Code:
19:40:39.0721 0x4ae4 TDSS rootkit removing tool 3.1.0.11 Aug 5 2016 12:13:31
19:40:46.0003 0x4ae4 ============================================================
19:40:46.0003 0x4ae4 Current date / time: 2016/09/11 19:40:46.0003
19:40:46.0003 0x4ae4 SystemInfo:
19:40:46.0004 0x4ae4
19:40:46.0004 0x4ae4 OS Version: 10.0.10586 ServicePack: 0.0
19:40:46.0004 0x4ae4 Product type: Workstation
19:40:46.0004 0x4ae4 ComputerName: NABIL-PC
19:40:46.0004 0x4ae4 UserName: NABIL
19:40:46.0004 0x4ae4 Windows directory: C:\WINDOWS
19:40:46.0004 0x4ae4 System windows directory: C:\WINDOWS
19:40:46.0004 0x4ae4 Running under WOW64
19:40:46.0004 0x4ae4 Processor architecture: Intel x64
19:40:46.0004 0x4ae4 Number of processors: 4
19:40:46.0004 0x4ae4 Page size: 0x1000
19:40:46.0004 0x4ae4 Boot type: Normal boot
19:40:46.0004 0x4ae4 CodeIntegrityOptions = 0x00000001
19:40:46.0004 0x4ae4 ============================================================
19:40:46.0083 0x4ae4 KLMD registered as C:\WINDOWS\system32\drivers\34425297.sys
19:40:46.0083 0x4ae4 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 10586.545, osProperties = 0x19
19:40:46.0519 0x4ae4 System UUID: {C06ACB29-C246-51EA-CAC1-0DCCD3A4C04E}
19:40:46.0864 0x4ae4 Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:40:46.0865 0x4ae4 Drive \Device\Harddisk1\DR1 - Size: 0x1BF2976000 ( 111.79 Gb ), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:40:46.0867 0x4ae4 ============================================================
19:40:46.0867 0x4ae4 \Device\Harddisk0\DR0:
19:40:46.0867 0x4ae4 MBR partitions:
19:40:46.0867 0x4ae4 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07800
19:40:46.0867 0x4ae4 \Device\Harddisk1\DR1:
19:40:46.0867 0x4ae4 MBR partitions:
19:40:46.0867 0x4ae4 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
19:40:46.0867 0x4ae4 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xDE80800
19:40:46.0867 0x4ae4 ============================================================
19:40:46.0868 0x4ae4 C: <-> \Device\Harddisk1\DR1\Partition2
19:40:46.0889 0x4ae4 M: <-> \Device\Harddisk0\DR0\Partition1
19:40:46.0890 0x4ae4 ============================================================
19:40:46.0890 0x4ae4 Initialize success
19:40:46.0890 0x4ae4 ============================================================
19:48:33.0185 0x0820 ============================================================
19:48:33.0185 0x0820 Scan started
19:48:33.0185 0x0820 Mode: Manual; SigCheck; TDLFS;
19:48:33.0185 0x0820 ============================================================
19:48:33.0185 0x0820 KSN ping started
19:48:33.0239 0x0820 KSN ping finished: true
19:48:33.0971 0x0820 ================ Scan system memory ========================
19:48:33.0971 0x0820 System memory - ok
19:48:33.0972 0x0820 ================ Scan services =============================
19:48:33.0996 0x0820 1394ohci - ok
19:48:33.0999 0x0820 3ware - ok
19:48:34.0003 0x0820 [ 73C035299E3044636104CA7A7634A6AC, ED1D4904E2D1D1C72ED9697297AE1B64860098BA2F6F63F7A1426413007DF138 ] a2acc C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys
19:48:34.0106 0x0820 a2acc - ok
19:48:34.0208 0x0820 [ 1DF600AAA554D358108FF241A667112B, 9CD99BB0A22570B4AE62A0F66122457E57E10965552A8C6FD9C6E4090DAF150E ] a2AntiMalware C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
19:48:34.0285 0x0820 a2AntiMalware - ok
19:48:34.0291 0x0820 [ D27A8B7BB0E15DFBFC6B4E774EE17AD9, CBAD45B3FFFD30C34AF918009F699B65F89043D0799FC25D2472381912F86F93 ] A2DDA C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys
19:48:34.0300 0x0820 A2DDA - ok
19:48:34.0304 0x0820 [ 05936579605018BD2BC528FF2C1AD95F, 763C2E76F9078F6A74D5BCCB4DD8A10C82AEB9C9F5A45C3706A587FA2D03E7D3 ] a2injectiondriver C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys
19:48:34.0312 0x0820 a2injectiondriver - ok
19:48:34.0314 0x0820 [ B1AB7116D14667A2238DAEFE20B7F4D0, DC8A9093A6F759657C3354931A462FCCAF3533A907FB7152380EB2E9B4AD3BF8 ] a2util C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys
19:48:34.0323 0x0820 a2util - ok
19:48:34.0347 0x0820 [ 7494475F1BE72A371685F96A6B6044D9, 7F0A8BC9D2565F153D9BA2E55691CD742C8EA90FD61084A13CA8AD0581625EB7 ] ABBYY.Licensing.FineReader.Professional.12.0 C:\Program Files (x86)\ABBYY FineReader 12\NetworkLicenseServer.exe
19:48:34.0375 0x0820 ABBYY.Licensing.FineReader.Professional.12.0 - ok
19:48:34.0379 0x0820 ACPI - ok
19:48:34.0381 0x0820 acpiex - ok
19:48:34.0383 0x0820 acpipagr - ok
19:48:34.0385 0x0820 AcpiPmi - ok
19:48:34.0388 0x0820 acpitime - ok
19:48:34.0393 0x0820 [ 059E8944776CD96C4D48ADECE806D140, E9621B6FDA9A942A443A88C41D6199AB55D1AE4C1FD240437F9547B044D1B2D7 ] AdaptiveSleepService C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
19:48:34.0404 0x0820 AdaptiveSleepService - detected UnsignedFile.Multi.Generic ( 1 )
19:48:34.0442 0x0820 Detect skipped due to KSN trusted
19:48:34.0442 0x0820 AdaptiveSleepService - ok
19:48:34.0446 0x0820 [ 68E7DEA59FDEF410BAF29FDB5B7A6EEF, B808FCF0C30B465A1330E47947B84FC722A3B4C46260E261C54B1EED725A288F ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:48:34.0456 0x0820 AdobeARMservice - ok
19:48:34.0474 0x0820 [ 32B31B696CB8E8F380831DFEB80A67E4, 8C8F6E16F2FB3E8F10569261B7712BBC931A2924B6C27D561E7F828041C4F3E6 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:48:34.0486 0x0820 AdobeFlashPlayerUpdateSvc - ok
19:48:34.0490 0x0820 ADP80XX - ok
19:48:34.0493 0x0820 AFD - ok
19:48:34.0495 0x0820 agp440 - ok
19:48:34.0529 0x0820 [ E20C1118524DF19945BCD83A3843E8CF, 90C87096E9E2595DAA503CFD9C24D7D8F9CB2D567ACAB06FBF5527C8A6059409 ] AGSService C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
19:48:34.0567 0x0820 AGSService - ok
19:48:34.0575 0x0820 ahcache - ok
19:48:34.0578 0x0820 AJRouter - ok
19:48:34.0580 0x0820 ALG - ok
19:48:34.0585 0x0820 [ DBEB48BCEE52B1281D096A7A83C2FB6C, 0CAF22983DA2ACC59363DF862AFC68832B55FFA6217134BC38E6E5570AAE7EB3 ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
19:48:34.0603 0x0820 AMD External Events Utility - ok
19:48:34.0605 0x0820 AmdK8 - ok
19:48:34.0608 0x0820 amdkmdag - ok
19:48:34.0618 0x0820 [ 29ECFFBCED648EDFD1872AFEB4402E2B, 159C4DB6A578C5CBF092DEB1EC26545818B95E89C302553B7B421C5A754AEB04 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
19:48:34.0637 0x0820 amdkmdap - ok
19:48:34.0642 0x0820 [ 3F11DB5FF2B4E52CA4B5979A37B97A6F, 59350E37AB2FE8D7290B0B9A4C84ADBC69A4EBCEA5AD208E2E5D047C8EE5B65A ] amdkmpfd C:\WINDOWS\system32\drivers\amdkmpfd.sys
19:48:34.0651 0x0820 amdkmpfd - ok
19:48:34.0653 0x0820 AmdPPM - ok
19:48:34.0655 0x0820 amdsata - ok
19:48:34.0658 0x0820 amdsbs - ok
19:48:34.0660 0x0820 amdxata - ok
19:48:34.0662 0x0820 AppHostSvc - ok
19:48:34.0664 0x0820 AppID - ok
19:48:34.0666 0x0820 AppIDSvc - ok
19:48:34.0669 0x0820 Appinfo - ok
19:48:34.0673 0x0820 [ 3B3774C868868257533EC7E715BB6D53, 4AF1DADCEDBD80BE6EDEC696DF59E65B51D31E33F4C84413CA03C7BD959FF4E5 ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
19:48:34.0682 0x0820 Apple Mobile Device Service - ok
19:48:34.0685 0x0820 AppMgmt - ok
19:48:34.0688 0x0820 AppReadiness - ok
19:48:34.0691 0x0820 AppXSvc - ok
19:48:34.0693 0x0820 arcsas - ok
19:48:34.0697 0x0820 [ E536856E96A7605EBF580D62A868E5FE, 70D0F6ECB05E923C1B274605CB3320091D35D7622003FF7E4806645519C70F01 ] ASGT C:\Windows\SysWOW64\ASGT.exe
19:48:34.0702 0x0820 ASGT - detected UnsignedFile.Multi.Generic ( 1 )
19:48:34.0741 0x0820 Detect skipped due to KSN trusted
19:48:34.0741 0x0820 ASGT - ok
19:48:34.0750 0x0820 aspnet_state - ok
19:48:34.0753 0x0820 [ E1AFEE1584C74050DE0DD16DE2A54BF3, 77C8D98159D8BCDC7917B04977949823D50C49D0D13587310E060A4B8893AE42 ] AsrAppCharger C:\WINDOWS\system32\DRIVERS\AsrAppCharger.sys
19:48:34.0762 0x0820 AsrAppCharger - ok
19:48:34.0766 0x0820 [ 2C74F5379459FFA27B3C139E9EF8A62D, DFEE555A39CC4A66FC937E75389119FAF2721079FC4A537B5A8B46D852EA08B7 ] Asus Product Register Service C:\Program Files (x86)\ASUS\APRP\AsusProductRegisterService.exe
19:48:34.0773 0x0820 Asus Product Register Service - detected UnsignedFile.Multi.Generic ( 1 )
19:48:34.0811 0x0820 Detect skipped due to KSN trusted
19:48:34.0811 0x0820 Asus Product Register Service - ok
