Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Virus / unzählige Fenster öffnen sich

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 07.01.2013, 10:58   #1
herbcyy
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Hallo,
ich habe ein Problem mit einem vermutlichem Virus. Sobald ich meinen PC starte, öffnet sich immer ein kleines Fenster.Eigentlich wollte ich einen Screenshot davon posten, allerdings geht dieses im abgesichertem Modus leider nicht. Dieses Fenster öffnet sich immer wieder und das im Vordergrund, sodass ich erst wieder des Desktop anklicken muss um weiter arbeiten zu können. Das Fenster öffnet sich immer wieder, sodass ich nach einiger Zeit hunderte davon offen habe.

Ich werde nun meinen PC normal starten und versuchen den Screenshot hochzuladen.

Vielen Dank schonmal im Vorraus für die Hilfe

Hier ist der Screenshot. Im Moment öffnet sich der Virus nicht, aber ich möchte noch erwähnen, dass ich das gleiche Problem vor einem Monat schonmal hatte, aber plötzlich öffneten sich keine Fenster und ich dachte es wäre vorbei.
Angehängte Grafiken
Dateityp: jpg v.jpg (34,4 KB, 287x aufgerufen)

Alt 07.01.2013, 15:48   #2
markusg
/// Malware-holic
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Hi
Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die
    OTL.exe
    .
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere nun den Inhalt in die
    Textbox.
Code:
ATTFilter
activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread
__________________

__________________

Alt 07.01.2013, 18:53   #3
herbcyy
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Vielen Danke ! Allerdings hat sich nach dem Scan nur dir OTL.txt Datei geöffnet ?

OTL.text :

OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 07.01.2013 18:40:17 - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\jonas\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,82 Gb Available Physical Memory | 70,66% Memory free
7,99 Gb Paging File | 6,84 Gb Available in Paging File | 85,64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,51 Gb Total Space | 581,91 Gb Free Space | 62,47% Space Free | Partition Type: NTFS
Drive D: | 59,53 Gb Total Space | 41,71 Gb Free Space | 70,08% Space Free | Partition Type: NTFS
 
Computer Name: JONAS-PC | User Name: jonas | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\jonas\Downloads\OTL.exe (OldTimer Tools)
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AppleChargerSrv) -- C:\Windows\SysNative\AppleChargerSrv.exe ()
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Browser Manager) -- C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Radio.fx) -- C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe ()
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (BITCOMET_HELPER_SERVICE) -- C:\Program Files (x86)\BitComet\tools\BitCometService.exe (www.BitComet.com)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (JMB36X) -- C:\Windows\SysWOW64\XSrvSetup.exe ()
SRV - (ES lite Service) -- C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE ()
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (LVUVC64) -- C:\Windows\SysNative\drivers\LVUVC64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) -- C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (LADF_SBVM) -- C:\Windows\SysNative\drivers\ladfSBVMamd64.sys (Logitech)
DRV:64bit: - (LADF_DHP2) -- C:\Windows\SysNative\drivers\ladfDHP2amd64.sys (Logitech)
DRV:64bit: - (AppleCharger) -- C:\Windows\SysNative\drivers\AppleCharger.sys ()
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (RTHDMIAzAudService) -- C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiPcie) -- C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows (R) Server 2003 DDK provider)
DRV - (WinRing0_1_2_0) -- C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys (OpenLibSys.org)
DRV - (GVTDrv64) -- C:\Windows\GVTDrv64.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://start.facemoods.com/?a=bf2&s={searchTerms}&f=4
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.babylon.com/?affID=115303&tt=4412_4&babsrc=HP_ss&mntrId=5ac8997b0000000000001c6f653cf6f2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?affID=115303&tt=4412_4&babsrc=HP_ss&mntrId=5ac8997b0000000000001c6f653cf6f2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 EC 9D 12 CD 6B CC 01  [binary data]
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = hxxp://start.facemoods.com/?a=bf2&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = hxxp://search.babylon.com/?q={searchTerms}&affID=115303&tt=4412_4&babsrc=SP_ss&mntrId=5ac8997b0000000000001c6f653cf6f2
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "InnoGames Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2682599&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "hxxp://search.babylon.com/?affID=115303&tt=4412_4&babsrc=HP_ss&mntrId=5ac8997b0000000000001c6f653cf6f2"
FF - prefs.js..extensions.enabledAddons: ffxtlbr@Facemoods.com:1.4.1
FF - prefs.js..extensions.enabledAddons: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.29
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.7
FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.9
FF - prefs.js..extensions.enabledAddons: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.22
FF - prefs.js..extensions.enabledAddons: {c7478d43-2bd5-4844-98b8-c2a6aa9ed677}:3.14.1.0
FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.5.0
FF - prefs.js..extensions.enabledAddons: {9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}:1.0
FF - prefs.js..extensions.enabledAddons: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}:2.0
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2682599&q="
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@gamersfirst.com/LiveLauncher: C:\Program Files (x86)\GamersFirst\LIVE!\nplivelauncher.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\jonas\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\jonas\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012.03.09 20:39:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.12.01 18:38:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.10.28 12:57:13 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}: C:\Users\jonas\AppData\Roaming\08001.071 [2012.09.15 20:18:14 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012.11.04 10:12:25 | 000,000,000 | ---D | M]
 
[2011.07.29 19:22:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Extensions
[2012.11.04 10:23:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\6jszngmt.default\extensions
[2011.09.05 16:09:42 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\6jszngmt.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.09.23 14:43:38 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\6jszngmt.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2012.04.15 15:52:33 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\6jszngmt.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.08.08 16:06:53 | 000,000,000 | ---D | M] (InnoGames Community Toolbar) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\6jszngmt.default\extensions\{c7478d43-2bd5-4844-98b8-c2a6aa9ed677}
[2012.08.08 16:06:58 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\6jszngmt.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012.08.31 17:00:02 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\6jszngmt.default\extensions\ffxtlbr@babylon.com
[2011.09.23 14:36:22 | 000,000,000 | ---D | M] (Facemoods) -- C:\Users\jonas\AppData\Roaming\mozilla\Firefox\Profiles\6jszngmt.default\extensions\ffxtlbr@Facemoods.com
[2012.02.17 09:56:13 | 000,550,833 | ---- | M] () (No name found) -- C:\Users\jonas\AppData\Roaming\mozilla\firefox\profiles\6jszngmt.default\extensions\DivXWebPlayer@divx.com.xpi
[2012.11.04 10:12:22 | 000,002,536 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\mozilla\firefox\profiles\6jszngmt.default\searchplugins\browsemngr.xml
[2011.08.14 13:54:48 | 000,000,921 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\mozilla\firefox\profiles\6jszngmt.default\searchplugins\conduit.xml
[2012.08.07 19:09:27 | 000,001,056 | ---- | M] () -- C:\Users\jonas\AppData\Roaming\mozilla\firefox\profiles\6jszngmt.default\searchplugins\icqplugin.xml
[2012.10.28 12:57:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012.04.02 23:26:32 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.10.28 12:57:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012.11.04 10:12:25 | 000,000,000 | ---D | M] (Browser Manager) -- C:\PROGRAMDATA\BROWSER MANAGER\2.3.796.11\{16CDFF19-861D-48E3-A751-D99A27784753}\FIREFOXEXTENSION
[2012.09.15 20:18:14 | 000,000,000 | ---D | M] (Java Link Helper) -- C:\USERS\JONAS\APPDATA\ROAMING\08001.071
[2011.12.01 18:38:27 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.09.09 05:49:04 | 001,037,112 | ---- | M] (BitComet) -- C:\Program Files (x86)\mozilla firefox\plugins\npBitCometAgent.dll
[2011.10.06 21:03:53 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.11.04 10:11:53 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2011.10.06 21:03:53 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011.10.06 21:03:53 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.09.23 14:36:22 | 000,002,046 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
[2011.10.06 21:03:53 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.10.06 21:03:53 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011.10.06 21:03:53 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage: hxxp://search.babylon.com/?affID=115303&tt=4412_4&babsrc=HP_ss&mntrId=5ac8997b0000000000001c6f653cf6f2
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://search.babylon.com/?affID=115303&tt=4412_4&babsrc=HP_ss&mntrId=5ac8997b0000000000001c6f653cf6f2
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\jonas\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\jonas\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\jonas\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\jonas\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: BitCometAgent (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npBitCometAgent.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\jonas\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Users\jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Users\jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Skype Click to Call = C:\Users\jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
CHR - Extension: Mehr Leistung und Videoformate f\u00FCr dein HTML5 \u003Cvideo\u003E = C:\Users\jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Settings Protector = C:\Users\jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\
CHR - Extension: Google Mail = C:\Users\jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (no name) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [ICQ] C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [RfxSrvTray] C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software)
O4 - HKCU..\Run: [Spotify] C:\Users\jonas\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\jonas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &Alles mit BitComet herunterladen - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Mit BitComet herunter&laden - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: &Alles mit BitComet herunterladen - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\jonas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Mit BitComet herunter&laden - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FB700AE6-4404-40A4-BC45-1687876A2E26}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20 - AppInit_DLLs: (c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{16705ae7-e788-11e1-a022-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{16705ae7-e788-11e1-a022-806e6f6e6963}\Shell\AutoRun\command - "" = G:\Password.exe
O33 - MountPoints2\{9227689c-ba0d-11e0-9971-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{9227689c-ba0d-11e0-9971-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\start.html
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
 
MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk -  - File not found
MsConfig:64bit - StartUpFolder: C:^Users^jonas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk - C:\PROGRA~2\OPENOF~1.ORG\program\QUICKS~1.EXE - ()
MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig:64bit - StartUpReg: APSDaemon - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MsConfig:64bit - StartUpReg: Google Update - hkey= - key= - C:\Users\jonas\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
MsConfig:64bit - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: Logitech G35 - hkey= - key= - C:\Program Files (x86)\Logitech\G35\G35.exe (Logitech(c))
MsConfig:64bit - StartUpReg: Logitech Vid - hkey= - key= - C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
MsConfig:64bit - StartUpReg: LWS - hkey= - key= - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
MsConfig:64bit - StartUpReg: NUSB3MON - hkey= - key= - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
MsConfig:64bit - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
MsConfig:64bit - StartUpReg: rfxsrvtray - hkey= - key= - C:\Program Files (x86)\Tobit Radio.fx\Client\rfx-tray.exe (Tobit.Software)
MsConfig:64bit - StartUpReg: SpeedUpMyPC - hkey= - key= - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Ltd)
MsConfig:64bit - StartUpReg: Spotify Web Helper - hkey= - key= - C:\Users\jonas\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
MsConfig:64bit - StartUpReg: SunJavaUpdateSched - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig:64bit - StartUpReg: UseerSideBar - hkey= - key= - C:\Users\jonas\AppData\Roaming\prapproxy32.exe ()
MsConfig:64bit - StartUpReg: Windows Mobile-based device management - hkey= - key= - C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
 
