F4980EEAD98269D0F0EF67 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
23:44:21.0181 0x1f2c  diagnosticshub.standardcollector.service - ok
23:44:21.0308 0x1f2c  [ 6079A6F6406C4FFB552F66384F25F919, 8B38645F1F4A8F72DF18373EDCD3828DDF8D4E2A406E42E654F21C0C1A5EB661 ] DiagTrack      C:\WINDOWS\system32\diagtrack.dll
23:44:21.0640 0x1f2c  DiagTrack - ok
23:44:21.0671 0x1f2c  [ 35B9D46560339A5A7F0CAC6ED702C817, F70480B01533B7029F90E2DE297E9E829660300DDE7A7D009B0AC2684E7691A7 ] disk            C:\WINDOWS\system32\drivers\disk.sys
23:44:21.0740 0x1f2c  disk - ok
23:44:21.0756 0x1f2c  [ 6CF67B5720DFBF28BCDDC37307369A74, C3347722FBB65F303A889B71E5B3453388C5076194B5A58962940021B05BCB28 ] DM9USB          C:\WINDOWS\System32\drivers\dm9usb.sys
23:44:21.0874 0x1f2c  DM9USB - ok
23:44:21.0923 0x1f2c  [ 53757B27986CDC970725FAE35F45CA11, 3B332C2FBD502BAD959DDD65C86FEAFA78DFDDF6405F130F2F26A8AF9424E21B ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll
23:44:22.0077 0x1f2c  DmEnrollmentSvc - ok
23:44:22.0096 0x1f2c  [ 815F45161A4571C2C44491564F3D5968, 32E7AE8414A178CE429C0CDFCF718E3C11C705FB3155EA5CA0EAD48AAE507B01 ] dmvsc          C:\WINDOWS\System32\drivers\dmvsc.sys
23:44:22.0165 0x1f2c  dmvsc - ok
23:44:22.0188 0x1f2c  [ 6E5EE6E420FECD64DE463C5F01CBFE71, F173C56895E80AA03D70CD78B3AB659C2EEAACFF43BE3B6EF3939D6F4AD4F62D ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll
23:44:22.0289 0x1f2c  dmwappushservice - ok
23:44:22.0327 0x1f2c  [ 7F8A3ABF7750326E18CE953CCE262670, 5DBD159E8A455A42764FC73CF7DCAC849B5896848C5589B00BD36697804C0A3B ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
23:44:22.0421 0x1f2c  Dnscache - ok
23:44:22.0470 0x1f2c  [ 8F46B4C3F9BA19C26A26D0A11137B20B, BA0A66DBA98D77FD85A7CD2D4593F2B2A1A3B4D32BBECBCFFBEB5A54DCB0D8ED ] dot3svc        C:\WINDOWS\System32\dot3svc.dll
23:44:22.0582 0x1f2c  dot3svc - ok
23:44:22.0615 0x1f2c  [ AB798F6DF51BCCB31E1E42E5F77ACB4F, 656E2AC9E6FAA2F5AC306D4A0AAC05010C21459AA4F06B9C494174A1730B4D64 ] dowidoly        C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\jnsf589C.tmp
23:44:22.0790 0x1f2c  dowidoly - detected UnsignedFile.Multi.Generic ( 1 )
23:44:22.0936 0x1f2c  dowidoly ( UnsignedFile.Multi.Generic ) - warning
23:44:23.0144 0x1f2c  [ CA09EAEE92C6FDDC6B05057F11A0372D, 14DB5C186B69644AA93C445BF31CC9670204F95A47B77B6EACB19B4A316378AD ] DPS            C:\WINDOWS\system32\dps.dll
23:44:23.0227 0x1f2c  DPS - ok
23:44:23.0247 0x1f2c  [ E87CD3E4F9AC0A2C181990CB781DD4BA, 693F30DF8D4AE732BBB36D250D89DEC05C291B0A0998CBE87677E4F019253432 ] DptfDevPch      C:\WINDOWS\system32\DRIVERS\DptfDevPch.sys
23:44:23.0291 0x1f2c  DptfDevPch - ok
23:44:23.0322 0x1f2c  [ 1C3C798B4150F7A047853838EBE2A95B, 8A44147DAB1FCBD5F23B5D427D12D0D5CA4A8260216ECE155CD849D09328069A ] DptfDevProc    C:\WINDOWS\system32\DRIVERS\DptfDevProc.sys
23:44:23.0379 0x1f2c  DptfDevProc - ok
23:44:23.0422 0x1f2c  [ 133C04EDB13A8A7740FFA3D7DD397C80, 56A28AF194354A6AA48A9204F13C845A4B3FE4E3139BBDE31DDDE318F3FB20C9 ] DptfManager    C:\WINDOWS\system32\DRIVERS\DptfManager.sys
23:44:23.0488 0x1f2c  DptfManager - ok
23:44:23.0507 0x1f2c  [ 8A18176B5108C2FBB23ADA9D548BDD3A, 204E39EE27B6FEDB75E97950B1608DEB0641248857FF0FDD2B66168929967043 ] DptfParticipantProcessorService C:\WINDOWS\system32\DptfParticipantProcessorService.exe
23:44:23.0541 0x1f2c  DptfParticipantProcessorService - ok
23:44:23.0558 0x1f2c  [ 82239362B0C3CDA6C2E69EAB73FA8A97, 73ADB64C365E5C1F2DF92B91982E65577ADC58DE84ECF0399F0C1C380602E630 ] DptfPolicyConfigTDPService C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe
23:44:23.0598 0x1f2c  DptfPolicyConfigTDPService - ok
23:44:23.0616 0x1f2c  [ FAFA22CD7FD7B0A195239E738F7B7030, 9DF3810F814ACD4A694F25482E57ADEA01F1072CEAA4AC14ED5D383A4D2DE385 ] DptfPolicyCriticalService C:\WINDOWS\system32\DptfPolicyCriticalService.exe
23:44:23.0653 0x1f2c  DptfPolicyCriticalService - ok
23:44:23.0670 0x1f2c  [ 06B40DF90D494E2242C63DCACB354B8E, A10EB3EF74EDA33CF710B74E52D97A2B3B7874F3C5212016ED1FB89F8070D6A9 ] DptfPolicyLpmService C:\WINDOWS\system32\DptfPolicyLpmService.exe
23:44:23.0706 0x1f2c  DptfPolicyLpmService - ok
23:44:23.0721 0x1f2c  [ 4DD17AA07FA0A75E79B47E5B7F18964D, 157983BEAD4C8F7218E46392F8672E7052C8E81CF842A9E82DAA8AE8CC4020C9 ] dptf_cpu        C:\WINDOWS\System32\drivers\dptf_cpu.sys
23:44:23.0826 0x1f2c  dptf_cpu - ok
23:44:23.0841 0x1f2c  [ 285C138043A4DE3A5E11FCE19FD75914, DB64D8A97BFE1D381920C739A4E90392823AF88609C59F5226EFAF5BEB5CC5A5 ] dptf_pch        C:\WINDOWS\System32\drivers\dptf_pch.sys
23:44:23.0946 0x1f2c  dptf_pch - ok
23:44:23.0958 0x1f2c  [ AE6BD4C879A8C849E53947C92DF3B3A0, 8C29774CB2D30D901C54AAC0C8ACE709351EE40E5C8FB9951B2A18B4A03F28B7 ] drmkaud        C:\WINDOWS\system32\DRIVERS\drmkaud.sys
23:44:23.0994 0x1f2c  drmkaud - ok
23:44:24.0014 0x1f2c  [ 7433474BE77F065D2FA628671FE31A3E, 063ADDC68F48036749E6EC7B2F66284DB29F90F62E9468D16B4EF5A0FDC45E35 ] DsmSvc          C:\WINDOWS\System32\DeviceSetupManager.dll
23:44:24.0084 0x1f2c  DsmSvc - ok
23:44:24.0101 0x1f2c  [ 5FCA45C24501DA7390065D3706A9FC3F, 093FD840F1502ECC6F05B9723CA523B3F15CF39A5D2B9106E1267739B3F2C52C ] DsSvc          C:\WINDOWS\System32\DsSvc.dll
23:44:24.0167 0x1f2c  DsSvc - ok
23:44:24.0278 0x1f2c  [ A90C76FB62526DEB5A5557A8839841AB, 939BDA8A4F73E834A319D45C97B0892B0A44886A9191BA20D1121622BAE413FA ] DXGKrnl        C:\WINDOWS\System32\drivers\dxgkrnl.sys
23:44:24.0472 0x1f2c  DXGKrnl - ok
23:44:24.0495 0x1f2c  [ 9FCE4EF7D5E274F862D9A2526B5F4779, 81D42D5475C2801C8E0C233A0BA827569D8A70590017C91C665C8B232D9BFAA9 ] EapHost        C:\WINDOWS\System32\eapsvc.dll
23:44:24.0572 0x1f2c  EapHost - ok
23:44:24.0720 0x1f2c  [ 7EC6FC0266D74BD47ABB130A328B70EC, 3856790AF967AB03B1A89F97328DC4D5A6854ACDA6169681A9AFB03D7CF791F9 ] ebdrv          C:\WINDOWS\system32\drivers\evbda.sys
23:44:24.0975 0x1f2c  ebdrv - ok
23:44:24.0993 0x1f2c  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] EFS            C:\WINDOWS\System32\lsass.exe
23:44:25.0028 0x1f2c  EFS - ok
23:44:25.0040 0x1f2c  [ 8D74B8B5D6F7C5BC4C525BAF2B083FF1, DA5656F745B3911F96871887FDFDC40F4D9C820622A0AA27EFE4BA93662833CA ] EhStorClass    C:\WINDOWS\system32\drivers\EhStorClass.sys
23:44:25.0073 0x1f2c  EhStorClass - ok
23:44:25.0086 0x1f2c  [ 4D49B99DCACA1FC782A94DB596246504, 878B27A128093640830AB4C78973E1D896CF3AA918FA24FAB1029F0C9D1CB98B ] EhStorTcgDrv    C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
23:44:25.0122 0x1f2c  EhStorTcgDrv - ok
23:44:25.0137 0x1f2c  [ 80A7999DE02CE678B865832E1CE78CD6, 2576EBB6E4D630A906DE724F125099E52A962B5B68B9F9BCA849A7B29D8C8689 ] embeddedmode    C:\WINDOWS\System32\embeddedmodesvc.dll
23:44:25.0196 0x1f2c  embeddedmode - ok
23:44:25.0215 0x1f2c  [ B4264DEF962801CDB83C008DE30758D1, 57886688102BE727450BA45932044A5A389B5822A0C1C08C2AFFBA380F70C3F3 ] EntAppSvc      C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
23:44:25.0304 0x1f2c  EntAppSvc - ok
23:44:25.0322 0x1f2c  [ D315FF43E23DF424ECEC2F6C930203E4, 68940EDA34DC4945CDD0D8018D96A0DA8F99F16A930946D14E4FECEE033FCB80 ] EpsonScanSvc    C:\WINDOWS\system32\EscSvc64.exe
23:44:25.0348 0x1f2c  EpsonScanSvc - ok
23:44:25.0356 0x1f2c  [ 77B60DEC7DCB4233E4A69D3F52E5DB24, 3A5C905E37A93899051497C90E5BA8E1D003B56C6906CADFD2F1CDF52052D248 ] ErrDev          C:\WINDOWS\System32\drivers\errdev.sys
23:44:25.0398 0x1f2c  ErrDev - ok
23:44:25.0415 0x1f2c  [ B5BB7C38E9EEC3FB462861E8E9ED1912, 0EC736EF2CE9D34581FB7BDE6C185EC03B763F5088142E458D07CC602ED9CB2B ] ETDSMBus        C:\WINDOWS\System32\drivers\ETDSMBus.sys
23:44:25.0470 0x1f2c  ETDSMBus - ok
23:44:25.0504 0x1f2c  [ F89083AB8B9F51C0031C1CBD0A9A7E35, 9EE973A25134960E62D1A6A1E34AD9B3F7690E71C1AD31A23FA2081A73438754 ] EventSystem    C:\WINDOWS\system32\es.dll
23:44:25.0570 0x1f2c  EventSystem - ok
23:44:25.0604 0x1f2c  [ 27E9D2103887F6D52367F5D07352B07A, 75D5EF634FF5BE68408C01B7DB28904B1AE7D6DBEBB5C5396F79CB46348CC3C4 ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
23:44:25.0655 0x1f2c  EvtEng - ok
23:44:25.0676 0x1f2c  [ FCD2C63754C2E739A8EEAD9BC63F9DDC, C57A72ABA4C0BD71F914B9C8FF965DCFF585A205498F19A4584A4BAF7674839D ] exfat          C:\WINDOWS\system32\drivers\exfat.sys
23:44:25.0734 0x1f2c  exfat - ok
23:44:25.0755 0x1f2c  [ C077AA74EDDAF69985EB27597BCB342A, 8CE48D37E39A6DFA3C8E959CA92A49029100446DC40044EE009D55FB9CDE378A ] fastfat        C:\WINDOWS\system32\drivers\fastfat.sys
23:44:25.0792 0x1f2c  fastfat - ok
23:44:25.0813 0x1f2c  [ 77CE56471AF984800F318F3734D768C7, 72D540072374A56C2C497F0532A50705D3F0637F2C0C96B1D715F2EDFCA3AA2D ] Fax            C:\WINDOWS\system32\fxssvc.exe
23:44:25.0863 0x1f2c  Fax - ok
23:44:25.0870 0x1f2c  [ 99598ECA5E41996E005D5B9D9FF1EFA2, 91345CD50EF02431B69093505C1C5F5DC6A1AA6BF192EE9392ED4D5626B60462 ] fdc            C:\WINDOWS\System32\drivers\fdc.sys
23:44:25.0893 0x1f2c  fdc - ok
23:44:25.0898 0x1f2c  [ EF0DD43A4CBAB367BCA1AFBDC9971E4F, 73E161C45D63FDDE71EE2438137913724DC513860539D1E7F6BD861F5D1B33F3 ] fdPHost        C:\WINDOWS\system32\fdPHost.dll
23:44:25.0924 0x1f2c  fdPHost - ok
23:44:25.0930 0x1f2c  [ 34DAC585994CD3B4E910DE11C584EF3D, A6C6A4CB5413EA61F1A54E2D3AD71A311CEA2C26218544D2D2D4A5CFEC52DE8C ] FDResPub        C:\WINDOWS\system32\fdrespub.dll
23:44:25.0956 0x1f2c  FDResPub - ok
23:44:25.0964 0x1f2c  [ B68DA1FE3CA2311AFD38DD6905CA7F71, 4B395DFB1B47D2507CA4D9DC996A70D0A3BDB1A245CD6DA6C42B2A299AFCCF37 ] fhsvc          C:\WINDOWS\system32\fhsvc.dll
23:44:25.0995 0x1f2c  fhsvc - ok
23:44:26.0002 0x1f2c  [ F44F666B0EACC3181544FFCF8CA0FFC7, 83F771CF9DAE1C504B30731EEC55355EA1253174252DA2192ADF1D228B3735C3 ] FileCrypt      C:\WINDOWS\system32\drivers\filecrypt.sys
23:44:26.0027 0x1f2c  FileCrypt - ok
23:44:26.0034 0x1f2c  [ 78A210DDFDF2C9EC884631D2DAA573F0, 5D39C6EF4AC690A9749EEDBE2478FFF15A22877A2861EDA103C7BF1607B0C1BD ] FileInfo        C:\WINDOWS\system32\drivers\fileinfo.sys
23:44:26.0053 0x1f2c  FileInfo - ok
23:44:26.0059 0x1f2c  [ 1A97DB5E701A186989F3795223C3BE39, F7982220D4DF7E104955E63CACE352394E2577DEF49506EA126127F820EB62DF ] Filetrace      C:\WINDOWS\system32\drivers\filetrace.sys
23:44:26.0087 0x1f2c  Filetrace - ok
23:44:26.0093 0x1f2c  [ 46626665F0E5906E45619B4EFD6186B8, 37FDD3B8AD49FD29E54DA5567EA77F28A53498AE56348F7A2628E5E5549D638B ] flpydisk        C:\WINDOWS\System32\drivers\flpydisk.sys
23:44:26.0115 0x1f2c  flpydisk - ok
23:44:26.0130 0x1f2c  [ FDA72ACA14D516D18C33AFCD0FD9260F, 6509612DEC82EA74614B5C9A7B432305A1A468C97B88BED9E141DF2929B621B1 ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
23:44:26.0159 0x1f2c  FltMgr - ok
23:44:26.0169 0x1f2c  [ 7F8A3219F3110ACF8B67CFAB09433F9C, 0DA9DC021847D512F5829487BFC3820A91C5DD9C32624CC0ACF12735E35A8D34 ] FLxHCIv        C:\WINDOWS\System32\Drivers\FLxHCIv.sys
23:44:26.0205 0x1f2c  FLxHCIv - ok
23:44:26.0256 0x1f2c  [ 289EFA0470B308F01BAF955DE81E0682, F88081AD427BD90B3085A07439D1BDBB4966A898D49B0ABEFF7829D68BE532A5 ] FontCache      C:\WINDOWS\system32\FntCache.dll
23:44:26.0361 0x1f2c  FontCache - ok
23:44:26.0369 0x1f2c  [ 59241194DBDF30A2B4029E402F377900, 47A92E9CD8494C403B377799D395670A393766647E24CD83B15338CE2AA50266 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
23:44:26.0382 0x1f2c  FontCache3.0.0.0 - ok
23:44:26.0407 0x1f2c  [ B6848AE7BF5BD5182075D948DF7588DC, 0245D35CA48451D0743347338EE2E8E8AB6C6FD8ABE0B91E7FE2830714D30BE0 ] FrameServer    C:\WINDOWS\system32\FrameServer.dll
23:44:26.0464 0x1f2c  FrameServer - ok
23:44:26.0472 0x1f2c  [ D152CCBFC8251670BF0AAFE00D6BC782, 9DE82D8FC4E1DAF8FF23EE08C0B7CB5051A9224E64544D262CFA4996A41B04E1 ] FsDepends      C:\WINDOWS\system32\drivers\FsDepends.sys
23:44:26.0491 0x1f2c  FsDepends - ok
23:44:26.0496 0x1f2c  [ 6D6BB5C7363CD35FA715E826F3D029EE, C214F791EB39E8B25CE57ED9D6C1D56EE1AF6021BCB380980BD42A6338A6C9F7 ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:44:26.0513 0x1f2c  Fs_Rec - ok
23:44:26.0534 0x1f2c  [ B719EAA1EC93586955B013BD7DD61356, 0D0D94CF33322EEC0AD08835D0314E578F9687F361CD436A2073A4D2C0D56C86 ] fvevol          C:\WINDOWS\system32\DRIVERS\fvevol.sys
23:44:26.0573 0x1f2c  fvevol - ok
23:44:26.0580 0x1f2c  [ EF78034773CE506323655A868C949144, DF195BEEE6704FBCC6D2D9E1BF6723E52ED502A1459F495B7D18481E6A79B5BC ] gencounter      C:\WINDOWS\System32\drivers\vmgencounter.sys
23:44:26.0601 0x1f2c  gencounter - ok
23:44:26.0606 0x1f2c  [ B55FEBC6A00DAA1FE074F020B6907516, 67071FBAC2ABA47AB71358A5F08E92E034A55343878F00137E90B3B1F7362976 ] genericusbfn    C:\WINDOWS\System32\drivers\genericusbfn.sys
23:44:26.0627 0x1f2c  genericusbfn - ok
23:44:26.0636 0x1f2c  [ DDD8A8CDDC7F13EF57D1DAAE71865936, 9D472A8689F72F24D40D5B94849690F53C67849FDF6162A94EF4FB330A3DA566 ] GPIOClx0101    C:\WINDOWS\system32\Drivers\msgpioclx.sys
23:44:26.0659 0x1f2c  GPIOClx0101 - ok
23:44:26.0694 0x1f2c  [ C9316C91895057669386E620C89580E5, 5C7BF2C890E77AE3D401BB1F9F76B42D8A0ECD98118F17929FCD4097C768D90A ] gpsvc          C:\WINDOWS\System32\gpsvc.dll
23:44:26.0771 0x1f2c  gpsvc - ok
23:44:26.0777 0x1f2c  [ 7ACD8F69B5D6EC97E6D2C006E19BED88, FC69214C9308EA64B88EF4C3C95800586DDBB44C8540846B79A161BAD8203B6E ] GpuEnergyDrv    C:\WINDOWS\system32\drivers\gpuenergydrv.sys
23:44:26.0787 0x1f2c  GpuEnergyDrv - ok
23:44:26.0787 0x1f2c  [ E1B44A75947137F4143308D566889837, EC7E883E7AF38BF3AC0AC513CFDE0186038443E9ACC7AD616EE6BD0EC09AACB9 ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:44:26.0803 0x1f2c  gupdate - ok
23:44:26.0803 0x1f2c  [ E1B44A75947137F4143308D566889837, EC7E883E7AF38BF3AC0AC513CFDE0186038443E9ACC7AD616EE6BD0EC09AACB9 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:44:26.0819 0x1f2c  gupdatem - ok
23:44:26.0834 0x1f2c  [ 10E3515FE5DBA6656FA62C29342EC4A1, 2051F10F74ED712B1766EB61E87FADE25AB3D0970BABFD320600D1B0D6377F26 ] HDAudBus        C:\WINDOWS\System32\drivers\HDAudBus.sys
23:44:26.0866 0x1f2c  HDAudBus - ok
23:44:26.0866 0x1f2c  [ B90D284B97CD4CA9DE7430AAAD887A56, 2F14F985C39B7801ED64590979CF2114924E9547F5B11D2B37A74DBFFDD9E7C5 ] HidBatt        C:\WINDOWS\System32\drivers\HidBatt.sys
23:44:26.0888 0x1f2c  HidBatt - ok
23:44:26.0903 0x1f2c  [ B2FE11643CC6ACDEE6C247DD36018FDB, 5796613C7DBF8B2A9E860E006FF1A245B6BE7D10E3F6685AD142B48E5C237B8C ] HidBth          C:\WINDOWS\System32\drivers\hidbth.sys
23:44:26.0919 0x1f2c  HidBth - ok
23:44:26.0919 0x1f2c  [ D24355488A2D4D2323518EC1AC7A6D9E, ED2176A2093726087EDDA25B86E9CDD4BA35F4E748E3A6DE0B15C4C97646B5C7 ] hidi2c          C:\WINDOWS\System32\drivers\hidi2c.sys
23:44:26.0935 0x1f2c  hidi2c - ok
23:44:26.0950 0x1f2c  [ 0AF9ABBA4F3F55C6C803890D64BC3C29, D3DE6FA308F8E7CD4F16387F46AE4B2F7EC9BBA07BF87652B660A0D645710571 ] hidinterrupt    C:\WINDOWS\System32\drivers\hidinterrupt.sys
23:44:26.0966 0x1f2c  hidinterrupt - ok
23:44:26.0966 0x1f2c  [ CDBCF8E9AB06D88A1E1191D32F320C5D, F76963AB7CF2BAB3A220013879AECD3976BFD851CFB66B5A69A9EA2541048861 ] HidIr          C:\WINDOWS\System32\drivers\hidir.sys
23:44:26.0988 0x1f2c  HidIr - ok
23:44:26.0988 0x1f2c  [ C900FE0DD6A1E2220084B8F1C427790C, 802194EBEDA1A50EDA300078B0888AAC1F17A42E67147B7B3B9C50AD8D4E5C89 ] hidserv        C:\WINDOWS\system32\hidserv.dll
23:44:27.0004 0x1f2c  hidserv - ok
23:44:27.0019 0x1f2c  [ 2B7002EEACFC2687788A34ADB204293D, 040B5FC43459E80AD56CEBB26EC7676F449310537ADCD3272C2064241E328834 ] HidUsb          C:\WINDOWS\System32\drivers\hidusb.sys
23:44:27.0035 0x1f2c  HidUsb - ok
23:44:27.0050 0x1f2c  [ 44D54C8356588525D7AD0FDCFDDA0811, 46963ADBF14FA8A9B0E6564106ADEA49BBD4EBD9E43DF389CCD31F9B9BD080D9 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
23:44:27.0084 0x1f2c  HomeGroupListener - ok
23:44:27.0088 0x1f2c  [ 86161A89F16851728802590EC7C92608, 3A3B05BB4E115410D27063B30C0EF3F18295F542050F329F1E466C81A9E23A46 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
23:44:27.0135 0x1f2c  HomeGroupProvider - ok
23:44:27.0135 0x1f2c  [ F5CA18197B4646E04DB9EB2D6642CC4D, 5BA3342DDF1BCB67E4156169FE9A33E7BC2641C729E9F1A80C0E80953C6AB114 ] HpSAMD          C:\WINDOWS\system32\drivers\HpSAMD.sys
23:44:27.0151 0x1f2c  HpSAMD - ok
23:44:27.0166 0x1f2c  [ 83198A09E62B7DEBDA394F5D1516D74C, CBF8E4EC18048FD4308FF23A7C7DE3FCAFFCD777105DFC468B8D2C1B205431BE ] HpSvc          C:\Program Files (x86)\LuDaShi\lpi\HpSvc.dll
23:44:27.0184 0x1f2c  HpSvc - ok
23:44:27.0204 0x1f2c  [ 65E358D604267CBAACB74A2598BBE22B, A645E48641D638A58789B7948FC3DD5072179C0919B546A6DB08094FA9321A30 ] HTTP            C:\WINDOWS\system32\drivers\HTTP.sys
23:44:27.0251 0x1f2c  HTTP - ok
23:44:27.0267 0x1f2c  [ 0C84C250F80EAEC2C9768464CC1A9626, 212E1003B78F9B98FEB084FD1FDB59B26A9DE4C9120F24D4361FBBF0F3C035E7 ] HvHost          C:\WINDOWS\System32\hvhostsvc.dll
23:44:27.0289 0x1f2c  HvHost - ok
23:44:27.0289 0x1f2c  [ 3756E15BB86689412775DF22A442FC46, AD9DF5B542B30C89F9904CB574E75BD2D18A31F67032F0E2453290E912FC5DE3 ] hvservice      C:\WINDOWS\system32\drivers\hvservice.sys
23:44:27.0304 0x1f2c  hvservice - ok
23:44:27.0336 0x1f2c  [ EF558A02D734A1403583E95CCEEC2487, F0D052DAF48A62E4A90D067BFCB5EE9563804DE68D0EA82E0E11C8D16AD19D29 ] HWiNFO32        C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS
23:44:27.0336 0x1f2c  HWiNFO32 - ok
23:44:27.0351 0x1f2c  [ 771EDDA9830A3079F996F34D681FB6E5, F452AD656872A1C8B2D6DCE232CE01EBD456C46F4934A7601E78470F2A2CBF38 ] hwpolicy        C:\WINDOWS\system32\drivers\hwpolicy.sys
23:44:27.0367 0x1f2c  hwpolicy - ok
23:44:27.0367 0x1f2c  [ 3B9F315E7FA72CC25228EB097DD9C694, B26F1E494428EF197A0C97645C05BB3CA093827A005D35C987F1D6778BC4E52C ] hyperkbd        C:\WINDOWS\System32\drivers\hyperkbd.sys
23:44:27.0389 0x1f2c  hyperkbd - ok
23:44:27.0389 0x1f2c  [ B54B30992620C97230013A74461C8517, CAF09BDCDD6DE2A39CB8AE2C65E6F8FE12D8E93D84BBEF6C6A98F872BF54A4E3 ] i8042prt        C:\WINDOWS\System32\drivers\i8042prt.sys
23:44:27.0420 0x1f2c  i8042prt - ok
23:44:27.0420 0x1f2c  [ C6B8743B213F06AA60943D8366FE968F, 758954F70B810063914B243115B2C753B2BCE40190F95C30ACBA0BF04EBD5B33 ] iagpio          C:\WINDOWS\System32\drivers\iagpio.sys
23:44:27.0436 0x1f2c  iagpio - ok
23:44:27.0451 0x1f2c  [ 9A2A2F3C69B9A30B6E78536F6D258BAD, 5E28E132A7300E6F5E0C6439D6BA00F1AEF66D729FF671FDA91274A25A921463 ] iai2c          C:\WINDOWS\System32\drivers\iai2c.sys
23:44:27.0485 0x1f2c  iai2c - ok
23:44:27.0489 0x1f2c  [ 5A0E850F8CD17791A3E6A3CF81D0CA28, 10A965A49D53360DD250E0758B6BB142872298A21C732EB026ACB93492C5C6CF ] iaLPSS2i_GPIO2  C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys
23:44:27.0505 0x1f2c  iaLPSS2i_GPIO2 - ok
23:44:27.0520 0x1f2c  [ 7508F1096803385D6376BFD0BD473AC4, 1F32EC23CDC94DCB9710E6663B5C3BD83568545DDC2C741CFC13550A4E4DD2BE ] iaLPSS2i_I2C    C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys
23:44:27.0536 0x1f2c  iaLPSS2i_I2C - ok
23:44:27.0552 0x1f2c  [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO    C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
23:44:27.0552 0x1f2c  iaLPSSi_GPIO - ok
23:44:27.0567 0x1f2c  [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C    C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
23:44:27.0589 0x1f2c  iaLPSSi_I2C - ok
23:44:27.0621 0x1f2c  [ 0609694A9C4D6C71319732FA82C6E5C5, 5507D20AB9C86B11564C953C6F535976A0D201295C642EA0CABF435DAD908251 ] iaStorA        C:\WINDOWS\system32\drivers\iaStorA.sys
23:44:27.0668 0x1f2c  iaStorA - ok
23:44:27.0705 0x1f2c  [ 97E553D03219D3D51705C7235D9EAEBD, 5D4578C8804AF32D1DC0868E34D6538138DC15F9568CA7E21051B1C82C0D8D55 ] iaStorAV        C:\WINDOWS\system32\drivers\iaStorAV.sys
23:44:27.0737 0x1f2c  iaStorAV - ok
23:44:27.0752 0x1f2c  [ 20E83F4632E15A5E9E716FF2E8AC7FAE, 7CA1A4924F432AD30ED7FA6247C6513DA173EE31132AE115E85C0ED7E5971029 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
23:44:27.0752 0x1f2c  IAStorDataMgrSvc - ok
23:44:27.0768 0x1f2c  [ 8350FE3BCDE3428BC040877BB7E9EAEB, 77F9456351CA640C6B7862907C0580627E761EC807B551976A95657EB4D6CC20 ] iaStorV        C:\WINDOWS\system32\drivers\iaStorV.sys
23:44:27.0790 0x1f2c  iaStorV - ok
23:44:27.0806 0x1f2c  [ 3BA03F7C7700DDF4C383DDE9252F5817, 3E90F69D0010E7764349D9AE865D577E431FEBC67DA554B400BC808DD286E203 ] ibbus          C:\WINDOWS\System32\drivers\ibbus.sys
23:44:27.0853 0x1f2c  ibbus - ok
23:44:27.0853 0x1f2c  ibtsiva - ok
23:44:27.0868 0x1f2c  [ 445E2B8B742D430CDD979FF8551B97BA, C9DA1B2FAD3875ECAF6360D844204266C986F917B5272699BE00A1D5F99839EB ] ibtusb          C:\WINDOWS\system32\DRIVERS\ibtusb.sys
23:44:27.0890 0x1f2c  ibtusb - ok
23:44:27.0890 0x1f2c  [ 937AC47F7356554DA05D9722C356EB55, 9EABC9F19B4E1193B669D2674967F5C6F03FAD348EDF0615E3F78554FF9A83CC ] icssvc          C:\WINDOWS\System32\tetheringservice.dll
23:44:27.0921 0x1f2c  icssvc - ok
23:44:28.0106 0x1f2c  [ D12E20EA9F42FACE950E05FE4700A4B7, 2D78B042274A6DA5A44B3B23FB17D590858E352712962A7B90C476664BB5A221 ] igfx            C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
23:44:28.0354 0x1f2c  igfx - ok
23:44:28.0369 0x1f2c  [ AB747396F38F96A7A182FA8A9E95D0DA, 461431FD5197878E0BEC94BB7EB1D5A31CE9FE8A80357AEED110064E881C8CBE ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
23:44:28.0407 0x1f2c  igfxCUIService2.0.0.0 - ok
23:44:28.0423 0x1f2c  [ E71AC94964ED675B3ED0727059B7F97B, 5468B5E9B75B10EA0BFBD81827FFC9CABFC69A4065CC5A5792DBC289D4DA27EE ] ikbevent        C:\WINDOWS\system32\DRIVERS\ikbevent.sys
23:44:28.0438 0x1f2c  ikbevent - ok
23:44:28.0470 0x1f2c  [ F2934208C0E50C0B971A7981AB90BED2, B936BFBBD71E731CC2CDB8B47D262F2EF09726FF921C2DA0841910CA2401423D ] IKEEXT          C:\WINDOWS\System32\ikeext.dll
23:44:28.0523 0x1f2c  IKEEXT - ok
23:44:28.0523 0x1f2c  [ D073054784FBD418735BECF4588C14D7, DFA1D42063EAF3107B9BFD67F0BB3E83F5CFCFDD7825BC8C367C3D008E5465FD ] ImControllerService C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
23:44:28.0586 0x1f2c  ImControllerService - ok
23:44:28.0592 0x1f2c  [ 2FDB67F5B9F4E96B40FDC9D1AA0B686F, B556328D54F886792A89588F3FEFE38F7129E3D7A417CDC012778FA4EF37A8C1 ] imsevent        C:\WINDOWS\system32\DRIVERS\imsevent.sys
23:44:28.0608 0x1f2c  imsevent - ok
23:44:28.0608 0x1f2c  [ 2A01C96DF5802D3434634E55C91232D8, A3ABEF36E2FD2CF5C371ADBF92566A09669A1D990ABE4677370F57F2EEAF8121 ] IndirectKmd    C:\WINDOWS\System32\drivers\IndirectKmd.sys
23:44:28.0623 0x1f2c  IndirectKmd - ok
23:44:28.0639 0x1f2c  [ F0F581A2299CB2BAB1DF2597BCDDB80F, EE485AF3049C87666BC6D6BFFC8A0EB4B95831D9061EB81848ECEE29C4232BF4 ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
23:44:28.0654 0x1f2c  intaud_WaveExtensible - ok
23:44:28.0739 0x1f2c  [ 4C60B08DFC8E2543075FF13C9E68DD55, C8314F957102DD843763C9CC9A2356AB390FC79E4E636CC43AC80BA6431D2F76 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
23:44:28.0870 0x1f2c  IntcAzAudAddService - ok
23:44:28.0901 0x1f2c  [ E300D1E37B737ED14F7A08CD5604E5D9, 5C1135081E29D7F4A97D5CAA2C8FBE1DD04EC7A3D8E648E69F2AA9EBDD88EBBB ] IntcDAud        C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
23:44:28.0930 0x1f2c  IntcDAud - ok
23:44:28.0963 0x1f2c  [ 0DB1E3F6189C628675F855C0EB510419, 989F539E82105019D2D81255369B96DC65826CD2A421DA09809155B26F69C555 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
23:44:30.0292 0x1f2c  Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
23:44:30.0469 0x1f2c  Detect skipped due to KSN trusted
23:44:30.0470 0x1f2c  Intel(R) Capability Licensing Service Interface - ok
23:44:30.0506 0x1f2c  [ 492AAF2FF66F437F0E796574B116EFC3, 6BF21C61ED05705DD58203952A750D1AB4D4B62F3A2B640BBBD9B85D1ECC3E5C ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
23:44:32.0097 0x1f2c  Intel(R) Capability Licensing Service TCP IP Interface - ok
23:44:32.0105 0x1f2c  [ 9F7E87F6595D065A8A200A291043045E, 6944F72F73EADC6C9B7691F2C1C6DF1898F22C88EFA78EC0BA8CB5FFD9CE057B ] intelide        C:\WINDOWS\system32\drivers\intelide.sys
23:44:32.0122 0x1f2c  intelide - ok
23:44:32.0129 0x1f2c  [ A6BD2E20AE1BC5CB2776C87C28E4F4CA, BD8BE67CED9A4982D785CE9ECBEFE868C3A2E37DF7F9592B9F9049B807A1554B ] intelpep        C:\WINDOWS\system32\drivers\intelpep.sys
23:44:32.0147 0x1f2c  intelpep - ok
23:44:32.0156 0x1f2c  [ 2A48DA39542636DB0FA3BA915385D1B3, 6CA0916F5F4B1E81AE6A6233276320599BFA7C129267177703E3BB6468FB4683 ] intelppm        C:\WINDOWS\System32\drivers\intelppm.sys
23:44:32.0185 0x1f2c  intelppm - ok