19:48:34.0814 0x0820 AsyncMac - ok
19:48:34.0816 0x0820 atapi - ok
19:48:34.0823 0x0820 [ F06A4C6E131FD7D6E253FC0B6844298C, 431FEFB929D984C2573E186C65CE35385808FDB9795C776870AF39305E9465FA ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdWT6.sys
19:48:34.0839 0x0820 AtiHDAudioService - ok
19:48:34.0842 0x0820 AudioEndpointBuilder - ok
19:48:34.0844 0x0820 Audiosrv - ok
19:48:34.0847 0x0820 AxInstSV - ok
19:48:34.0849 0x0820 b06bdrv - ok
19:48:34.0851 0x0820 BasicDisplay - ok
19:48:34.0854 0x0820 BasicRender - ok
19:48:34.0858 0x0820 bcmfn - ok
19:48:34.0860 0x0820 bcmfn2 - ok
19:48:34.0862 0x0820 BDESVC - ok
19:48:34.0865 0x0820 Beep - ok
19:48:34.0888 0x0820 [ 96E6FDA70874EBB1E616BCF216EE118A, E1DBD5E610457CC2FF5E3DA6426F292C3514C15986E632A4F515E8206E77F7B5 ] BEService C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
19:48:34.0912 0x0820 BEService - ok
19:48:34.0916 0x0820 BFE - ok
19:48:34.0918 0x0820 BITS - ok
19:48:34.0931 0x0820 [ B5C2F92EE1106DFE7BB1CCE4D35B6037, E399C390687589194D8AAD385055F0CFA7D52AD9E837D8FF95008B8EB2B34E50 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
19:48:34.0945 0x0820 Bonjour Service - ok
19:48:34.0948 0x0820 bowser - ok
19:48:34.0950 0x0820 BrokerInfrastructure - ok
19:48:34.0953 0x0820 Browser - ok
19:48:34.0956 0x0820 BthAvrcpTg - ok
19:48:34.0959 0x0820 BthHFEnum - ok
19:48:34.0961 0x0820 bthhfhid - ok
19:48:34.0964 0x0820 BthHFSrv - ok
19:48:34.0966 0x0820 BTHMODEM - ok
19:48:34.0970 0x0820 bthserv - ok
19:48:34.0973 0x0820 buttonconverter - ok
19:48:34.0975 0x0820 CapImg - ok
19:48:34.0977 0x0820 cdfs - ok
19:48:34.0980 0x0820 CDPSvc - ok
19:48:34.0983 0x0820 cdrom - ok
19:48:34.0985 0x0820 CertPropSvc - ok
19:48:34.0988 0x0820 circlass - ok
19:48:34.0992 0x0820 [ B794DCF38C965FA2F93C45A7C3D582C5, 0E483EAF835B85AA4B6F449F9BB68AF0A3EE4192D29CD72F4B812F1E4D9E9A7C ] cleanhlp C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys
19:48:35.0001 0x0820 cleanhlp - ok
19:48:35.0004 0x0820 CLFS - ok
19:48:35.0007 0x0820 ClipSVC - ok
19:48:35.0014 0x0820 CmBatt - ok
19:48:35.0017 0x0820 CNG - ok
19:48:35.0019 0x0820 cnghwassist - ok
19:48:35.0032 0x0820 CompositeBus - ok
19:48:35.0035 0x0820 COMSysApp - ok
19:48:35.0038 0x0820 condrv - ok
19:48:35.0041 0x0820 CoreMessagingRegistrar - ok
19:48:35.0046 0x0820 CryptSvc - ok
19:48:35.0048 0x0820 CSC - ok
19:48:35.0051 0x0820 CscService - ok
19:48:35.0054 0x0820 dam - ok
19:48:35.0058 0x0820 DcomLaunch - ok
19:48:35.0061 0x0820 DcpSvc - ok
19:48:35.0064 0x0820 defragsvc - ok
19:48:35.0067 0x0820 DeviceAssociationService - ok
19:48:35.0070 0x0820 DeviceInstall - ok
19:48:35.0073 0x0820 DevQueryBroker - ok
19:48:35.0076 0x0820 Dfsc - ok
19:48:35.0079 0x0820 Dhcp - ok
19:48:35.0083 0x0820 diagnosticshub.standardcollector.service - ok
19:48:35.0086 0x0820 DiagTrack - ok
19:48:35.0097 0x0820 [ EA3F6BAE990D67FCA171871359BE8749, 754361DC3181D259638BCD5B2B24B228375084F54E26977BC04BC183AB7542C0 ] DigitalWave.Update.Service C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
19:48:35.0110 0x0820 DigitalWave.Update.Service - ok
19:48:35.0139 0x0820 [ 91DF13EC831BDCFA36A7A12CD13D66B9, 5054281FE91D4BE0DB446F6F30E3D59E669185555F6C20B988DEC250713FFCED ] Disc Soft Lite Bus Service C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
19:48:35.0167 0x0820 Disc Soft Lite Bus Service - ok
19:48:35.0172 0x0820 disk - ok
19:48:35.0175 0x0820 DmEnrollmentSvc - ok
19:48:35.0178 0x0820 dmvsc - ok
19:48:35.0181 0x0820 dmwappushservice - ok
19:48:35.0183 0x0820 Dnscache - ok
19:48:35.0188 0x0820 dot3svc - ok
19:48:35.0192 0x0820 DPS - ok
19:48:35.0195 0x0820 drmkaud - ok
19:48:35.0198 0x0820 DsmSvc - ok
19:48:35.0201 0x0820 DsSvc - ok
19:48:35.0204 0x0820 [ 496C3C6BC3D930D0960C9E75AA30F4A7, 3FE0E86DA8C2C6A990BB2F1B92C22BD3483882B8D69FF8025BB68A199362C234 ] dtlitescsibus C:\WINDOWS\System32\drivers\dtlitescsibus.sys
19:48:35.0213 0x0820 dtlitescsibus - ok
19:48:35.0216 0x0820 DXGKrnl - ok
19:48:35.0229 0x0820 [ 2AAC97A2DDFE3149851A9F8E002F2721, 7CDCB2BA56A6417C49A94D45BC674678073EB6B999FB0665EC329A26C5E9BCA7 ] e1dexpress C:\WINDOWS\system32\DRIVERS\e1d65x64.sys
19:48:35.0247 0x0820 e1dexpress - ok
19:48:35.0251 0x0820 Eaphost - ok
19:48:35.0254 0x0820 ebdrv - ok
19:48:35.0257 0x0820 EFS - ok
19:48:35.0260 0x0820 EhStorClass - ok
19:48:35.0263 0x0820 EhStorTcgDrv - ok
19:48:35.0265 0x0820 embeddedmode - ok
19:48:35.0270 0x0820 EntAppSvc - ok
19:48:35.0276 0x0820 [ D315FF43E23DF424ECEC2F6C930203E4, 68940EDA34DC4945CDD0D8018D96A0DA8F99F16A930946D14E4FECEE033FCB80 ] EpsonScanSvc C:\WINDOWS\system32\EscSvc64.exe
19:48:35.0287 0x0820 EpsonScanSvc - ok
19:48:35.0290 0x0820 ErrDev - ok
19:48:35.0296 0x0820 [ 32710ECBE3C17C6F769BAC88CD1756FF, BB9B269F0322FFBFAC459EC15BA9410A5FF5CDCBD38F67F8482720ACB1799C2B ] ESProtectionDriver C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys
19:48:35.0305 0x0820 ESProtectionDriver - ok
19:48:35.0311 0x0820 EventSystem - ok
19:48:35.0314 0x0820 exfat - ok
19:48:35.0317 0x0820 fastfat - ok
19:48:35.0320 0x0820 Fax - ok
19:48:35.0323 0x0820 fdc - ok
19:48:35.0325 0x0820 fdPHost - ok
19:48:35.0329 0x0820 FDResPub - ok
19:48:35.0332 0x0820 fhsvc - ok
19:48:35.0335 0x0820 FileCrypt - ok
19:48:35.0339 0x0820 FileInfo - ok
19:48:35.0342 0x0820 Filetrace - ok
19:48:35.0345 0x0820 flpydisk - ok
19:48:35.0348 0x0820 FltMgr - ok
19:48:35.0351 0x0820 FontCache - ok
19:48:35.0355 0x0820 FontCache3.0.0.0 - ok
19:48:35.0358 0x0820 FsDepends - ok
19:48:35.0361 0x0820 Fs_Rec - ok
19:48:35.0364 0x0820 fvevol - ok
19:48:35.0367 0x0820 gagp30kx - ok
19:48:35.0371 0x0820 [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
19:48:35.0379 0x0820 GEARAspiWDM - ok
19:48:35.0382 0x0820 gencounter - ok
19:48:35.0385 0x0820 genericusbfn - ok
19:48:35.0392 0x0820 [ 4AB1EEFAA88D73AA1580C20461235616, D5530E57589EE42A658741358BFE543ACD38031A6AAC3AB88421233233CBD31C ] GladFileMonSvc C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe
19:48:35.0402 0x0820 GladFileMonSvc - ok
19:48:35.0405 0x0820 GPIOClx0101 - ok
19:48:35.0409 0x0820 gpsvc - ok
19:48:35.0412 0x0820 GpuEnergyDrv - ok
19:48:35.0419 0x0820 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:48:35.0428 0x0820 gupdate - ok
19:48:35.0434 0x0820 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:48:35.0443 0x0820 gupdatem - ok
19:48:35.0447 0x0820 HdAudAddService - ok
19:48:35.0450 0x0820 HDAudBus - ok
19:48:35.0453 0x0820 HidBatt - ok
19:48:35.0456 0x0820 HidBth - ok
19:48:35.0460 0x0820 hidi2c - ok
19:48:35.0463 0x0820 hidinterrupt - ok
19:48:35.0466 0x0820 HidIr - ok
19:48:35.0470 0x0820 hidserv - ok
19:48:35.0474 0x0820 HidUsb - ok
19:48:35.0477 0x0820 HomeGroupListener - ok
19:48:35.0481 0x0820 HomeGroupProvider - ok
19:48:35.0484 0x0820 HpSAMD - ok
19:48:35.0487 0x0820 HTTP - ok
19:48:35.0501 0x0820 [ E5805896A55D4166C20F216249F40FA3, F426BF60D5B916E7A778EF24C49FE1FFE1B2977C2ABD2977FD5C38C6E6CB139F ] HWiNFO32 C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS
19:48:35.0510 0x0820 HWiNFO32 - ok
19:48:35.0513 0x0820 hwpolicy - ok
19:48:35.0517 0x0820 hyperkbd - ok
19:48:35.0520 0x0820 HyperVideo - ok
19:48:35.0523 0x0820 i8042prt - ok
19:48:35.0527 0x0820 iai2c - ok
19:48:35.0530 0x0820 iaLPSS2i_I2C - ok
19:48:35.0534 0x0820 iaLPSSi_GPIO - ok
19:48:35.0538 0x0820 iaLPSSi_I2C - ok
19:48:35.0569 0x0820 [ 12859E1215AA083A42E7ADCDE5C061D1, 262F9C65C3FA7EB69C4FA7C6547E1C79DB49697A083309909BC78726A116557F ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
19:48:35.0599 0x0820 iaStorA - ok
19:48:35.0603 0x0820 iaStorAV - ok
19:48:35.0608 0x0820 [ 7281AED93FB30FDD1CBAF07591FA453A, BD912798D8E28AF27C5FE01455D97224013D30066E35230888E64D0AC346893F ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
19:48:35.0616 0x0820 IAStorDataMgrSvc - ok
19:48:35.0619 0x0820 iaStorV - ok
19:48:35.0623 0x0820 ibbus - ok
19:48:35.0627 0x0820 icssvc - ok
19:48:35.0632 0x0820 IEEtwCollectorService - ok
19:48:35.0639 0x0820 [ EDCCC8C13B1EB882F77BA0ABB84566E7, DB299C1D2CFC197CF2FE69358F5EEDE94DCC4C919AF5D2CDFFF0DE476612C988 ] IJPLMSVC C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
19:48:35.0649 0x0820 IJPLMSVC - ok