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.12.21 12:36:17 | 000,000,000 | ---D | C] -- C:\Users\jonas\Desktop\Musik
[2012.12.20 14:32:03 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{1FD00A7B-6C45-40E1-AF54-7903324B5E40}
[2012.12.11 14:56:23 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{5A75AAA3-31C7-43C1-82E7-90019E9CA8C5}
[2012.12.09 10:24:17 | 000,000,000 | ---D | C] -- C:\Users\jonas\AppData\Local\{2CEEF8B3-BABA-4B8E-B7F0-2975A584D21E}
[3 C:\Users\jonas\Documents\*.tmp files -> C:\Users\jonas\Documents\*.tmp -> ]
[2 C:\Users\jonas\Desktop\*.tmp files -> C:\Users\jonas\Desktop\*.tmp -> ]
[2 C:\Users\jonas\AppData\Roaming\*.tmp files -> C:\Users\jonas\AppData\Roaming\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013.01.07 18:37:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.07 18:37:45 | 3218,493,440 | -HS- | M] () -- C:\hiberfil.sys
[2013.01.07 18:13:02 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4186555144-3616624444-2202780133-1001UA.job
[2013.01.07 11:07:51 | 000,014,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.07 11:07:51 | 000,014,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.07 11:06:12 | 001,549,010 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.01.07 11:06:12 | 000,672,042 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.01.07 11:06:12 | 000,631,122 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.01.07 11:06:12 | 000,138,338 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.01.07 11:06:12 | 000,114,044 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.01.07 11:00:15 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job
[2012.12.21 15:21:08 | 716,298,358 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012.12.20 21:26:04 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4186555144-3616624444-2202780133-1001Core.job
[2012.12.16 16:17:22 | 000,002,495 | ---- | M] () -- C:\Users\jonas\Desktop\Google Chrome.lnk
[2012.12.09 09:14:45 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012.12.09 09:14:45 | 000,281,768 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012.12.09 09:06:59 | 000,271,200 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012.12.08 21:27:55 | 000,001,630 | ---- | M] () -- C:\Users\Public\Desktop\Logitech Webcam Software  .lnk
[3 C:\Users\jonas\Documents\*.tmp files -> C:\Users\jonas\Documents\*.tmp -> ]
[2 C:\Users\jonas\Desktop\*.tmp files -> C:\Users\jonas\Desktop\*.tmp -> ]
[2 C:\Users\jonas\AppData\Roaming\*.tmp files -> C:\Users\jonas\AppData\Roaming\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.11.18 18:18:09 | 001,525,968 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.10.27 10:12:28 | 000,042,440 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2012.09.21 20:08:36 | 010,919,784 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.09.21 20:08:36 | 000,338,136 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.09.21 20:08:36 | 000,103,272 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2012.07.03 21:14:18 | 000,017,408 | ---- | C] () -- C:\Users\jonas\AppData\Local\WebpageIcons.db
[2012.04.16 20:01:30 | 002,681,344 | ---- | C] () -- C:\Windows\SysWow64\dvmsg.dll
[2012.01.07 13:43:34 | 000,098,304 | ---- | C] () -- C:\Windows\SysWow64\redmonnt.dll
[2011.12.22 16:13:44 | 000,127,372 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011.09.23 22:06:27 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2011.09.10 20:54:29 | 046,633,004 | ---- | C] () -- C:\Users\jonas\ts3_recording_11_09_10_21_54_28.wav
[2011.09.10 20:48:24 | 029,589,164 | ---- | C] () -- C:\Users\jonas\ts3_recording_11_09_10_21_48_23.wav
[2011.09.10 20:47:29 | 003,776,684 | ---- | C] () -- C:\Users\jonas\ts3_recording_11_09_10_21_47_27.wav
[2011.09.10 20:22:09 | 007,013,804 | ---- | C] () -- C:\Users\jonas\ts3_recording_11_09_10_21_22_8.wav
[2011.09.10 20:21:45 | 004,005,164 | ---- | C] () -- C:\Users\jonas\ts3_recording_11_09_10_21_21_43.wav
[2011.09.07 19:15:51 | 000,004,096 | -H-- | C] () -- C:\Users\jonas\AppData\Local\keyfile3.drm
[2011.08.30 09:58:06 | 000,000,000 | ---- | C] () -- C:\Users\jonas\AppData\Local\{9208B311-DAF0-4471-B85E-7A06354BB445}
[2011.08.24 12:21:11 | 000,606,764 | ---- | C] () -- C:\Users\jonas\ts3_recording_11_08_24_13_21_10.wav
[2011.08.09 19:46:05 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2011.07.29 20:15:50 | 000,030,528 | ---- | C] () -- C:\Windows\GVTDrv64.sys
[2011.07.29 20:15:07 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.07.29 20:04:38 | 000,281,768 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.07.29 20:04:36 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.07.29 19:29:30 | 000,072,304 | R--- | C] () -- C:\Windows\SysWow64\XSrvSetup.exe
[2011.07.29 19:24:39 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2011.04.09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2009.10.31 11:08:11 | 000,123,840 | RHS- | C] () -- C:\Users\jonas\AppData\Roaming\prapproxy32.exe
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2012.08.07 19:08:52 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\08001.066
[2012.08.08 11:04:05 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\08001.067
[2012.08.18 18:22:33 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\08001.069
[2012.08.30 16:21:05 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\08001.070
[2012.09.15 20:18:14 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\08001.071
[2012.01.07 13:43:24 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\Babylon
[2012.02.12 22:06:45 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\BitComet
[2012.02.05 19:50:21 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\Dropbox
[2011.12.25 15:25:02 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\DVDVideoSoft
[2011.09.05 16:09:42 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\DVDVideoSoftIEHelpers
[2013.01.07 11:00:32 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\ICQ
[2012.08.07 19:08:28 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\kock
[2011.07.29 19:50:57 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\Leadertech
[2011.11.11 19:36:09 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\LolClient
[2012.05.24 09:26:17 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\LolClient2
[2011.08.03 14:16:45 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\Notepad++
[2011.09.11 17:34:12 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\OpenCandy
[2011.09.13 12:51:14 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\OpenOffice.org
[2013.01.07 07:32:54 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\Spotify
[2011.07.30 14:31:33 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\TeamViewer
[2011.08.25 00:04:24 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\Teeworlds
[2012.04.16 20:02:07 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\Tobit
[2012.12.20 19:25:37 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\TS3Client
[2012.09.13 19:31:32 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\UAs
[2012.11.04 10:27:37 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\Uniblue
[2012.09.14 17:20:14 | 000,000,000 | ---D | M] -- C:\Users\jonas\AppData\Roaming\xmldm
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %SYSTEMDRIVE%\*. >
[2011.12.03 11:12:28 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2011.07.29 18:36:28 | 000,000,000 | ---D | M] -- C:\691c3f809b605f3c6e7c
[2012.11.18 18:20:24 | 000,000,000 | ---D | M] -- C:\9066f772310511bdab
[2011.07.29 19:39:22 | 000,000,000 | ---D | M] -- C:\AMD
[2012.12.08 21:29:06 | 000,000,000 | -HSD | M] -- C:\Config.Msi
[2009.07.14 06:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2011.07.29 19:15:39 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2012.11.10 10:06:54 | 000,000,000 | ---D | M] -- C:\Downloads
[2012.11.27 20:20:35 | 000,000,000 | -HSD | M] -- C:\found.000
[2012.11.29 19:47:27 | 000,000,000 | -HSD | M] -- C:\found.001
[2012.10.28 16:11:16 | 000,000,000 | ---D | M] -- C:\Fraps
[2011.07.29 20:07:35 | 000,000,000 | ---D | M] -- C:\ICQ7.5
[2012.03.08 21:29:48 | 000,000,000 | ---D | M] -- C:\LeagueOfLegends
[2011.08.09 12:10:48 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2009.07.14 04:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2012.11.04 10:13:52 | 000,000,000 | R--D | M] -- C:\Program Files
[2012.11.21 16:35:51 | 000,000,000 | R--D | M] -- C:\Program Files (x86)
[2012.11.18 18:51:00 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2011.07.29 19:15:40 | 000,000,000 | -HSD | M] -- C:\Programme
[2011.10.22 00:48:25 | 000,000,000 | ---D | M] -- C:\RaidTool
[2011.07.29 19:15:40 | 000,000,000 | -HSD | M] -- C:\Recovery
[2012.03.08 21:30:24 | 000,000,000 | ---D | M] -- C:\Riot Games
[2013.01.07 12:43:35 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2011.07.29 19:15:48 | 000,000,000 | R--D | M] -- C:\Users
[2013.01.07 10:47:11 | 000,000,000 | ---D | M] -- C:\Windows
[2011.07.29 19:56:02 | 000,000,000 | ---D | M] -- C:\Windows.old
[2011.07.29 20:07:42 | 000,000,000 | ---D | M] -- C:\Xfire
[2012.08.09 16:11:33 | 000,000,000 | ---D | M] -- C:\xmldm
[2012.02.07 20:27:53 | 000,000,000 | ---D | M] -- C:\_OTL
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< C:\Windows\system32\*.tsp >
[2009.07.14 02:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 02:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 02:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 02:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.20 13:16:53 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,632 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.09.11 17:34:45 | 000,000,340 | ---- | C] () -- C:\Windows\Tasks\DriverScanner.job
[2012.02.17 09:58:14 | 000,001,068 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4186555144-3616624444-2202780133-1001Core.job
[2012.02.17 09:58:15 | 000,001,120 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4186555144-3616624444-2202780133-1001UA.job
 
< MD5 for: AGP440.SYS  >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.02.26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
 
< MD5 for: IASTORV.SYS  >
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 14:33:38 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.03.11 07:19:16 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 07:41:26 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
[2011.03.11 07:23:00 | 000,410,496 | ---- | M] (Intel Corporation) MD5=B75E45C564E944A2657167D197AB29DA -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16778_none_0b141c81a16e25e6\iaStorV.sys
[2011.03.11 07:25:49 | 000,410,496 | ---- | M] (Intel Corporation) MD5=BFDC9D75698800CFE4D1698BF2750EA2 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.20921_none_0bccc8c8ba6985c1\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.20 14:27:22 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.20 13:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
[2011.03.11 07:23:06 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=6C1D5F70E7A6A3FD1C90D840EDC048B9 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16778_none_95dd8d30d8a4cfbe\nvstor.sys
[2011.03.11 07:25:53 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=AE274836BA56518E279087363A781214 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.20921_none_96963977f1a02f99\nvstor.sys
[2011.03.11 07:19:21 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 07:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 14:33:48 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
[2010.11.20 13:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2009.07.14 02:41:56 | 001,008,640 | ---- | M] (Microsoft Corporation) MD5=72D7B3EA16946E8F0CF7458150031CC6 -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[2009.07.14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=E8B0FFC209E504CB7E79FC24E6C085F0 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
[2010.11.20 14:27:27 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\SysNative\drivers\ws2ifsl.sys
[2009.07.14 01:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=6BCC1D7D2FD2453957C5479A32364E52 -- C:\Windows\winsxs\amd64_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_ab7b927be17eace8\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %USERPROFILE%\*.* >
[2013.01.07 18:36:51 | 004,194,304 | -HS- | M] () -- C:\Users\jonas\ntuser.dat
[2013.01.07 18:36:51 | 000,262,144 | -HS- | M] () -- C:\Users\jonas\ntuser.dat.LOG1
[2011.07.29 19:15:51 | 000,000,000 | -HS- | M] () -- C:\Users\jonas\ntuser.dat.LOG2
[2011.07.29 19:26:29 | 000,065,536 | -HS- | M] () -- C:\Users\jonas\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2011.07.29 19:26:29 | 000,524,288 | -HS- | M] () -- C:\Users\jonas\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2011.07.29 19:26:29 | 000,524,288 | -HS- | M] () -- C:\Users\jonas\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2012.09.04 20:43:11 | 000,065,536 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{282dec55-f6c2-11e1-8a9e-1c6f653cf6f2}.TM.blf
[2012.09.04 20:43:11 | 000,524,288 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{282dec55-f6c2-11e1-8a9e-1c6f653cf6f2}.TMContainer00000000000000000001.regtrans-ms
[2012.09.04 20:43:11 | 000,524,288 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{282dec55-f6c2-11e1-8a9e-1c6f653cf6f2}.TMContainer00000000000000000002.regtrans-ms
[2012.10.19 22:22:11 | 000,065,536 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{6a28fc16-1a1e-11e2-b1a6-1c6f653cf6f2}.TM.blf
[2012.10.19 22:22:11 | 000,524,288 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{6a28fc16-1a1e-11e2-b1a6-1c6f653cf6f2}.TMContainer00000000000000000001.regtrans-ms
[2012.10.19 22:22:11 | 000,524,288 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{6a28fc16-1a1e-11e2-b1a6-1c6f653cf6f2}.TMContainer00000000000000000002.regtrans-ms
[2012.01.21 01:12:27 | 000,065,536 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{6d3f5921-43bf-11e1-930a-1c6f653cf6f2}.TM.blf
[2012.01.21 01:12:27 | 000,524,288 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{6d3f5921-43bf-11e1-930a-1c6f653cf6f2}.TMContainer00000000000000000001.regtrans-ms
[2012.01.21 01:12:27 | 000,524,288 | -HS- | M] () -- C:\Users\jonas\ntuser.dat{6d3f5921-43bf-11e1-930a-1c6f653cf6f2}.TMContainer00000000000000000002.regtrans-ms
[2011.07.29 19:15:51 | 000,000,020 | -HS- | M] () -- C:\Users\jonas\ntuser.ini
[2011.08.24 12:21:15 | 000,606,764 | ---- | M] () -- C:\Users\jonas\ts3_recording_11_08_24_13_21_10.wav
[2011.09.10 20:22:06 | 004,005,164 | ---- | M] () -- C:\Users\jonas\ts3_recording_11_09_10_21_21_43.wav
[2011.09.10 20:22:46 | 007,013,804 | ---- | M] () -- C:\Users\jonas\ts3_recording_11_09_10_21_22_8.wav
[2011.09.10 20:47:49 | 003,776,684 | ---- | M] () -- C:\Users\jonas\ts3_recording_11_09_10_21_47_27.wav
[2011.09.10 20:50:58 | 029,589,164 | ---- | M] () -- C:\Users\jonas\ts3_recording_11_09_10_21_48_23.wav
[2011.09.10 20:58:32 | 046,633,004 | ---- | M] () -- C:\Users\jonas\ts3_recording_11_09_10_21_54_28.wav
 