Piristibulus 16.08.2016 22:59

Teil 2:
Code:

23:44:32.0194 0x1f2c  [ 4A922CAB4AB5F29F1BECC9D95B4B7F05, 7C1006799E26A0B4DF49373A4D0509748C602588CFB3C1CBB409E335F5DF9593 ] iorate          C:\WINDOWS\system32\drivers\iorate.sys
23:44:32.0211 0x1f2c  iorate - ok
23:44:32.0220 0x1f2c  [ FE85D0A86CA7A5A99CF8CD04DE7F80AE, 544C01FC01EE728EB5667158207E5F4418FE77A88BA318192A834722DB766F4E ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:44:32.0244 0x1f2c  IpFilterDriver - ok
23:44:32.0275 0x1f2c  [ 89548E57FD0A7BC703541C69C0286B13, 261698B302DF5B80C57FC4257E0A0AABC8DEFFED16D8CD142AD8E7CB51AF2007 ] iphlpsvc        C:\WINDOWS\System32\iphlpsvc.dll
23:44:32.0343 0x1f2c  iphlpsvc - ok
23:44:32.0353 0x1f2c  [ 450DBDD716C7911F83E05F78EE18BFA2, 43C0DA172F632131898F315A53DEDD1AE99FB0620AB32B3A5B99FEC498C9AAE5 ] IPMIDRV        C:\WINDOWS\System32\drivers\IPMIDrv.sys
23:44:32.0373 0x1f2c  IPMIDRV - ok
23:44:32.0385 0x1f2c  [ F1DAECC3B3D6399875D4F10529D6A77C, 6533D2F858816BE6570C998510919FCA2904EC6EF806F61C1FD325E88133111B ] IPNAT          C:\WINDOWS\system32\drivers\ipnat.sys
23:44:32.0418 0x1f2c  IPNAT - ok
23:44:32.0428 0x1f2c  [ 7475A2903BB704B446AA6309E34D3362, C94643A1626A9716015EBA7041A1224098501EB7DAA704CBFCAD3DC6F3CFC6AF ] irda            C:\WINDOWS\system32\drivers\irda.sys
23:44:32.0456 0x1f2c  irda - ok
23:44:32.0464 0x1f2c  [ 9725E7F0C64CE9916A5CDABE8D6E13C3, 04AF9E48FEF208A2850DF28352E8FDCBF4018982C72C0F67EE12C048C4070116 ] IRENUM          C:\WINDOWS\system32\drivers\irenum.sys
23:44:32.0488 0x1f2c  IRENUM - ok
23:44:32.0495 0x1f2c  [ 8C604213A2E73088BFFE6CD2E6F1AE53, B4C4FEE4D398A29F72EC27D5668071D7E68CD943FFFC38624DD5DF5BEBDF46D3 ] irmon          C:\WINDOWS\System32\irmon.dll
23:44:32.0520 0x1f2c  irmon - ok
23:44:32.0528 0x1f2c  [ 58040898883A96160D41739C80328BBF, 7F85C91C905811416E266A263DDEFCDCB0B45376AAE51B551AB636C16577DB9F ] isapnp          C:\WINDOWS\system32\drivers\isapnp.sys
23:44:32.0545 0x1f2c  isapnp - ok
23:44:32.0559 0x1f2c  [ C9FD02D62E09337B67B0C61EC8CA38CC, DC77E935ECC8474BE9018F0937CB11C137073582B20A0EE107CE247FD9E1F9C1 ] iScsiPrt        C:\WINDOWS\System32\drivers\msiscsi.sys
23:44:32.0585 0x1f2c  iScsiPrt - ok
23:44:32.0593 0x1f2c  [ 4EE2423C38F43D37F8497A672FD10BDC, 031C5272DD28809255CF4FA8E6DE45DBFBD9A363BBD5156D0AEE0787C4297980 ] ISCT            C:\WINDOWS\System32\drivers\ISCTD64.sys
23:44:32.0628 0x1f2c  ISCT - ok
23:44:32.0644 0x1f2c  [ 52069AEB42D3D0F97CBCA1085EBF55E6, ADB2EFFF563B3FE113FCD156FD1E469BC24FC1D68AFEDCA21306F76592C9FF88 ] jhi_service    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
23:44:32.0663 0x1f2c  jhi_service - ok
23:44:32.0669 0x1f2c  Jzidom Module - ok
23:44:32.0679 0x1f2c  [ 210808437570BDDEE71A43535E3A2D30, EF5DE6EE4FF58F44CDE4D4E7F298ABBC9086EC05CC3AE4903060DA878115AC1E ] kbdclass        C:\WINDOWS\System32\drivers\kbdclass.sys
23:44:32.0699 0x1f2c  kbdclass - ok
23:44:32.0707 0x1f2c  [ 2D05785B0C58D90A34EA15032EADBBA9, 3E1238FF7F6ECA522761830FE7EA7587B704FCB3ECE8C6BF94CC17A640B678ED ] kbdhid          C:\WINDOWS\System32\drivers\kbdhid.sys
23:44:32.0729 0x1f2c  kbdhid - ok
23:44:32.0737 0x1f2c  [ 813BA3EB2CE038F2A5382DDD75CAD60B, 99FA444027CAC247B54317730D54AB0C4C000AE076B97E47470FDA9834594312 ] kdnic          C:\WINDOWS\System32\drivers\kdnic.sys
23:44:32.0761 0x1f2c  kdnic - ok
23:44:32.0770 0x1f2c  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] KeyIso          C:\WINDOWS\system32\lsass.exe
23:44:32.0789 0x1f2c  KeyIso - ok
23:44:32.0799 0x1f2c  [ 9FA1B5D84F596F0664F0465F302044DC, 47B41D3D6119B5B20C83AF84D315C4AB40B5534D687736A8B67BD985A3B232C1 ] KSecDD          C:\WINDOWS\system32\Drivers\ksecdd.sys
23:44:32.0820 0x1f2c  KSecDD - ok
23:44:32.0832 0x1f2c  [ 3B342AD20A76FAEC4851A38774B99AB4, 5003427A1BA8AFA2273C623BCF1A9CC5D60654A346FE4A2FB43CDAD2732E8BB3 ] KSecPkg        C:\WINDOWS\system32\Drivers\ksecpkg.sys
23:44:32.0854 0x1f2c  KSecPkg - ok
23:44:32.0862 0x1f2c  [ 4ED115CD1A1099705F56B5E0FFF97CC6, 9CC49DF2CD6AAAE405BA661D13EFC1E05111D1DE3D1E50C39C425AF1F075610B ] ksthunk        C:\WINDOWS\system32\drivers\ksthunk.sys
23:44:32.0896 0x1f2c  ksthunk - ok
23:44:32.0914 0x1f2c  [ 8125BDF7ADC261F75EF0CAD92456E350, 184797AA1D58C4FF743BA60D48590B88B781EE7779205E45E0679DEC79F3E185 ] KtmRm          C:\WINDOWS\system32\msdtckrm.dll
23:44:32.0952 0x1f2c  KtmRm - ok
23:44:32.0961 0x1f2c  [ 31CBF3DB2E83C988728F792EC27F51ED, E20FF15A2D51B2015F5426952FB7E0C9FCBB4E0933B1A095A2F49845FDD16F22 ] KuaiZipDrive    C:\WINDOWS\system32\drivers\KuaiZipDrive.sys
23:44:32.0996 0x1f2c  KuaiZipDrive - ok
23:44:33.0008 0x1f2c  [ D3B57404176A89A75E1DDCE287FB670B, 364C6DD9166243D0CA47DE4D05D22CE000D2B52845D56FA0EF2C894BD34DFF87 ] KuaizipUpdateChecker C:\Program Files\؟ىر¹\X86\kuaizipUpdateChecker.dll
23:44:33.0047 0x1f2c  KuaizipUpdateChecker - ok
23:44:33.0047 0x1f2c  [ 8CCAB08815B50AD78B823DB3F96C8604, 265E6D582EB7207B5CC577D61CB7BC3646F613047F168CD69BB776C37780EBF5 ] LanmanServer    C:\WINDOWS\system32\srvsvc.dll
23:44:33.0094 0x1f2c  LanmanServer - ok
23:44:33.0111 0x1f2c  [ 752FE77F22592016A5EBBF399EC12E14, 231CF3E069FF64A4E8C81D0799A73924D864585B25382EFF8D1707F87747AC9E ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
23:44:33.0131 0x1f2c  LanmanWorkstation - ok
23:44:33.0147 0x1f2c  [ 3CDD29A1A62BBFC7F9EE31F31E322A69, 61F657041A9F537001A39745D953FC9B77EE4DDFC2F32A1C58965827840BF268 ] LDrvSvc        C:\Program Files (x86)\OSTotoSoft\DriverTalent\LDrvSvc.dll
23:44:33.0217 0x1f2c  LDrvSvc - ok
23:44:33.0237 0x1f2c  [ DA297A7BAB4E3889CFF60C02AE7BFB5D, 9E533D6FE2C9777A298F1E09C6E74F4135CC32D406382655EA9C0B7B2C533F3E ] Lenovo EasyPlus Hotspot C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe
23:44:33.0259 0x1f2c  Lenovo EasyPlus Hotspot - ok
23:44:33.0273 0x1f2c  [ 031199B929009F268A478F0283E1CE32, B7BFB848A03535C16798085D489AB294935955F2982330B39190B2074BF9122B ] LenovoWiFiHotspotSvr C:\Windows\System32\LenovoWiFiHotspotSvr.exe
23:44:33.0315 0x1f2c  LenovoWiFiHotspotSvr - ok
23:44:33.0324 0x1f2c  [ F8EBAA1FE6D3BF84752931DE1BFA0E2A, 2F3C512712BA709BBBBD779D9E792DBE324876C402CDCEF0345B8B7ABE1D232A ] lfsvc          C:\WINDOWS\System32\lfsvc.dll
23:44:33.0343 0x1f2c  lfsvc - ok
23:44:33.0351 0x1f2c  [ F2E1302599E445F3E1A305123A92A8BC, 162D5C8045463931E8465544144F11567AA0F246AEAC3828A13284C283F01633 ] LicenseManager  C:\WINDOWS\system32\LicenseManagerSvc.dll
23:44:33.0374 0x1f2c  LicenseManager - ok
23:44:33.0382 0x1f2c  [ 5933A6673F00D8255C52957E40C2D601, 0AA1281F8B3F97E360592D1B35EE7D3D614F1AB46007F9884CFFB1C5E647575E ] lltdio          C:\WINDOWS\system32\drivers\lltdio.sys
23:44:33.0405 0x1f2c  lltdio - ok
23:44:33.0418 0x1f2c  [ 88A3C935725FA6EA1A228DCC26CF9C6F, 9B1F70644EEFA1EE7CE151A8A970430087339B7A6345F2E0252370929D4AFAC6 ] lltdsvc        C:\WINDOWS\System32\lltdsvc.dll
23:44:33.0452 0x1f2c  lltdsvc - ok
23:44:33.0461 0x1f2c  [ 3F858E28AEE6545FA1B64134DFD5C2CE, FFD7B4FB0A7B61BC6B76A172134673842F2CF00E96FA3ED4A8273DC525B6BB92 ] lmhosts        C:\WINDOWS\System32\lmhsvc.dll
23:44:33.0485 0x1f2c  lmhosts - ok
23:44:33.0496 0x1f2c  [ B16F2A40E738277AB75515D4B024305E, 38F48CCD72FA2B32DFD3123C0864AB724AC673414EEE09C6F582754177CD4B98 ] LMS            C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
23:44:33.0528 0x1f2c  LMS - ok
23:44:33.0543 0x1f2c  [ 8E1B0946948CCC0BC1FA3CB70374A795, 0B894C129A35E223FF9594725AC90916CBD597FAD2211A18FC2AE03EA8679597 ] LSI_SAS        C:\WINDOWS\system32\drivers\lsi_sas.sys
23:44:33.0559 0x1f2c  LSI_SAS - ok
23:44:33.0574 0x1f2c  [ 4F68163FC04C973500DC4DA0946917B0, DF060C29109EB3978CEDFE781999B0C4C1E8C0FDB133428058D8400C53315EEC ] LSI_SAS2i      C:\WINDOWS\system32\drivers\lsi_sas2i.sys
23:44:33.0596 0x1f2c  LSI_SAS2i - ok
23:44:33.0596 0x1f2c  [ E5AC5F2815938651CDCC27F425474673, 3AF0598982153C36A766506FA088F7B84333CC96FEBB050402547AFC613AF9F7 ] LSI_SAS3i      C:\WINDOWS\system32\drivers\lsi_sas3i.sys
23:44:33.0627 0x1f2c  LSI_SAS3i - ok
23:44:33.0627 0x1f2c  [ CCF6EC9FB9B8F18E05B4253E81013E48, EBE8D77FEE8B99BD8C29702404774D554673C96DF3FDF3DCEA9C99E22C2709FC ] LSI_SSS        C:\WINDOWS\system32\drivers\lsi_sss.sys
23:44:33.0643 0x1f2c  LSI_SSS - ok
23:44:33.0674 0x1f2c  [ 5570D03E2048AC7961BEF6FFEE3A2CA5, FD0232312D87015FA0B8062FA175A44410F8C1C9778145CCDD57BA1C23929C87 ] LSM            C:\WINDOWS\System32\lsm.dll
23:44:33.0728 0x1f2c  LSM - ok
23:44:33.0728 0x1f2c  [ B9D6F27D06565CEFF51FD012B74822CB, D6526314DC2F58745969B7132722C60DB33442CB55ADAB28E7EF64EB088E32DF ] LsvUIService    C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
23:44:33.0805 0x1f2c  LsvUIService - ok
23:44:33.0817 0x1f2c  [ C9579D32219E5B936AC3A48D470117EC, E61A77191B6BA25D29B1221FEBBE826BBC11F825C0E35A72B4CEFFF8B7FE59A8 ] luafv          C:\WINDOWS\system32\drivers\luafv.sys
23:44:33.0852 0x1f2c  luafv - ok
23:44:33.0885 0x1f2c  [ 96C2218301EAE9AD23A69E0DA1E5D6EB, BA33A4635DE6E5F53E82C376446252DBB514064928B4944A5E3142EF7CC1DEC1 ] MaohaWifiNetPro C:\Program Files (x86)\GreatMaker\MaohaWiFi\MaoHaWiFiNet64.sys
23:44:33.0945 0x1f2c  MaohaWifiNetPro - ok
23:44:33.0956 0x1f2c  [ 710C517D863BDBD036B72BF94D4F8517, 39CF433D19DCDCCE082D805534F07BDA0840D8BEFC37293DC1486E86153A874D ] MaohaWifiSvr    C:\Program Files (x86)\GreatMaker\MaohaWiFi\MaohaWifiSvr.exe
23:44:34.0058 0x1f2c  MaohaWifiSvr - ok
23:44:34.0068 0x1f2c  [ 6D4111E1852A9F0BFC07BB69F3141841, 9BFF4517F26F1E9DF4DA6633B542EAA20A698B9397D2ED73134E7AEF306FBB15 ] MapsBroker      C:\WINDOWS\System32\moshost.dll
23:44:34.0095 0x1f2c  MapsBroker - ok
23:44:34.0106 0x1f2c  [ 47701ECA633574E122687693B5C5D35C, 1DB12767462347504956450FAD0D90B6E682E2E8959A6C5DF3792C3C3DA289B1 ] mbamchameleon  C:\WINDOWS\system32\drivers\mbamchameleon.sys
23:44:34.0120 0x1f2c  mbamchameleon - ok
23:44:34.0133 0x1f2c  [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy  C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
23:44:34.0150 0x1f2c  MBAMSwissArmy - ok
23:44:34.0159 0x1f2c  [ C3CDCCF07486BD2616A7B82946E07AC0, 1EF95DAB2DA856BC7D7573B2EB2D9006DF337F827F0B56A161D0C97F45DB755E ] megasas        C:\WINDOWS\system32\drivers\megasas.sys
23:44:34.0178 0x1f2c  megasas - ok
23:44:34.0200 0x1f2c  [ FADB2FE017E69EECE0E1BA78661C2E8C, BE99B49031D8B4B670B6F6B6E829E54406779CF6F1D8AFE8AB79A73E6764AB2F ] megasr          C:\WINDOWS\system32\drivers\megasr.sys
23:44:34.0238 0x1f2c  megasr - ok
23:44:34.0251 0x1f2c  [ 84178491109A97D0A0CFF0840A644CD9, B822A9F7C9623764430435DBCE1380386D0A0D9784779DDD3A7A2E59FC29AFF6 ] MEIx64          C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
23:44:34.0276 0x1f2c  MEIx64 - ok
23:44:34.0286 0x1f2c  [ 55A417C3E41F2A98666CF929EC19108E, A38C262B2863C87E4151525BF26D6AC16E7982D370E2C6998EB15C88C4BC8254 ] MessagingService C:\WINDOWS\System32\MessagingService.dll
23:44:34.0312 0x1f2c  MessagingService - ok
23:44:34.0329 0x1f2c  [ 573CE2135CA79AAB6EFB110EEB998F75, 225C81228C1261BA562DCC08C97A37754A8472A4C9A4C5BE5C19A40C15B93F62 ] mfeelamk        C:\WINDOWS\system32\drivers\mfeelamk.sys
23:44:34.0353 0x1f2c  mfeelamk - ok
23:44:34.0382 0x1f2c  [ FD60818B66B2E8A5415EA840E99A9D8F, 5D2F22909354534B821D958FBEF6A40EB4F642F53C7B509D00949096EF716F36 ] mlx4_bus        C:\WINDOWS\System32\drivers\mlx4_bus.sys
23:44:34.0436 0x1f2c  mlx4_bus - ok
23:44:34.0446 0x1f2c  [ 68F6977F1CFBAAC770D940A8C0326FA1, 90EE1E7DAC680EAA5AD50E9B0B9FD8FCE8DD6A02D5EF941B5AA5084CBD40BB80 ] MMCSS          C:\WINDOWS\system32\drivers\mmcss.sys
23:44:34.0470 0x1f2c  MMCSS - ok
23:44:34.0478 0x1f2c  [ D842ADDB5911945D51F61A0B1C8F36E3, 5EB93A1FD2D2D9FAB6121356E1AB18F2ADE9550D3033274AF7CA8F7FD51E59ED ] Modem          C:\WINDOWS\system32\drivers\modem.sys
23:44:34.0504 0x1f2c  Modem - ok
23:44:34.0513 0x1f2c  [ 9CCCB7FC3EDADEBA461D78615A6011A6, C120B58F25E8CCFD971EB78645C0682F367AD56DC15F2D8C1980CE75B04719DF ] monitor        C:\WINDOWS\System32\drivers\monitor.sys
23:44:34.0541 0x1f2c  monitor - ok
23:44:34.0550 0x1f2c  [ 27A07B2FB2E3057DA8DAEA4F25D843C7, 09D2B39E6B9AAEC879E5871DD6BCFF2AEF0B894F3B44649665A685F8B3CA6F27 ] mouclass        C:\WINDOWS\System32\drivers\mouclass.sys
23:44:34.0569 0x1f2c  mouclass - ok
23:44:34.0578 0x1f2c  [ 7BD6E7F7C9001AB21B8362CFFEE80B25, C470C3363EEF3A60409A5934988BFB9B72AE7C2BB63CC2C2D006D7EB1C797F6A ] mouhid          C:\WINDOWS\System32\drivers\mouhid.sys
23:44:34.0601 0x1f2c  mouhid - ok
23:44:34.0612 0x1f2c  [ F5BDAEE4B7D369D4C74668DCFBA3FF10, 100F39288E56AFE0D39D1CC235BDC9F3727C873CD3114E092DA7A08810BD3EB2 ] mountmgr        C:\WINDOWS\system32\drivers\mountmgr.sys
23:44:34.0632 0x1f2c  mountmgr - ok
23:44:34.0643 0x1f2c  [ C01441BA6F99890B7FF6CD0260B7750A, E02FFB1E8A3E423C9392ADAA9DF5FECF800DFAB3E09B74A029106DC337995539 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
23:44:34.0661 0x1f2c  MozillaMaintenance - ok
23:44:34.0669 0x1f2c  MPCKpt - ok
23:44:34.0685 0x1f2c  [ E5F8E0143A8B64F2ED68674909B14075, 86518EFC5E832ABF153C266C7AC52128C90A741EFD074F593EC4F4BE8DEDAE95 ] MPCProtectService C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe
23:44:34.0707 0x1f2c  MPCProtectService - ok
23:44:34.0718 0x1f2c  [ 30844BD376F9D01E62C820BEF446F1F8, 910D672EDB544A20AEB4450B4D89830F46EDD28CE0021156176315C5D068A1B4 ] mpsdrv          C:\WINDOWS\system32\drivers\mpsdrv.sys
23:44:34.0742 0x1f2c  mpsdrv - ok
23:44:34.0773 0x1f2c  [ 779CFDB17EA07A6D26FEBBAC95B65772, 74D9542E8DCCD07396A45A45D2F500AA6F9DCC1DB785A6153EB3067E42F576A4 ] MpsSvc          C:\WINDOWS\system32\mpssvc.dll
23:44:34.0840 0x1f2c  MpsSvc - ok
23:44:34.0853 0x1f2c  [ 50C2389CD04C5B8632E3DC2D733EF15D, 0F83A8A5F405BC6F401B5A75D45F6D07C61C0CA692D2A77C63E742622F5BF921 ] MRxDAV          C:\WINDOWS\system32\drivers\mrxdav.sys
23:44:34.0885 0x1f2c  MRxDAV - ok
23:44:34.0905 0x1f2c  [ C9BB4E2FCAB693FEB00CF940060D94F4, DBE5DACBAB0CF803EBBDC414FD4D2A159B9062892DE923E22E56CBCDB80F13A7 ] mrxsmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:44:34.0937 0x1f2c  mrxsmb - ok
23:44:34.0954 0x1f2c  [ 8F58AEAE00B39AC9AD93755E777B19D8, 335E4D9E9E81609BEAFA08376EE29C35DA6A1839FAFC37399B9066F03BFFFBC1 ] mrxsmb10        C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
23:44:34.0987 0x1f2c  mrxsmb10 - ok
23:44:34.0999 0x1f2c  [ 6C83C4A8278E48455DA13E554CEB45F1, 9389EF464F242861FCE8C22D2EB19E8574BF3E56C1A4FB064DE9E7480631E7F6 ] mrxsmb20        C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
23:44:35.0017 0x1f2c  mrxsmb20 - ok
23:44:35.0029 0x1f2c  [ 74C9D21523DAE0C18F413C196DF0058A, 3DB4B8CA368D9DD82FAE2C2BC828A21142C8D29780A7C8667188C447519FF702 ] MsBridge        C:\WINDOWS\system32\drivers\bridge.sys
23:44:35.0053 0x1f2c  MsBridge - ok
23:44:35.0063 0x1f2c  [ 308F08347923DEEDE7BC03EC7D485841, 72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0 ] MSDTC          C:\WINDOWS\System32\msdtc.exe
23:44:35.0091 0x1f2c  MSDTC - ok
23:44:35.0109 0x1f2c  [ F01B849D9D4A8CEAF32D4FDBD0B83C92, D2473AC4C6E6C03DEF13EA73EC78FB878BDC95C047651BF79A16C9DEA82AD046 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
23:44:35.0129 0x1f2c  Msfs - ok
23:44:35.0137 0x1f2c  [ 22ECD8F5D1DFADF2011BBB1700CB871D, 8F9EFF51137394EFA5471B8A29C541710063B65806B075B4925A84D5B6BC3BBB ] msgpiowin32    C:\WINDOWS\System32\drivers\msgpiowin32.sys
23:44:35.0155 0x1f2c  msgpiowin32 - ok
23:44:35.0163 0x1f2c  [ FD870F6968A145E4D2BA8A8842686B03, 34B8F601F3B5E42B4D0A41E2AF7DB4EB4E5B627DA8DA9A2A2D46B153AF23AEB1 ] mshidkmdf      C:\WINDOWS\System32\drivers\mshidkmdf.sys
23:44:35.0178 0x1f2c  mshidkmdf - ok
23:44:35.0185 0x1f2c  [ 30364757963A028CE5DF0FBAAC270173, C72588A6A52FF8E418A15D2C407A4DB7EA768585423720145F8253D5CA519DC2 ] mshidumdf      C:\WINDOWS\System32\drivers\mshidumdf.sys
23:44:35.0206 0x1f2c  mshidumdf - ok
23:44:35.0213 0x1f2c  [ 6BB0FEDDAE7135FA37FFAFF4D9E0E876, B41A3C0FFDFC493D6325ED493445AFCED04EC9DFF2B38125616FC5419AD1ACC4 ] msisadrv        C:\WINDOWS\system32\drivers\msisadrv.sys
23:44:35.0229 0x1f2c  msisadrv - ok
23:44:35.0240 0x1f2c  [ 07E3E54734B14F43A4A95A849C0A0DE2, 314AA02EA84D267B32DBAEBEA6C1AC1A266DED1E8D35A17B41D1D2AC75E8049E ] MSiSCSI        C:\WINDOWS\system32\iscsiexe.dll
23:44:35.0269 0x1f2c  MSiSCSI - ok