19:48:35.0653 0x0820 [ E18725531054FE222115873AC1CCB02B, 0FC4B9D5DF77E19E4732759B848B4BCBBD44A124304FA8333BB3B7BC37E15FB8 ] ikbevent C:\WINDOWS\system32\DRIVERS\ikbevent.sys
19:48:35.0662 0x0820 ikbevent - ok
19:48:35.0665 0x0820 IKEEXT - ok
19:48:35.0670 0x0820 [ 45060257BCA3D60204FEC29F6E6DE458, C9FB92FEEFC0DC5386B545A8E429D60B932360B9044A920F6F2EDD5CF3B7B5A0 ] imsevent C:\WINDOWS\system32\DRIVERS\imsevent.sys
19:48:35.0678 0x0820 imsevent - ok
19:48:35.0755 0x0820 [ C1B6594EDD7FE73FFB03D48A9CAE25DE, B9995F65B06F28E146A7B50E4D77C2E50D68CB65D5F69798E6644AA23B7AEB5F ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
19:48:35.0837 0x0820 IntcAzAudAddService - ok
19:48:35.0860 0x0820 [ DDA8E5AD97231AB50B81FED04C28F64C, 5C9E8F7CC45A9AE7FF12A02641562E271D84894DFA7C50218AC2AAA298251B60 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
19:48:35.0879 0x0820 Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
19:48:35.0917 0x0820 Detect skipped due to KSN trusted
19:48:35.0917 0x0820 Intel(R) Capability Licensing Service Interface - ok
19:48:35.0936 0x0820 [ 86FE509640D77FB0998FC8B1FF5523C6, 13E895DEB9B84379251699D7E52C5E3FD888994425DE01B6C4634F9E959D5584 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
19:48:35.0955 0x0820 Intel(R) Capability Licensing Service TCP IP Interface - ok
19:48:35.0964 0x0820 [ EE65488B7294FBCB113EAC9FD492345C, D1D6B22CD94324387171B188D295AA716900654DA1DC9F3DC18D0CD528F2BBEA ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
19:48:35.0973 0x0820 Intel(R) ME Service - ok
19:48:35.0980 0x0820 [ 26FBC0AEDE7C6A67781202E0E2ECB6A6, BEF9E7CB2B2DD7A8091483EC53B812CA3F079CEC949DE545ABED6BE617A9ED55 ] Intel(R) PROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
19:48:35.0993 0x0820 Intel(R) PROSet Monitoring Service - ok
19:48:35.0997 0x0820 intelide - ok
19:48:36.0000 0x0820 intelpep - ok
19:48:36.0004 0x0820 intelppm - ok
19:48:36.0009 0x0820 [ A01C412699B6F21645B2885C2BAE4454, EA85BBE63D6F66F7EFEE7007E770AF820D57F914C7F179C5FEE3EF2845F19C41 ] IOMap C:\WINDOWS\system32\drivers\IOMap64.sys
19:48:36.0017 0x0820 IOMap - ok
19:48:36.0020 0x0820 IoQos - ok
19:48:36.0024 0x0820 IpFilterDriver - ok
19:48:36.0028 0x0820 iphlpsvc - ok
19:48:36.0031 0x0820 IPMIDRV - ok
19:48:36.0035 0x0820 IPNAT - ok
19:48:36.0051 0x0820 [ 2BFF13AC46A5850161317D0F924B5B42, B8A09F66435EC6582F8772515988503CC13DC200A370EBB8C3FE661F2EA688DA ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
19:48:36.0068 0x0820 iPod Service - ok
19:48:36.0072 0x0820 IRENUM - ok
19:48:36.0076 0x0820 isapnp - ok
19:48:36.0079 0x0820 iScsiPrt - ok
19:48:36.0083 0x0820 [ 4EE2423C38F43D37F8497A672FD10BDC, 031C5272DD28809255CF4FA8E6DE45DBFBD9A363BBD5156D0AEE0787C4297980 ] ISCT C:\WINDOWS\System32\drivers\ISCTD64.sys
19:48:36.0092 0x0820 ISCT - ok
19:48:36.0099 0x0820 [ 5C9B001D8970C2DA36254A916F3DA8F7, 625AC5C3DFAE52BD34EC3F93742D1D2C229785E4F0F3484CFB7B8728A1C830DF ] iumsvc C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
19:48:36.0110 0x0820 iumsvc - ok
19:48:36.0117 0x0820 [ BF5D3A2624177C413680DEF19A465AF8, B9909D3E6CB6F9971293116387865AD15CB9D47513C7FAA9C36BE4D2847A41EB ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
19:48:36.0127 0x0820 jhi_service - ok
19:48:36.0131 0x0820 kbdclass - ok
19:48:36.0134 0x0820 kbdhid - ok
19:48:36.0138 0x0820 kdnic - ok
19:48:36.0142 0x0820 KeyIso - ok
19:48:36.0146 0x0820 [ 0F9FD9565E6EB157FA9BE11ED9C1DC9F, 7565255F0A28D065F8F30F876E7DF3E46EF2E6FEDF420ECA7D454CF49887B2DE ] KMS-R@1n C:\Windows\KMS-R@1n.exe
19:48:36.0150 0x0820 KMS-R@1n - detected UnsignedFile.Multi.Generic ( 1 )
19:48:36.0188 0x0820 Detect skipped due to KSN trusted
19:48:36.0188 0x0820 KMS-R@1n - ok
19:48:36.0192 0x0820 KSecDD - ok
19:48:36.0195 0x0820 KSecPkg - ok
19:48:36.0200 0x0820 ksthunk - ok
19:48:36.0204 0x0820 KtmRm - ok
19:48:36.0208 0x0820 LanmanServer - ok
19:48:36.0212 0x0820 LanmanWorkstation - ok
19:48:36.0219 0x0820 lfsvc - ok
19:48:36.0223 0x0820 LicenseManager - ok
19:48:36.0282 0x0820 [ C2BDC7EA68CAE9E9A088F77BAC88FB92, EBD7B98C00DD320DAAD39C15A8D9D49CB9F3691BF41F1553039F4060BAB29A24 ] LiveUpdateSvc C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
19:48:36.0329 0x0820 LiveUpdateSvc - ok
19:48:36.0335 0x0820 lltdio - ok
19:48:36.0339 0x0820 lltdsvc - ok
19:48:36.0343 0x0820 lmhosts - ok
19:48:36.0356 0x0820 [ 02A9CBACE666877BBBA4FD66B22F6D4A, 0E783BA7A8F00CEC8F03CFEE03999CA5DB9E4DB7CCE62D9171CFCF36AFBE4BB1 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
19:48:36.0369 0x0820 LMS - ok
19:48:36.0376 0x0820 LSI_SAS - ok
19:48:36.0380 0x0820 LSI_SAS2i - ok
19:48:36.0384 0x0820 LSI_SAS3i - ok
19:48:36.0388 0x0820 LSI_SSS - ok
19:48:36.0393 0x0820 LSM - ok
19:48:36.0396 0x0820 luafv - ok
19:48:36.0401 0x0820 MapsBroker - ok
19:48:36.0414 0x0820 [ DE111E937CB01E149FD749F67CDA7DD9, 1434FD87072FE4032D40E2B59DA301B0B35A301DAD4A6E7FE53BE8044BD2B465 ] MbaeSvc C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
19:48:36.0433 0x0820 MbaeSvc - ok
19:48:36.0438 0x0820 [ CFBC6C6D8A492697CABD1D353EE64933, DDAA844908324740C891EB8F08E2A8BB00457063B31C4A762745C1C2415FC12D ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
19:48:36.0446 0x0820 MBAMProtector - ok
19:48:36.0485 0x0820 [ 40C126CB15FAB7D6C66490DCA9C1AED2, B32CEE2D2409232C245427D5E9647FDF59AF1D8AB5E8A98EE2D1F1314599FD14 ] MBAMService C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
19:48:36.0508 0x0820 MBAMService - ok
19:48:36.0524 0x0820 [ 08DECFCB9BA97786165A69AB1015BC30, EDC8C8447B57BD412E2DEBCA9B5B1B58C19D40105DC7CE9520DE214081696B05 ] MBAMWebAccessControl C:\WINDOWS\system32\drivers\mwac.sys
19:48:36.0533 0x0820 MBAMWebAccessControl - ok
19:48:36.0569 0x0820 [ 6EF327DBB5DC9D6310ADE48CAB14959D, AFDC81E83E9EC9424C14431E531E976C419715754952D92BE2691186C55F0E9B ] McComponentHostService C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe
19:48:36.0581 0x0820 McComponentHostService - ok
19:48:36.0585 0x0820 megasas - ok
19:48:36.0590 0x0820 megasr - ok
19:48:36.0605 0x0820 [ 6ECDA51525C123C55ABC470F2144F925, 7B2E8976F126219AF0953FD641E613A9336CCC80843AF4A37AA71067D55CCBBB ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
19:48:36.0617 0x0820 MEIx64 - ok
19:48:36.0622 0x0820 MessagingService - ok
19:48:36.0661 0x0820 mlx4_bus - ok
19:48:36.0666 0x0820 MMCSS - ok
19:48:36.0670 0x0820 Modem - ok
19:48:36.0674 0x0820 monitor - ok
19:48:36.0681 0x0820 [ C030F9E822A057C1A7A9BB4EA3E8877E, 2CCEC87DEB972B6B0196A08D3781002929E9107137FE3A61F1626D3BEE26630A ] MotioninJoyXFilter C:\WINDOWS\system32\DRIVERS\MijXfilt.sys
19:48:36.0689 0x0820 MotioninJoyXFilter - detected UnsignedFile.Multi.Generic ( 1 )
19:48:36.0726 0x0820 Detect skipped due to KSN trusted
19:48:36.0726 0x0820 MotioninJoyXFilter - ok
19:48:36.0731 0x0820 mouclass - ok
19:48:36.0735 0x0820 mouhid - ok
19:48:36.0740 0x0820 mountmgr - ok
19:48:36.0744 0x0820 mpsdrv - ok
19:48:36.0748 0x0820 MpsSvc - ok
19:48:36.0753 0x0820 MQAC - ok
19:48:36.0757 0x0820 MRxDAV - ok
19:48:36.0762 0x0820 mrxsmb - ok
19:48:36.0767 0x0820 mrxsmb10 - ok
19:48:36.0771 0x0820 mrxsmb20 - ok
19:48:36.0775 0x0820 MsBridge - ok
19:48:36.0780 0x0820 MSDTC - ok
19:48:36.0790 0x0820 Msfs - ok
19:48:36.0795 0x0820 msgpiowin32 - ok
19:48:36.0799 0x0820 mshidkmdf - ok
19:48:36.0803 0x0820 mshidumdf - ok
19:48:36.0808 0x0820 msisadrv - ok
19:48:36.0813 0x0820 MSiSCSI - ok
19:48:36.0817 0x0820 msiserver - ok
19:48:36.0821 0x0820 MSKSSRV - ok
19:48:36.0826 0x0820 MsLldp - ok
19:48:36.0830 0x0820 MSMQ - ok
19:48:36.0834 0x0820 MSPCLOCK - ok
19:48:36.0838 0x0820 MSPQM - ok
19:48:36.0843 0x0820 MsRPC - ok
19:48:36.0850 0x0820 mssmbios - ok
19:48:36.0854 0x0820 MSTEE - ok
19:48:36.0859 0x0820 MTConfig - ok
19:48:36.0863 0x0820 Mup - ok
19:48:36.0868 0x0820 mvumis - ok
19:48:36.0886 0x0820 [ E605F35F03C881DC46902E0E2F5985B3, C97F0C733377E35B463EF7F6A5B879DA21AB512719899160C09278615FE39A21 ] MyEpson Portal Service C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
19:48:36.0904 0x0820 MyEpson Portal Service - ok
19:48:36.0912 0x0820 NativeWifiP - ok
19:48:36.0933 0x0820 [ DF1A606A45C5280BD2DEFEFC17311489, 690656E73211BF34A1A839EAAA6B090D66040773228506C571E40699CB4927F4 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
19:48:36.0951 0x0820 NAUpdate - ok