< %USERPROFILE%\Local Settings\Temp\*.exe >
 
< %USERPROFILE%\Local Settings\Temp\*.dll >
 
< %USERPROFILE%\Application Data\*.exe >
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
 
<           >

< End of report >
         
--- --- ---
__________________

Alt 07.01.2013, 19:33   #4
markusg
/// Malware-holic
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



hi

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:
ATTFilter
:OTL
[2009.10.31 11:08:11 | 000,123,840 | RHS- | C] () -- C:\Users\jonas\AppData\Roaming\prapproxy32.exe
 :Files
:Commands
[EMPTYFLASH] 
[emptytemp]
         


• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.


Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang
in den Thread posten!




Drücke bitte die + E Taste.
  • Öffne dein Systemlaufwerk ( meistens C: )
  • Suche nun
    folgenden Ordner: _OTL und öffne diesen.
  • Mache einen Rechtsklick auf den Ordner Movedfiles --> Senden an --> Zip-Komprimierter Ordner

  • Dies wird eine Movedfiles.zip Datei in _OTL erstellen
  • Lade diese bitte in unseren Uploadchannel
    hoch. ( Durchsuchen --> C:\_OTL\Movedfiles.zip )
Teile mir mit ob der Upload problemlos geklappt hat. Danke im voraus
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.01.2013, 19:49   #5
herbcyy
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Ist das die richtige Datei ?
Hoffs mal ;-)
Beim Upload gabs keine Probleme

Zitat:
[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183


Alt 07.01.2013, 19:56   #6
markusg
/// Malware-holic
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Hi,
upload war erfolgreich, danke
download tdss killer:
http://www.trojaner-board.de/82358-t...entfernen.html
Klicke auf Change parameters
• Setze die Haken bei Verify driver digital signatures und Detect TDLFS file system
• Klick auf OK und anschließend auf Start scan
- bei funden erst mal immer skip wählen, log posten
__________________
--> Virus / unzählige Fenster öffnen sich

Alt 07.01.2013, 20:04   #7
herbcyy
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Hier der Log:

Zitat:
20:00:58.0330 1540 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
20:00:58.0449 1540 ============================================================
20:00:58.0449 1540 Current date / time: 2013/01/07 20:00:58.0449
20:00:58.0449 1540 SystemInfo:
20:00:58.0449 1540
20:00:58.0449 1540 OS Version: 6.1.7601 ServicePack: 1.0
20:00:58.0449 1540 Product type: Workstation
20:00:58.0449 1540 ComputerName: JONAS-PC
20:00:58.0449 1540 UserName: jonas
20:00:58.0449 1540 Windows directory: C:\Windows
20:00:58.0449 1540 System windows directory: C:\Windows
20:00:58.0449 1540 Running under WOW64
20:00:58.0449 1540 Processor architecture: Intel x64
20:00:58.0449 1540 Number of processors: 6
20:00:58.0449 1540 Page size: 0x1000
20:00:58.0449 1540 Boot type: Safe boot with network
20:00:58.0449 1540 ============================================================
20:00:59.0249 1540 Drive \Device\Harddisk0\DR0 - Size: 0xEE8156000 (59.63 Gb), SectorSize: 0x200, Cylinders: 0x1E67, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:00:59.0257 1540 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:00:59.0260 1540 ============================================================
20:00:59.0260 1540 \Device\Harddisk0\DR0:
20:00:59.0260 1540 MBR partitions:
20:00:59.0260 1540 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:00:59.0260 1540 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x770D000
20:00:59.0260 1540 \Device\Harddisk1\DR1:
20:00:59.0260 1540 MBR partitions:
20:00:59.0260 1540 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
20:00:59.0260 1540 ============================================================
20:00:59.0280 1540 C: <-> \Device\Harddisk1\DR1\Partition1
20:00:59.0281 1540 D: <-> \Device\Harddisk0\DR0\Partition2
20:00:59.0281 1540 ============================================================
20:00:59.0281 1540 Initialize success
20:00:59.0281 1540 ============================================================
20:01:28.0310 1568 ============================================================
20:01:28.0310 1568 Scan started
20:01:28.0310 1568 Mode: Manual; SigCheck; TDLFS;
20:01:28.0310 1568 ============================================================
20:01:28.0527 1568 ================ Scan system memory ========================
20:01:28.0527 1568 System memory - ok
20:01:28.0527 1568 ================ Scan services =============================
20:01:28.0645 1568 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
20:01:28.0670 1568 1394ohci - ok
20:01:28.0706 1568 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
20:01:28.0715 1568 ACPI - ok
20:01:28.0727 1568 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
20:01:28.0735 1568 AcpiPmi - ok
20:01:28.0856 1568 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:01:28.0862 1568 AdobeARMservice - ok
20:01:28.0882 1568 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
20:01:28.0893 1568 adp94xx - ok
20:01:28.0906 1568 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
20:01:28.0915 1568 adpahci - ok
20:01:28.0922 1568 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
20:01:28.0929 1568 adpu320 - ok
20:01:28.0953 1568 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
20:01:28.0975 1568 AeLookupSvc - ok
20:01:29.0020 1568 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
20:01:29.0029 1568 AFD - ok
20:01:29.0040 1568 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
20:01:29.0046 1568 agp440 - ok
20:01:29.0057 1568 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
20:01:29.0064 1568 ALG - ok
20:01:29.0074 1568 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
20:01:29.0080 1568 aliide - ok
20:01:29.0115 1568 [ DCEEE24E57E8176115207312F827C130 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
20:01:29.0125 1568 AMD External Events Utility - ok
20:01:29.0141 1568 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
20:01:29.0147 1568 amdide - ok
20:01:29.0165 1568 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
20:01:29.0171 1568 AmdK8 - ok
20:01:29.0298 1568 [ F6640D83AF0FD74C50E23E68548EA9A0 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
20:01:29.0359 1568 amdkmdag - ok
20:01:29.0375 1568 [ 20B63276A1920B41E1C56720B395049B ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
20:01:29.0375 1568 amdkmdap - ok
20:01:29.0390 1568 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
20:01:29.0406 1568 AmdPPM - ok
20:01:29.0437 1568 [ 53D8D46D51D390ABDB54ECA623165CB7 ] amdsata C:\Windows\system32\DRIVERS\amdsata.sys
20:01:29.0453 1568 amdsata - ok
20:01:29.0468 1568 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
20:01:29.0484 1568 amdsbs - ok
20:01:29.0500 1568 [ 75C51148154E34EB3D7BB84749A758D5 ] amdxata C:\Windows\system32\DRIVERS\amdxata.sys
20:01:29.0500 1568 amdxata - ok
20:01:29.0578 1568 [ C27D46B06D340293670450FCE9DFB166 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
20:01:29.0593 1568 AntiVirSchedulerService - ok
20:01:29.0624 1568 [ 72D90E56563165984224493069C69ED4 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
20:01:29.0624 1568 AntiVirService - ok
20:01:29.0656 1568 AODDriver - ok
20:01:29.0702 1568 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
20:01:29.0718 1568 AppID - ok
20:01:29.0734 1568 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
20:01:29.0765 1568 AppIDSvc - ok
20:01:29.0780 1568 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
20:01:29.0812 1568 Appinfo - ok
20:01:29.0890 1568 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:01:29.0890 1568 Apple Mobile Device - ok
20:01:29.0905 1568 [ 301AA64F9643BC453D90A66C4C0E7204 ] AppleCharger C:\Windows\system32\DRIVERS\AppleCharger.sys
20:01:29.0905 1568 AppleCharger - ok
20:01:29.0921 1568 [ 95EF7247C50C7241FDAE39A9B3AFF4AE ] AppleChargerSrv C:\Windows\system32\AppleChargerSrv.exe
20:01:29.0921 1568 AppleChargerSrv - ok
20:01:29.0936 1568 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
20:01:29.0936 1568 arc - ok
20:01:29.0952 1568 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
20:01:29.0952 1568 arcsas - ok
20:01:30.0061 1568 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
20:01:30.0061 1568 aspnet_state - ok
20:01:30.0077 1568 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
20:01:30.0092 1568 AsyncMac - ok
20:01:30.0155 1568 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
20:01:30.0155 1568 atapi - ok
20:01:30.0186 1568 [ 7C5D273E29DCC5505469B299C6F29163 ] AtiPcie C:\Windows\system32\DRIVERS\AtiPcie.sys
20:01:30.0202 1568 AtiPcie - ok
20:01:30.0233 1568 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:01:30.0264 1568 AudioEndpointBuilder - ok
20:01:30.0264 1568 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
20:01:30.0295 1568 AudioSrv - ok
20:01:30.0295 1568 [ B1224E6B086CD6548315B04AB575A23E ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
20:01:30.0311 1568 avgntflt - ok
20:01:30.0311 1568 [ ED45F12CFA62B83765C9C1496758CC87 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
20:01:30.0326 1568 avipbb - ok
20:01:30.0362 1568 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
20:01:30.0372 1568 AxInstSV - ok
20:01:30.0399 1568 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
20:01:30.0408 1568 b06bdrv - ok
20:01:30.0429 1568 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
20:01:30.0437 1568 b57nd60a - ok
20:01:30.0460 1568 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
20:01:30.0467 1568 BDESVC - ok
20:01:30.0486 1568 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
20:01:30.0507 1568 Beep - ok
20:01:30.0553 1568 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
20:01:30.0578 1568 BFE - ok
20:01:30.0641 1568 BITCOMET_HELPER_SERVICE - ok
20:01:30.0659 1568 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
20:01:30.0686 1568 BITS - ok
20:01:30.0702 1568 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
20:01:30.0708 1568 blbdrive - ok
20:01:30.0756 1568 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
20:01:30.0765 1568 Bonjour Service - ok
20:01:30.0802 1568 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
20:01:30.0809 1568 bowser - ok
20:01:30.0818 1568 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:01:30.0826 1568 BrFiltLo - ok
20:01:30.0840 1568 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:01:30.0848 1568 BrFiltUp - ok
20:01:30.0882 1568 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
20:01:30.0889 1568 Browser - ok
20:01:30.0985 1568 [ 52BE156F6C23B2995AFACE7091D18493 ] Browser Manager C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
20:01:31.0012 1568 Browser Manager - ok
20:01:31.0027 1568 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
20:01:31.0035 1568 Brserid - ok
20:01:31.0046 1568 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
20:01:31.0054 1568 BrSerWdm - ok
20:01:31.0060 1568 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
20:01:31.0068 1568 BrUsbMdm - ok
20:01:31.0078 1568 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
20:01:31.0084 1568 BrUsbSer - ok
20:01:31.0093 1568 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
20:01:31.0101 1568 BTHMODEM - ok
20:01:31.0114 1568 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
20:01:31.0135 1568 bthserv - ok
20:01:31.0150 1568 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
20:01:31.0171 1568 cdfs - ok
20:01:31.0238 1568 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
20:01:31.0245 1568 cdrom - ok
20:01:31.0275 1568 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
20:01:31.0296 1568 CertPropSvc - ok