23:44:35.0276 0x1f2c  msiserver - ok
23:44:35.0285 0x1f2c  [ 13D614E6B51ECF36746C48CE829FA7F6, CAD63C0A4F7110093F84C58252C5803F14E3FC46584B79DA17EC86D49FEAEA64 ] MSKSSRV        C:\WINDOWS\system32\DRIVERS\MSKSSRV.sys
23:44:35.0312 0x1f2c  MSKSSRV - ok
23:44:35.0321 0x1f2c  [ 642CDE46351D5D2D90311E77072AB46D, B2D3033E607BA2F6E6B9CFB1CBF154CD0CE910EA473C56343EC81B9B94044CCA ] MsLldp          C:\WINDOWS\system32\drivers\mslldp.sys
23:44:35.0344 0x1f2c  MsLldp - ok
23:44:35.0351 0x1f2c  [ F2302A5CE63CA7673200FAFCEEEDB6AF, B8C44FC2DC0332183DE325CDBF511101F3307225295EDD428CE575A8DE15C223 ] MSPCLOCK        C:\WINDOWS\system32\DRIVERS\MSPCLOCK.sys
23:44:35.0381 0x1f2c  MSPCLOCK - ok
23:44:35.0388 0x1f2c  [ 6114512EA26E835BA522C63635429DB5, 0F91CE41B4555316A79AEF3047C152D538CC9C7C329987C9FD0E3D961AFC87C8 ] MSPQM          C:\WINDOWS\system32\DRIVERS\MSPQM.sys
23:44:35.0412 0x1f2c  MSPQM - ok
23:44:35.0428 0x1f2c  [ AA538E16E644D00E3BA5349BBA9598EC, 64A68B06883FE7ED34E04AB119BA819753F1222923EDD4E802C35D402B89D075 ] MsRPC          C:\WINDOWS\system32\drivers\MsRPC.sys
23:44:35.0456 0x1f2c  MsRPC - ok
23:44:35.0469 0x1f2c  [ 0543BEFD41EC4D25C7F7CF36409CEC7D, 631622CFEC49952C0470531B23FFFFF483DC0EFFEF7A97B1179A600392C05DDD ] mssmbios        C:\WINDOWS\System32\drivers\mssmbios.sys
23:44:35.0484 0x1f2c  mssmbios - ok
23:44:35.0491 0x1f2c  [ C1569E4DB8EFE3617847BF041A3C842F, 99ADE5E7F50E04CAEC737F7F90741CCA8EE628996BA5EB6C6BC62184884429B6 ] MSTEE          C:\WINDOWS\system32\DRIVERS\MSTEE.sys
23:44:35.0519 0x1f2c  MSTEE - ok
23:44:35.0526 0x1f2c  [ 130B16970154BA9876B09E5C4BAC63BE, BE3AF8FC5A26AB9C9DBA9C015C2E1FD3C4CD9CB423A2BBDABA91428BF8620553 ] MTConfig        C:\WINDOWS\System32\drivers\MTConfig.sys
23:44:35.0547 0x1f2c  MTConfig - ok
23:44:35.0557 0x1f2c  [ 15D987C8F6CCD4AC94E070C5986762CB, 452FB0C48B86C7F8F53794CC2DDBF2B900B03A0383B2DE8F6A830F8CB0AFBAD8 ] Mup            C:\WINDOWS\system32\Drivers\mup.sys
23:44:35.0574 0x1f2c  Mup - ok
23:44:35.0583 0x1f2c  [ 3D2C5B4995CA0751D32DEA0DE9FDFE44, A26958785FD9E05E2CA97078C9BB277CD44222BF5F7D9E8DC2F3F6AAAFFC6483 ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
23:44:35.0598 0x1f2c  mvumis - ok
23:44:35.0628 0x1f2c  [ E605F35F03C881DC46902E0E2F5985B3, C97F0C733377E35B463EF7F6A5B879DA21AB512719899160C09278615FE39A21 ] MyEpson Portal Service C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
23:44:35.0667 0x1f2c  MyEpson Portal Service - ok
23:44:35.0676 0x1f2c  MySQLpearstem - ok
23:44:35.0693 0x1f2c  [ AB6031419C320BBDF456102ADD011D7E, 3308C30CA5C50F08D6FCF662980C9B8ED04B744F65B0D77E60EFC655BC1F310B ] MyWiFiDHCPDNS  C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
23:44:35.0706 0x1f2c  MyWiFiDHCPDNS - ok
23:44:35.0728 0x1f2c  [ DB31EBB04C871F422C36A0962DA7D38B, B1BC2344744F537FB2C7D07B415F860195B7795E185253F05C0817A3764FEC10 ] NativeWifiP    C:\WINDOWS\system32\DRIVERS\nwifi.sys
23:44:35.0765 0x1f2c  NativeWifiP - ok
23:44:35.0774 0x1f2c  [ C3D9870E680D9D843B18F4626C3858FE, 43596CAC9FB488F810FBA954C52BC4D13F7D32028C40ACFE33DFD7EE36A65C17 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
23:44:35.0794 0x1f2c  NcaSvc - ok
23:44:35.0806 0x1f2c  [ 04CE2C0F0759EACD886BA4B658B60D5D, E34D0976FC5936C8629800D826DB127072D1DFC3D350EFACA3AA1B8119551762 ] NcbService      C:\WINDOWS\System32\ncbservice.dll
23:44:35.0838 0x1f2c  NcbService - ok
23:44:35.0848 0x1f2c  [ E6094065008FE423377294050E7CEA2D, 86E200227256407530E2C28243DEFBC3CB6E9497644404D9AD79DA242286DF7B ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
23:44:35.0877 0x1f2c  NcdAutoSetup - ok
23:44:35.0886 0x1f2c  [ 629CB21AC49C8867E0F29DF1C16DB7B4, 20663E68C69D0A1A2FE99A0C2A9DEFABF49786A1DC8F7F4E1699458AF57D7E79 ] ndfltr          C:\WINDOWS\System32\drivers\ndfltr.sys
23:44:35.0899 0x1f2c  ndfltr - ok
23:44:35.0930 0x1f2c  [ 36DD2C614720EC2970CB5E870BA69D8D, 692BDA4201119E0561E17E7E1A72320DBECDE3F8E4E65FBEA1B2C1128E16508B ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
23:44:35.0978 0x1f2c  NDIS - ok
23:44:35.0989 0x1f2c  [ 6DD605338FAAF6BA17662AA874E0D162, 636607829F5D7C3B7A4683C0A2DD594360D72F2AA3F8710153BE32575AE34A15 ] NdisCap        C:\WINDOWS\system32\drivers\ndiscap.sys
23:44:36.0012 0x1f2c  NdisCap - ok
23:44:36.0023 0x1f2c  [ E34196F285F8B8879E1FF36C31F7179E, 77A4F24F995D4C0689C43F9956E08DCEC62517E4F8B1B9EAA1852B5293DB5B9A ] NdisImPlatform  C:\WINDOWS\system32\drivers\NdisImPlatform.sys
23:44:36.0059 0x1f2c  NdisImPlatform - ok
23:44:36.0068 0x1f2c  [ 1FAD2398673F30CEC616B89C46B7DCBA, 70302049E6AE2BC6B3A7A9DE54D3F940AD6A9771CC2EBCCEC65994E67A25ECB5 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:44:36.0099 0x1f2c  NdisTapi - ok
23:44:36.0109 0x1f2c  [ AEB8ECBE66CC46854066CB1F5623E179, 2F650A85A9DAE38887610C0B876621035616CEDB65D4BBBD7F1405616D218AAF ] Ndisuio        C:\WINDOWS\system32\drivers\ndisuio.sys
23:44:36.0130 0x1f2c  Ndisuio - ok
23:44:36.0138 0x1f2c  [ 7340104C2BF2F126714F7CDE85E63610, 45B64EC6F3A4C43F7D74806789067658C6EF0D44D36B841F4D26E1EBC95AF66C ] NdisVirtualBus  C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
23:44:36.0162 0x1f2c  NdisVirtualBus - ok
23:44:36.0175 0x1f2c  [ 07ADC1F8DCBEB8104D75129B11584B8C, CB51A294D9FD4E210DBEEF05A1E60A96CE52D6D138EF62A54E1F608F90FED300 ] NdisWan        C:\WINDOWS\System32\drivers\ndiswan.sys
23:44:36.0211 0x1f2c  NdisWan - ok
23:44:36.0224 0x1f2c  [ 07ADC1F8DCBEB8104D75129B11584B8C, CB51A294D9FD4E210DBEEF05A1E60A96CE52D6D138EF62A54E1F608F90FED300 ] ndiswanlegacy  C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:44:36.0261 0x1f2c  ndiswanlegacy - ok
23:44:36.0270 0x1f2c  [ 78A12E3DF035B5D054986949B19BE43C, AD9B34F89B9F27D473BD5FCE6694A40FCCB808B61ABEDD6F70F1AF6C7E73ABF8 ] ndproxy        C:\WINDOWS\system32\DRIVERS\NDProxy.sys
23:44:36.0302 0x1f2c  ndproxy - ok
23:44:36.0313 0x1f2c  [ 04C8859355C1DC9C0FA198D1894D71C2, E7C67E73009341B5D402470C686781B3C7BBE2531CE26665E08E711B990B1A77 ] Ndu            C:\WINDOWS\system32\drivers\Ndu.sys
23:44:36.0348 0x1f2c  Ndu - ok
23:44:36.0358 0x1f2c  [ 6C76780A01FC2B885BD6E957B5C36B02, DB7834F03A765F65C773E772D8051AFADB22CA4B5074180AA397857A0C47A068 ] NetAdapterCx    C:\WINDOWS\system32\drivers\NetAdapterCx.sys
23:44:36.0383 0x1f2c  NetAdapterCx - ok
23:44:36.0392 0x1f2c  [ 5D1513BD6430307C9DB86C6E351372ED, D2AB709CF7CFA5B857B084AFC821914A975B7DDDCE154229981F19448973BD6D ] NetBIOS        C:\WINDOWS\system32\drivers\netbios.sys
23:44:36.0411 0x1f2c  NetBIOS - ok
23:44:36.0433 0x1f2c  [ 6FEBB0A847FFD5F057B9AC8889F1B9A7, 558BCC64C59079E6569F61CCE1219A124B3313FC4E6CB5CBCC94124D202FF19D ] NetBT          C:\WINDOWS\system32\DRIVERS\netbt.sys
23:44:36.0468 0x1f2c  NetBT - ok
23:44:36.0478 0x1f2c  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] Netlogon        C:\WINDOWS\system32\lsass.exe
23:44:36.0497 0x1f2c  Netlogon - ok
23:44:36.0512 0x1f2c  [ D3BF2DA9216A4CF22A97820A50A67EFF, D00CBE0A7ECFB449D9B48967A01EE56141404EBE229893D5A1710781AD5F2551 ] Netman          C:\WINDOWS\System32\netman.dll
23:44:36.0547 0x1f2c  Netman - ok
23:44:36.0568 0x1f2c  [ F2645D51DD8AABC8BC72358409410437, 8CB97628923D6CEA6EFAD7E666BE92C154060BD108C28D46287A520A14B18ADA ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
23:44:36.0617 0x1f2c  netprofm - ok
23:44:36.0633 0x1f2c  [ 724EA060EF56BAB4DED8F731FA56279B, E07FFE11D7B5C94D6B56940C6423ACB85910F6E8789E788EC91EEEE1C02B247F ] NetSetupSvc    C:\WINDOWS\System32\NetSetupSvc.dll
23:44:36.0668 0x1f2c  NetSetupSvc - ok
23:44:36.0682 0x1f2c  [ EFA857E2B0CC7C9DFEF48A2187B910F7, 424475568CD70237F056838388A5F7BDCD1B09349085498644C75940B12E8EAF ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
23:44:36.0700 0x1f2c  NetTcpPortSharing - ok
23:44:36.0805 0x1f2c  [ AC754EB741173D97931947D834F1FE94, 1DC03E5561B4CAFF126038D56AEC43C39642920B1EA1EEC23E2BFCEB644BC94A ] NETwNb64        C:\WINDOWS\System32\drivers\Netwbw02.sys
23:44:36.0934 0x1f2c  NETwNb64 - ok
23:44:36.0954 0x1f2c  [ B996DE26A2E16053C9485F5905B05320, 30EB2CEB466A4F05A44F7CBFCDFD8CC3C27B5FCF1269C1B9410C48AB362D2A75 ] NgcCtnrSvc      C:\WINDOWS\System32\NgcCtnrSvc.dll
23:44:36.0992 0x1f2c  NgcCtnrSvc - ok
23:44:37.0028 0x1f2c  [ 2EC2F2E4C88BA9B72D1F6B92234BCD53, 4DC98EBE5A3B34ED654017F076F457970D3FBF749DC54A6533DAABDE85A7C4FE ] NgcSvc          C:\WINDOWS\system32\ngcsvc.dll
23:44:37.0104 0x1f2c  NgcSvc - ok
23:44:37.0120 0x1f2c  [ 02E736F9861F1A6134736CF7473C513F, 7C574A50980885B213EFC0C394AFE613879B669246A4EA5EA6B5F791F7F6F32E ] NitroDriverReadSpool9 C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
23:44:37.0142 0x1f2c  NitroDriverReadSpool9 - ok
23:44:37.0161 0x1f2c  [ 0B5083278F195C26FE9E0140AEAEDCBE, B4D505963D5EBA14EC80E6D0BB8B862D96D1D1C3A57F4744AEBA3FF4BFB1997A ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
23:44:37.0214 0x1f2c  NlaSvc - ok
23:44:37.0239 0x1f2c  [ CD2C0C25ECFCF816306126D3C208614B, C0C8B59BDDB349A593DFF5107841EB76618631C867D7C8F234C9ECBD76713CB0 ] nlsX86cc        C:\WINDOWS\SysWOW64\NLSSRV32.EXE
23:44:37.0252 0x1f2c  nlsX86cc - ok
23:44:37.0263 0x1f2c  [ 001CBD7A2CD45C4EB39C01C3C677EF73, F4AAF4D60DB1232921C7811A62287B55C7C098B7A1FF9A40D88AF58A5ABECBA2 ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
23:44:37.0295 0x1f2c  Npfs - ok
23:44:37.0305 0x1f2c  [ 90F5DC9802AAA00CD0B6E2AD9E7FFADC, 71C0777829299DECA6ACD42F38802DBE3C29A42CFBD8A396F39DFA44D1F55B6C ] npsvctrig      C:\WINDOWS\System32\drivers\npsvctrig.sys
23:44:37.0328 0x1f2c  npsvctrig - ok
23:44:37.0337 0x1f2c  [ 1993C85962692EF7024501E7FE92D466, F5BCAA8308495EBF8BB061C2015E07C202A779668D171364D7E312975BC18B10 ] nsi            C:\WINDOWS\system32\nsisvc.dll
23:44:37.0365 0x1f2c  nsi - ok
23:44:37.0374 0x1f2c  [ 0C6218321A09A7B51BA7FFAFBA4CCB21, 330B3FA793A78410B28DFC8250BBF24442E3BB80434A7938BB96F02337614E0D ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
23:44:37.0397 0x1f2c  nsiproxy - ok
23:44:37.0499 0x1f2c  [ D1AF837A1555990602A51A3ED238EC80, 37F25AAC4431C665F014FF7EB2FBB395621581200CB5029D4C3F5040E9181F52 ] NTFS            C:\WINDOWS\system32\drivers\NTFS.sys
23:44:37.0678 0x1f2c  NTFS - ok
23:44:37.0704 0x1f2c  [ 6E6DD6F9DD2A034CF85E94047DBDB992, 63D0A0756F551B7668D1CBAB24B29FD462C706E8A81690BC248D6C92061FE215 ] Null            C:\WINDOWS\system32\drivers\Null.sys
23:44:37.0729 0x1f2c  Null - ok
23:44:37.0741 0x1f2c  [ D261DF41F0840F734856A2B4F5E072C7, 2E703556D0C919375D0B7770513456844B13362190643D5524663EC8546E0FF5 ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
23:44:37.0765 0x1f2c  nvraid - ok
23:44:37.0778 0x1f2c  [ 23B702B555EB0436B9DAA0BC63DA65CE, D454F80D9657CFEC852F022C12D7B2C1A2D7D247ECC591EDB07B9369DFD8C99E ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
23:44:37.0806 0x1f2c  nvstor - ok
23:44:37.0828 0x1f2c  [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
23:44:37.0857 0x1f2c  odserv - ok
23:44:37.0875 0x1f2c  [ 17997DC2441F7E29CDFC6458E0392764, 636CCE2DA1EF8195B33F8D6D5C8CC151D58EBF08DC9AD8ACCCE7ABD41A69639F ] OneSyncSvc      C:\WINDOWS\System32\APHostService.dll
23:44:37.0914 0x1f2c  OneSyncSvc - ok
23:44:37.0934 0x1f2c  [ E6D14F57D20E1C70482BA3ABAC367E4B, 9C0C5337F38EBC446FBC968098C55DF7FF101CF2291FD3A98EC7055F36964BC8 ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:44:37.0953 0x1f2c  ose - ok
23:44:37.0971 0x1f2c  [ 4578ECA1FCEF4E7C787D84F78625143B, F5FE84D6D7412A4C037772593C434253D590E476B0B7498987A1697BED86A510 ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
23:44:38.0012 0x1f2c  p2pimsvc - ok
23:44:38.0031 0x1f2c  [ 2BBCED66D7AFC968BDBB0E4D8524DF0A, 762D916390F9DE69B3EA1D31244224F910645F8E5CEF4C505B76B215BFDFCD9A ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
23:44:38.0075 0x1f2c  p2psvc - ok
23:44:38.0081 0x1f2c  [ 6B81BF7853D161DB8AC62CD8B9C2DE6B, B2DC06D135FD2501217DDA7349556EB873309E02188D4C3901807BA24FAB30C7 ] Parport        C:\WINDOWS\System32\drivers\parport.sys
23:44:38.0096 0x1f2c  Parport - ok
23:44:38.0112 0x1f2c  [ F9C32E5ECA5D29852A93C3888A4CC4B2, D52FFB5B85962D5C8FF8016627CBAE69472DDBA559261B6C7FD6DC4C677BB7C0 ] partmgr        C:\WINDOWS\system32\drivers\partmgr.sys
23:44:38.0128 0x1f2c  partmgr - ok
23:44:38.0159 0x1f2c  [ CE515B2C6E2EA50053A8862398646B38, C85D370E5250AFCF44796CE274B5A100C6829DC28BF1D4C6991EF61DE46FD10A ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
23:44:38.0197 0x1f2c  PcaSvc - ok
23:44:38.0212 0x1f2c  [ 55E45E0A89429AE9C62D728B9C4891C0, 729922C3488866C8D67F00E82C082F2E8E6F05180F4767AD30FC7E1FFE4946C5 ] pci            C:\WINDOWS\system32\drivers\pci.sys
23:44:38.0228 0x1f2c  pci - ok
23:44:38.0243 0x1f2c  [ 214DCC87E3898F738075D1341252A552, E721FBBC3510DDB848A8CAEA3B6031EE988F42252DBC3BF7BDB6ABD9A0D9FABD ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
23:44:38.0259 0x1f2c  pciide - ok
23:44:38.0278 0x1f2c  [ AED76A3333B3A31536E430020E0226FC, EC255B79B0908E3C142D92E35B79D90A3F2594BA012CA2B1B04A6A8745153430 ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
23:44:38.0297 0x1f2c  pcmcia - ok
23:44:38.0312 0x1f2c  PCSUService - ok
23:44:38.0328 0x1f2c  [ E63FB38B6E75B39467492FBAD2CD512A, DB406C92BA2460C833A49B98EB5BD58348E868F643A0123B0C9B5315FFC6A124 ] pcw            C:\WINDOWS\system32\drivers\pcw.sys
23:44:38.0344 0x1f2c  pcw - ok
23:44:38.0359 0x1f2c  [ 2CCD68D8A6BBFF2DE0EC54F086C5F3BC, D3D5A56F0C1BEBA9A05CE82F4BBD011E40A15358C00A668F9614F7E002A65A08 ] pdc            C:\WINDOWS\system32\drivers\pdc.sys
23:44:38.0381 0x1f2c  pdc - ok
23:44:38.0397 0x1f2c  [ 1509A77F840AA9E72CF8247D0CF2FBDE, 2D47AD4D8F5C2D871E603FB6D72D25EFD0E63FA3A542DAADAB9D82ED074C0E0B ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
23:44:38.0444 0x1f2c  PEAUTH - ok
23:44:38.0459 0x1f2c  [ 540116170E2135FCD5DDE77702166B67, CBEC51C2D47532F1781B3255040F303263420B204C2F8BB2B5D1EC342F57B285 ] percsas2i      C:\WINDOWS\system32\drivers\percsas2i.sys
23:44:38.0477 0x1f2c  percsas2i - ok
23:44:38.0481 0x1f2c  [ 8356F87553BF49C703CF382033815898, 245EB941566D848F134629690BF271B1CBEAB6440771D3D8D7AED3756835354E ] percsas3i      C:\WINDOWS\system32\drivers\percsas3i.sys
23:44:38.0497 0x1f2c  percsas3i - ok
23:44:38.0513 0x1f2c  [ CB5343FF52A702A9ACFAAE6BE972FE09, EAA5362D91D05D382DF4EBBAA3FD575456F23CAD531CC6F1270F8254892DBF02 ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
23:44:38.0528 0x1f2c  PerfHost - ok
23:44:38.0544 0x1f2c  [ AC8BC4D8BD937897EA765C1ACCF1BDE4, 0AC36AE36644AD728F9C46208F43F4A9A6323E8C28A7A0EE0A10A536D8FA175F ] PGService      C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
23:44:38.0582 0x1f2c  PGService - ok
23:44:38.0613 0x1f2c  [ 33CB582342A8FC574EE439D583495137, D8F087C42DA05E5584C8C124452B4A5CE7F2D56D7DA4AB733D7492A8D7D87BC2 ] PG_Service_Launcher C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
23:44:38.0681 0x1f2c  PG_Service_Launcher - ok
23:44:38.0697 0x1f2c  [ 3A6D56E0E072AB0F022FE03ED8C2693A, 8AA5823F68FEDEDB5E8916BD35832BC438A781142CF1672983D593B903083A68 ] PhoneCompanionPusher C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
23:44:38.0778 0x1f2c  PhoneCompanionPusher - ok
23:44:38.0782 0x1f2c  [ 0B2E100645AFAB3204313148DFE42322, C28FA6EF4FD8001E8F3367A7CB32E44F5D6A3E1EFBEC3C947A2FD3C3B0AF3568 ] PhoneCompanionVap C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe
23:44:38.0844 0x1f2c  PhoneCompanionVap - ok
23:44:38.0860 0x1f2c  [ CFA4868B2932396D47BCC8E7350907C1, C757910212982F54CF9B2CFFCB632D58E3A07E468A2DA42CDF97BFB6A05823DE ] PhoneSvc        C:\WINDOWS\System32\PhoneService.dll
23:44:38.0913 0x1f2c  PhoneSvc - ok
23:44:38.0929 0x1f2c  [ 06A31E2C90347128A1A25290568E152C, 7F0BC96C116A5C6B9796233CA975B1F6A73D554A533191F38295D60221E503C4 ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll
23:44:38.0944 0x1f2c  PimIndexMaintenanceSvc - ok
23:44:38.0997 0x1f2c  [ F931F21E4287FE3ECCF09B54A232BBA2, CEB7AB3236E5F30214027092B7B695ED35F7A1E007DF4046797D1E4DFEF49EC8 ] pla            C:\WINDOWS\system32\pla.dll
23:44:39.0060 0x1f2c  pla - ok
23:44:39.0081 0x1f2c  [ FEA494AC3A1BAE63C1F2AF267D49F1DB, 0722FEA2481740B53EF26B1CA59166C63C157A5C708AC93DF3FBB74A27266C9C ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
23:44:39.0097 0x1f2c  PlugPlay - ok