19:48:36.0957 0x0820 NcaSvc - ok
19:48:36.0962 0x0820 NcbService - ok
19:48:36.0965 0x0820 NcdAutoSetup - ok
19:48:36.0971 0x0820 ndfltr - ok
19:48:36.0975 0x0820 NDIS - ok
19:48:36.0980 0x0820 NdisCap - ok
19:48:36.0985 0x0820 NdisImPlatform - ok
19:48:36.0989 0x0820 NdisTapi - ok
19:48:36.0993 0x0820 Ndisuio - ok
19:48:36.0998 0x0820 NdisVirtualBus - ok
19:48:37.0003 0x0820 NdisWan - ok
19:48:37.0007 0x0820 ndiswanlegacy - ok
19:48:37.0012 0x0820 ndproxy - ok
19:48:37.0017 0x0820 Ndu - ok
19:48:37.0022 0x0820 [ EE00C544C025958AF50C7B199F3C8595, D774DB020D9C46D1AA0B2DB9FA2C36C4A9C38D904CC6929695321D32ACA0D4D1 ] Netaapl C:\WINDOWS\System32\drivers\netaapl64.sys
19:48:37.0035 0x0820 Netaapl - ok
19:48:37.0040 0x0820 NetBIOS - ok
19:48:37.0048 0x0820 NetBT - ok
19:48:37.0052 0x0820 Netlogon - ok
19:48:37.0058 0x0820 Netman - ok
19:48:37.0065 0x0820 NetMsmqActivator - ok
19:48:37.0069 0x0820 NetPipeActivator - ok
19:48:37.0074 0x0820 netprofm - ok
19:48:37.0079 0x0820 NetSetupSvc - ok
19:48:37.0084 0x0820 NetTcpActivator - ok
19:48:37.0088 0x0820 NetTcpPortSharing - ok
19:48:37.0093 0x0820 netvsc - ok
19:48:37.0102 0x0820 NgcCtnrSvc - ok
19:48:37.0106 0x0820 NgcSvc - ok
19:48:37.0111 0x0820 NlaSvc - ok
19:48:37.0116 0x0820 Npfs - ok
19:48:37.0121 0x0820 npsvctrig - ok
19:48:37.0126 0x0820 nsi - ok
19:48:37.0130 0x0820 nsiproxy - ok
19:48:37.0139 0x0820 NTFS - ok
19:48:37.0143 0x0820 Null - ok
19:48:37.0148 0x0820 nvraid - ok
19:48:37.0153 0x0820 nvstor - ok
19:48:37.0157 0x0820 nv_agp - ok
19:48:37.0162 0x0820 OneSyncSvc - ok
19:48:37.0213 0x0820 [ 11E0B35479C895888BA3D7F619DCFFF3, 6ED82C19898101EC00BD64A9F90595C3D20AD2D2902AA8765B740FB3B9312DDF ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:48:37.0225 0x0820 ose64 - ok
19:48:37.0332 0x0820 [ FE9C0029E1AF26350D9985D00520E5C8, 967079CCF7B2CBD4B48C9F076675C26AF93A1CEC26C96811F279414E34004EE6 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
19:48:37.0413 0x0820 osppsvc - ok
19:48:37.0425 0x0820 p2pimsvc - ok
19:48:37.0430 0x0820 p2psvc - ok
19:48:37.0435 0x0820 Parport - ok
19:48:37.0441 0x0820 partmgr - ok
19:48:37.0445 0x0820 PcaSvc - ok
19:48:37.0450 0x0820 pci - ok
19:48:37.0455 0x0820 pciide - ok
19:48:37.0460 0x0820 pcmcia - ok
19:48:37.0465 0x0820 pcw - ok
19:48:37.0470 0x0820 pdc - ok
19:48:37.0475 0x0820 PEAUTH - ok
19:48:37.0480 0x0820 PeerDistSvc - ok
19:48:37.0485 0x0820 percsas2i - ok
19:48:37.0490 0x0820 percsas3i - ok
19:48:37.0508 0x0820 PerfHost - ok
19:48:37.0524 0x0820 PhoneSvc - ok
19:48:37.0530 0x0820 PimIndexMaintenanceSvc - ok
19:48:37.0575 0x0820 pla - ok
19:48:37.0581 0x0820 PlugPlay - ok
19:48:37.0585 0x0820 PNRPAutoReg - ok
19:48:37.0591 0x0820 PNRPsvc - ok
19:48:37.0596 0x0820 PolicyAgent - ok
19:48:37.0605 0x0820 Power - ok
19:48:37.0610 0x0820 PptpMiniport - ok
19:48:37.0681 0x0820 [ C9908063F90F5541098BF19EA63E1327, AA6B5E4D01CD8061D5953FDE3025FE4AF01B265C182B8818107A035E4FFAD0DF ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
19:48:37.0775 0x0820 PrintNotify - ok
19:48:37.0782 0x0820 Processor - ok
19:48:37.0788 0x0820 ProfSvc - ok
19:48:37.0793 0x0820 Psched - ok
19:48:37.0798 0x0820 QWAVE - ok
19:48:37.0804 0x0820 QWAVEdrv - ok
19:48:37.0810 0x0820 RasAcd - ok
19:48:37.0815 0x0820 RasAgileVpn - ok
19:48:37.0820 0x0820 RasAuto - ok
19:48:37.0825 0x0820 Rasl2tp - ok
19:48:37.0831 0x0820 RasMan - ok
19:48:37.0836 0x0820 RasPppoe - ok
19:48:37.0841 0x0820 RasSstp - ok
19:48:37.0847 0x0820 rdbss - ok
19:48:37.0856 0x0820 rdpbus - ok
19:48:37.0861 0x0820 RDPDR - ok
19:48:37.0875 0x0820 RdpVideoMiniport - ok
19:48:37.0880 0x0820 rdyboost - ok
19:48:37.0885 0x0820 ReFSv1 - ok
19:48:37.0895 0x0820 RemoteAccess - ok
19:48:37.0900 0x0820 RemoteRegistry - ok
19:48:37.0906 0x0820 RetailDemo - ok
19:48:37.0912 0x0820 RpcEptMapper - ok
19:48:37.0917 0x0820 RpcLocator - ok
19:48:37.0923 0x0820 RpcSs - ok
19:48:37.0928 0x0820 rspndr - ok
19:48:37.0934 0x0820 s3cap - ok
19:48:37.0939 0x0820 SamSs - ok
19:48:37.0947 0x0820 [ 5EFBBFCC6ADAC121C8E2FE76641ED329, 0EAB16C7F54B61620277977F8C332737081A46BC6BBDE50742B6904BDD54F502 ] SANDRA C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1\WNt600x64\Sandra.sys
19:48:37.0955 0x0820 SANDRA - ok
19:48:37.0961 0x0820 [ DB066DBB99FB20AA7B3CE28C4E592180, 19590B7B718AE7706E4145B1998C77420CC64FF8E345DDE4716192B999612E4C ] SandraAgentSrv C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1\RpcAgentSrv.exe
19:48:37.0968 0x0820 SandraAgentSrv - detected UnsignedFile.Multi.Generic ( 1 )
19:48:38.0005 0x0820 Detect skipped due to KSN trusted
19:48:38.0005 0x0820 SandraAgentSrv - ok
19:48:38.0011 0x0820 sbp2port - ok
19:48:38.0016 0x0820 SCardSvr - ok
19:48:38.0023 0x0820 ScDeviceEnum - ok
19:48:38.0028 0x0820 scfilter - ok
19:48:38.0034 0x0820 Schedule - ok
19:48:38.0040 0x0820 SCPolicySvc - ok
19:48:38.0046 0x0820 sdbus - ok
19:48:38.0052 0x0820 SDRSVC - ok
19:48:38.0057 0x0820 sdstor - ok
19:48:38.0063 0x0820 seclogon - ok
19:48:38.0068 0x0820 SENS - ok
19:48:38.0074 0x0820 SensorDataService - ok
19:48:38.0079 0x0820 SensorService - ok
19:48:38.0085 0x0820 SensrSvc - ok
19:48:38.0090 0x0820 SerCx - ok
19:48:38.0096 0x0820 SerCx2 - ok
19:48:38.0102 0x0820 Serenum - ok
19:48:38.0107 0x0820 Serial - ok
19:48:38.0113 0x0820 sermouse - ok
19:48:38.0131 0x0820 SessionEnv - ok
19:48:38.0145 0x0820 sfloppy - ok
19:48:38.0151 0x0820 SharedAccess - ok
19:48:38.0158 0x0820 ShellHWDetection - ok
19:48:38.0164 0x0820 SiSRaid2 - ok
19:48:38.0169 0x0820 SiSRaid4 - ok
19:48:38.0183 0x0820 [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
19:48:38.0198 0x0820 SkypeUpdate - ok
19:48:38.0204 0x0820 [ E4F6FAAA2B531594A523AD4544F4A013, BE561215835BBB934780BDFF35F756BC975056B98F0453F40B92AFA363B63DDA ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
19:48:38.0213 0x0820 SmbDrvI - ok
19:48:38.0219 0x0820 smphost - ok
19:48:38.0225 0x0820 SmsRouter - ok
19:48:38.0244 0x0820 SNMPTRAP - ok
19:48:38.0249 0x0820 spaceport - ok
19:48:38.0255 0x0820 SpbCx - ok
19:48:38.0261 0x0820 Spooler - ok
19:48:38.0267 0x0820 sppsvc - ok
19:48:38.0272 0x0820 srv - ok
19:48:38.0278 0x0820 srv2 - ok
19:48:38.0284 0x0820 srvnet - ok
19:48:38.0290 0x0820 SSDPSRV - ok
19:48:38.0296 0x0820 SstpSvc - ok
19:48:38.0319 0x0820 [ 9DA3B55B17B54789AFB8C657D4ACE4D7, 5E4599E682327E3B8097A88A69ED73F96254A29054744D5DFB782054863F131E ] ss_conn_service C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
19:48:38.0336 0x0820 ss_conn_service - ok
19:48:38.0347 0x0820 [ 31A20120B76C8F6D350D4EF6668B0381, 86971AC0963470039D44E8BFA72FEB188E8ED579FCB96AD4492CEBFEF887823E ] Start10 C:\Program Files (x86)\Stardock\Start101\Start10Srv.exe
19:48:38.0359 0x0820 Start10 - ok
19:48:38.0366 0x0820 StateRepository - ok
19:48:38.0390 0x0820 [ E06AA279D85877268E34E9A9BC41F560, 6EFE7E3850CD19B919053293B6D8CB61CC638D3B1626BB62594C681625132689 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
19:48:38.0418 0x0820 Steam Client Service - ok
19:48:38.0426 0x0820 stexstor - ok
19:48:38.0431 0x0820 stisvc - ok
19:48:38.0437 0x0820 storahci - ok
19:48:38.0444 0x0820 storflt - ok
19:48:38.0450 0x0820 stornvme - ok
19:48:38.0456 0x0820 storqosflt - ok
19:48:38.0462 0x0820 StorSvc - ok
19:48:38.0467 0x0820 storufs - ok
19:48:38.0473 0x0820 storvsc - ok
19:48:38.0479 0x0820 svsvc - ok
19:48:38.0485 0x0820 swenum - ok
19:48:38.0491 0x0820 swprv - ok
19:48:38.0497 0x0820 Synth3dVsc - ok
19:48:38.0503 0x0820 SysMain - ok
19:48:38.0509 0x0820 SystemEventsBroker - ok
19:48:38.0516 0x0820 TabletInputService - ok
19:48:38.0522 0x0820 TapiSrv - ok
19:48:38.0528 0x0820 Tcpip - ok
19:48:38.0534 0x0820 Tcpip6 - ok
19:48:38.0545 0x0820 tcpipreg - ok
19:48:38.0555 0x0820 tdx - ok
19:48:38.0561 0x0820 terminpt - ok
19:48:38.0567 0x0820 TermService - ok
19:48:38.0573 0x0820 Themes - ok
19:48:38.0579 0x0820 TieringEngineService - ok
19:48:38.0585 0x0820 tiledatamodelsvc - ok
19:48:38.0592 0x0820 TimeBroker - ok
19:48:38.0598 0x0820 TPM - ok
19:48:38.0604 0x0820 TrkWks - ok
19:48:38.0610 0x0820 TrustedInstaller - ok
19:48:38.0621 0x0820 tsusbflt - ok
19:48:38.0627 0x0820 TsUsbGD - ok
19:48:38.0633 0x0820 tzautoupdate - ok
19:48:38.0640 0x0820 uagp35 - ok