20:01:31.0308 1568 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
20:01:31.0316 1568 circlass - ok
20:01:31.0342 1568 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
20:01:31.0351 1568 CLFS - ok
20:01:31.0391 1568 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:01:31.0397 1568 clr_optimization_v2.0.50727_32 - ok
20:01:31.0428 1568 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:01:31.0434 1568 clr_optimization_v2.0.50727_64 - ok
20:01:31.0497 1568 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:01:31.0503 1568 clr_optimization_v4.0.30319_32 - ok
20:01:31.0509 1568 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:01:31.0515 1568 clr_optimization_v4.0.30319_64 - ok
20:01:31.0530 1568 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
20:01:31.0536 1568 CmBatt - ok
20:01:31.0556 1568 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
20:01:31.0556 1568 cmdide - ok
20:01:31.0602 1568 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
20:01:31.0618 1568 CNG - ok
20:01:31.0634 1568 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
20:01:31.0634 1568 Compbatt - ok
20:01:31.0649 1568 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
20:01:31.0665 1568 CompositeBus - ok
20:01:31.0665 1568 COMSysApp - ok
20:01:31.0665 1568 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
20:01:31.0680 1568 crcdisk - ok
20:01:31.0712 1568 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
20:01:31.0712 1568 CryptSvc - ok
20:01:31.0758 1568 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
20:01:31.0774 1568 DcomLaunch - ok
20:01:31.0790 1568 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
20:01:31.0821 1568 defragsvc - ok
20:01:31.0852 1568 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
20:01:31.0883 1568 DfsC - ok
20:01:31.0914 1568 [ 113212D25D0C9BB8901A9833774DA97F ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
20:01:31.0930 1568 dg_ssudbus - ok
20:01:31.0946 1568 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
20:01:31.0961 1568 Dhcp - ok
20:01:31.0961 1568 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
20:01:31.0992 1568 discache - ok
20:01:32.0008 1568 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
20:01:32.0008 1568 Disk - ok
20:01:32.0055 1568 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
20:01:32.0055 1568 Dnscache - ok
20:01:32.0086 1568 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
20:01:32.0102 1568 dot3svc - ok
20:01:32.0133 1568 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
20:01:32.0148 1568 DPS - ok
20:01:32.0164 1568 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
20:01:32.0180 1568 drmkaud - ok
20:01:32.0211 1568 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
20:01:32.0226 1568 DXGKrnl - ok
20:01:32.0258 1568 EagleX64 - ok
20:01:32.0273 1568 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
20:01:32.0304 1568 EapHost - ok
20:01:32.0351 1568 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
20:01:32.0380 1568 ebdrv - ok
20:01:32.0406 1568 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
20:01:32.0412 1568 EFS - ok
20:01:32.0433 1568 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
20:01:32.0444 1568 elxstor - ok
20:01:32.0453 1568 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
20:01:32.0459 1568 ErrDev - ok
20:01:32.0521 1568 [ B8FA96995726D1FA58476E352C02AD82 ] ES lite Service C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
20:01:32.0526 1568 ES lite Service - ok
20:01:32.0554 1568 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
20:01:32.0578 1568 EventSystem - ok
20:01:32.0597 1568 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
20:01:32.0620 1568 exfat - ok
20:01:32.0633 1568 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
20:01:32.0656 1568 fastfat - ok
20:01:32.0670 1568 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
20:01:32.0676 1568 fdc - ok
20:01:32.0697 1568 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
20:01:32.0718 1568 fdPHost - ok
20:01:32.0723 1568 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
20:01:32.0745 1568 FDResPub - ok
20:01:32.0754 1568 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
20:01:32.0760 1568 FileInfo - ok
20:01:32.0772 1568 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
20:01:32.0794 1568 Filetrace - ok
20:01:32.0801 1568 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
20:01:32.0807 1568 flpydisk - ok
20:01:32.0836 1568 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
20:01:32.0845 1568 FltMgr - ok
20:01:32.0886 1568 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
20:01:32.0900 1568 FontCache - ok
20:01:32.0954 1568 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:01:32.0959 1568 FontCache3.0.0.0 - ok
20:01:32.0975 1568 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
20:01:32.0981 1568 FsDepends - ok
20:01:33.0016 1568 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
20:01:33.0022 1568 Fs_Rec - ok
20:01:33.0058 1568 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
20:01:33.0069 1568 fvevol - ok
20:01:33.0088 1568 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
20:01:33.0095 1568 gagp30kx - ok
20:01:33.0117 1568 [ 7907E14F9BCF3A4689C9A74A1A873CB6 ] gdrv C:\Windows\gdrv.sys
20:01:33.0122 1568 gdrv - ok
20:01:33.0164 1568 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:01:33.0169 1568 GEARAspiWDM - ok
20:01:33.0223 1568 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
20:01:33.0249 1568 gpsvc - ok
20:01:33.0265 1568 [ 8126331FBD4ED29EB3B356F9C905064D ] GVTDrv64 C:\Windows\GVTDrv64.sys
20:01:33.0271 1568 GVTDrv64 - ok
20:01:33.0284 1568 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
20:01:33.0290 1568 hcw85cir - ok
20:01:33.0336 1568 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:01:33.0346 1568 HdAudAddService - ok
20:01:33.0367 1568 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
20:01:33.0376 1568 HDAudBus - ok
20:01:33.0379 1568 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
20:01:33.0379 1568 HidBatt - ok
20:01:33.0395 1568 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
20:01:33.0411 1568 HidBth - ok
20:01:33.0411 1568 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
20:01:33.0426 1568 HidIr - ok
20:01:33.0442 1568 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
20:01:33.0457 1568 hidserv - ok
20:01:33.0489 1568 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
20:01:33.0489 1568 HidUsb - ok
20:01:33.0520 1568 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
20:01:33.0535 1568 hkmsvc - ok
20:01:33.0567 1568 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
20:01:33.0582 1568 HomeGroupListener - ok
20:01:33.0613 1568 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
20:01:33.0613 1568 HomeGroupProvider - ok
20:01:33.0645 1568 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
20:01:33.0660 1568 HpSAMD - ok
20:01:33.0691 1568 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
20:01:33.0707 1568 HTTP - ok
20:01:33.0723 1568 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
20:01:33.0723 1568 hwpolicy - ok
20:01:33.0754 1568 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
20:01:33.0769 1568 i8042prt - ok
20:01:33.0769 1568 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
20:01:33.0785 1568 iaStorV - ok
20:01:33.0847 1568 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
20:01:33.0847 1568 IDriverT ( UnsignedFile.Multi.Generic ) - warning
20:01:33.0847 1568 IDriverT - detected UnsignedFile.Multi.Generic (1)
20:01:33.0879 1568 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:01:33.0894 1568 idsvc - ok
20:01:33.0925 1568 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
20:01:33.0925 1568 iirsp - ok
20:01:33.0941 1568 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
20:01:33.0972 1568 IKEEXT - ok
20:01:34.0024 1568 [ 0ADF714079AE174A39D69036143E4C50 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
20:01:34.0052 1568 IntcAzAudAddService - ok
20:01:34.0061 1568 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
20:01:34.0068 1568 intelide - ok
20:01:34.0088 1568 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
20:01:34.0095 1568 intelppm - ok
20:01:34.0115 1568 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
20:01:34.0137 1568 IPBusEnum - ok
20:01:34.0162 1568 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:01:34.0183 1568 IpFilterDriver - ok
20:01:34.0205 1568 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
20:01:34.0215 1568 iphlpsvc - ok
20:01:34.0235 1568 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
20:01:34.0242 1568 IPMIDRV - ok
20:01:34.0253 1568 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
20:01:34.0275 1568 IPNAT - ok
20:01:34.0334 1568 [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
20:01:34.0348 1568 iPod Service - ok
20:01:34.0364 1568 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
20:01:34.0373 1568 IRENUM - ok
20:01:34.0376 1568 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
20:01:34.0382 1568 isapnp - ok
20:01:34.0397 1568 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
20:01:34.0406 1568 iScsiPrt - ok
20:01:34.0448 1568 [ F3A41EC4C6506E76E07A219B3A1DF8D2 ] JMB36X C:\Windows\SysWOW64\XSrvSetup.exe
20:01:34.0454 1568 JMB36X - ok
20:01:34.0495 1568 [ 1C368C1A2733DCC5B8E15420AA2B0F6D ] JRAID C:\Windows\system32\DRIVERS\jraid.sys
20:01:34.0501 1568 JRAID - ok
20:01:34.0528 1568 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
20:01:34.0534 1568 kbdclass - ok