23:44:39.0113 0x1f2c  [ 56D7A89423325121C4A9BD5C326414F3, 649048C23D1973C3504E26B35362AC99DFE9BF31FFE73F45B43306A212AEA34C ] PNRPAutoReg    C:\WINDOWS\system32\pnrpauto.dll
23:44:39.0129 0x1f2c  PNRPAutoReg - ok
23:44:39.0144 0x1f2c  [ 4578ECA1FCEF4E7C787D84F78625143B, F5FE84D6D7412A4C037772593C434253D590E476B0B7498987A1697BED86A510 ] PNRPsvc        C:\WINDOWS\system32\pnrpsvc.dll
23:44:39.0160 0x1f2c  PNRPsvc - ok
23:44:39.0182 0x1f2c  [ F70CAC34B455D05EAA04B2F8FB58E1CB, 295BFFB3DA03C5CE5462C11D3240024B68AC06E8DEA9062A739BE2CCEE19EB5D ] PolicyAgent    C:\WINDOWS\System32\ipsecsvc.dll
23:44:39.0213 0x1f2c  PolicyAgent - ok
23:44:39.0229 0x1f2c  [ 60C8376B48BA96F07AEA536527433D44, EB988C119C3E71169B91ED2A744C71933DD35447DC4A8249E80EC24E9E7077D4 ] Power          C:\WINDOWS\system32\umpo.dll
23:44:39.0244 0x1f2c  Power - ok
23:44:39.0260 0x1f2c  [ 5645B9D9788CCA2C88B9534996ED2D6D, 4988942DF163DB5B9B1A08CE6B628D2C47C2E2EAA30AEAE4EFE21C8CF4C8DC5D ] PptpMiniport    C:\WINDOWS\System32\drivers\raspptp.sys
23:44:39.0298 0x1f2c  PptpMiniport - ok
23:44:39.0383 0x1f2c  [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify    C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
23:44:39.0583 0x1f2c  PrintNotify - ok
23:44:39.0630 0x1f2c  [ 372913E12677A8CBBBABDD8311894F9D, A5233D95A0D22D2A9DB214E7CB79A99D389B67189FF6A87D0AD4610A333A637F ] Processor      C:\WINDOWS\System32\drivers\processr.sys
23:44:39.0646 0x1f2c  Processor - ok
23:44:39.0661 0x1f2c  [ B2DC3BA675F95343D55EC989FE303561, C53FCA036358B0B11BBE5348074FA24831CF67C9FEE31A3DC9CF88B6178CFBC8 ] ProfSvc        C:\WINDOWS\system32\profsvc.dll
23:44:39.0715 0x1f2c  ProfSvc - ok
23:44:39.0730 0x1f2c  [ FC98407B85A31161851FDE245517574F, 2CCD706CF243934FCDA32B24CE0C385EA2E67F206E0306FA584496F583A20CD1 ] Psched          C:\WINDOWS\system32\drivers\pacer.sys
23:44:39.0783 0x1f2c  Psched - ok
23:44:39.0799 0x1f2c  [ 7A68710BAC9B6809314B86C0CB1CBC4A, C02D97993D1F6FE6EFBA5B1366B3A4FE8CE1136A95F3A2DA07BA59554C163501 ] QWAVE          C:\WINDOWS\system32\qwave.dll
23:44:39.0839 0x1f2c  QWAVE - ok
23:44:39.0849 0x1f2c  [ 819602BBBFDB0BD46DEA3715BF0DD452, D4007FF1E5296316B53436CA3598D6B1CF4F60AB77D5B02F3E595081EDD5D879 ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
23:44:39.0853 0x1f2c  QWAVEdrv - ok
23:44:39.0869 0x1f2c  [ CDF47037A0939F56D11F699629C276AD, A63F2A3FE80FB8084E3870E907505694B79EE1D9E56E292C01D481FEFD2534B0 ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:44:39.0885 0x1f2c  RasAcd - ok
23:44:39.0900 0x1f2c  [ 28C2EA278070EE12701D0EDF8CB0EC36, F10288C1C6835840026DB30285345EF892DE989F43C948E7F4760B8895FF675F ] RasAgileVpn    C:\WINDOWS\System32\drivers\AgileVpn.sys
23:44:39.0931 0x1f2c  RasAgileVpn - ok
23:44:39.0950 0x1f2c  [ 7B82197BF35CC3BE59AEF8B706AB8A16, AB0216164A548A48CD21F5F035E57E867584A96890B9887EC08F8DABDD89F990 ] RasAuto        C:\WINDOWS\System32\rasauto.dll
23:44:39.0969 0x1f2c  RasAuto - ok
23:44:39.0969 0x1f2c  [ 17E565710172ED71B8531D8822E1C5D1, 0CA39ABD9E544DDAD9D9D7D1FC50444274C31E18F9BF73069051D9F62833698F ] Rasl2tp        C:\WINDOWS\System32\drivers\rasl2tp.sys
23:44:40.0016 0x1f2c  Rasl2tp - ok
23:44:40.0032 0x1f2c  [ DF0702D6A190452E1BFA52F36E58640A, 37B7B8220CDE965F1232D883CEEEDDDB309ABA0ACBE38486E69B9052D39187C4 ] RasMan          C:\WINDOWS\System32\rasmans.dll
23:44:40.0085 0x1f2c  RasMan - ok
23:44:40.0100 0x1f2c  [ 9387DF155233D45D4E010F4F2FB52A57, CABC25DA4E512809AED0085767BDD94BF3C1DA792BFF8A009B5465D9110E7060 ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:44:40.0131 0x1f2c  RasPppoe - ok
23:44:40.0150 0x1f2c  [ F0F4EEDEEBEE7A4244FAFB96A16B5712, F64717E601BD5EB674003009507B8CDD6F69F00E8670D6895EC64786166A0E8D ] RasSstp        C:\WINDOWS\System32\drivers\rassstp.sys
23:44:40.0170 0x1f2c  RasSstp - ok
23:44:40.0201 0x1f2c  [ BBE0FC9C9E7C556DA6E6E6904739DF7E, E6F0C48371EEB92B796DA0AE49DA575AC0B4403146F75A1040DC2C1A44CAB0F6 ] rdbss          C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:44:40.0232 0x1f2c  rdbss - ok
23:44:40.0254 0x1f2c  [ 79A415E6FA915EFC00297DAB16EC2635, 47BB49F6D756214193D38A4AB182B541AAC180381C3111FF7F9B0AD4C44D8733 ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
23:44:40.0281 0x1f2c  rdpbus - ok
23:44:40.0294 0x1f2c  [ 7135785C21CA79D270D11037C43D3F19, 654A3C65CF891ED8C82A740D10CF607FC7D709185E664DE03288CEB5B25F03A6 ] RDPDR          C:\WINDOWS\system32\drivers\rdpdr.sys
23:44:40.0331 0x1f2c  RDPDR - ok
23:44:40.0354 0x1f2c  [ 97A61A3CB2B5CB4FC32B3224EF333448, E4F2E8BCEE3639BE57BBC8A8E67FDE42C3A5158F1204684B0ECD216F4AA044A3 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
23:44:40.0388 0x1f2c  RdpVideoMiniport - ok
23:44:40.0403 0x1f2c  [ 69BB204AE07EE84ECFAB1BF13C4BD04B, 1CA832CBF4AE4821EEA2A19F9519C2D1D00406B8CCE2A86FE3B33A5F293DB218 ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
23:44:40.0430 0x1f2c  rdyboost - ok
23:44:40.0464 0x1f2c  [ 940D6F5A2B0A61EE4170DF84F6C95C20, F8EE846DC8015EDFE7CB5BEEDC977EAA9C586BAC2216DE69D8ECCBDBC7408649 ] ReFSv1          C:\WINDOWS\system32\drivers\ReFSv1.sys
23:44:40.0555 0x1f2c  ReFSv1 - ok
23:44:40.0568 0x1f2c  [ 6242A806ED208E80BB788CCA967F672E, B960DAB695BE43665B1F9E433BE5E774E2831012AE2E9C8404CECBCE496A3022 ] RegSrvc        C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
23:44:40.0584 0x1f2c  RegSrvc - ok
23:44:40.0606 0x1f2c  [ FD2B3A645798A2EFB7FB61AC42AAA611, 8A121D361A73CA19AA87B1AD33B8020A99444BF4C8904944AD5913C5083859B8 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
23:44:40.0647 0x1f2c  RemoteAccess - ok
23:44:40.0660 0x1f2c  [ 3183B161B1F05333F6C325577FEF3596, D6A89B2A021377B6F371E5B9EFC36FF018822B28F0ED41F8CD2F00C5C8605707 ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
23:44:40.0691 0x1f2c  RemoteRegistry - ok
23:44:40.0714 0x1f2c  [ 94DCF20DF6170B557AFD386E37C128BC, 70FB7C7A7D2BFA95EACEEE38B39E1DCA93DA63AE1898C4F54956B9413C60EB88 ] RetailDemo      C:\WINDOWS\system32\RDXService.dll
23:44:40.0757 0x1f2c  RetailDemo - ok
23:44:40.0765 0x1f2c  [ E82F3B1918C6A5FE6EB761CDF1E772AF, 0C993FCB7BFD6E01B70A1821E0DEAFA2CB241AF8C2E6D4CC120F59C1B5F6FF5F ] RFCOMM          C:\WINDOWS\System32\drivers\rfcomm.sys
23:44:40.0796 0x1f2c  RFCOMM - ok
23:44:40.0812 0x1f2c  [ FBA61BB4C484A01A655AFB18FF86C417, D53B2110CB09D0A909C4E330C468351BFE076BB056CCDDCB8ADA2FB91E96352E ] RichVideo64    C:\Program Files\CyberLink\Shared files\RichVideo64.exe
23:44:40.0827 0x1f2c  RichVideo64 - ok
23:44:40.0843 0x1f2c  [ 237AAA173D673B77740BE6AE3359AE47, E9683DBF594522A6C7331EB3F6EE33920B3E232689E814F0063871D6540479C7 ] rijufoze        C:\Program Files (x86)\04905D8E-1471276344-11E4-B57F-68F7284155E1\hnst6DCB.tmp
23:44:40.0896 0x1f2c  rijufoze - detected UnsignedFile.Multi.Generic ( 1 )
23:44:41.0012 0x1f2c  rijufoze ( UnsignedFile.Multi.Generic ) - warning
23:44:41.0012 0x1f2c  Force sending object to P2P due to detect: rijufoze
23:44:41.0327 0x1f2c  Object send P2P result: true
23:44:41.0427 0x1f2c  [ 068220E1B417556F4226E6A3CA0A1C24, 381DD82EF6EAEE83B5B3FA123D04A4D1EEB3407737683C22BBA787C39DCAFFE3 ] RmSvc          C:\WINDOWS\System32\RMapi.dll
23:44:41.0463 0x1f2c  RmSvc - ok
23:44:41.0465 0x1f2c  [ 672724C8B21B7DC56646045DE4D5B860, 79986E80A92C949C543959F1E35647A9788DAB2892AC20B6DEA5C0BBC0CEDE9E ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
23:44:41.0481 0x1f2c  RpcEptMapper - ok
23:44:41.0497 0x1f2c  [ 109C1D609951E886D3643B15C1EDD1C2, 347D8E7C50EC7F96217C7421D9BC8A42C9DF50B94169CB58DCF857A63C33C2EA ] RpcLocator      C:\WINDOWS\system32\locator.exe
23:44:41.0512 0x1f2c  RpcLocator - ok
23:44:41.0543 0x1f2c  [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] RpcSs          C:\WINDOWS\system32\rpcss.dll
23:44:41.0581 0x1f2c  RpcSs - ok
23:44:41.0596 0x1f2c  [ 5FF28F097C9699097B473F8FC7C1AA7D, 695560F1DBD85073F3D6CB1FF16F16504CA044EA62E940E463A16BBA8B86E2FA ] rspndr          C:\WINDOWS\system32\drivers\rspndr.sys
23:44:41.0612 0x1f2c  rspndr - ok
23:44:41.0628 0x1f2c  [ 6CBF283C7EBD07B7BB01D3E33B11BB28, 90B7AF25EFDBC71FDDD48D668BF410DB828ABD512FC02146E76962A8FF053DE9 ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
23:44:41.0643 0x1f2c  RtkAudioService - ok
23:44:41.0665 0x1f2c  [ AE4607D7C7AA83A863BFA214483E8EE4, 828CC9F40BAB2F65AF75608D37ED17EF608E73E911132DD085F0685F163EFEC6 ] RTSUER          C:\WINDOWS\system32\Drivers\RtsUer.sys
23:44:41.0697 0x1f2c  RTSUER - ok
23:44:41.0785 0x1f2c  [ 11FB11B89D7889506F1DF51AD31A7E6C, F58735A6FEC79B6C19B5B23F310D4836AA8A7EA033B56E74D5AF58BE1FFF05D1 ] rtsuvc          C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
23:44:41.0858 0x1f2c  rtsuvc - ok
23:44:41.0874 0x1f2c  [ 82F73415998B255CA3137E66FABDABEF, 34021170DB62274A01A7ACB7BECA688EEB8A9CE0E02916721FA1CAA8C349E24D ] rtux64w10      C:\WINDOWS\System32\drivers\rtux64w10.sys
23:44:41.0896 0x1f2c  rtux64w10 - ok
23:44:41.0911 0x1f2c  [ B5DAEE69BACA64D2BB004568E22D8756, C0072CF6B438ED756435A182D55AC55F3AD356ACBD483DE06A94893D3CA8CCC5 ] s3cap          C:\WINDOWS\System32\drivers\vms3cap.sys
23:44:41.0943 0x1f2c  s3cap - ok
23:44:41.0958 0x1f2c  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] SamSs          C:\WINDOWS\system32\lsass.exe
23:44:41.0974 0x1f2c  SamSs - ok
23:44:41.0992 0x1f2c  [ 5E73FB63E2DBC75FE0C17DEB0010CE0E, 9DAC47486262397D03BC01F7438CAB62CF33BD7B5283F5B9548C770A3D6D0ADC ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
23:44:42.0012 0x1f2c  sbp2port - ok
23:44:42.0012 0x1f2c  [ 3CD0130FFDEAEACF0905B482F3934EA3, 1EC355B63135FD2563093EBB206741C0C4CCE0551A662F6DC86C875146A88B06 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
23:44:42.0058 0x1f2c  SCardSvr - ok
23:44:42.0074 0x1f2c  [ 9EE060D6560FFBFBDB2ED5D6ED192294, 14387B69CD26D12BE31A23251B6AA8EDFC4D6CDE4FA558F0950DE91D2DD03946 ] ScDeviceEnum    C:\WINDOWS\System32\ScDeviceEnum.dll
23:44:42.0096 0x1f2c  ScDeviceEnum - ok
23:44:42.0096 0x1f2c  [ 3D9A82B03C92D1FEC42CB171D6F57778, DC027F02F5EB5F1D10DB6F405FB0C15D4D5C922445F5F3C916624113278AF072 ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
23:44:42.0112 0x1f2c  scfilter - ok
23:44:42.0143 0x1f2c  [ D4DB6B318A0A0C74A90260725A228C0B, 57BA2EF9D880488C785C806ABF9EE753A48E589129442D72F815CD6EFFA07B22 ] Schedule        C:\WINDOWS\system32\schedsvc.dll
23:44:42.0196 0x1f2c  Schedule - ok
23:44:42.0196 0x1f2c  [ 9055ADDFBA4C8B914C914CE693B55C0A, DB213AC36E14D856B81D2AFE46815402537A2ABEEA15032A9FF436F953129441 ] scmbus          C:\WINDOWS\system32\drivers\scmbus.sys
23:44:42.0212 0x1f2c  scmbus - ok
23:44:42.0227 0x1f2c  [ B6F2363584E62960846F7C3F00124A4F, 252189FF9D623CF69BF415FF7C7FE74B0BBF756B632420578BFAFF6595616CF7 ] scmdisk0101    C:\WINDOWS\System32\drivers\scmdisk0101.sys
23:44:42.0243 0x1f2c  scmdisk0101 - ok
23:44:42.0258 0x1f2c  [ 9450FA11E9DE6715FCB71A519A8FF90B, B7E341C6E4CE967FCDD0D17A497C07E8A1C6B0AACE8A6E8E5D6C21EF73F13E16 ] SCPolicySvc    C:\WINDOWS\System32\certprop.dll
23:44:42.0274 0x1f2c  SCPolicySvc - ok
23:44:42.0296 0x1f2c  SCService - ok
23:44:42.0296 0x1f2c  [ FCBB8A17B4437B2CA8CC8DA8CB1D306E, 5FA762B1B6C8A45ED6F304A45B500038537ABD3DF6328F3C8E2BD43CBDEAB835 ] sdbus          C:\WINDOWS\System32\drivers\sdbus.sys
23:44:42.0328 0x1f2c  sdbus - ok
23:44:42.0328 0x1f2c  [ F3714DBAA42C15F78FFCDFE4273214EB, 2D018970B92C5F0744FAE10A2FC298F3DCEA5C2EDEB760F4F0651337B9878ABF ] SDRSVC          C:\WINDOWS\System32\SDRSVC.dll
23:44:42.0359 0x1f2c  SDRSVC - ok
23:44:42.0374 0x1f2c  [ 120DFCB71D6C502613A9E2D50E16850C, 2C294010AD1C9C380CD5221A37720544178B7358C8C8553AF44055E4CEE5DAF5 ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
23:44:42.0397 0x1f2c  sdstor - ok
23:44:42.0428 0x1f2c  [ EFD644DD091E1D94555FC3BBC95EA66D, FBDDA6680BEC378CCF12A32D9186020E884DA15A1E789D1531B1E687FC7B54B1 ] seclogon        C:\WINDOWS\system32\seclogon.dll
23:44:42.0512 0x1f2c  seclogon - ok
23:44:42.0575 0x1f2c  [ 07F83829E7429E60298440CD1E601A6A, 9F1229CD8DD9092C27A01F5D56E3C0D59C2BB9F0139ABF042E56F343637FDA33 ] semav6msr64    C:\WINDOWS\system32\drivers\semav6msr64.sys
23:44:42.0635 0x1f2c  semav6msr64 - ok
23:44:42.0678 0x1f2c  [ B605A44ACA1FCFF736235A4D7AEDA548, 48D8B5BC027CFE91AF7402C463327572181D4C1B1E2942F4D05792EED070B2DC ] SENS            C:\WINDOWS\System32\sens.dll
23:44:42.0778 0x1f2c  SENS - ok
23:44:42.0952 0x1f2c  [ 1CC993A041899B48D5DF4D3F4A4425FC, 8D138B3A92C0E181C865A37AD55EE2D55CC352ED9B60BF60BE0AC610F13F8FA1 ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe
23:44:43.0420 0x1f2c  SensorDataService - ok
23:44:43.0497 0x1f2c  [ 7BFD114F0F308CE29AEB8F16056D0658, 0CD3B3C69DCB3EAD8F8EF5C633911DD4F2C1167DC6FE28107EE38713A35A1F5C ] SensorService  C:\WINDOWS\system32\SensorService.dll
23:44:43.0699 0x1f2c  SensorService - ok
23:44:43.0753 0x1f2c  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] SensorsHIDClassDriver C:\WINDOWS\System32\drivers\WUDFRd.sys
23:44:43.0900 0x1f2c  SensorsHIDClassDriver - ok
23:44:43.0952 0x1f2c  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] SensorsSimulatorDriver C:\WINDOWS\System32\drivers\WUDFRd.sys
23:44:44.0073 0x1f2c  SensorsSimulatorDriver - ok
23:44:44.0116 0x1f2c  [ E6F00415DADCEEC860E7AB42BFD19A65, 274CAF22F93D43B6DB6953730E3DF8DA94776B24EEE74B80AB4CD780BC1366A9 ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
23:44:44.0254 0x1f2c  SensrSvc - ok
23:44:44.0288 0x1f2c  [ 401D706DDC0A7AF18C3DD228ADF74551, 27C0B38D7C2E3F6FF06201124E63483931F6071954B2B99EC0143C464238C0B7 ] SerCx          C:\WINDOWS\system32\drivers\SerCx.sys
23:44:44.0355 0x1f2c  SerCx - ok
23:44:44.0395 0x1f2c  [ 7084D11083F0CDCA8B5C76F9846ABF5D, F639920882B0E784D8CFAF0D4C0F0C411937B6831E5DD99B0ABFBFE06BA4742F ] SerCx2          C:\WINDOWS\system32\drivers\SerCx2.sys
23:44:44.0471 0x1f2c  SerCx2 - ok
23:44:44.0501 0x1f2c  [ 3FF478A8ED32A83C36581425F6282B6C, 787646A17098EA7CF36064D0A950C1D470D4A280C8C5AC40023D566E53860EAE ] Serenum        C:\WINDOWS\System32\drivers\serenum.sys
23:44:44.0568 0x1f2c  Serenum - ok
23:44:44.0601 0x1f2c  [ 92509187AA171A80521528B36F753E1D, FE0DA272B8A155ECC161E99586C4AE7EE17B1C84BC330DA1566C83B8E03FA825 ] Serial          C:\WINDOWS\System32\drivers\serial.sys
23:44:44.0657 0x1f2c  Serial - ok
23:44:44.0680 0x1f2c  [ 433D38FF6D08B993847EA2A10EB8CB52, 29BA75DB6D1AC761BBDFB5AC8874FC7D763E1CD10D290E369063B34CE951270F ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
23:44:44.0736 0x1f2c  sermouse - ok
23:44:44.0838 0x1f2c  [ D525D273BE5691BDACE72B07AB0D1E02, 9231BD2137E71B3D555CEBBA8811297F239FDA08BF573CA4741D03D76718B5B1 ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
23:44:44.0956 0x1f2c  SessionEnv - ok
23:44:44.0987 0x1f2c  [ 697D3EE0740AEAB62B66ABCA1C83D13B, FCF54A0071ED04AD3FC8551C67FE5FD49089DC0510F753052CAC5972A65C9E3D ] sfloppy        C:\WINDOWS\System32\drivers\sfloppy.sys
23:44:45.0055 0x1f2c  sfloppy - ok
23:44:45.0112 0x1f2c  [ 3D0069B8F0C2FB1B0F13DBDB57593DAD, 4CEC91BC45A51C4E445D2DD8A13AC97719D5AAC1DBA8EA9166D2A354E7857378 ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
23:44:45.0248 0x1f2c  SharedAccess - ok
23:44:45.0301 0x1f2c  [ 482E6BE8A07832E824080D352075ACA1, 4123A76C8E805AF4FE229C53E9C174095C0937913BA81A63FE9B45C44AA5B15F ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
23:44:45.0443 0x1f2c  ShellHWDetection - ok
23:44:45.0476 0x1f2c  [ CF3BDF9EAD8D3EF671E9339B44B185BA, C17EC6D5B00F49D9C8B5B6C262A85F34ED71C58450659F006B3632AA84F68E23 ] shpamsvc        C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
23:44:45.0539 0x1f2c  shpamsvc - ok
23:44:45.0563 0x1f2c  [ A34CE1830E45DA98932295FDE4B7908A, FC553ECF4D64B4B10B7FDE5352707785517A18D487A80665BAFC7261E3F35CDC ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
23:44:45.0600 0x1f2c  SiSRaid2 - ok
23:44:45.0627 0x1f2c  [ A7B5C670770E908DA5FEF5BF1136E933, 8D3BB6FF65E631C34BE8EA766481B2FDB2E1E916A4FD67F86705A8975A136E6C ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
23:44:45.0665 0x1f2c  SiSRaid4 - ok
23:44:45.0699 0x1f2c  [ 6749AD471D1D44CBD1F30257C861F77B, D5A554F35E380948F13BFE0673B49F8FD8AE5A438BF3645857522E2560A58685 ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
23:44:45.0747 0x1f2c  SkypeUpdate - ok