19:48:38.0646 0x0820 UASPStor - ok
19:48:38.0652 0x0820 UcmCx0101 - ok
19:48:38.0658 0x0820 UcmUcsi - ok
19:48:38.0664 0x0820 Ucx01000 - ok
19:48:38.0670 0x0820 UdeCx - ok
19:48:38.0677 0x0820 udfs - ok
19:48:38.0683 0x0820 UEFI - ok
19:48:38.0689 0x0820 Ufx01000 - ok
19:48:38.0695 0x0820 UfxChipidea - ok
19:48:38.0701 0x0820 ufxsynopsys - ok
19:48:38.0717 0x0820 UI0Detect - ok
19:48:38.0723 0x0820 uliagpkx - ok
19:48:38.0729 0x0820 umbus - ok
19:48:38.0735 0x0820 UmPass - ok
19:48:38.0742 0x0820 UmRdpService - ok
19:48:38.0749 0x0820 UnistoreSvc - ok
19:48:38.0811 0x0820 upnphost - ok
19:48:38.0817 0x0820 UrsChipidea - ok
19:48:38.0823 0x0820 UrsCx01000 - ok
19:48:38.0830 0x0820 UrsSynopsys - ok
19:48:38.0838 0x0820 [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\WINDOWS\System32\Drivers\usbaapl64.sys
19:48:38.0851 0x0820 USBAAPL64 - ok
19:48:38.0858 0x0820 usbccgp - ok
19:48:38.0865 0x0820 usbcir - ok
19:48:38.0871 0x0820 usbehci - ok
19:48:38.0878 0x0820 usbhub - ok
19:48:38.0884 0x0820 USBHUB3 - ok
19:48:38.0891 0x0820 usbohci - ok
19:48:38.0897 0x0820 usbprint - ok
19:48:38.0903 0x0820 usbser - ok
19:48:38.0910 0x0820 USBSTOR - ok
19:48:38.0916 0x0820 usbuhci - ok
19:48:38.0923 0x0820 USBXHCI - ok
19:48:38.0930 0x0820 UserDataSvc - ok
19:48:38.0995 0x0820 UserManager - ok
19:48:39.0002 0x0820 UsoSvc - ok
19:48:39.0009 0x0820 VaultSvc - ok
19:48:39.0016 0x0820 vdrvroot - ok
19:48:39.0022 0x0820 vds - ok
19:48:39.0029 0x0820 VerifierExt - ok
19:48:39.0035 0x0820 vhdmp - ok
19:48:39.0042 0x0820 vhf - ok
19:48:39.0049 0x0820 vmbus - ok
19:48:39.0055 0x0820 VMBusHID - ok
19:48:39.0062 0x0820 vmicguestinterface - ok
19:48:39.0069 0x0820 vmicheartbeat - ok
19:48:39.0075 0x0820 vmickvpexchange - ok
19:48:39.0082 0x0820 vmicrdv - ok
19:48:39.0088 0x0820 vmicshutdown - ok
19:48:39.0096 0x0820 vmictimesync - ok
19:48:39.0102 0x0820 vmicvmsession - ok
19:48:39.0108 0x0820 vmicvss - ok
19:48:39.0115 0x0820 volmgr - ok
19:48:39.0122 0x0820 volmgrx - ok
19:48:39.0128 0x0820 volsnap - ok
19:48:39.0135 0x0820 vpci - ok
19:48:39.0142 0x0820 vsmraid - ok
19:48:39.0148 0x0820 VSS - ok
19:48:39.0155 0x0820 VSTXRAID - ok
19:48:39.0162 0x0820 vwifibus - ok
19:48:39.0168 0x0820 vwififlt - ok
19:48:39.0175 0x0820 W32Time - ok
19:48:39.0182 0x0820 w3logsvc - ok
19:48:39.0190 0x0820 W3SVC - ok
19:48:39.0197 0x0820 WacomPen - ok
19:48:39.0204 0x0820 WalletService - ok
19:48:39.0211 0x0820 wanarp - ok
19:48:39.0218 0x0820 wanarpv6 - ok
19:48:39.0225 0x0820 WAS - ok
19:48:39.0231 0x0820 wbengine - ok
19:48:39.0239 0x0820 WbioSrvc - ok
19:48:39.0246 0x0820 Wcmsvc - ok
19:48:39.0252 0x0820 wcncsvc - ok
19:48:39.0259 0x0820 WcsPlugInService - ok
19:48:39.0267 0x0820 WdBoot - ok
19:48:39.0274 0x0820 Wdf01000 - ok
19:48:39.0280 0x0820 WdFilter - ok
19:48:39.0287 0x0820 WdiServiceHost - ok
19:48:39.0294 0x0820 WdiSystemHost - ok
19:48:39.0301 0x0820 wdiwifi - ok
19:48:39.0308 0x0820 WdNisDrv - ok
19:48:39.0314 0x0820 WdNisSvc - ok
19:48:39.0322 0x0820 WebClient - ok
19:48:39.0329 0x0820 Wecsvc - ok
19:48:39.0336 0x0820 WEPHOSTSVC - ok
19:48:39.0343 0x0820 wercplsupport - ok
19:48:39.0350 0x0820 WerSvc - ok
19:48:39.0357 0x0820 WFPLWFS - ok
19:48:39.0364 0x0820 WiaRpc - ok
19:48:39.0371 0x0820 WIMMount - ok
19:48:39.0378 0x0820 WinDefend - ok
19:48:39.0397 0x0820 WindowsTrustedRT - ok
19:48:39.0404 0x0820 WindowsTrustedRTProxy - ok
19:48:39.0412 0x0820 WinHttpAutoProxySvc - ok
19:48:39.0419 0x0820 WinMad - ok
19:48:39.0429 0x0820 Winmgmt - ok
19:48:39.0436 0x0820 WinRM - ok
19:48:39.0455 0x0820 WINUSB - ok
19:48:39.0462 0x0820 WinVerbs - ok
19:48:39.0470 0x0820 WlanSvc - ok
19:48:39.0477 0x0820 wlidsvc - ok
19:48:39.0484 0x0820 WmiAcpi - ok
19:48:39.0497 0x0820 wmiApSrv - ok
19:48:39.0504 0x0820 WMPNetworkSvc - ok
19:48:39.0516 0x0820 [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof C:\WINDOWS\system32\drivers\Wof.sys
19:48:39.0531 0x0820 Wof - ok
19:48:39.0545 0x0820 workfolderssvc - ok
19:48:39.0552 0x0820 wpcfltr - ok
19:48:39.0559 0x0820 WPDBusEnum - ok
19:48:39.0566 0x0820 WpdUpFltr - ok
19:48:39.0574 0x0820 WpnService - ok
19:48:39.0582 0x0820 [ 7CA09731EB7FC99B910C7F239E57720F, 502F8917A0811F37C39B2B3F5E9B4F38A0E899C30CB29D3ECD87A50FF228E536 ] WPRO_41_2001 C:\WINDOWS\system32\drivers\WPRO_41_2001.sys
19:48:39.0591 0x0820 WPRO_41_2001 - ok
19:48:39.0598 0x0820 ws2ifsl - ok
19:48:39.0613 0x0820 [ 69671F82C17650612B68519ADA192F65, 282A0B8E5455DEEAE8AFED270A438F67463324C1B2A11369A7D3B0D47987EE53 ] WsAppService C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppService.exe
19:48:39.0625 0x0820 WsAppService - detected UnsignedFile.Multi.Generic ( 1 )
19:48:39.0662 0x0820 Detect skipped due to KSN trusted
19:48:39.0662 0x0820 WsAppService - ok
19:48:39.0670 0x0820 wscsvc - ok
19:48:39.0677 0x0820 WSDPrintDevice - ok
19:48:39.0688 0x0820 [ 41B8BD5F7E665710E4E3FA4C5CE0FDC8, 653F215F741B33F1E43FAA520F3F20DDD9A65721EADE68B196E382F877EB5359 ] WsDrvInst C:\Program Files (x86)\Wondershare\MobileGo\DriverInstall.exe
19:48:39.0698 0x0820 WsDrvInst - ok
19:48:39.0706 0x0820 WSDScan - ok
19:48:39.0713 0x0820 WSearch - ok
19:48:39.0727 0x0820 WSService - ok
19:48:39.0734 0x0820 wuauserv - ok
19:48:39.0742 0x0820 WudfPf - ok
19:48:39.0749 0x0820 WUDFRd - ok
19:48:39.0757 0x0820 wudfsvc - ok
19:48:39.0764 0x0820 WUDFWpdFs - ok
19:48:39.0771 0x0820 WUDFWpdMtp - ok
19:48:39.0779 0x0820 WwanSvc - ok
19:48:39.0787 0x0820 XblAuthManager - ok
19:48:39.0794 0x0820 XblGameSave - ok
19:48:39.0802 0x0820 xboxgip - ok
19:48:39.0809 0x0820 XboxNetApiSvc - ok
19:48:39.0817 0x0820 xinputhid - ok
19:48:39.0831 0x0820 [ 2C6BC21B2D5B58D8B1D638C1704CB494, 0AABCEB627E274E338DDD9BA664BAA128D7C00AF04C95C776C2AFFA6BB17F680 ] xusb21 C:\WINDOWS\system32\DRIVERS\xusb21.sys
19:48:39.0841 0x0820 xusb21 - ok
19:48:39.0842 0x0820 ================ Scan global ===============================
19:48:39.0849 0x0820 [ Global ] - ok
19:48:39.0850 0x0820 ================ Scan MBR ==================================
19:48:39.0872 0x0820 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
19:48:39.0943 0x0820 \Device\Harddisk0\DR0 - ok
19:48:39.0944 0x0820 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
19:48:39.0983 0x0820 \Device\Harddisk1\DR1 - ok
19:48:39.0984 0x0820 ================ Scan VBR ==================================
19:48:39.0985 0x0820 [ 52229DCFF00A9CB9FADFFE2BBC89B527 ] \Device\Harddisk0\DR0\Partition1
19:48:39.0986 0x0820 \Device\Harddisk0\DR0\Partition1 - ok
19:48:39.0987 0x0820 [ C0D3076AF00DB06B3724EC0B6D7444A2 ] \Device\Harddisk1\DR1\Partition1
19:48:39.0988 0x0820 \Device\Harddisk1\DR1\Partition1 - ok
19:48:39.0990 0x0820 [ 979C122A32EC148AB1FDA57C7C389A01 ] \Device\Harddisk1\DR1\Partition2
19:48:39.0991 0x0820 \Device\Harddisk1\DR1\Partition2 - ok
19:48:39.0991 0x0820 ================ Scan generic autorun ======================
19:48:40.0208 0x0820 [ C584AF9EB11C90469DE2747BE583EB01, B7F149F48CAEB3230469CF078841C6B31BD4EDEF9CDB295AF53B8B69ED50824F ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
19:48:40.0476 0x0820 RTHDVCPL - ok
19:48:40.0507 0x0820 [ ED43758BF94B8A5221D69F1B7F63F13D, F6E7418823E45085F4D4F50DD25A55ED517C0A335C6C2F69A1139B30677D3DA9 ] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
19:48:40.0531 0x0820 XboxStat - ok
19:48:40.0542 0x0820 [ 20C08CA080F650B730B1E3FDEA9AD532, 1D2B0914412378E0B5834A95BDD86F8927B6A8D37F4E044C904CE381F1C19A75 ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
19:48:40.0558 0x0820 AdobeAAMUpdater-1.0 - ok
19:48:40.0564 0x0820 [ 747CEF68DA0B3BABD64B74C0E06C050E, C640AF94F66025E8B9937A37A361547580DB3F0B5F62F21E8B30A087BE018015 ] C:\Program Files\iTunes\iTunesHelper.exe
19:48:40.0576 0x0820 iTunesHelper - ok
19:48:40.0578 0x0820 Logitech Download Assistant - ok
19:48:40.0665 0x0820 [ 6B34B34C61D69D9B7B7A46B364C9FC47, 43E9BC13021399EA859A04DC9824C195C984D8037842747834858194B84D14F6 ] C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
19:48:40.0779 0x0820 StartCN - ok
19:48:40.0799 0x0820 [ 50B4BD30A102B5E7BFAEB87629C94466, A6AA1097A77F5AA84111F98C84E51B7219B893308E16D909D8915AB46C6E71EE ] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe
19:48:40.0817 0x0820 LexwareInfoService - ok