20:01:34.0550 1568 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
20:01:34.0557 1568 kbdhid - ok
20:01:34.0567 1568 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
20:01:34.0573 1568 KeyIso - ok
20:01:34.0585 1568 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
20:01:34.0592 1568 KSecDD - ok
20:01:34.0626 1568 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
20:01:34.0633 1568 KSecPkg - ok
20:01:34.0641 1568 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
20:01:34.0662 1568 ksthunk - ok
20:01:34.0686 1568 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
20:01:34.0710 1568 KtmRm - ok
20:01:34.0744 1568 [ 86DCBF8A41C78561A1DA07AB5E7B1CCC ] LADF_DHP2 C:\Windows\system32\DRIVERS\ladfDHP2amd64.sys
20:01:34.0749 1568 LADF_DHP2 - ok
20:01:34.0769 1568 [ 175C04C7813CE64616B5CB046E5E1383 ] LADF_SBVM C:\Windows\system32\DRIVERS\ladfSBVMamd64.sys
20:01:34.0776 1568 LADF_SBVM - ok
20:01:34.0807 1568 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
20:01:34.0830 1568 LanmanServer - ok
20:01:34.0857 1568 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:01:34.0879 1568 LanmanWorkstation - ok
20:01:34.0901 1568 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
20:01:34.0922 1568 lltdio - ok
20:01:34.0942 1568 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
20:01:34.0965 1568 lltdsvc - ok
20:01:34.0977 1568 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
20:01:34.0999 1568 lmhosts - ok
20:01:35.0023 1568 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
20:01:35.0030 1568 LSI_FC - ok
20:01:35.0035 1568 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
20:01:35.0042 1568 LSI_SAS - ok
20:01:35.0047 1568 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:01:35.0054 1568 LSI_SAS2 - ok
20:01:35.0062 1568 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:01:35.0069 1568 LSI_SCSI - ok
20:01:35.0085 1568 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
20:01:35.0107 1568 luafv - ok
20:01:35.0129 1568 [ A401CFF74982D8DF851F20307C806073 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys
20:01:35.0138 1568 LVRS64 - ok
20:01:35.0210 1568 [ 13384CB5F5813E65F31078D6ABFAAF38 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys
20:01:35.0261 1568 LVUVC64 - ok
20:01:35.0276 1568 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
20:01:35.0282 1568 megasas - ok
20:01:35.0297 1568 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
20:01:35.0306 1568 MegaSR - ok
20:01:35.0307 1568 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
20:01:35.0322 1568 MMCSS - ok
20:01:35.0348 1568 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
20:01:35.0370 1568 Modem - ok
20:01:35.0382 1568 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
20:01:35.0390 1568 monitor - ok
20:01:35.0413 1568 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
20:01:35.0420 1568 mouclass - ok
20:01:35.0469 1568 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
20:01:35.0475 1568 mouhid - ok
20:01:35.0511 1568 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
20:01:35.0518 1568 mountmgr - ok
20:01:35.0547 1568 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
20:01:35.0555 1568 mpio - ok
20:01:35.0564 1568 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
20:01:35.0586 1568 mpsdrv - ok
20:01:35.0622 1568 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
20:01:35.0648 1568 MpsSvc - ok
20:01:35.0681 1568 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
20:01:35.0691 1568 MRxDAV - ok
20:01:35.0724 1568 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
20:01:35.0731 1568 mrxsmb - ok
20:01:35.0762 1568 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:01:35.0770 1568 mrxsmb10 - ok
20:01:35.0779 1568 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:01:35.0786 1568 mrxsmb20 - ok
20:01:35.0813 1568 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
20:01:35.0819 1568 msahci - ok
20:01:35.0830 1568 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
20:01:35.0837 1568 msdsm - ok
20:01:35.0849 1568 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
20:01:35.0857 1568 MSDTC - ok
20:01:35.0877 1568 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
20:01:35.0898 1568 Msfs - ok
20:01:35.0908 1568 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
20:01:35.0929 1568 mshidkmdf - ok
20:01:35.0932 1568 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
20:01:35.0938 1568 msisadrv - ok
20:01:35.0956 1568 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
20:01:35.0979 1568 MSiSCSI - ok
20:01:35.0982 1568 msiserver - ok
20:01:36.0002 1568 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
20:01:36.0023 1568 MSKSSRV - ok
20:01:36.0029 1568 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
20:01:36.0050 1568 MSPCLOCK - ok
20:01:36.0057 1568 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
20:01:36.0078 1568 MSPQM - ok
20:01:36.0113 1568 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
20:01:36.0122 1568 MsRPC - ok
20:01:36.0125 1568 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
20:01:36.0132 1568 mssmbios - ok
20:01:36.0139 1568 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
20:01:36.0161 1568 MSTEE - ok
20:01:36.0173 1568 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
20:01:36.0179 1568 MTConfig - ok
20:01:36.0187 1568 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
20:01:36.0193 1568 Mup - ok
20:01:36.0225 1568 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
20:01:36.0249 1568 napagent - ok
20:01:36.0268 1568 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
20:01:36.0279 1568 NativeWifiP - ok
20:01:36.0316 1568 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
20:01:36.0322 1568 NDIS - ok
20:01:36.0338 1568 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
20:01:36.0353 1568 NdisCap - ok
20:01:36.0369 1568 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
20:01:36.0384 1568 NdisTapi - ok
20:01:36.0416 1568 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
20:01:36.0447 1568 Ndisuio - ok
20:01:36.0462 1568 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
20:01:36.0494 1568 NdisWan - ok
20:01:36.0509 1568 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
20:01:36.0540 1568 NDProxy - ok
20:01:36.0540 1568 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
20:01:36.0556 1568 NetBIOS - ok
20:01:36.0603 1568 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
20:01:36.0618 1568 NetBT - ok
20:01:36.0634 1568 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
20:01:36.0650 1568 Netlogon - ok
20:01:36.0681 1568 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
20:01:36.0696 1568 Netman - ok
20:01:36.0774 1568 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:01:36.0774 1568 NetMsmqActivator - ok
20:01:36.0790 1568 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:01:36.0790 1568 NetPipeActivator - ok
20:01:36.0821 1568 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
20:01:36.0837 1568 netprofm - ok
20:01:36.0852 1568 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:01:36.0852 1568 NetTcpActivator - ok
20:01:36.0868 1568 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:01:36.0868 1568 NetTcpPortSharing - ok
20:01:36.0884 1568 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
20:01:36.0884 1568 nfrd960 - ok
20:01:36.0915 1568 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
20:01:36.0930 1568 NlaSvc - ok
20:01:36.0930 1568 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
20:01:36.0946 1568 Npfs - ok
20:01:36.0977 1568 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
20:01:36.0993 1568 nsi - ok
20:01:37.0008 1568 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
20:01:37.0024 1568 nsiproxy - ok
20:01:37.0071 1568 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
20:01:37.0086 1568 Ntfs - ok
20:01:37.0102 1568 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
20:01:37.0118 1568 Null - ok
20:01:37.0149 1568 [ 785298579B5F9B4032152DFBB992FDB6 ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
20:01:37.0164 1568 nusb3hub - ok
20:01:37.0196 1568 [ DF2750481B4964814467C974F2B0EEF1 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
20:01:37.0196 1568 nusb3xhc - ok
20:01:37.0227 1568 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
20:01:37.0227 1568 nvraid - ok
20:01:37.0242 1568 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
20:01:37.0242 1568 nvstor - ok
20:01:37.0274 1568 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
20:01:37.0274 1568 nv_agp - ok
20:01:37.0289 1568 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
20:01:37.0289 1568 ohci1394 - ok
20:01:37.0336 1568 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:01:37.0352 1568 ose - ok
20:01:37.0367 1568 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
20:01:37.0367 1568 p2pimsvc - ok
20:01:37.0383 1568 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
20:01:37.0398 1568 p2psvc - ok
20:01:37.0414 1568 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
20:01:37.0414 1568 Parport - ok
20:01:37.0445 1568 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
20:01:37.0445 1568 partmgr - ok
20:01:37.0461 1568 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
20:01:37.0461 1568 PcaSvc - ok
20:01:37.0476 1568 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
20:01:37.0492 1568 pci - ok
20:01:37.0492 1568 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
20:01:37.0492 1568 pciide - ok
20:01:37.0508 1568 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