23:44:45.0769 0x1f2c  [ 1B96814008B0D75F0050C21E9B0D0C6F, AD3E606D546C432F494C14DE49B845EEC4D3EC039418F005F782E37BC4E14502 ] SmbDrvI        C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
23:44:45.0792 0x1f2c  SmbDrvI - ok
23:44:45.0810 0x1f2c  [ 3CF50AFD283566573E0412E5D512184A, 382825D5592F13088FB82A0452F9FAC917767A808B521F1BDACB78B70797FB5A ] smphost        C:\WINDOWS\System32\smphost.dll
23:44:45.0857 0x1f2c  smphost - ok
23:44:45.0898 0x1f2c  [ 0B217141AC1283655402CDB356577735, 6EFA4CA46CFC8B7156CE7E5CA89B7F7073E16D66C2FC13F4DB95FEB78CCF698F ] SmsRouter      C:\WINDOWS\system32\SmsRouterSvc.dll
23:44:45.0999 0x1f2c  SmsRouter - ok
23:44:46.0048 0x1f2c  [ 6F4CE07D420FB657B5936F71101ABD41, CEC52984C56E578E0FFE12BE1B8148335F788B7D1751F2D0E79B944A41113C20 ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
23:44:46.0101 0x1f2c  SNMPTRAP - ok
23:44:46.0142 0x1f2c  [ 3DB9C2950439B61A038BF83E697C7A14, 6BF5EA5D4A251CB982F336840A60EF4241A3FC7442E7CD4D7C82199F5BF8D4D2 ] spaceport      C:\WINDOWS\system32\drivers\spaceport.sys
23:44:46.0212 0x1f2c  spaceport - ok
23:44:46.0235 0x1f2c  [ E03264C4C25B568F92ED1656AD541E64, D42942BFFBC7213D204FAF84F4FE015FC23A6ACB29B5E752834EDBC17A3AC20D ] SpbCx          C:\WINDOWS\system32\drivers\SpbCx.sys
23:44:46.0268 0x1f2c  SpbCx - ok
23:44:46.0316 0x1f2c  [ DA5A9752A702E86AFC10F06115A8AF4C, 1EBF973AAEE0D851934CFD99BF6FC3B33D6EF5EDE95F81450D2EA18117172FC9 ] Spooler        C:\WINDOWS\System32\spoolsv.exe
23:44:46.0411 0x1f2c  Spooler - ok
23:44:46.0566 0x1f2c  [ D9B2C0D75F4463EE117F56D59D3CD670, 6E43BCF9388BCA58E2BDF64B71022334542727B0CDDE5F8DAF2AA8CFEA5F619F ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
23:44:46.0800 0x1f2c  sppsvc - ok
23:44:46.0821 0x1f2c  [ E8276BE984738AA44070CFDE6EFC9300, F0B09D3E08BDB1B8AEBA97A700271E97AB2506793B42D96415B23DB68DA99FA8 ] SQLWriter      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
23:44:46.0837 0x1f2c  SQLWriter - ok
23:44:46.0852 0x1f2c  [ EDCDCD95B916DB156A903AC6256F0CCF, 4158EFE298235EDE2C34CE9F3978A4F3690379F14B21F917647EEAA0A8C1DE4A ] srv            C:\WINDOWS\system32\DRIVERS\srv.sys
23:44:46.0900 0x1f2c  srv - ok
23:44:46.0937 0x1f2c  [ DF7147DE10921DBAAE9F9EEF94590E10, 2222BA441227056DA17194648B3AF49655650F7BBA9E4A9ACEF519E392099C6D ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
23:44:47.0018 0x1f2c  srv2 - ok
23:44:47.0041 0x1f2c  [ 416D224AF7481A4179F018FB1F9A5B6B, 38159D7957A8091DFC5C32DCAC4DB07FDE14BBE4E75B4E61B4FBB332E3F9259D ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
23:44:47.0084 0x1f2c  srvnet - ok
23:44:47.0100 0x1f2c  [ 44758105AB3EA34E815D4B6CA1153311, 7F223A20D2538C123BAC6F75BE0E126876A116F09502FD980C05B8916E26E1B7 ] SSDPSRV        C:\WINDOWS\System32\ssdpsrv.dll
23:44:47.0152 0x1f2c  SSDPSRV - ok
23:44:47.0184 0x1f2c  [ B97C7EC07218A8002323718202BF5E77, 39D3254383E3F49FD3E2DFF8212F4B5744D8D5E0A6BB320516C5EE525AD211EB ] SstpSvc        C:\WINDOWS\system32\sstpsvc.dll
23:44:47.0215 0x1f2c  SstpSvc - ok
23:44:47.0308 0x1f2c  [ DF762D30EF0EE10E569C507BE75EAA6B, C23BA05E778CF1A547E7D3FE2226E0E68917570C56D5E703E599CAF2FD10BD17 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll
23:44:47.0457 0x1f2c  StateRepository - ok
23:44:47.0504 0x1f2c  [ 345C39599C3D4940D12F5F9F42A79229, B5D6C716D374E453940C2A23772B9E063CBCB06DA74574F0F19F813AE65F4A78 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
23:44:47.0950 0x1f2c  Steam Client Service - ok
23:44:47.0965 0x1f2c  [ 29D26E1347AE1BBD4201014E19880B2C, 9E2153AD96CE4F189EEE43BB02515532C619FB1CA02D8F6DEF517AC3347AAA14 ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
23:44:47.0981 0x1f2c  stexstor - ok
23:44:48.0003 0x1f2c  [ 91CB95B35481155BFE29C217CD237F27, CA66957DF1441D991453BEF02D768D44E5D9A484BC23C8874E8A7AC20904CB06 ] stisvc          C:\WINDOWS\System32\wiaservc.dll
23:44:48.0050 0x1f2c  stisvc - ok
23:44:48.0065 0x1f2c  [ 0FE3B9A9E40DE1029B0AC2368A3F765D, AB06795E456DB9CE4E5A91DD1C2638B4D474CE1C5DB4819D5EE17A337D74A231 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
23:44:48.0096 0x1f2c  storahci - ok
23:44:48.0103 0x1f2c  [ C5E0ACE4771F5575D9D5B457ABF3AD03, 365880BC5AC313F25C313EFB7758301F98D9B2BF4C5FC9499F98C2B7F8407D96 ] storflt        C:\WINDOWS\system32\drivers\vmstorfl.sys
23:44:48.0119 0x1f2c  storflt - ok
23:44:48.0119 0x1f2c  [ C1CFB9C19BF1134D8B9A7CF89BEC0AD1, 60DDF10777B30F3F70E4D52AFEABE71C7B509D0F2E3829106ED42ED330F8BCF4 ] stornvme        C:\WINDOWS\system32\drivers\stornvme.sys
23:44:48.0134 0x1f2c  stornvme - ok
23:44:48.0150 0x1f2c  [ BEBF85EB4D90E6996047DA027D0ED26E, DF109CF0F07CDD1B9B702C2A076D4DD5366DAAD971CC9359AF0358E79981706F ] storqosflt      C:\WINDOWS\system32\drivers\storqosflt.sys
23:44:48.0165 0x1f2c  storqosflt - ok
23:44:48.0181 0x1f2c  [ EAB902EB8DCF9436354C7CF71A41C223, BB855A7C296AE60C025C7D488EB24BB7AB72FC716A12BE0BBE14B95DFCD290ED ] StorSvc        C:\WINDOWS\system32\storsvc.dll
23:44:48.0219 0x1f2c  StorSvc - ok
23:44:48.0235 0x1f2c  [ 8E73037A6F8938475692FFCC26EBF385, F78C5CD1A3CD17AA831EEC82426B14006B4DDBC9085A4814E04E8C37FD6B05F7 ] storufs        C:\WINDOWS\system32\drivers\storufs.sys
23:44:48.0235 0x1f2c  storufs - ok
23:44:48.0250 0x1f2c  [ 9D9DED47DA10E845EFF2DD57C94C809B, 520D0CE7A867051B80C8141E351FE5A5BCE3C99776093F234DB77D3407B1F104 ] storvsc        C:\WINDOWS\system32\drivers\storvsc.sys
23:44:48.0266 0x1f2c  storvsc - ok
23:44:48.0266 0x1f2c  [ 224C92E442B1B8C20C274332F1ACF00D, CDE5DCFB7A21089464A6E2ABB29BBE08B184C3433C218756AA5902A8F67C0B2C ] svsvc          C:\WINDOWS\system32\svsvc.dll
23:44:48.0298 0x1f2c  svsvc - ok
23:44:48.0304 0x1f2c  [ 505E0C40B5D0ADDCBB414640F59BD2E0, DF4B5E65FE6FF2224F298A2A2FAC9B648C082DFF8463148633647580A9FAD34D ] swenum          C:\WINDOWS\System32\drivers\swenum.sys
23:44:48.0304 0x1f2c  swenum - ok
23:44:48.0319 0x1f2c  [ 2EE27411B5904C63D723BEA391819F58, C88C11D460E90398E16011B8A2CED5EE5626084F24790EA6115532F8F70060C6 ] swprv          C:\WINDOWS\System32\swprv.dll
23:44:48.0350 0x1f2c  swprv - ok
23:44:48.0366 0x1f2c  [ 32F46FB0F290D16DAA452B289C985795, 73F88AAAA6026DB4C27F1D054145216DCC3F1960946FB2A7A90518DD1D5737CB ] Synth3dVsc      C:\WINDOWS\System32\drivers\Synth3dVsc.sys
23:44:48.0382 0x1f2c  Synth3dVsc - ok
23:44:48.0435 0x1f2c  [ 6954AF16E100598A724B164EEE7D7AC1, 0B9811282D1B9C3FFEEA4807FC7E90D19C37C6C703F5BC3EA08A2CFCCFC1C5BF ] SynTP          C:\WINDOWS\system32\DRIVERS\SynTP.sys
23:44:48.0504 0x1f2c  SynTP - ok
23:44:48.0535 0x1f2c  [ 5AE7713E95B16B00370952031CD36927, 0AEB9C95C3461ABFCB41594E46FEF9C2845ABF4D3FE238750E6AFD037BD8E057 ] SynTPEnhService C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
23:44:48.0582 0x1f2c  SynTPEnhService - ok
23:44:48.0682 0x1f2c  [ FED48B19D6F55D7A3AB498D85729D1BA, FA5E0E02BC2E2DE108C55991E3B063CC947072228B53539F42F922661510DE7C ] SysMain        C:\WINDOWS\system32\sysmain.dll
23:44:48.0851 0x1f2c  SysMain - ok
23:44:48.0905 0x1f2c  [ D9FEA79BF6AF136F8E656AE045C2FEC8, E6F08A93348E035185F0F1C6B6277E636F4F25D1136E3ACCA63488DAEEC7114B ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
23:44:49.0020 0x1f2c  SystemEventsBroker - ok
23:44:49.0067 0x1f2c  [ 2BE3A44B764D6C43CBF4650E862CB807, 78920DA47F3A0C26503FB62EF159455A860E57A9A39C72AEE23A9324168EC1D2 ] SystemUsageReportSvc_WILLAMETTE C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe
23:44:49.0267 0x1f2c  SystemUsageReportSvc_WILLAMETTE - ok
23:44:49.0312 0x1f2c  [ 86E7FD5C8DBEC1EB51C4368561402B75, 86EE61414CD5854E39E33F67BF5DA4377B569B3ED4D18882C470BC6784891DA1 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
23:44:49.0380 0x1f2c  TabletInputService - ok
23:44:49.0435 0x1f2c  [ 3929C8FC134AC672C4F3F85160956257, CD3195CA58BA6F55EA0DDA2BE6AB58280AD1CA488D7AAA1539DD05FB99374F36 ] TapiSrv        C:\WINDOWS\System32\tapisrv.dll
23:44:49.0536 0x1f2c  TapiSrv - ok
23:44:49.0691 0x1f2c  [ 172B5A199F917B4BACB38F13BCAA11CB, 8491C9E284658920544F5EFED7125D50135C43360BD50B78F962578D9716C719 ] Tcpip          C:\WINDOWS\system32\drivers\tcpip.sys
23:44:49.0923 0x1f2c  Tcpip - ok
23:44:50.0108 0x1f2c  [ 172B5A199F917B4BACB38F13BCAA11CB, 8491C9E284658920544F5EFED7125D50135C43360BD50B78F962578D9716C719 ] Tcpip6          C:\WINDOWS\system32\drivers\tcpip.sys
23:44:50.0355 0x1f2c  Tcpip6 - ok
23:44:50.0424 0x1f2c  [ 8DBB1BE20C36E6D19BCC89EEA00B953C, 8B97A7E53E1D77363AFF6A5AAEAD89EBAE28DCB8D82753C804FD7CD5646500AF ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
23:44:50.0476 0x1f2c  tcpipreg - ok
23:44:50.0539 0x1f2c  [ 9D2DD64A0B51C56285512DC9454340F6, ABB90CE6A55269F71AFB08E04969CF9A4EFD93F7A7189AF920EEE3E005214DDD ] tdx            C:\WINDOWS\system32\DRIVERS\tdx.sys
23:44:50.0577 0x1f2c  tdx - ok
23:44:50.0608 0x1f2c  [ 06130AFFECEB94525FC2352936576B70, 10EBE2C8FDC087D29E2FFB328F0F7905A5374AB8CC9FAE8699E7676DBC8CBF91 ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
23:44:50.0655 0x1f2c  terminpt - ok
23:44:50.0739 0x1f2c  [ FB68E5F02316C42BE7282DA492351C6F, AC31D841FEA58B776127E138DB20F8D48E26FD8C00CE2FA9695EA14EBF159A0A ] TermService    C:\WINDOWS\System32\termsrv.dll
23:44:50.0893 0x1f2c  TermService - ok
23:44:50.0925 0x1f2c  [ 2AF438EC0D361A7BBB70E604A686602C, 4BE6A0461EB2CB94288614434A1CEC81C2ED46241721FD5BBD8ABE0680F7C804 ] Themes          C:\WINDOWS\system32\themeservice.dll
23:44:50.0994 0x1f2c  Themes - ok
23:44:51.0041 0x1f2c  [ 1482B8ED5CACA87992A882B853B83CEE, 613247F0E362A109090E8563D977DECC50C64D45D6962905FA84A2D59329045C ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe
23:44:51.0141 0x1f2c  TieringEngineService - ok
23:44:51.0225 0x1f2c  [ 3B3C607C3C62DFBEF61938DA2CAB94DF, E5EEA7F45A7BBFDF6F0003CD77E39958C451DD1B4B401876B5619A3C20F5C370 ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll
23:44:51.0379 0x1f2c  tiledatamodelsvc - ok
23:44:51.0426 0x1f2c  [ C1F8CBE2D4843E0CCC3EFEA2EC60D4AB, 9D07527D982066922318C77AECE99280DE55034C375ACE145E827A6BEB5C3B70 ] TimeBrokerSvc  C:\WINDOWS\System32\TimeBrokerServer.dll
23:44:51.0557 0x1f2c  TimeBrokerSvc - ok
23:44:51.0625 0x1f2c  [ 798C8CB861EB09C5AFB77468E5449BBB, F6631E779159B99B097A59792D11713809CA493618B6A210A4BC905F16782094 ] TPM            C:\WINDOWS\System32\drivers\tpm.sys
23:44:51.0710 0x1f2c  TPM - ok
23:44:51.0767 0x1f2c  [ 3B91F35089240F6187AD681A5EC28BDE, 3D035CB73BC8E7831DCD0FB7D9DAD91CE51D3D0F9D9C8B866A0009BD508B6702 ] TrkWks          C:\WINDOWS\System32\trkwks.dll
23:44:51.0866 0x1f2c  TrkWks - ok
23:44:51.0908 0x1f2c  [ AF343840E793BE63A9C646760BE8F2CD, 483FE55873A01DB7ACEC99B6823DAACC9EA7C67D36C6F12698113B31A7D5B8BE ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
23:44:52.0010 0x1f2c  TrustedInstaller - ok
23:44:52.0085 0x1f2c  [ A6F4025664C9D4BC2A9EDAB4092706D7, 89808A1679C0E716F86F06EE7701DCC289200894F0FA1F120DA2AC3A45FDB312 ] tsusbflt        C:\WINDOWS\system32\drivers\TsUsbFlt.sys
23:44:52.0165 0x1f2c  tsusbflt - ok
23:44:52.0210 0x1f2c  [ 37A96AD493E110C0BF1EE0AC0F9E7DBD, F2A6894A4AEE18DF2B92222CDB0801A13AEEB7212071F0431430788339B30E23 ] TsUsbGD        C:\WINDOWS\System32\drivers\TsUsbGD.sys
23:44:52.0283 0x1f2c  TsUsbGD - ok
23:44:52.0327 0x1f2c  [ 79E264287F17D56D768440B0270466DE, ABF9DC95C5E939B30BFD9BF9EDFDB3BD78A9DFCB055B945965303B6A60E6D7A7 ] tunnel          C:\WINDOWS\System32\drivers\tunnel.sys
23:44:52.0412 0x1f2c  tunnel - ok
23:44:52.0453 0x1f2c  [ 0F38FCE8C61CC14DE3718FAB5FFC0D3A, 527071956BDC0F2863DCDFEDD314DB5265A6AE525F810186F508E0D58A97D767 ] tzautoupdate    C:\WINDOWS\system32\tzautoupdate.dll
23:44:52.0541 0x1f2c  tzautoupdate - ok
23:44:52.0579 0x1f2c  [ AA65954F512BA097DD190790876DD991, C1BB2B8F54F064D01190327B5E7949EBBDA21D6FC6F94D9FCD20F685C2F855FA ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
23:44:52.0635 0x1f2c  UASPStor - ok
23:44:52.0659 0x1f2c  UCBrowserSvc - ok
23:44:52.0702 0x1f2c  [ EB482DBC9786F1A9E3ED5AB6864794FA, 4154B259587D743612830F67800450DD04031C215A8459CC26E11D3498640BA0 ] UCGuard        C:\WINDOWS\system32\DRIVERS\ucguard.sys
23:44:52.0832 0x1f2c  UCGuard - ok
23:44:52.0878 0x1f2c  [ AB6268022C3A5B529075A39C33904DA6, 2717F1704640201F2681711543EA39A74C3E89C7DB232EC5DD89FD8AA6F07846 ] UcmCx0101      C:\WINDOWS\system32\Drivers\UcmCx.sys
23:44:52.0953 0x1f2c  UcmCx0101 - ok
23:44:52.0994 0x1f2c  [ 7ED2EDA43D21C7A5F589A7960E265C52, 7DB8A595236FBB8A264D7AB155201357212855050ABB5B1036EF32F1223FDCC2 ] UcmTcpciCx0101  C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
23:44:53.0110 0x1f2c  UcmTcpciCx0101 - ok
23:44:53.0153 0x1f2c  [ 169351463039B45F5CDED9768879F712, 990C8C4AEF9ED7FF6BCEAE67F7BDAA037777B142B8D96A74F8715C941A5C63C6 ] UcmUcsi        C:\WINDOWS\System32\drivers\UcmUcsi.sys
23:44:53.0250 0x1f2c  UcmUcsi - ok
23:44:53.0296 0x1f2c  [ 08A9E3AD29B215484FBB68CDC175DF3A, 3EFFF99C3BC4A1454E3D2B5177AE587ED3041AB4CE2A95BA7E28A2124E38E1E5 ] Ucx01000        C:\WINDOWS\system32\drivers\ucx01000.sys
23:44:53.0351 0x1f2c  Ucx01000 - ok
23:44:53.0386 0x1f2c  [ DA70AEE267491AA56BC63AA0C0C96CA2, 0A0AADB27607F9292BB3CE000CFDDB19BD4CA09EAAD926C4925CB43B17817AD9 ] UdeCx          C:\WINDOWS\system32\drivers\udecx.sys
23:44:53.0441 0x1f2c  UdeCx - ok
23:44:53.0485 0x1f2c  [ FBC5ECF6D5A868D0B116C2DBB02B8168, 945AA76C60ABAD6075B5C8F9172C018F75BCF393A1CB8B329F5E68E664627775 ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
23:44:53.0582 0x1f2c  udfs - ok
23:44:53.0611 0x1f2c  [ B918E40FAA9CD118CCA4AD388B748C98, 4B539B7B656F02C5E5BAEE52A677757B05CC11C5500D619850A564C28FAB8115 ] UEFI            C:\WINDOWS\System32\drivers\UEFI.sys
23:44:53.0652 0x1f2c  UEFI - ok
23:44:53.0692 0x1f2c  [ 0FD75222C1AD2687AB365BEBEA400DD4, AD10DBCA59EB7D34FD8F963CE267F36774A9BC613F8D637903B12AC88C328E8A ] Ufx01000        C:\WINDOWS\system32\drivers\ufx01000.sys
23:44:53.0753 0x1f2c  Ufx01000 - ok
23:44:53.0785 0x1f2c  [ C1A78C53E01C641AE41BFA65797819F5, 0B9FE1BD724B3315199A1B1DA2F03255E4FE744DA3CE6CD0F77699A8E42E9359 ] UfxChipidea    C:\WINDOWS\System32\drivers\UfxChipidea.sys
23:44:53.0825 0x1f2c  UfxChipidea - ok
23:44:53.0853 0x1f2c  [ 767307212110EBEFB93EC9A5BE9E85B9, 368797400FE54802CE74F34B773CE2AF09EB8DEA6C035B55419A52F0B5A6FAD0 ] ufxsynopsys    C:\WINDOWS\System32\drivers\ufxsynopsys.sys
23:44:53.0895 0x1f2c  ufxsynopsys - ok
23:44:53.0959 0x1f2c  [ 8578F83EC5175920F2D8586FFF9DCE47, 049A16AC87F93E761150C8286633FFCA62EE85F5645DDE77D36BD0EB6481FF83 ] UI0Detect      C:\WINDOWS\system32\UI0Detect.exe
23:44:54.0016 0x1f2c  UI0Detect - ok
23:44:54.0045 0x1f2c  [ DC460AAA18CA2342FBBFB2DF9B044472, 14D45E059C596AE97506D26705F248CA1C2269160B31A60341060E8A93146CBD ] umbus          C:\WINDOWS\System32\drivers\umbus.sys
23:44:54.0096 0x1f2c  umbus - ok
23:44:54.0120 0x1f2c  [ C3CF0377917ECE6D65D7623E1E61568F, 4909695E04CBC86BFCFFBC15F332C367521054B7B4D3C141C7CA6B2E40E090B9 ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
23:44:54.0161 0x1f2c  UmPass - ok
23:44:54.0198 0x1f2c  [ 640CF093C1CF16D5FD317616CA348F31, BEC34D1AACA83BF5A84CE01F6A668E3CA5A33C56A446DC42EFFF7C43D22E1AE6 ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
23:44:54.0278 0x1f2c  UmRdpService - ok
23:44:54.0354 0x1f2c  [ B8272BB8D4982C496FDC704809C38E02, F93855D932FB1DBBCC86E82C0FE0DC9ECF93BBD629D2CA9D0BE7E075E114B7FF ] UnistoreSvc    C:\WINDOWS\System32\unistore.dll
23:44:54.0504 0x1f2c  UnistoreSvc - ok
23:44:54.0564 0x1f2c  [ 6CDA3536F6BAB7896A57EAB7DC07F379, 8FBE6457ECD1ABB518D9800EBA8A017774FFAA8EABD2EDC0825181A12FE9AEF6 ] upnphost        C:\WINDOWS\System32\upnphost.dll
23:44:54.0657 0x1f2c  upnphost - ok
23:44:54.0679 0x1f2c  [ 6B46FC140C9AF68E6E7697D66D59CB4D, F018B4784D65F1A8140A6EA69C35D6A7ECE01738694052FD54AFD2B81A8F2FF8 ] UrsChipidea    C:\WINDOWS\System32\drivers\urschipidea.sys
23:44:54.0709 0x1f2c  UrsChipidea - ok
23:44:54.0730 0x1f2c  [ B4402E7F0923F660270442CE76877ABE, 1C2DD26EAB71F75EA576E8DAABAF71FD7DC3DF807CF025617C774CEF33C0B718 ] UrsCx01000      C:\WINDOWS\system32\drivers\urscx01000.sys
23:44:54.0761 0x1f2c  UrsCx01000 - ok
23:44:54.0781 0x1f2c  [ 9DD431F1B94789CFB527E5D19261F124, 8F5A249A97C5B14B282E3147DD21951D2AD34B651E762814C12F4C26D74EC70C ] UrsSynopsys    C:\WINDOWS\System32\drivers\urssynopsys.sys