19:48:40.0912 0x0820 [ A8D9ADD3A366F7E475304EDC9FB382A8, 6589C37AA6A5159BC4EF8988719E124A179991E7D2DADD755713E86DB04686B9 ] C:\Program Files (x86)\ABBYY FineReader 12\Bonus.ScreenshotReader.exe
19:48:40.0999 0x0820 Bonus.SSR.FR12 - detected UnsignedFile.Multi.Generic ( 1 )
19:48:41.0037 0x0820 Detect skipped due to KSN trusted
19:48:41.0037 0x0820 Bonus.SSR.FR12 - ok
19:48:41.0104 0x0820 [ 1A774CBE54318A3411539BA10D47BEF5, 99CDBD90429FCAFA1C814E49EFF1160E8DC7D43B8F82E8AC33116BE7D42DBA9B ] C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
19:48:41.0160 0x0820 Malwarebytes Anti-Exploit - ok
19:48:41.0252 0x0820 [ 6F5C9785C05D23DABE407653C12B8A05, 3EC2AACE39D47BC3C34CC8F53DA652A5FFE3A09304AB77AFCF17D4E5CC10F82E ] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe
19:48:41.0317 0x0820 ISUSPM - ok
19:48:41.0404 0x0820 [ C43B7F065407BB18FC359AA4FB436DB5, B4B0C83810A2A4472F89D0135CDFE85BC15AAB0216414502B7EFC7E1313B648D ] C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe
19:48:41.0494 0x0820 OmniPage Preload - ok
19:48:41.0521 0x0820 [ 130924FEDB988C2E01A33E8B2C9CD588, BA0634A5A590A027D1562F5EA6B0B977C9E39CDA601B50790A8EE6098D5E82E6 ] C:\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe
19:48:41.0535 0x0820 Nuance OmniPage Ultimate-reminder - ok
19:48:41.0561 0x0820 [ F44FD5B2D864BB57061B7F667980D17A, 2E3081AC8B9EC1435EB7A0B4A830C1EB25F5212C9776C10DC7284C1ED94199ED ] C:\Program Files (x86)\Nuance\PDFCreate8\pdfcreate8hook.exe
19:48:41.0594 0x0820 PDFCreHook - ok
19:48:41.0601 0x0820 [ 28B8ECAE3A212BC442C89ED32F28740C, 3A6CD16F56702FE8407C2E124FD4668A488D89C894E4B9E34E03AF036DEAAD60 ] C:\Program Files (x86)\Nuance\PDFCreate8\RegistryController.exe
19:48:41.0612 0x0820 PDF8 Registry Controller - ok
19:48:41.0642 0x0820 [ 53C3DFF8527E91787533D3FAF38D0A93, 9AD1FCB61F6DB4FE7F33799414465E65E07A40410C24992F7C9B779557468C25 ] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe
19:48:41.0679 0x0820 Acrobat Assistant 8.0 - ok
19:48:41.0796 0x0820 OneDriveSetup - ok
19:48:41.0797 0x0820 OneDriveSetup - ok
19:48:41.0828 0x0820 [ 91DD4AD85BB341CC8CF5187EA06FD171, 68330A5EBDA7E4A51926EC2085D71C11BD2857A6EB1D4749DEE7A6D1D5679B98 ] C:\Users\NABIL\AppData\Local\Microsoft\OneDrive\OneDrive.exe
19:48:41.0853 0x0820 OneDrive - ok
19:48:42.0046 0x0820 [ 3D5D4137594D2EBA8868EAD504B89366, D5FEB5B8303B083A79A4617E59B2FB34FAD71BE72F3F8DD6E4B69B3D03FE658A ] C:\Program Files\DAEMON Tools Lite\DTAgent.exe
19:48:42.0196 0x0820 DAEMON Tools Lite Automount - ok
19:48:42.0205 0x0820 Skype - ok
19:48:42.0207 0x0820 Speech Recognition - ok
19:48:42.0249 0x0820 [ 5EC5BE9EE2702B3B574BE7AD975590BC, 21DB2BCFEA9DC10CF0AD80CC737C438ABC79BA671A79F3C152BC679EB63E6BCD ] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
19:48:42.0287 0x0820 Adobe Acrobat Synchronizer - ok
19:48:42.0315 0x0820 [ F7BF95877017F53DDAEBC4E87A309168, F7849DBC61E5E7C42B97D011364ADC7C20257994FECBFA988C8CB2E779392F80 ] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
19:48:42.0330 0x0820 iCloudServices - ok
19:48:42.0384 0x0820 [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\asd\AppData\Local\Microsoft\OneDrive\OneDrive.exe
19:48:42.0412 0x0820 OneDrive - ok
19:48:42.0547 0x0820 [ 3D5D4137594D2EBA8868EAD504B89366, D5FEB5B8303B083A79A4617E59B2FB34FAD71BE72F3F8DD6E4B69B3D03FE658A ] C:\Program Files\DAEMON Tools Lite\DTAgent.exe
19:48:42.0615 0x0820 DAEMON Tools Lite Automount - ok
19:48:42.0665 0x0820 [ ADF6C78FC95716CA45A68FD3DA1C1A78, 8250D47AC8C25A3A2DB8AB2148350F7086141F91DB317D0431DA545430B843F5 ] C:\Program Files (x86)\Steam\steam.exe
19:48:42.0718 0x0820 Steam - ok
19:48:42.0764 0x0820 [ 5EC5BE9EE2702B3B574BE7AD975590BC, 21DB2BCFEA9DC10CF0AD80CC737C438ABC79BA671A79F3C152BC679EB63E6BCD ] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
19:48:42.0783 0x0820 Adobe Acrobat Synchronizer - ok
19:48:42.0857 0x0820 Uninstall C:\Users\asd\AppData\Local\Microsoft\OneDrive\17.3.6386.0412_1\amd64 - ok
19:48:42.0861 0x0820 Uninstall C:\Users\asd\AppData\Local\Microsoft\OneDrive\17.3.6386.0412_1 - ok
19:48:42.0941 0x0820 OneDriveSetup - ok
19:48:42.0953 0x0820 [ 61F488AC3053DEB2AADB6A34DEBC8876, B5C5E0325F0FB4A37E80F08273B7483630F676C6342519564798CE7D1F121CB7 ] C:\Users\bazet\AppData\Local\Microsoft\OneDrive\OneDrive.exe
19:48:42.0974 0x0820 OneDrive - ok
19:48:42.0975 0x0820 WAB Migrate - ok
19:48:42.0976 0x0820 OneDriveSetup - ok
19:48:42.0994 0x0820 [ EFC73875D6A2DECAD030633A9A75F00A, AA7B65649B37FFC68A6FFB23CBBE73E1BB873C840B9EA0049421D2B4C0EC364F ] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILEE.EXE
19:48:43.0008 0x0820 EPLTarget\P0000000000000000 - ok
19:48:43.0009 0x0820 WAB Migrate - ok
19:48:43.0011 0x0820 OneDriveSetup - ok
19:48:43.0011 0x0820 WAB Migrate - ok
19:48:43.0012 0x0820 Waiting for KSN requests completion. In queue: 91
19:48:44.0030 0x0820 AV detected via SS2: Emsisoft Anti-Malware, C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2start.exe ( 9.0.0.4668 ), 0x40010 ( disabled : outofdate )
19:48:44.0033 0x0820 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.494 ), 0x61100 ( enabled : updated )
19:48:44.0036 0x0820 Win FW state via NFP2: enabled ( trusted )
19:48:44.0127 0x0820 ============================================================
19:48:44.0127 0x0820 Scan finished
19:48:44.0127 0x0820 ============================================================
19:48:44.0131 0x323c Detected object count: 0
19:48:44.0131 0x323c Actual detected object count: 0 Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
durchgeführt von NABIL (Administrator) auf NABIL-PC (11-09-2016 20:02:25)
Gestartet von C:\Users\NABIL\Downloads
Geladene Profile: NABIL (Verfügbare Profile: NABIL & asd & bazet & Gast & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start101\Start10Srv.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
(Gladinet, INC) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
() C:\Windows\SysWOW64\ASGT.exe
() C:\Windows\KMS-R@1n.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\ASUS\APRP\AsusProductRegisterService.exe
(ABBYY Production LLC) C:\Program Files (x86)\ABBYY FineReader 12\NetworkLicenseServer.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
() C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start101\Start10_64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(Wondershare) C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe
(Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\agent.exe
(Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Gladinet, INC) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetClient.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDFCreate8\PdfCreate8Hook.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1608.2213.0_x64__8wekyb3d8bbwe\Calculator.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Valve Corporation) M:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) M:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
(Valve Corporation) M:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) M:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) M:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEpson Portal\mep.exe
(AO Kaspersky Lab) C:\Users\NABIL\Downloads\tdsskiller.exe
(AO Kaspersky Lab) C:\Users\NABIL\AppData\Local\Temp\{D0F90BAE-133B-4DA8-A184-20208F6568FD}\{061B3142-B031-4678-A94D-628B6536EFD0}.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Windows\KMS-R@1nhook.exe
(Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16697352 2016-08-26] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-01-07] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-06-01] (Apple Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6613896 2016-06-24] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LexwareInfoService] => C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM-x32\...\Run: [Bonus.SSR.FR12] => C:\Program Files (x86)\ABBYY FineReader 12\Bonus.ScreenshotReader.exe [1517088 2014-09-22] (ABBYY Production LLC.)
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2631120 2016-07-28] (Malwarebytes Corporation)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-13] (Flexera Software LLC.)
HKLM-x32\...\Run: [OmniPage Preload] => C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe [3021528 2014-11-25] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Nuance OmniPage Ultimate-reminder] => "C:\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\OmniPage Ultimate\Ereg\Ereg.ini"
HKLM-x32\...\Run: [PDFCreHook] => C:\Program Files (x86)\Nuance\PDFCreate8\pdfcreate8hook.exe [1109016 2014-11-27] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF8 Registry Controller] => C:\Program Files (x86)\Nuance\PDFCreate8\RegistryController.exe [189976 2014-11-27] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1867448 2016-07-28] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1279120 2012-09-27] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-225648569-1694930765-1264359465-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-225648569-1694930765-1264359465-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-225648569-1694930765-1264359465-1000\...\Run: [Speech Recognition] => C:\WINDOWS\Speech\Common\sapisvr.exe [45056 2015-10-30] (Microsoft Corporation)
HKU\S-1-5-21-225648569-1694930765-1264359465-1000\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [884920 2016-06-30] (Adobe Systems Incorporated)
HKU\S-1-5-21-225648569-1694930765-1264359465-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-04-22] (Apple Inc.)
IFEO\OSppSvc.exe: [Debugger] KMS-R@1nhook.exe
IFEO\SppExtComObj.exe: [Debugger] KMS-R@1nhook.exe
ShellIconOverlayIdentifiers: [GladinetIconOverlay] -> {3C3DC57A-7535-48AF-BB9E-C3576A4F34D0} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GlOverlayIcon.dll [2013-08-08] (Gladinet, INC)
ShellIconOverlayIdentifiers: [GladinetUploading] -> {959A18D3-9CC9-41e8-B76F-34ED9A89D4EA} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GlOverlayIconU.dll [2013-08-08] (Gladinet, INC)
ShellIconOverlayIdentifiers-x32: [GladinetIconOverlay] -> {3C3DC57A-7535-48AF-BB9E-C3576A4F34D0} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GlOverlayIcon32.dll [2013-08-08] (Gladinet, INC)
ShellIconOverlayIdentifiers-x32: [GladinetUploading] -> {959A18D3-9CC9-41e8-B76F-34ED9A89D4EA} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GlOverlayIconU32.dll [2013-08-08] (Gladinet, INC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-15]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MobileGo Service.lnk [2016-04-06]
ShortcutTarget: MobileGo Service.lnk -> C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe (Wondershare)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Nuance Cloud Connector.lnk [2016-02-23]
ShortcutTarget: Nuance Cloud Connector.lnk -> C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladLauncher.exe ()
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Hosts: Es ist mehr als ein Eintrag in der Hosts Datei zu finden. Siehe Hosts-Bereich in Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{281f7690-3078-4910-b67d-7743d4eb2a9a}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{F37B658C-DD8B-4CF0-8B0B-6CE9D411B48F}: [NameServer] 208.67.222.222 208.67.220.220
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-225648569-1694930765-1264359465-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/androidnews/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-07-19] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Adblock IE -> {667BEE43-20BD-4CE3-94AC-E63E04D4B191} -> C:\Program Files\MGTEK\Adblock IE\adblockie.dll [2013-05-08] (MGTEK)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_102\bin\ssv.dll [2016-07-30] (Oracle Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (Seiko Epson Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-05-16] (Adobe Systems Incorporated)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-07-12] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_102\bin\jp2ssv.dll [2016-07-30] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-05-16] (Adobe Systems Incorporated)
BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-07-19] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO-x32: Adblock IE -> {667BEE43-20BD-4CE3-94AC-E63E04D4B191} -> C:\Program Files (x86)\MGTEK\Adblock IE\adblockie.dll [2013-05-08] (MGTEK)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\ssv.dll [2016-07-30] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-05-16] (Adobe Systems Incorporated)
BHO-x32: ZeonIEEventHelper Class -> {C7DA0384-42AA-428c-B832-88AC343DE1A8} -> C:\Program Files (x86)\Nuance\PDFCreate8\Bin\GZeonIEFavClient.dll [2013-05-16] (Zeon Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-07-12] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\jp2ssv.dll [2016-07-30] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-05-16] (Adobe Systems Incorporated)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (Seiko Epson Corporation)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-05-16] (Adobe Systems Incorporated)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Nuance PDF - {BCCE15AE-AC7E-4bc9-94AF-2A714A412BCB} - C:\Program Files (x86)\Nuance\PDFCreate8\Bin\GZeonIEFavClient.dll [2013-05-16] (Zeon Corporation)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-05-16] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKU\S-1-5-21-225648569-1694930765-1264359465-1000 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-05-16] (Adobe Systems Incorporated)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-30] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\dtplugin\npDeployJava1.dll [2016-07-30] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\plugin2\npjp2.dll [2016-07-30] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> m:\Program Files\VideoLAN\VLC\npvlc.dll [2013-09-25] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-07-29] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-30] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw.dll [2016-02-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.102.2 -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\dtplugin\npDeployJava1.dll [2016-07-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.102.2 -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\plugin2\npjp2.dll [2016-07-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-03-18] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-07-29] (Adobe Systems)
FF Plugin HKU\S-1-5-21-225648569-1694930765-1264359465-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)
FF Extension: (Kein Name) - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release6352\ff [nicht gefunden]
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2016-02-22] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat DC - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2016-06-01]
Chrome:
=======
CHR Profile: C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-02]
CHR Extension: (YouTube) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Adblock Plus) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-09-01]
CHR Extension: (Google-Suche) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02]
CHR Extension: (Adblock Plus) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\fancjlijdfajbmighlldmgmeobfmempn [2015-03-23]
CHR Extension: (Google Docs Offline) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-19]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-19]
CHR Extension: (Google Mail) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR Extension: (Chrome Media Router) - C:\Users\NABIL\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-01]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4907232 2014-12-01] (Emsisoft GmbH)
R2 ABBYY.Licensing.FineReader.Professional.12.0; C:\Program Files (x86)\ABBYY FineReader 12\NetworkLicenseServer.exe [961744 2014-07-13] (ABBYY Production LLC)
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [138752 2016-06-24] () [Datei ist nicht signiert]
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2159320 2016-08-22] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [Datei ist nicht signiert]
R2 Asus Product Register Service; C:\Program Files (x86)\ASUS\APRP\AsusProductRegisterService.exe [62128 2012-09-11] () [Datei ist nicht signiert]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1145216 2015-05-19] ()
R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [382312 2015-11-27] (Digital Wave Ltd.)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 GladFileMonSvc; C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe [30032 2013-08-08] (Gladinet, INC)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-30] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Datei ist nicht signiert]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-12] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 KMS-R@1n; C:\Windows\KMS-R@1n.exe [26112 2016-02-11] () [Datei ist nicht signiert]
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2934048 2015-11-10] (IObit)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [750032 2016-07-28] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe [327944 2016-07-19] (McAfee, Inc.)
R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [703984 2014-09-22] (SEIKO EPSON CORPORATION)
S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1\RpcAgentSrv.exe [73200 2015-02-15] (SiSoftware) [Datei ist nicht signiert]
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
R2 Start10; C:\Program Files (x86)\Stardock\Start101\Start10Srv.exe [219664 2015-02-03] (Stardock Software, Inc)
S3 vmicvss; C:\Windows\System32\ICSvc.dll [511488 2015-10-30] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.1.6.0\WsAppService.exe [388608 2016-01-28] (Wondershare) [Datei ist nicht signiert]
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\MobileGo\DriverInstall.exe [124168 2016-01-19] (Wondershare)
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [62152 2014-10-28] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-12-22] (Advanced Micro Devices)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-09-10] (Disc Soft Ltd)
R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d65x64.sys [531424 2015-12-22] (Intel Corporation)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [74984 2016-07-28] ()
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-11-08] (REALiX(tm))
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21048 2013-03-14] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21048 2013-03-14] ()
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [23680 2010-02-23] (ASUSTeK Computer Inc.)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-03-14] ()
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
S3 MotioninJoyXFilter; C:\Windows\System32\DRIVERS\MijXfilt.sys [121416 2012-05-12] (MotioninJoy) [Datei ist nicht signiert]
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1\WNt600x64\Sandra.sys [23112 2009-08-07] (SiSoftware)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2015-12-22] (Synaptics Incorporated)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2016-04-30] ()
U4 idsvc; kein ImagePath
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-09-11 19:40 - 2016-09-11 19:49 - 00099796 _____ C:\TDSSKiller.3.1.0.11_11.09.2016_19.40.39_log.txt
2016-09-11 19:40 - 2016-09-11 19:40 - 04747704 _____ (AO Kaspersky Lab) C:\Users\NABIL\Downloads\tdsskiller.exe
2016-09-11 19:40 - 2016-09-11 19:40 - 00250064 ____N (Kaspersky Lab, Yury Parshin) C:\WINDOWS\system32\Drivers\34425297.sys
2016-09-11 19:37 - 2016-09-11 20:02 - 00032855 _____ C:\Users\NABIL\Downloads\FRST.txt
2016-09-11 19:37 - 2016-09-11 20:02 - 00000000 ____D C:\FRST
2016-09-11 19:37 - 2016-09-11 19:39 - 00074242 _____ C:\Users\NABIL\Downloads\Addition.txt
2016-09-11 19:36 - 2016-09-11 19:36 - 02397696 _____ (Farbar) C:\Users\NABIL\Downloads\FRST64.exe
2016-09-04 20:53 - 2016-09-04 20:53 - 00005208 _____ C:\Users\NABIL\Downloads\relink.to__Rampage_2009_German_DTS_DL_1080p_BluRay_x264_-_SoW_158023ecdb764581577579d64a4c06.dlc
2016-09-04 20:19 - 2016-09-04 20:19 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-09-04 20:19 - 2016-08-26 09:18 - 72520720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2016-09-04 20:19 - 2016-08-26 09:18 - 24414760 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRenderAVX64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 24323312 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRender64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 17377488 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioCapture64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 15202040 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE3.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 14057256 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRealtek64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 13122584 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO3064.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 12988352 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO4064.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 10534696 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSSTAPO.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 07172920 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 07096192 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 06947183 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2016-09-04 20:19 - 2016-08-26 09:18 - 06374320 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV3apo.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 06264640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 05793528 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 05593616 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 05341352 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 05293064 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2016-09-04 20:19 - 2016-08-26 09:18 - 03299824 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 03291320 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 03283248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 03203592 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 03134720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02895104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2016-09-04 20:19 - 2016-08-26 09:18 - 02825104 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO7064.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02776224 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02706864 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02439048 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02203752 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02190992 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02110600 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02073096 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 02050184 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01965816 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01959608 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01920820 _____ C:\WINDOWS\system32\Drivers\rtkSSTsetting.dat
2016-09-04 20:19 - 2016-08-26 09:18 - 01780624 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01607136 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64APO.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01591064 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01529144 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64Proxy.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01508936 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01435144 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01422928 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO6064.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01382240 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01360520 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01337648 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01334384 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxSpeechAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01213664 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO5064.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01186840 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSstCApoPropPage.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01166160 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01115144 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01041744 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01003864 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 01001800 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00999856 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO2064.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00965032 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00962136 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00931624 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00923744 _____ (Sony Corporation) C:\WINDOWS\system32\MISS_APO.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00873464 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00864344 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00858200 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00854032 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00743968 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00727440 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00725944 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00708312 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00689888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00678184 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00677672 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00618192 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00601144 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00574760 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00571376 _____ (Intel Corporation) C:\WINDOWS\system32\tbb_waves.