23:44:54.0805 0x1f2c  UrsSynopsys - ok
23:44:54.0824 0x1f2c  [ 93F169DE94DBAC5DAF4755AFF10193DD, 381E6751EB97426B9BF30929E4B82A665D1ED985DA60BE18D3C17CF2BB41F848 ] usbaudio        C:\WINDOWS\system32\drivers\usbaudio.sys
23:44:54.0860 0x1f2c  usbaudio - ok
23:44:54.0881 0x1f2c  [ C87E32B90F085970D9637FBAD45EF6FE, C180EACD2EE479277DA5DBF39E43B428BD7945141B2451CB3946B0C1E495E76F ] usbccgp        C:\WINDOWS\System32\drivers\usbccgp.sys
23:44:54.0905 0x1f2c  usbccgp - ok
23:44:54.0922 0x1f2c  [ 0B663856474AC41924D9E9112203858F, 9E09F2A6279B48CAC09F8C7AA1F1BE02864D540C2ED1460CBA9FABCF0A546A1E ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
23:44:54.0937 0x1f2c  usbcir - ok
23:44:54.0953 0x1f2c  [ F83D2250256203AC5DA5E8601C1AFDD7, AC0D90E2DB3051798B9D287CF3D0E92FED4000822E65A82775A29CF896B76F04 ] usbehci        C:\WINDOWS\System32\drivers\usbehci.sys
23:44:54.0984 0x1f2c  usbehci - ok
23:44:55.0016 0x1f2c  [ 7FFD26742321919590ED77FCA556D65F, F7FAB63C36F8519F5A7B9091C507F3CB580C390322FAF9155CCE7F66C965B968 ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
23:44:55.0038 0x1f2c  usbhub - ok
23:44:55.0085 0x1f2c  [ 7A749B2863B5561BE34B39E8E249AD8F, E5B67DFAF5407007FD0CC408D6B4BA19DF59584819FC715E9F9E0FBF3EA00AAB ] USBHUB3        C:\WINDOWS\System32\drivers\UsbHub3.sys
23:44:55.0122 0x1f2c  USBHUB3 - ok
23:44:55.0138 0x1f2c  [ D2109F1F4FEBF1DAC415CDC5DE876479, C8A871EBD0E5EF004BA622A73DAC36C03608CD317FDCD0A6A98608DF4CC10D55 ] usbohci        C:\WINDOWS\System32\drivers\usbohci.sys
23:44:55.0169 0x1f2c  usbohci - ok
23:44:55.0185 0x1f2c  [ 29C9572F2D061CFC3C0BD48A3163E343, 2527DCC9E6D421F5DC40051C787A5270EB077746785465C9AA2A2AEEF47307D5 ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
23:44:55.0223 0x1f2c  usbprint - ok
23:44:55.0238 0x1f2c  [ 429477D6DEF3321FF7D3EF23CAAADA00, BB7D2AFE99736AAFFA8B0B2DABF7D6A6D5CB9563B1DE6A7E86CE7DC9D27F31C0 ] usbser          C:\WINDOWS\System32\drivers\usbser.sys
23:44:55.0269 0x1f2c  usbser - ok
23:44:55.0285 0x1f2c  [ 0CC16F7B91C57AE9A4E44425A295FDAA, 7CEE11955E5742DA390601F565412C14A7481B8747C495CCD246696C56B426DC ] USBSTOR        C:\WINDOWS\System32\drivers\USBSTOR.SYS
23:44:55.0318 0x1f2c  USBSTOR - ok
23:44:55.0323 0x1f2c  [ C917D09064CDBD18F75ADC9B2C48F847, A7F6223346CCD7E84186CD0C0715014F8E3A4398298925A43290224678620D23 ] usbuhci        C:\WINDOWS\System32\drivers\usbuhci.sys
23:44:55.0354 0x1f2c  usbuhci - ok
23:44:55.0370 0x1f2c  [ 95BCCEFBC40D06484CF16144FE79B8A5, 8ABA73C5FFEDD319FB96B807AD08716698E557522478DF1A2C5D662675636AE0 ] USBXHCI        C:\WINDOWS\System32\drivers\USBXHCI.SYS
23:44:55.0420 0x1f2c  USBXHCI - ok
23:44:55.0478 0x1f2c  [ 4CC81AB9D380A6264FF4C0C1512CF965, 76C33053D1C9155B0F3F8392FF982AD4EABEE2BBBEE89EA41DBFE8E436973EB0 ] UserDataSvc    C:\WINDOWS\System32\userdataservice.dll
23:44:55.0623 0x1f2c  UserDataSvc - ok
23:44:55.0685 0x1f2c  [ 8F6DAAFDDDA27D83ACC8C7FF1536CAF6, 5E1B67A5B388CBB3B193C238546BAD4DC5F5DF54859E16607A60681E6D38FA73 ] UserManager    C:\WINDOWS\System32\usermgr.dll
23:44:55.0786 0x1f2c  UserManager - ok
23:44:55.0823 0x1f2c  [ F4D8F67474DDA4FEF3935393AAA0173F, 5EB1700895E33972816DE4C2B920769CCE5580B83CAB8B2D7A8A6264F3A42B80 ] USER_ESRV_SVC_WILLAMETTE C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
23:44:55.0854 0x1f2c  USER_ESRV_SVC_WILLAMETTE - ok
23:44:55.0885 0x1f2c  [ C7CC4F8EA7FC1DE4221103B39360ABA0, 00B12186D731C3869022DCE763B243123D4E0B9BD0EA52AD9C95F9416F13FFD1 ] UsoSvc          C:\WINDOWS\system32\usocore.dll
23:44:55.0955 0x1f2c  UsoSvc - ok
23:44:55.0986 0x1f2c  [ FD0FC10A8CFD7AFEC58BBBE649BAA470, 9BDBD540FCF33FC01AB896D50A872E2FB5A007225FA003C528E6DCBDBEE19C25 ] VaultSvc        C:\WINDOWS\system32\lsass.exe
23:44:56.0002 0x1f2c  VaultSvc - ok
23:44:56.0055 0x1f2c  [ 87640B7EDD84E7F6D3C68A7BD2EB067B, 70AE7AAC17216C771908A1CFC0581F9C7DDC2D9C547A8D5203CFE73BF6216F09 ] VBoxDrv        C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys
23:44:56.0120 0x1f2c  VBoxDrv - ok
23:44:56.0124 0x1f2c  [ C42E4C5200CCDF94954215910A92ADD6, 3AE0BD3B7DEEAAD2411E87829ED931B7EC365534C141F688EB92FE8351AFC9F3 ] VBoxNetAdp      C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys
23:44:56.0156 0x1f2c  VBoxNetAdp - ok
23:44:56.0171 0x1f2c  [ 88DC4343B07D0CA1248D4F598ACD850C, 15BC2B76227ABA62F6CB3C76ADD576D8AA87FCF20F4555EA333FD1458EDB5AF9 ] VBoxNetLwf      C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys
23:44:56.0202 0x1f2c  VBoxNetLwf - ok
23:44:56.0223 0x1f2c  [ 5379DB8F681E7A91B3A454AA5153C31D, D935475CAA37374F8990B4F197300A379B2A931F3852C1DB61E7DF8332719520 ] VBoxUSBMon      C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys
23:44:56.0240 0x1f2c  VBoxUSBMon - ok
23:44:56.0256 0x1f2c  [ 0CBDE344FB48E42D78E29469F202ADBC, A1C3FBA5409DD3BBEAF1D3CE2583D6C8A621C0E4F534155EC540AFD67BC9E8CA ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
23:44:56.0271 0x1f2c  vdrvroot - ok
23:44:56.0303 0x1f2c  [ 0783EDE1FA94649ED7F3CEF6A734041A, 1A13A613EF6B67459031C7994FFC6F32F73E02E0F123A171618E4F011C635684 ] vds            C:\WINDOWS\System32\vds.exe
23:44:56.0372 0x1f2c  vds - ok
23:44:56.0387 0x1f2c  [ 723195568C8755CAD57F7933C5F2C5C2, 5C403799F67223605F825BC16D217C1EF5E1A0DDF00AC6380FE8976339B67D9B ] VerifierExt    C:\WINDOWS\system32\drivers\VerifierExt.sys
23:44:56.0425 0x1f2c  VerifierExt - ok
23:44:56.0472 0x1f2c  [ C12B4859FC255AA6B3021CF8BB14A11F, E95922351825D23ABCADD173E9256FC9AFFF28555DD1971CFF5666A2055958C5 ] vhdmp          C:\WINDOWS\System32\drivers\vhdmp.sys
23:44:56.0525 0x1f2c  vhdmp - ok
23:44:56.0541 0x1f2c  [ 7929228F0E8B0C2FA0495A17A4FC27F6, 1F1667B10A96B1D85ED165F62A5C0EF28C37F828B8280EA08BFCC1BAC03F2C90 ] vhf            C:\WINDOWS\System32\drivers\vhf.sys
23:44:56.0588 0x1f2c  vhf - ok
23:44:56.0603 0x1f2c  [ AEE432ED868831B1F068E373598F6D93, BAE91F47B0CB94B826CA010B490AD924D7B715911DF3FCE62F9165F3B571105C ] vmbus          C:\WINDOWS\system32\drivers\vmbus.sys
23:44:56.0640 0x1f2c  vmbus - ok
23:44:56.0658 0x1f2c  [ 9444B23FC694B5F90F21B0FC7F10D8DD, 86F92856F5C985DD8E5993B51E85E1F47EF8C9B2FB37468998C94266963BB4BD ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
23:44:56.0690 0x1f2c  VMBusHID - ok
23:44:56.0703 0x1f2c  [ 4D0287F566B36536DD812A54C015FC4A, 01D6508CA59CF04A47902B1F7C202FD14A81240E0B447588D919DD1072B040CF ] vmgid          C:\WINDOWS\System32\drivers\vmgid.sys
23:44:56.0721 0x1f2c  vmgid - ok
23:44:56.0737 0x1f2c  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll
23:44:56.0768 0x1f2c  vmicguestinterface - ok
23:44:56.0784 0x1f2c  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmicheartbeat  C:\WINDOWS\System32\icsvc.dll
23:44:56.0821 0x1f2c  vmicheartbeat - ok
23:44:56.0837 0x1f2c  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll
23:44:56.0884 0x1f2c  vmickvpexchange - ok
23:44:56.0906 0x1f2c  [ DC3172A6EB5DDB5EF94CB734CB7D4E63, 812971E0C2C18C876FFC9A46F1563801894C2EE9DD01CE1A641A0C68C0C1C6E2 ] vmicrdv        C:\WINDOWS\System32\icsvcext.dll
23:44:56.0937 0x1f2c  vmicrdv - ok
23:44:56.0953 0x1f2c  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmicshutdown    C:\WINDOWS\System32\icsvc.dll
23:44:56.0984 0x1f2c  vmicshutdown - ok
23:44:57.0006 0x1f2c  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmictimesync    C:\WINDOWS\System32\icsvc.dll
23:44:57.0038 0x1f2c  vmictimesync - ok
23:44:57.0053 0x1f2c  [ A6CA116884BE5352829D2E538AD56A87, 9C58A15E15433EA92E3DDB38BB446700BD620D43B0F46EDD578349676B4B4D76 ] vmicvmsession  C:\WINDOWS\System32\icsvc.dll
23:44:57.0085 0x1f2c  vmicvmsession - ok
23:44:57.0106 0x1f2c  [ DC3172A6EB5DDB5EF94CB734CB7D4E63, 812971E0C2C18C876FFC9A46F1563801894C2EE9DD01CE1A641A0C68C0C1C6E2 ] vmicvss        C:\WINDOWS\System32\icsvcext.dll
23:44:57.0153 0x1f2c  vmicvss - ok
23:44:57.0169 0x1f2c  [ 29075915F9BDC3437F8BED71C067D399, 2C7718080C11DFDD4C9A2085537F78F5633369B4A27D9C64168F0249594A4AA2 ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
23:44:57.0185 0x1f2c  volmgr - ok
23:44:57.0207 0x1f2c  [ 6BDB6CE6D2D9E3D3F28F1C97E12B62E2, 5E77D7AF858D7B90FF395F39B86D6F96413D1DDEA28BC9FB40C5524A4DF6DAD0 ] volmgrx        C:\WINDOWS\system32\drivers\volmgrx.sys
23:44:57.0238 0x1f2c  volmgrx - ok
23:44:57.0254 0x1f2c  [ BF2546583BB75F01DDA60A7921DFB230, 579BD0BC55F4F03CD8D1FCDAC3975A1649C688820F2F7FC1AD354132D9E3BEE9 ] volsnap        C:\WINDOWS\system32\drivers\volsnap.sys
23:44:57.0285 0x1f2c  volsnap - ok
23:44:57.0304 0x1f2c  [ AC2E20A74D09D24485BE8396CE04F07B, 23FCE8BEE01B89E5CDCA536D75DBA6DCE3E92E13178A66836CEB7829310A89D1 ] volume          C:\WINDOWS\system32\drivers\volume.sys
23:44:57.0307 0x1f2c  volume - ok
23:44:57.0323 0x1f2c  [ 04BEC879AD7B3FDDD0339B19FECB0160, 8C92755DDB41AD7DDA1643D7F32FAA0FCA7E2C65C69611EB5EC1B3276EA8DBC7 ] vpci            C:\WINDOWS\System32\drivers\vpci.sys
23:44:57.0354 0x1f2c  vpci - ok
23:44:57.0369 0x1f2c  [ FD9BCB8920973CEAD4D49DC7A6D8A618, 34AB4A485FB40DF737600006D8323BE927FB0BDA2BC170F4C123BE775EAE7CC8 ] vsmraid        C:\WINDOWS\system32\drivers\vsmraid.sys
23:44:57.0385 0x1f2c  vsmraid - ok
23:44:57.0438 0x1f2c  [ 01FFD5AF533F2CFDF26DDDC9313731C1, BFF0F2E57CD2358AC8F519F6F5692A46D97EC4E9B763D47101CEF31712FD4738 ] VSS            C:\WINDOWS\system32\vssvc.exe
23:44:57.0554 0x1f2c  VSS - ok
23:44:57.0570 0x1f2c  [ 99030F89DE0CFA7428A38D498CE5DDD7, 64E64962BC19047FC55EB73F007D25953E86D8DF0D6EA6D28E0BB47D5A50E8AF ] VSStandardCollectorService140 C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe
23:44:57.0585 0x1f2c  VSStandardCollectorService140 - ok
23:44:57.0607 0x1f2c  [ 0C111F220798CCE80484026E06822379, B98A5E44D3ABA67E6DE99E18BF3C2C606923E6269E262665C721F672ACBBED2A ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
23:44:57.0639 0x1f2c  VSTXRAID - ok
23:44:57.0654 0x1f2c  [ 607639716E9DB1CEF4E18B5B229293B4, 1D997177093F907EFE8A04AD10443BB9C355C0D7657DBD449E7EE7FCABC3ECBC ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
23:44:57.0686 0x1f2c  vwifibus - ok
23:44:57.0708 0x1f2c  [ B1ED64E628763148BF84FBE23F2AD711, 6182A39675E6049BC3DD353694720795A8E3D0331509AA8ABA4883D5C569AD5E ] vwififlt        C:\WINDOWS\system32\drivers\vwififlt.sys
23:44:57.0739 0x1f2c  vwififlt - ok
23:44:57.0755 0x1f2c  [ 59920894C38A827091A06AF559834E47, 8B40FE0B1BA3B2A79BFF70803D039DB921F85C978724722E5E5AFF188FA75471 ] vwifimp        C:\WINDOWS\System32\drivers\vwifimp.sys
23:44:57.0770 0x1f2c  vwifimp - ok
23:44:57.0804 0x1f2c  [ E7DE2794DF35F02868513D9594BF10FD, 89CB88814A5F7ACCFAC6FB5E3388B6922E1F8DCBB275531826DD04419BF74A7A ] W32Time        C:\WINDOWS\system32\w32time.dll
23:44:57.0855 0x1f2c  W32Time - ok
23:44:57.0870 0x1f2c  [ 55D00B785A7587F4263D125817871283, B92400B229099C1E243F2B149881A1423A2E9C8CA2D77D868B9B923BFDEC7FF2 ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
23:44:57.0903 0x1f2c  WacomPen - ok
23:44:57.0924 0x1f2c  [ 1483BE4D0135C378CB61D3CD73AB3E03, B7309C9E4F370860C507BF52D17234CDF4A7FAE95D2D822714E07EF5DEC0249B ] WalletService  C:\WINDOWS\system32\WalletService.dll
23:44:57.0971 0x1f2c  WalletService - ok
23:44:57.0986 0x1f2c  [ CEF3D306C09BEC1A800E9B4A06F859F6, 75D21F97E9F94FA97024F945AF512FEC94F88DD8073F3FAD92A6E0A9FDC586DB ] wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:44:58.0024 0x1f2c  wanarp - ok
23:44:58.0040 0x1f2c  [ CEF3D306C09BEC1A800E9B4A06F859F6, 75D21F97E9F94FA97024F945AF512FEC94F88DD8073F3FAD92A6E0A9FDC586DB ] wanarpv6        C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:44:58.0071 0x1f2c  wanarpv6 - ok
23:44:58.0124 0x1f2c  [ 30B8286F8FE1AE90A583100D45E02247, 3C86A4A5E21F9A1267EA231B20914E0A162BA4C25FE8917AD3AB6D504DA5BE0C ] wbengine        C:\WINDOWS\system32\wbengine.exe
23:44:58.0309 0x1f2c  wbengine - ok
23:44:58.0405 0x1f2c  [ 6BE945D6DE02713BAD8627205CDF9F48, F6548EAF5D67DA4682D8B31E5B565606DEAAB9276B44F25F1A4203AB61B9400B ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
23:44:58.0525 0x1f2c  WbioSrvc - ok
23:44:58.0557 0x1f2c  [ CD24DEEA22152524CCFE859591D12A57, C60ACF77647E5D6EDC10BBBCF974DF264145123C8EDB6506AFA9C949EBA53D7F ] wcifs          C:\WINDOWS\system32\drivers\wcifs.sys
23:44:58.0610 0x1f2c  wcifs - ok
23:44:58.0688 0x1f2c  [ 32960EA9CF836D7DD77767DCB68CE230, 679446A4FAB0331C181D2716CAEA225267C6164BB9867E360C5B3D6AB1083195 ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
23:44:58.0873 0x1f2c  Wcmsvc - ok
23:44:58.0942 0x1f2c  [ D50645235A507B0546B1B5CF7D0B8849, 19F5FE10C953B8EE8EEDA9A9F7F2E97AA193BB085E7FC364066686089ADD1C9F ] wcncsvc        C:\WINDOWS\System32\wcncsvc.dll
23:44:59.0042 0x1f2c  wcncsvc - ok
23:44:59.0073 0x1f2c  [ AEA1093B751339267D8C8C1EF3D669CF, 8F3325E7FB16BD856A0593C36F2E3E018909038C52CD5F92E116E0C1366F31CB ] wcnfs          C:\WINDOWS\system32\drivers\wcnfs.sys
23:44:59.0127 0x1f2c  wcnfs - ok
23:44:59.0158 0x1f2c  [ D520B1B849B6D4D707AB31722B952C2D, 149BABB7BD63C1F212ADD9306C84FFB2A5CE6DC435BD3213EAB787E9B222C61F ] WdBoot          C:\WINDOWS\system32\drivers\WdBoot.sys
23:44:59.0189 0x1f2c  WdBoot - ok
23:44:59.0274 0x1f2c  [ 5030C76047D756263093A47B82970868, E772F15973F6DE36851DD230F1F4190746CD81CA1E7284DC074711C4BF45CAF0 ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
23:44:59.0358 0x1f2c  Wdf01000 - ok
23:44:59.0412 0x1f2c  [ 29FF9199EDEB4F5470BB134D1A2563D2, 94713F98A6EA6042203D5DD0DE6758F5F0F331F7D4BB05E91EF20CEEEBD6780F ] WdFilter        C:\WINDOWS\system32\drivers\WdFilter.sys
23:44:59.0468 0x1f2c  WdFilter - ok
23:44:59.0512 0x1f2c  [ E7A7E8803E66B7CCED95D327A4DBC135, 401ECD953D4014A95C9022822D9ACEC1A68C917281DBA2365503A473FC6D9507 ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
23:44:59.0590 0x1f2c  WdiServiceHost - ok
23:44:59.0612 0x1f2c  [ E7A7E8803E66B7CCED95D327A4DBC135, 401ECD953D4014A95C9022822D9ACEC1A68C917281DBA2365503A473FC6D9507 ] WdiSystemHost  C:\WINDOWS\system32\wdi.dll
23:44:59.0712 0x1f2c  WdiSystemHost - ok
23:44:59.0812 0x1f2c  [ 373DF27CD5D5E50FFA2A90FEE0C0D994, 09E6C6C690AEE1C1A9A84BBA87A934040B2A20F677E5F5B2D24F8433B61BD81E ] wdiwifi        C:\WINDOWS\system32\DRIVERS\wdiwifi.sys
23:45:00.0018 0x1f2c  wdiwifi - ok
23:45:00.0086 0x1f2c  [ EFCC801981E66DBF5193149817569FF4, 4FCDC89EB38A0AB349C403678BEC07383CC7C942955468827CCAC462F6BA2AE9 ] wdm_usb        C:\WINDOWS\system32\DRIVERS\usb2ser.sys
23:45:00.0171 0x1f2c  wdm_usb - ok
23:45:00.0221 0x1f2c  [ 17CF416CFF408190F5A4CBD79AB12E55, E376C8865C7EA633AE20D2CF940E4C7584AC783BAAF7941780FB6C4C84802F33 ] WdNisDrv        C:\WINDOWS\system32\Drivers\WdNisDrv.sys
23:45:00.0292 0x1f2c  WdNisDrv - ok
23:45:00.0327 0x1f2c  WdNisSvc - ok
23:45:00.0399 0x1f2c  [ 3570C4E14F85CE0B537D126727ACA91C, A474C9E6B6E4E5945C63367C1D3D24D4782C4A4FEB00FAE15DFED099D8283078 ] WebClient      C:\WINDOWS\System32\webclnt.dll
23:45:00.0526 0x1f2c  WebClient - ok
23:45:00.0582 0x1f2c  [ 1785F9C96A0BDEC1F6E0C79EF412F342, D6D4EDA69457BEDDA69C2F60FC4C2FAC97D46CD8E9C1804CCD68F169383583E3 ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
23:45:00.0700 0x1f2c  Wecsvc - ok
23:45:00.0746 0x1f2c  [ B9175D63527B05131F2FA504CF0265F2, 1E43A17788F1B6A29E2889C81E0BE100D64BD3A9DEE7C154D9581F01D2D7D05F ] WEPHOSTSVC      C:\WINDOWS\system32\wephostsvc.dll
23:45:00.0833 0x1f2c  WEPHOSTSVC - ok
23:45:00.0878 0x1f2c  [ 5C58EC0C9D4DE04DCDE56F6DCEA62080, 8ED386EDF4C39C339CE0BB2AC7E199C38705E5A6B3F56A4987B9A8ABD19BB59F ] wercplsupport  C:\WINDOWS\System32\wercplsupport.dll
23:45:00.0978 0x1f2c  wercplsupport - ok
23:45:01.0031 0x1f2c  [ F899B355CC95AF26AB36E84E8A0DD685, C400F2F80FFF6473FEF066943C4A2AFF0FFE988A4F755757A2E5005C2A10DAD8 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
23:45:01.0130 0x1f2c  WerSvc - ok
23:45:01.0183 0x1f2c  [ E1785942AC51FEE6826CDF02075C5AA9, 56FE7017684086F4F9C3A2C0D3AC00369BA0938BA3987EEBEE9A75B8E3CA0AE1 ] WFPLWFS        C:\WINDOWS\system32\drivers\wfplwfs.sys
23:45:01.0241 0x1f2c  WFPLWFS - ok
23:45:01.0281 0x1f2c  [ B154618505A6A9026EFA6AB8C4123BF1, 713648D71AA027B4472E7E75B942630DBE7383687984B02A5E99C9E4192C95EB ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
23:45:01.0346 0x1f2c  WiaRpc - ok
23:45:01.0382 0x1f2c  [ 0CF79A0EACFFBB75A50A469A27696D02, E112BF7B5A8D0B0AD2EA0E7B9FD4E8CFEC9371C8E94A60248292D688AFE715C4 ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
23:45:01.0429 0x1f2c  WIMMount - ok
23:45:01.0459 0x1f2c  WinDefend - ok
23:45:01.0561 0x1f2c  [ 0DE131733317EB4BE67028366B0CAAC6, AC7DADBF03A3752B4D33CA19F03DBCEDD6F56893C2DA25C98B0AB07063D990E3 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
23:45:01.0610 0x1f2c  WindowsTrustedRT - ok
23:45:01.0646 0x1f2c  [ 92EB5D38BDF10C790450F3E46BF93A0E, 0FC027398DBD43EDC1F7D703C0B6DB20294DF34E67C9288442039B1A5663CE1B ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
23:45:01.0687 0x1f2c  WindowsTrustedRTProxy - ok
23:45:01.0770 0x1f2c  [ C9E7D91A044B77CBCB4121C06610A86C, 9FF039D67A5CE4732920EA4F1F5CFD9DE0AAADC34829A007EA697030D42D3623 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
23:45:01.0914 0x1f2c  WinHttpAutoProxySvc - ok
23:45:01.0947 0x1f2c  [ F95DE20312ACCA7761446DE152BD1F7C, F6C5ACA500C2182437F4A7402BD81C3A2B77C0BBD78BA31FB574DC1997FCBFE6 ] WinMad          C:\WINDOWS\System32\drivers\winmad.sys
23:45:01.0987 0x1f2c  WinMad - ok
23:45:02.0032 0x1f2c  [ CD49CA8E3280ACEEC5ECF431A59F5EFD, 75F48EFC6DEE9E06B490703EE47602AFDEA51505285B02D2CF884601E71857CC ] Winmgmt        C:\WINDOWS\system32\wbem\WMIsvc.dll
23:45:02.0106 0x1f2c  Winmgmt - ok
23:45:02.0279 0x1f2c  [ F86E9029774478D276E0AAB7D169896D, EDCB96F745E1F16BDFF70B140B38412096FA29A407157183223AE6111CBB4B38 ] WinRM          C:\WINDOWS\system32\WsmSvc.dll
23:45:02.0637 0x1f2c  WinRM - ok
23:45:02.0714 0x1f2c  [ 4EFB346BFDAEEB29316AA52BBB9852B1, 4BC5554F44BD9549D0A929D77BD410FA3EB502A7D0170303D369268672505494 ] WINUSB          C:\WINDOWS\System32\drivers\WinUSB.SYS
23:45:02.0761 0x1f2c  WINUSB - ok
23:45:02.0789 0x1f2c  [ 8B9AFF5F08E66A6F1F1063DEC9457FB6, 98F2AF6988D125521FD34CAA48B9652922F0C8ECFAE9B0C1DF4B3CE6B9CF500F ] WinVerbs        C:\WINDOWS\System32\drivers\winverbs.sys
23:45:02.0827 0x1f2c  WinVerbs - ok
23:45:02.0881 0x1f2c  [ 4D694EDF85F1BFC463B15846D4E00A9B, 4ED44C0E22D2843121E4C8A58F97B526BB7D85C0D7A0BB4B1158A970258C791E ] wisvc          C:\WINDOWS\system32\flightsettings.dll
23:45:02.0991 0x1f2c  wisvc - ok
23:45:03.0105 0x1f2c  [ B155B02AFF09DEFBC7FC8B359747B2C3, 6F759629305B4BDF08FC9C99C8EE3F328D87E8703819D98E1452D6A9F5D9896C ] WlanSvc        C:\WINDOWS\System32\wlansvc.dll
23:45:03.0253 0x1f2c  WlanSvc - ok
23:45:03.0338 0x1f2c  [ 7A98AF088E0B1A5EB98863B14F493716, 8B2F8D02AC0637C72859AF29C05C01D7D1C81C6A15CBE2D579F27F3254E66076 ] wlidsvc        C:\WINDOWS\system32\wlidsvc.dll
23:45:03.0556 0x1f2c  wlidsvc - ok
23:45:03.0575 0x1f2c  [ 6F4F4F5A007D1710BD76FB311DA97C07, FC0FEA4364F6BA4E31DBC82735D09D429CA3BE9AFCFF5D5E1263D8B27FC2CE3E ] WmiAcpi        C:\WINDOWS\System32\drivers\wmiacpi.sys
23:45:03.0601 0x1f2c  WmiAcpi - ok
23:45:03.0643 0x1f2c  [ 3CDDFF6CAD962C5EF1C52FD667C358B6, F6F09145E9461EB17172988D26749FCF36920A1A683459334D04A6D072B31A92 ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
23:45:03.0677 0x1f2c  wmiApSrv - ok
23:45:03.0694 0x1f2c  WMPNetworkSvc - ok
23:45:03.0706 0x1f2c  [ EDADABA8665AB5C51BF59C4E2566BA7E, C85337881856B466F61DFA1E69FC2FD8250085D299A5DE052BFA80C83FD5EFD0 ] Wof            C:\WINDOWS\system32\drivers\Wof.sys
23:45:03.0737 0x1f2c  Wof - ok
23:45:03.0822 0x1f2c  [ 909CB4BBF7B08E78C363000E09E79A6F, 217205D1B5EE03274AFF9405AED6D2A5665CBA4C3876E84B53DA44920CDF9CB1 ] workfolderssvc  C:\WINDOWS\system32\workfolderssvc.dll
23:45:03.0985 0x1f2c  workfolderssvc - ok
23:45:04.0007 0x1f2c  [ F02930EB91596042F2221397D60AFCE5, 10E2AB0993B67CBAA9E11C68280608965064EC9F7E0C570F5B453FACADB8AB5D ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
23:45:04.0101 0x1f2c  WPDBusEnum - ok
23:45:04.0122 0x1f2c  [ 75A9284F01FE7CB1A7D5EAE5C1EB4F33, 390EF23AEA06D8711555F7979FF8BE0620B53C1A551638C4EC6FB7C6678965B3 ] WpdUpFltr      C:\WINDOWS\system32\drivers\WpdUpFltr.sys
23:45:04.0171 0x1f2c  WpdUpFltr - ok
23:45:04.0197 0x1f2c  [ 60E2EB3E7B7F15C25E02462159F90707, D8344B529EEC0D4922CAC3E6897CC9F191ACF1376017BE38ED6BF6019F1ED181 ] WpnService      C:\WINDOWS\system32\WpnService.dll
23:45:04.0274 0x1f2c  WpnService - ok
23:45:04.0295 0x1f2c  [ C7C91FB86A3C6CD7619725A88ED1884C, 132C43C518F37BF303D768BD5FB0AB835F693C43FE693937D804A34E940D770F ] WpnUserService  C:\WINDOWS\System32\WpnUserService.dll
23:45:04.0371 0x1f2c  WpnUserService - ok
23:45:04.0398 0x1f2c  [ 36D7B73ADC3E10607ED6EC874AFB5D1E, 1737B3E4D2CA76BB27903BF460E4960E6A0BC32D35069AC7C5E4B07F625F3282 ] ws2ifsl        C:\WINDOWS\system32\drivers\ws2ifsl.sys
23:45:04.0461 0x1f2c  ws2ifsl - ok
23:45:04.0478 0x1f2c  [ 519806FBCF00A0B17B8E03297DB0F551, 1911EA7168B06DBF3D36833120E4731437BF1ACC294C289B132C50280A40F548 ] wscsvc          C:\WINDOWS\System32\wscsvc.dll
23:45:04.0540 0x1f2c  wscsvc - ok
23:45:04.0554 0x1f2c  [ 696EC2EAA2A42A137CCBB9A84D6917C0, 424089F4F373962AF8357C5D4D43F35948989BE3F58EAD3690F565F4C1BBC66F ] WSDPrintDevice  C:\WINDOWS\System32\drivers\WSDPrint.sys
23:45:04.0596 0x1f2c  WSDPrintDevice - ok
23:45:04.0609 0x1f2c  [ 46E4A69825A7554A5DB784A55F8AD203, 7F347054FCDD5DEF93083D420E56EBE5EEBBAE2BD2FED9B2E75E85149DE52780 ] WSDScan        C:\WINDOWS\system32\DRIVERS\WSDScan.sys
23:45:04.0644 0x1f2c  WSDScan - ok
23:45:04.0656 0x1f2c  WSearch - ok
23:45:04.0681 0x1f2c  [ 72B4E9DF6456C43C42A1419B09486045, 536BA7377B5BEA7EA46864453933111DB88DB8FB689C68915ACD7261A996E61D ] wsvd            C:\WINDOWS\system32\DRIVERS\wsvd.sys
23:45:04.0696 0x1f2c  wsvd - ok
23:45:04.0765 0x1f2c  [ DB38A10568D01CCCDA442C8F52EDF657, C48AE43F8AE22B1A68E73E452C09CE8913885A549DCD33D017A16350AEA5EAB5 ] wuauserv        C:\WINDOWS\system32\wuaueng.dll
23:45:04.0915 0x1f2c  wuauserv - ok
23:45:04.0946 0x1f2c  [ AED7FE551E8672B824A56324076183EB, FFE543AAEFDEFFE6B20C244DB141A9425BDA88ED36F4870F0B70FEC433BDF0C1 ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
23:45:04.0968 0x1f2c  WudfPf - ok
23:45:04.0999 0x1f2c  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFRd          C:\WINDOWS\System32\drivers\WUDFRd.sys
23:45:05.0031 0x1f2c  WUDFRd - ok
23:45:05.0046 0x1f2c  [ 47F6450F28BAA32B2AB0D6BE00996249, C8A47D6ADF89AD613AB685C6224B9099DCEFDCD8ABCF703542AFDC356404116E ] wudfsvc        C:\WINDOWS\System32\WUDFSvc.dll
23:45:05.0078 0x1f2c  wudfsvc - ok
23:45:05.0091 0x1f2c  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFWpdFs      C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
23:45:05.0098 0x1f2c  WUDFWpdFs - ok
23:45:05.0114 0x1f2c  [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFWpdMtp      C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
23:45:05.0129 0x1f2c  WUDFWpdMtp - ok
23:45:05.0176 0x1f2c  [ 42DF36725C1B28EF40F94363BA9213ED, 87F7355FEF000326BFFC9ED24D6E32D05F36A549779A1D319603F94E6D8223FD ] WwanSvc        C:\WINDOWS\System32\wwansvc.dll
23:45:05.0245 0x1f2c  WwanSvc - ok
23:45:05.0261 0x1f2c  [ 38DDEB2AFE7D72B43DB116DACBFB97CD, 516368980793E22034298CA9C800D1AAD5B89979771182B74EB6E5FBC8BA1016 ] XblAuthManager  C:\WINDOWS\System32\XblAuthManager.dll
23:45:05.0314 0x1f2c  XblAuthManager - ok
23:45:05.0346 0x1f2c  [ 765FF96467A26C4C03281ECA426EC2D9, 2526B03C518D72F429C29BA4D4F11707AF277BF71520A1A92238A932950AE161 ] XblGameSave    C:\WINDOWS\System32\XblGameSave.dll
23:45:05.0399 0x1f2c  XblGameSave - ok
23:45:05.0415 0x1f2c  [ 59335CEA021FB89E07AD5DB5D17F09D0, 33FEFD5798BFA306FBEDCC8F2D0D984B6546A61B5026E921A8AC0466ADF2B698 ] xboxgip        C:\WINDOWS\System32\drivers\xboxgip.sys
23:45:05.0430 0x1f2c  xboxgip - ok
23:45:05.0461 0x1f2c  [ 335E6F2BE58523B295945C840C185B00, 94ED7E2CB212A3D55B8A2CB90CD1D02A6AF92DC0DDD487CB5B7CAC9883343460 ] XboxNetApiSvc  C:\WINDOWS\system32\XboxNetApiSvc.dll
23:45:05.0515 0x1f2c  XboxNetApiSvc - ok
23:45:05.0515 0x1f2c  [ 864F4209B03BE4267DDE09B067A165CA, C6751CB80940F320A742C38295E4FEEC85F99BE7D6C564AC5F5068E85A82421D ] xinputhid      C:\WINDOWS\System32\drivers\xinputhid.sys
23:45:05.0531 0x1f2c  xinputhid - ok
23:45:05.0546 0x1f2c  [ 17BFB2EE1B300127071ED386E9B8F47D, E485768AD6B356DAF565A958BB8E4DCFD6C2BF69D7938EFE065A99E81993F36F ] ymc            C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
23:45:05.0577 0x1f2c  ymc - ok
23:45:05.0577 0x1f2c  [ D4518D2080B3D29FCCDFAEC61529F537, 4941F4835283BD7F7A66F7C19501D7A6BB38C54C90EF59437681D7F02AAA385D ] YogaPicks.AppService C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
23:45:05.0678 0x1f2c  YogaPicks.AppService - ok
23:45:05.0968 0x1f2c  [ B429532039BAFD4A68AF0E7BC4CED6F8, 7CE6191793D3F58655F58CC2B0D201429AD883272E6565314B3F7B015B042076 ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
23:45:06.0298 0x1f2c  ZeroConfigService - ok
23:45:06.0357 0x1f2c  [ DA4878DF031FE6009D79BA758D4D5BAC, E1805A1657BD57CBDA2F5262B14710A39920D7FE481A6A2A546BCD15E8D68AAE ] ziphost        c:\program files\ziptool\ziphost.dll
23:45:06.0529 0x1f2c  ziphost - ok
23:45:06.0615 0x1f2c  [ D607CAF42E620BB80BFAE4D8D0644AD6, 8E203F0257773DB3EC30A45BEF707399E96A7AA80B97AEF25EFE91F61F707668 ] ZipProtect      c:\program files\ziptool\ZipProtect64.sys
23:45:06.0704 0x1f2c  ZipProtect - ok
23:45:06.0708 0x1f2c  ================ Scan global ===============================
23:45:06.0726 0x1f2c  [ 0C710DB449712EE13ACE733695DB7780, BBC7875B38D318CE4E88979D083AC72E8993254A466A8A6882DDE9E0C3B687A3 ] C:\WINDOWS\system32\basesrv.dll
23:45:06.0754 0x1f2c  [ 1FEF9536BA2779E2F3CB524E34BAC715, 6387C7E2FD538EFD9AC19B622AEC81F6F924576FDAB6F003AF5B6CBD33F6A379 ] C:\WINDOWS\system32\winsrv.dll
23:45:06.0785 0x1f2c  [ 1EE06E957B0B2CA52D26DA7861E160EF, 4B743A1C7010138F5F6684BBCF7CAD6FD05F49920BDD3FDB776347AA6B44AB94 ] C:\WINDOWS\system32\sxssrv.dll
23:45:06.0840 0x1f2c  [ 133390D061D94917125DC666DA67ECD0, 69D6FFF3E0A0C4D77A62B4D71E1E3A8D10D93C46782A1B05F0EC4B8919C384B9 ] C:\WINDOWS\system32\services.exe
23:45:06.0877 0x1f2c  [ Global ] - ok
23:45:06.0879 0x1f2c  ================ Scan MBR ==================================
23:45:06.0887 0x1f2c  [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
23:45:07.0023 0x1f2c  \Device\Harddisk0\DR0 - ok
23:45:07.0024 0x1f2c  ================ Scan VBR ==================================
23:45:07.0031 0x1f2c  [ 99C094ABF141497EF8D991DB057D58BC ] \Device\Harddisk0\DR0\Partition1
23:45:07.0036 0x1f2c  \Device\Harddisk0\DR0\Partition1 - ok
23:45:07.0045 0x1f2c  [ E9E0A1205F3060EAA0D1BCD47064CF63 ] \Device\Harddisk0\DR0\Partition2
23:45:07.0048 0x1f2c  \Device\Harddisk0\DR0\Partition2 - ok
23:45:07.0058 0x1f2c  [ DE5C1ABFDD2E9EB44970C5365B48273E ] \Device\Harddisk0\DR0\Partition3
23:45:07.0061 0x1f2c  \Device\Harddisk0\DR0\Partition3 - ok
23:45:07.0071 0x1f2c  [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition4
23:45:07.0072 0x1f2c  \Device\Harddisk0\DR0\Partition4 - ok
23:45:07.0085 0x1f2c  [ FEC425992E95F49203BECF108296B085 ] \Device\Harddisk0\DR0\Partition5
23:45:07.0091 0x1f2c  \Device\Harddisk0\DR0\Partition5 - ok
23:45:07.0100 0x1f2c  [ FDC4821B62D9AD53B052C7820DC8FFAA ] \Device\Harddisk0\DR0\Partition6
23:45:07.0108 0x1f2c  \Device\Harddisk0\DR0\Partition6 - ok
23:45:07.0117 0x1f2c  [ FA84D1E11286E87CEE878879AAC377A1 ] \Device\Harddisk0\DR0\Partition7
23:45:07.0123 0x1f2c  \Device\Harddisk0\DR0\Partition7 - ok
23:45:07.0125 0x1f2c  ================ Scan generic autorun ======================
23:45:07.0141 0x1f2c  [ 92BED6F62FBAC9E327A3BF599CE9AB32, 6ED9BB1B97AB0BDC64CE07FB8757651A83C918320320B84AB823933B8ACFDEB6 ] C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe
23:45:07.0190 0x1f2c  DptfPolicyLpmServiceHelper - ok
23:45:08.0239 0x1f2c  [ 2A7EAF9A5DCC6DF4DFA1162AE69A2AA7, DA2BEC60E08748774B38B727FF83850B64F8C39A17FD7559EE8318683C2E672E ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
23:45:09.0421 0x1f2c  RtHDVCpl - ok
23:45:09.0530 0x1f2c  [ 2BFBD5FB7B6EFFF59AD79BB8A8796926, BBD0BC11B9BAA0691BAAE7C7960F51183A6D5ACD322B7092E436900FA495FBDB ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
23:45:09.0656 0x1f2c  RtHDVBg_Dolby - ok
23:45:09.0997 0x1f2c  [ 6546BB9B4B32BE17C66479EBCF6F34BF, 79FF9DD229C8218499FE10ECE258CCAFF3FF258790840769948E4D05B017E9B8 ] C:\WINDOWS\RTFTrack.exe
23:45:10.0408 0x1f2c  RtsFT - ok
23:45:10.0426 0x1f2c  [ 4A0477ADCD07EC9D21257A2E456B16C5, CEF9C81730C12283A7600C3D921D89A62B14D1C46544B493F3AF7520DD2D1F79 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
23:45:10.0461 0x1f2c  IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
23:45:10.0616 0x1f2c  Detect skipped due to KSN trusted
23:45:10.0616 0x1f2c  IAStorIcon - ok
23:45:10.0662 0x1f2c  [ 5689BB0DB40DC712CC87A4F27925F939, 57164AEC7101BBB1E1321B1BD8CF91453F4A9AC549851885087B42E23D777DB2 ] C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe
23:45:10.0728 0x1f2c  Yoga PhoneCompanion - ok
23:45:10.0747 0x1f2c  [ 7ECEA25EAF0AE3333FF5B4449FBDB6D4, 2C35D9F85A968F4305B945D66B234955BA7F9D4A8FCBEAF085313E3413CC1C0F ] C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
23:45:10.0780 0x1f2c  AutoStartTransition - ok
23:45:10.0785 0x1f2c  Energy Manager - ok
23:45:10.0795 0x1f2c  [ ACFA436C851BC9204A6E2B8EBC8B888D, F895E7A77C2C04E61FD8D09909E08172FFEBF039D6DCF7C3D84FF1992D5FFFD3 ] C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe
23:45:10.0814 0x1f2c  Lenovo Utility - ok
23:45:10.0834 0x1f2c  [ 9602CE3F53844065AD38CC5F355E19DF, EA3109B8C733462E2F097C8582E299864ADC9904EF17CBA417006006E8E1D14E ] C:\WINDOWS\system32\flvga_tray.exe
23:45:10.0880 0x1f2c  flvga_tray64 - detected UnsignedFile.Multi.Generic ( 1 )
23:45:11.0107 0x1f2c  flvga_tray64 ( UnsignedFile.Multi.Generic ) - warning
23:45:11.0236 0x1f2c  [ 20C08CA080F650B730B1E3FDEA9AD532, 1D2B0914412378E0B5834A95BDD86F8927B6A8D37F4E044C904CE381F1C19A75 ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
23:45:11.0275 0x1f2c  AdobeAAMUpdater-1.0 - ok
23:45:11.0276 0x1f2c  SynTPEnh - ok
23:45:11.0280 0x1f2c  WindowsDefender - ok
23:45:11.0290 0x1f2c  [ C7645D43451C6D94D87F4D07BDE59C89, 495BBA47FC43EE23054FCD419F2F00457162D1C04296900C6AEA551102A810F3 ] C:\Windows\system32\rundll32.exe
23:45:11.0351 0x1f2c  Logitech Download Assistant - ok
23:45:11.0352 0x1f2c  SpaceSoundPro - ok
23:45:11.0374 0x1f2c  [ 6867EC437947A1DA443A1068B82FB8CD, 2428AA0ED8939346EBFB1C744BCA1064E4A429737C04B226C4264F24716E4856 ] C:\Program Files (x86)\mpck\otutnetwork.exe
23:45:11.0406 0x1f2c  OTUTPRODUCT_GKHNN - detected UnsignedFile.Multi.Generic ( 1 )
23:45:11.0485 0x1f2c  Detect turned to UDS exact due to KSN untrusted
23:45:11.0485 0x1f2c  OTUTPRODUCT_GKHNN ( UDS:DangerousObject.Multi.Generic ) - infected
23:45:11.0485 0x1f2c  Force sending object to P2P due to detect: C:\Program Files (x86)\mpck\otutnetwork.exe
23:45:11.0732 0x1f2c  Object send P2P result: true
23:45:11.0878 0x1f2c  [ 58D4F708D35E07139D62F32A31FAE7AE, 45C6E4ED441B655BB0185689CEB57EFCFF0F00970C074534BC05A4B43448F17F ] C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe
23:45:11.0878 0x1f2c  Yoga Picks - ok
23:45:11.0894 0x1f2c  [ 4E9AF25BA5E8219310E384AEA5B0EED8, 743062F755E7A88BA394E96CA26A988CCFDF73B441B779B3149D54A769CBC411 ] C:\Program Files (x86)\Cyberlink\Power2Go8\CLMLSvc_P2G8.exe
23:45:11.0911 0x1f2c  CLMLServer_For_P2G8 - ok
23:45:11.0931 0x1f2c  [ DD68093E7697D02FD019EC7FD4DBC1B1, 17D873A48F443DBA91956747ED76E4E12EDB2C569345A8DC28EAF4FDB1CF1E34 ] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe
23:45:11.0947 0x1f2c  CLVirtualDrive - ok
23:45:11.0963 0x1f2c  Dropbox - ok
23:45:12.0210 0x1f2c  [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe
23:45:12.0680 0x1f2c  OneDriveSetup - ok
23:45:13.0240 0x1f2c  [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe
23:45:13.0959 0x1f2c  OneDriveSetup - ok
23:45:13.0981 0x1f2c  Waiting for KSN requests completion. In queue: 117
23:45:15.0028 0x1f2c  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.0 ), 0x61100 ( enabled : updated )
23:45:15.0043 0x1f2c  Win FW state via NFP2: enabled ( trusted )
23:45:15.0221 0x1f2c  ============================================================
23:45:15.0221 0x1f2c  Scan finished
23:45:15.0221 0x1f2c  ============================================================
23:45:15.0245 0x1d20  Detected object count: 5
23:45:15.0245 0x1d20  Actual detected object count: 5