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00532384 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00514528 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00504312 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00500560 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00498648 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00472312 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00467160 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00447720 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00447184 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00445400 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00441272 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00438696 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\CAF64APO2.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00428232 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00416512 _____ (Harman) C:\WINDOWS\system32\HMUI.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00387320 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00381416 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00372744 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00366128 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00362056 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00360344 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00341152 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00341152 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00330568 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00327456 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00310424 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00272720 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00258864 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00253904 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00253864 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00252880 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00231920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00221968 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00214832 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00209536 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00203848 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00192984 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00190936 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00190936 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00179600 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00166208 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00158704 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00154368 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00151792 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00134200 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00122320 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00118600 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00118592 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00112496 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\Caf64api.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00110984 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00105304 _____ C:\WINDOWS\system32\audioLibVc.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00090920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00088352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00088328 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00084616 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00075544 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00023696 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2016-09-04 20:19 - 2016-08-26 09:18 - 00005604 _____ C:\WINDOWS\system32\cxapo.lncs
2016-09-04 20:19 - 2016-08-26 09:18 - 00000736 _____ C:\WINDOWS\system32\cxapo.prop
2016-09-04 20:13 - 2016-04-11 13:38 - 02838232 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll
2016-09-04 20:04 - 2016-09-04 20:08 - 348623152 _____ C:\Users\NABIL\Downloads\7917_PG448_Win10_TH_RS_Win8.1_Win8_Win7_WHQL.zip
2016-09-04 20:03 - 2016-09-04 20:03 - 01474568 _____ C:\Users\NABIL\Downloads\Realtek HD Audio Treiber inoffizielle WHQL Treiber - CHIP-Installer.exe
2016-09-04 20:02 - 2016-09-04 20:09 - 131494359 _____ (Realtek Semiconductor Corp.) C:\Users\NABIL\Downloads\0006-64bit_Win7_Win8_Win81_Win10_R279.exe
2016-08-21 20:23 - 2016-08-21 20:23 - 00000219 _____ C:\Users\NABIL\Desktop\Counter-Strike Global Offensive.url
2016-08-15 21:49 - 2016-08-15 21:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-08-14 20:54 - 2016-08-14 20:54 - 00110244 _____ C:\WINDOWS\Minidump\081416-17609-01.dmp
2016-08-14 17:29 - 2016-08-14 17:29 - 00000000 ____D C:\Program Files\ATI Technologies
2016-08-14 17:28 - 2016-09-04 20:20 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2016-08-12 01:07 - 2016-08-12 01:07 - 08892696 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd64.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 08738920 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 07115928 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00479368 _____ C:\WINDOWS\system32\amdmiracast.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00164280 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiu9p64.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00159088 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00154920 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00138688 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00138176 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00123120 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00123104 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00105344 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2016-08-12 01:07 - 2016-08-12 01:07 - 00105344 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 48819200 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 38266368 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 32555512 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atio6axx.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 27489280 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl12cl64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 26639360 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atioglxx.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 21641216 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl12cl.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 15729152 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticaldd64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 14320128 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticaldd.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 08830456 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdvlk64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 08627704 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmantle64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 07076352 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdvlk32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 06956032 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmantle32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 02376704 _____ C:\WINDOWS\system32\amdoclvp9lib64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 02286584 _____ C:\WINDOWS\SysWOW64\amdoclvp9lib32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 02147328 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 01837568 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00991232 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00883192 _____ (AMD) C:\WINDOWS\system32\coinst_16.30.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00751616 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00627192 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00459776 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00402944 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe
2016-08-12 01:06 - 2016-08-12 01:06 - 00350208 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODE.exe
2016-08-12 01:06 - 2016-08-12 01:06 - 00292352 _____ C:\WINDOWS\system32\dgtrayicon.exe
2016-08-12 01:06 - 2016-08-12 01:06 - 00287744 _____ (AMD) C:\WINDOWS\system32\atitmm64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00275968 _____ C:\WINDOWS\system32\GameManager64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00270336 _____ C:\WINDOWS\system32\clinfo.exe
2016-08-12 01:06 - 2016-08-12 01:06 - 00268792 _____ C:\WINDOWS\system32\hsa-thunk64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00249336 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00241152 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00234496 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00231424 _____ C:\WINDOWS\system32\atieah64.exe
2016-08-12 01:06 - 2016-08-12 01:06 - 00222208 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00209408 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2016-08-12 01:06 - 2016-08-12 01:06 - 00202744 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00201728 _____ C:\WINDOWS\system32\amdhdl64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00181760 _____ C:\WINDOWS\SysWOW64\amdhdl32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00176640 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00159736 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00137208 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00135168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00130560 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00123896 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6pxx.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00118784 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00113664 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00111616 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00109568 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00108544 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiglpxx.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00108544 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiglpxx.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00104448 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00083960 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00079864 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalrt64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00073216 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalcl64.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00069632 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalrt.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00068608 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODCLI.exe
2016-08-12 01:06 - 2016-08-12 01:06 - 00068096 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmmcl6.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00067584 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00066560 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalcl.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00060920 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\ati2erec.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00055800 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmmcl.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2016-08-12 01:06 - 2016-08-12 01:06 - 00021496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-09-11 19:42 - 2015-08-27 14:42 - 00000911 _____ C:\WINDOWS\Tasks\EPSON XP-412 413 415 Series Update {92EF7091-E3AF-4879-84FE-EE26D1C3216F}.job
2016-09-11 19:42 - 2015-08-27 14:42 - 00000725 _____ C:\WINDOWS\Tasks\EPSON XP-412 413 415 Series Invitation {92EF7091-E3AF-4879-84FE-EE26D1C3216F}.job
2016-09-11 19:36 - 2015-07-26 23:01 - 00000000 ____D C:\Users\NABIL\AppData\Roaming\TS3Client
2016-09-11 19:32 - 2013-10-25 18:03 - 00001136 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-11 19:16 - 2013-10-19 03:04 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-09-11 18:40 - 2013-10-08 21:23 - 00000000 ____D C:\Users\NABIL\AppData\Roaming\vlc
2016-09-11 12:32 - 2013-10-25 18:03 - 00001132 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-11 10:32 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-09-10 14:30 - 2016-02-23 01:50 - 00000000 ____D C:\Users\NABIL\AppData\Local\gladinet
2016-09-10 14:28 - 2014-04-17 17:43 - 00000000 ____D C:\ProgramData\TEMP
2016-09-10 14:27 - 2016-01-03 17:42 - 00000000 ____D C:\Users\NABIL\AppData\Roaming\Skype
2016-09-10 14:10 - 2016-02-21 13:31 - 00000000 ____D C:\Program Files (x86)\Steam
2016-09-10 14:10 - 2014-03-19 17:30 - 00000000 ____D C:\Users\NABIL\AppData\Local\JDownloader 2.0
2016-09-09 14:58 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-09-08 20:38 - 2015-11-08 01:18 - 00003978 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1446938337
2016-09-08 20:38 - 2015-11-08 01:18 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-09-08 20:38 - 2015-11-08 01:18 - 00000000 ____D C:\Program Files (x86)\Opera
2016-09-08 02:29 - 2016-01-27 18:45 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2016-09-04 20:27 - 2016-04-30 07:23 - 02089750 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-09-04 20:27 - 2016-02-13 18:59 - 00889234 _____ C:\WINDOWS\system32\perfh007.dat
2016-09-04 20:27 - 2016-02-13 18:59 - 00197816 _____ C:\WINDOWS\system32\perfc007.dat
2016-09-04 20:27 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-09-04 20:23 - 2013-11-12 22:14 - 00000000 ____D C:\ProgramData\AMD
2016-09-04 20:22 - 2014-11-08 04:57 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware
2016-09-04 20:21 - 2016-02-13 19:26 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-04 20:20 - 2016-04-30 07:22 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-09-04 20:20 - 2015-10-30 08:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
2016-09-04 20:20 - 2013-10-05 03:00 - 00000000 ___HD C:\Program Files (x86)\Temp
2016-09-04 20:19 - 2016-04-30 07:22 - 00000000 ____D C:\WINDOWS\system32\DAX2
2016-09-04 19:59 - 2015-07-26 23:01 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2016-09-01 09:14 - 2016-06-17 22:09 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-09-01 03:00 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-09-01 03:00 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-08-31 16:00 - 2016-04-30 07:23 - 00000000 ____D C:\Users\NABIL
2016-08-24 14:11 - 2016-06-05 19:08 - 00000000 ____D C:\Users\NABIL\Desktop\absagen vom 05.06.16
2016-08-24 13:47 - 2013-11-06 21:41 - 00000000 ____D C:\Users\NABIL\AppData\Local\Packages
2016-08-24 00:26 - 2013-10-25 16:51 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-08-15 21:49 - 2015-11-10 09:46 - 00002009 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-08-15 21:49 - 2015-11-10 09:46 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-08-15 10:01 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-08-14 22:47 - 2013-10-07 15:17 - 00000000 ____D C:\Users\NABIL\AppData\Local\ElevatedDiagnostics
2016-08-14 20:54 - 2016-07-27 17:51 - 00000000 ____D C:\WINDOWS\Minidump
2016-08-14 17:59 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\rescache
2016-08-14 17:29 - 2016-04-30 07:23 - 00000000 ____D C:\ProgramData\Package Cache
2016-08-14 17:29 - 2016-04-30 07:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2016-08-14 17:29 - 2016-04-30 07:23 - 00000000 ____D C:\Program Files (x86)\AMD
2016-08-14 17:28 - 2016-04-30 07:22 - 00000000 ____D C:\Program Files\AMD
2016-08-14 17:28 - 2014-05-28 01:55 - 00000000 ____D C:\AMD
2016-08-12 01:07 - 2016-04-23 00:56 - 10995344 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 10317568 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd6a.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 09340136 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdva.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 09131736 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 07258160 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdag.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 01547544 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 01273928 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 00183952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiuxp64.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 00152800 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiuxpag.dll
2016-08-12 01:07 - 2016-04-23 00:56 - 00137224 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiu9pag.dll
2016-08-12 01:06 - 2016-04-23 00:56 - 26706432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmdag.sys
2016-08-12 01:06 - 2016-04-23 00:56 - 01323008 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2016-08-12 01:06 - 2016-04-23 00:56 - 00991232 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2016-08-12 01:06 - 2016-04-23 00:56 - 00521728 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2016-08-12 01:06 - 2016-04-23 00:56 - 00518656 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmpag.sys
2016-08-12 01:06 - 2016-04-23 00:56 - 00287232 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-09-15 18:56 - 2015-09-15 18:56 - 0000000 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-09-15 18:56 - 2015-09-15 18:56 - 0000000 _____ () C:\Program Files (x86)\Common Files\AMD
2015-03-01 04:43 - 2015-03-01 05:31 - 14848000 _____ () C:\Users\NABIL\AppData\Roaming\Sandra.mdb
2016-04-30 07:22 - 2016-04-30 07:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Einige Dateien in TEMP:
====================
C:\Users\asd\AppData\Local\Temp\proxy_vole2008580591415989544.dll
C:\Users\asd\AppData\Local\Temp\proxy_vole5313419656434273934.dll
C:\Users\asd\AppData\Local\Temp\proxy_vole6505369171543915562.dll
C:\Users\NABIL\AppData\Local\Temp\i4jdel0.exe
C:\Users\NABIL\AppData\Local\Temp\MSETUP4.EXE
C:\Users\NABIL\AppData\Local\Temp\proxy_vole5631846365696866387.dll
C:\Users\NABIL\AppData\Local\Temp\proxy_vole571332217995924973.dll
C:\Users\NABIL\AppData\Local\Temp\proxy_vole576922321117719755.dll
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2016-09-09 20:18
==================== Ende von FRST.txt ============================ Ich hab das Programm deinstalliert was muss ich jetzt tun? |