danach ist der pc wieder abgestürzt, blue screen, beim Starten kam die Meldung:

"your pc/device needs to be repaired.
the operating system couldnt be laoded because a critical system driver is missing or contains errors.

file:\\WINDOWS\system32\drivers\38963701.sys
Error code: 0x000007b

You'll need to use recovery tools ..."

cosinus 17.08.2016 08:59

Bootet Windows jetzt garnicht mehr?

Piristibulus 17.08.2016 10:59

Ja, es bootet nicht mehr (direkt).
Ich bekomme einen Bildschirm mit der Meldung:

"Recovery
Your PC/Device needs to be repaired

The operating system couldn't be loaded because a critical system driver is missing or contains errors.

File:\\WINDOWS\system32\drivers\38963701.sys
Error code 0x000007b

You'll need to use recovery tools. If you don't have any installation media (like a CD rom or USB device), contact your PC aministrator or PC/Device manufacturer

Press Enter to try again
Press F8 for Start-Up Settings
Press Esc for UEFI Firmware settings"

Einen USB Recovery Stick hab ich leider nicht.

Mit Esc komme ich ins Boot-Menu

Bei F8 bekomme ich folgende Auswahl (wählbar mit Funktionstasten oder Zahlblock):

1) Enable debugging
2) Enable boot logging
3) Enable low-resolution video
4) Enable Safe mode
5) Enable Safe mode with networking
6) Enable Safe mode with command prompt
7) Disable driver signature enforcement
8) Disable early launch anti-malware protection
9) Disable automatic restart after failure

cosinus 17.08.2016 11:39

Dann wurde dein System schon zu stark durch die malware beschädigt. Ob du jetzt unbedingt ein kaputtes System reparieren willst um es danach noch weiter zu bereinigen musst du wissen, ich halte das für baren Unfug, dann lieber Daten sichern und sauber neu installieren.

Piristibulus 17.08.2016 11:51

Ich denke, sichern und sauber neu installieren ist besser.

Fragt sich nur, wie ich das mache.
Ich habe einige Dateien im Dokumenten-Ordner etc., wie ziehe ich mir die auf eine externe Festplatte?

Ich habe den Key für meine Win 10 Installation - vermutlich kann ich mir da über das Internetz einen Bootstick erstellen.

Aber was ist mit den Lenovo-eigenen Treibern? Hierzu habe ich leider keinen Recovery-Stick oder ähnliches.
Auf dem Laptop ist eine Partition D mit Lenovo-Daten.

Wie gehe ich hier am besten vor?

Und - ich habe auf dem Rechner Thunderbird, one-Drive, Dropbox u.ä. - soll ich hier besser die Passwörter für alles (Email etc., Amazon (war grad in Firefox eingeloggt, als es losging)) ändern? Wie sehr muss ich mir sorgen machen, dass die Malware Dateien in Dropbox und Onedrive verändert hat?

Danke und LG,
Piristibulus

cosinus 17.08.2016 12:55

Zitat:

Zitat von Piristibulus (Beitrag 1604884)
Ich denke, sichern und sauber neu installieren ist besser.

Fragt sich nur, wie ich das mache.

Live-Linux verwenden zB Ubuntu MATE im Ausprobiermodus. Dann alle Daten der Windows-Filesysteme auf ne externe Platte oder Stick kopieren.


Zitat:

Zitat von Piristibulus (Beitrag 1604884)
Ich habe den Key für meine Win 10 Installation - vermutlich kann ich mir da über das Internetz einen Bootstick erstellen.

Den wirst du wohl nicht brauchen, da für dieses System Windows 10 doch schonmal aktiviert war. Microsoft speichert die Aktivierung bei Windows 10 online und erkennt einen neu installierten Rechner auf dem schonmal W10 lief und auch aktiviert war. Hab ich bereits mehrmals gesehen und kann ich definitiv so bestätigen.


Zitat:

Zitat von Piristibulus (Beitrag 1604884)
Aber was ist mit den Lenovo-eigenen Treibern? Hierzu habe ich leider keinen Recovery-Stick oder ähnliches.
Auf dem Laptop ist eine Partition D mit Lenovo-Daten.

Ja und? :wtf:
Wenn was fehlt kann man immer noch bei Bedarf runterladen. Was wohl aber nur in Ausnahmefällen notwendig sein wird. W10 ist da schon sehr gut und selbstständig was das Holen/Installieren (richtiger) Treiber angeht.


Zitat:

Zitat von Piristibulus (Beitrag 1604884)
Wie gehe ich hier am besten vor?

Siehe oben. Lass und unbedingt die Flossen von Schlangenöl wie Treiber-Update-Wundertools. Windows macht es zu 99% selbst richtig.


Zitat:

Zitat von Piristibulus (Beitrag 1604884)
Und - ich habe auf dem Rechner Thunderbird, one-Drive, Dropbox u.ä. - soll ich hier besser die Passwörter für alles (Email etc., Amazon (war grad in Firefox eingeloggt, als es losging)) ändern? Wie sehr muss ich mir sorgen machen, dass die Malware Dateien in Dropbox und Onedrive verändert hat?

Ja von einem sauberen System aus sind alle Passwörter zu ändern-

Piristibulus 17.08.2016 13:00

Vielen Dank!!!

Hast Du hierzu evtl. auch einen Link der das ganze Schritt für Schritt beschreibt?

cosinus 17.08.2016 13:05

Du wirst da zig Anleitungen im Netz selber zu finden. Aber fürden Einsteig empfehle ich immer den hier => https://wiki.ubuntuusers.de/Einsteiger/

Die grundlegenden Sachen sollte man nämlich schon wissen, sonst artet das in 1001 Missverständnissen und ner Menge Frust aus. :kaffee:

Daran hat aber Linux nicht die Schuld oder so, alles was man noch nicht kennt muss man erst lernen. :blabla: (dfas wäre bei Windows auch so wenn du zB nur Mac- oder Linux-User wärst)

Piristibulus 17.08.2016 13:09

Vielen Dank! Dann werde ich mal schmöckern und gucken, wie es alles so läuft :-)

Vielen vielen Dank!

cosinus 17.08.2016 13:12

Wenn du zu Linux wechseln willst kannst du das gene tun, wir haben auch hier nen eigenen Bereich dafür! :abklatsch:

Piristibulus 17.08.2016 18:14

Kurze Zwischenfrage: Ich hatte auch eine externe Festplatte am Laufen, als der Maleware-Befall begann.
Soll ich diese an einem anderen PC checken, für den Fall, dass die Malware sich dort in andere Dateien eingenistet hat, oder ist dies nicht notwendig?
Ebenso mit alten PDFs, doc-Dateien, etc., die auf dem befallenen Rechner im Dokumenten-Ordner liegen und mit Ubuntu kopiert werden können?

Danke im Voraus!

Zitat:

Zitat von cosinus (Beitrag 1604895)
Live-Linux verwenden zB Ubuntu MATE im Ausprobiermodus. Dann alle Daten der Windows-Filesysteme auf ne externe Platte oder Stick kopieren.

inclusive Windows System Daten? riskiere ich dann dabei nicht, dass ich irgendwelche Malware, die noch schlummert, mit rüberziehe?

cosinus 17.08.2016 20:10

Es geht um deine eigenen Dateien!
Irgendwelche Windows-Systemdateien zu sichern die bei einer Neuinstallation vom Setup eh neu aufgespielt werden ist ja wohl sinnfrei doch drei

Piristibulus 19.08.2016 15:57

Zitat:

Zitat von cosinus (Beitrag 1604900)
Wenn du zu Linux wechseln willst kannst du das gene tun, wir haben auch hier nen eigenen Bereich dafür! :abklatsch:

Ich denke, dass werde ich bei Gelegenheit tun. Ich hab noch nen ollen PC rumstehen, da kann ich mich mal ein wenig damit vertraut machen.

Ganz ohne windows wirds bei mir zumindest in nächster Zeit nicht laufen, da ich auf einige Sachen angewiesen bin, die auf Linux noch nicht laufen...

Zitat:

Zitat von cosinus (Beitrag 1604982)
Es geht um deine eigenen Dateien!
Irgendwelche Windows-Systemdateien zu sichern die bei einer Neuinstallation vom Setup eh neu aufgespielt werden ist ja wohl sinnfrei doch drei

Danke Dir! Ich wollte nur sicher gehen, lieber dreimal dumm nachfragen, als voreilig was machen, was hinterher dann nicht so toll ist...

Piristibulus 21.08.2016 14:53

Zitat:

Zitat von cosinus (Beitrag 1604882)
dann lieber Daten sichern und sauber neu installieren.

erster Schritt erledigt.

Dann werde ich mal einen clean Install mit Windows 10 machen.

Kurze Fragen:

1. Kannst Du mir was empfehlen, um die gesichterten Daten (PDFs, Office-Dokumente, u.ä.), die jetzt auf einer externen Festplatte liegen, zu überrüfen - will nur sicher gehen, dass die diese Dateien nicht durch die Malware verändert wurden und der Spuk dann von neuem losgeht.

2. Gibt es hier auch eine Anweisung, für eine Neuinstallation von Windows10 incl. Hilfestellung, wie ich alle alten Dateien auf dem befallenen PC komplett "schrubbe", so dass nichts mehr von der Malware irgendwo übrig bleibt (die Chance, dass sie sich ins BIOS reingefressen haben kann ich ausschließen? Hoffe, die Frage ist nicht zu doof ...)


Vielen Dank im Voraus!

LG,
Piristibulus

Piristibulus 22.08.2016 23:27

Sodala,
Datensicherung, Neuinstallation von Windows 10 und Passwortänderung alles abgeschlossen.

Vielen lieben Dank, Cosinus, für die Hilfe.

War zwar überrascht, wie schnell bei der Neuinstallation von Windows 10 alles formatiert war, aber ich hoffe, alle Viren und Malwarereste sind mit allen anderen alten Daten zusammen weg.

Ich wäre Dir noch äußerst dankwar, wenn Du mir noch einen Tipp geben könntest, wie ich die geretteten Daten auf der externen Festplatte noch mal durchsuchen könnte, oder mache ich mir da zuviele Sorgen?

Ansonsten - ist Windows Defender plus Malwarebytes Anti-Maleware (plus CCleaner) bei Windows 10 ausreichend, oder sollte ich noch mal sowas wie Secunia mit draufpacken? Oder ein anderer Virenkiller außer Windows Defender?

Du meinstest weiter oben, Finger weg von Treiber-Update-Programmen ... Wie halte ich meine Treiber am Besten up-to-date?

Herzlichen Dank und beste Grüße,
Piristibulus

cosinus 22.08.2016 23:32

Ich denke du machst dir zu viele Sorgen, aber du kannst einfach mit ESET Online rübergehen. Wir haben dafür ne Anleitung, aber die ist für Kontrollscans bereinigter Systeme ausgelegt. Wenn du nur bestimmte Verzeichnisse scannen willst, entsprechend umstellen.



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Piristibulus 23.08.2016 11:31

Vielen Dank,
hier das Log:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=6ff8af6cdbb5ee4da2a050fa7979ac5b
# end=init
# utc_time=2016-08-22 11:02:15
# local_time=2016-08-23 01:02:15 (+0100, Mitteleuropنische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 30508
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=6ff8af6cdbb5ee4da2a050fa7979ac5b
# end=updated
# utc_time=2016-08-22 11:05:45
# local_time=2016-08-23 01:05:45 (+0100, Mitteleuropنische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=6ff8af6cdbb5ee4da2a050fa7979ac5b
# engine=30508
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-08-23 05:11:17
# local_time=2016-08-23 07:11:17 (+0100, Mitteleuropنische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 22447 3259693 0 0
# scanned=234637
# found=0
# cleaned=0
# scan_time=21931


cosinus 23.08.2016 12:19

keine Funde, was willst du mehr

Piristibulus 23.08.2016 12:56

Wunderbar! Hab vielen Dank für Deine Hilfe!

Wie sollte ich bei Windows 10 für die Zukunft am Besten in Sachen Sicherheit fahren?

Windows Defender plus MBAM? Gibt's sonst noch was zu beachten?

Besten Dank und liebe Grüße,
Piristibulus

PS: Dass bei der Neuinstallation schon die Spracheinstellungen wie vorher (installierte Sprachen, non-unicode-language-Settings, etc.) drauf sind, hat damit zu tun, weil sich der PC meine microsoft-Konto-Einstellungen gemerkt hat?

cosinus 23.08.2016 13:02

Lesestoff:
Virenscanner

Verwende ein einziges der folgenden Antivirusprogramme mit Echtzeitscanner und stets aktueller Signaturendatenbank:

   
 

Microsoft Security Essentials (MSE) ist ab Windows 8 fest eingebaut, wenn du also Windows 8, 8.1 oder 10 und dich für MSE entschieden hast, brauchst du nicht extra MSE zu installieren. Bei Windows 7 muss es aber manuell installiert oder über die Windows Updates als optionales Update bezogen werden. Selbstverständlich ist ein legales/aktiviertes Windows Voraussetzung dafür.

Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und/oder mit dem ESET Online Scanner scannen.

Optional:

http://filepony.de/icon/noscript.png NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. NoScript kann gerade bei technisch nicht allzu versierten Nutzern beim Surfen zum Nervfaktor werden; ob das Tool geeignet ist, muss jeder selbst mal ausprobieren und dann für sich entscheiden. Alternativen zu NoScript (wenn um das das Verhindern von Usertracking und Werbung auf Webseiten) geht wären da Ghostery oder uBlock. Ghostery ist eine sehr bekannte Erweiterung, die aber auch in Kritik geraten ist, vgl. dazu bitte diesen Thread => Ghostery schleift Werbung durch

http://filepony.de/icon/malwarebytes_anti_exploit.pngMalwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.

Piristibulus 23.08.2016 14:11

Lieber Cosinus,
vielen herzlichen Dank für all die Hilfe.
Dann, denke ich, kann der Thread hier ja abgeschlossen werden!


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:40 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131