20:01:37.0523 1568 pcmcia - ok
20:01:37.0523 1568 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
20:01:37.0539 1568 pcw - ok
20:01:37.0554 1568 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
20:01:37.0570 1568 PEAUTH - ok
20:01:37.0601 1568 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
20:01:37.0601 1568 PerfHost - ok
20:01:37.0648 1568 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
20:01:37.0679 1568 pla - ok
20:01:37.0726 1568 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
20:01:37.0726 1568 PlugPlay - ok
20:01:37.0726 1568 PnkBstrA - ok
20:01:37.0742 1568 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
20:01:37.0757 1568 PNRPAutoReg - ok
20:01:37.0757 1568 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
20:01:37.0773 1568 PNRPsvc - ok
20:01:37.0788 1568 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
20:01:37.0804 1568 PolicyAgent - ok
20:01:37.0835 1568 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
20:01:37.0851 1568 Power - ok
20:01:37.0882 1568 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
20:01:37.0913 1568 PptpMiniport - ok
20:01:37.0913 1568 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
20:01:37.0929 1568 Processor - ok
20:01:37.0960 1568 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
20:01:37.0960 1568 ProfSvc - ok
20:01:37.0976 1568 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
20:01:37.0976 1568 ProtectedStorage - ok
20:01:38.0007 1568 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
20:01:38.0022 1568 Psched - ok
20:01:38.0054 1568 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
20:01:38.0069 1568 ql2300 - ok
20:01:38.0085 1568 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
20:01:38.0100 1568 ql40xx - ok
20:01:38.0116 1568 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
20:01:38.0132 1568 QWAVE - ok
20:01:38.0132 1568 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
20:01:38.0147 1568 QWAVEdrv - ok
20:01:38.0272 1568 [ B40AA9BE30D62B288DBF4AAA83FB2A49 ] Radio.fx C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe
20:01:38.0319 1568 Radio.fx - ok
20:01:38.0366 1568 [ A55E7D0D873B2C97585B3B5926AC6ADE ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
20:01:38.0366 1568 RapiMgr - ok
20:01:38.0386 1568 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
20:01:38.0407 1568 RasAcd - ok
20:01:38.0425 1568 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
20:01:38.0446 1568 RasAgileVpn - ok
20:01:38.0457 1568 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
20:01:38.0482 1568 RasAuto - ok
20:01:38.0493 1568 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
20:01:38.0515 1568 Rasl2tp - ok
20:01:38.0552 1568 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
20:01:38.0575 1568 RasMan - ok
20:01:38.0584 1568 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
20:01:38.0606 1568 RasPppoe - ok
20:01:38.0616 1568 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
20:01:38.0638 1568 RasSstp - ok
20:01:38.0675 1568 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
20:01:38.0697 1568 rdbss - ok
20:01:38.0709 1568 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
20:01:38.0717 1568 rdpbus - ok
20:01:38.0720 1568 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
20:01:38.0741 1568 RDPCDD - ok
20:01:38.0766 1568 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
20:01:38.0787 1568 RDPENCDD - ok
20:01:38.0795 1568 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
20:01:38.0816 1568 RDPREFMP - ok
20:01:38.0843 1568 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
20:01:38.0851 1568 RDPWD - ok
20:01:38.0878 1568 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
20:01:38.0887 1568 rdyboost - ok
20:01:38.0902 1568 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
20:01:38.0924 1568 RemoteAccess - ok
20:01:38.0940 1568 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
20:01:38.0963 1568 RemoteRegistry - ok
20:01:38.0983 1568 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
20:01:39.0005 1568 RpcEptMapper - ok
20:01:39.0016 1568 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
20:01:39.0023 1568 RpcLocator - ok
20:01:39.0053 1568 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
20:01:39.0077 1568 RpcSs - ok
20:01:39.0096 1568 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
20:01:39.0118 1568 rspndr - ok
20:01:39.0158 1568 [ D6D381B76056C668679723938F06F16C ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys
20:01:39.0165 1568 RTHDMIAzAudService - ok
20:01:39.0212 1568 [ 4FBDA07EF0A3097CE14C5CABF723B278 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
20:01:39.0220 1568 RTL8167 - ok
20:01:39.0228 1568 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
20:01:39.0234 1568 SamSs - ok
20:01:39.0268 1568 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
20:01:39.0275 1568 sbp2port - ok
20:01:39.0295 1568 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
20:01:39.0318 1568 SCardSvr - ok
20:01:39.0338 1568 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
20:01:39.0358 1568 scfilter - ok
20:01:39.0385 1568 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
20:01:39.0416 1568 Schedule - ok
20:01:39.0447 1568 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
20:01:39.0463 1568 SCPolicySvc - ok
20:01:39.0494 1568 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
20:01:39.0510 1568 SDRSVC - ok
20:01:39.0510 1568 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
20:01:39.0541 1568 secdrv - ok
20:01:39.0557 1568 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
20:01:39.0572 1568 seclogon - ok
20:01:39.0588 1568 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
20:01:39.0603 1568 SENS - ok
20:01:39.0635 1568 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
20:01:39.0650 1568 SensrSvc - ok
20:01:39.0666 1568 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
20:01:39.0666 1568 Serenum - ok
20:01:39.0681 1568 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
20:01:39.0681 1568 Serial - ok
20:01:39.0713 1568 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
20:01:39.0713 1568 sermouse - ok
20:01:39.0744 1568 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
20:01:39.0775 1568 SessionEnv - ok
20:01:39.0775 1568 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
20:01:39.0791 1568 sffdisk - ok
20:01:39.0791 1568 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
20:01:39.0806 1568 sffp_mmc - ok
20:01:39.0822 1568 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
20:01:39.0822 1568 sffp_sd - ok
20:01:39.0837 1568 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
20:01:39.0837 1568 sfloppy - ok
20:01:39.0869 1568 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
20:01:39.0884 1568 SharedAccess - ok
20:01:39.0915 1568 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:01:39.0931 1568 ShellHWDetection - ok
20:01:39.0962 1568 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:01:39.0962 1568 SiSRaid2 - ok
20:01:39.0978 1568 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
20:01:39.0978 1568 SiSRaid4 - ok
20:01:40.0071 1568 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
20:01:40.0071 1568 SkypeUpdate - ok
20:01:40.0103 1568 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
20:01:40.0118 1568 Smb - ok
20:01:40.0134 1568 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
20:01:40.0149 1568 SNMPTRAP - ok
20:01:40.0165 1568 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
20:01:40.0165 1568 spldr - ok
20:01:40.0196 1568 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
20:01:40.0212 1568 Spooler - ok
20:01:40.0274 1568 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
20:01:40.0321 1568 sppsvc - ok
20:01:40.0337 1568 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
20:01:40.0352 1568 sppuinotify - ok
20:01:40.0402 1568 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
20:01:40.0411 1568 srv - ok
20:01:40.0420 1568 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
20:01:40.0429 1568 srv2 - ok
20:01:40.0440 1568 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
20:01:40.0447 1568 srvnet - ok
20:01:40.0475 1568 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
20:01:40.0498 1568 SSDPSRV - ok
20:01:40.0508 1568 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
20:01:40.0530 1568 SstpSvc - ok
20:01:40.0564 1568 [ 78CD64791F8634CF7B582FD085E57C4B ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
20:01:40.0571 1568 ssudmdm - ok
20:01:40.0602 1568 Steam Client Service - ok
20:01:40.0620 1568 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
20:01:40.0626 1568 stexstor - ok
20:01:40.0670 1568 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
20:01:40.0684 1568 stisvc - ok
20:01:40.0715 1568 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
20:01:40.0721 1568 swenum - ok
20:01:40.0741 1568 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
20:01:40.0766 1568 swprv - ok
20:01:40.0816 1568 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
20:01:40.0839 1568 SysMain - ok
20:01:40.0872 1568 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:01:40.0883 1568 TabletInputService - ok
20:01:40.0896 1568 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
20:01:40.0918 1568 TapiSrv - ok
20:01:40.0941 1568 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
20:01:40.0963 1568 TBS - ok
20:01:41.0016 1568 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
20:01:41.0041 1568 Tcpip - ok
20:01:41.0068 1568 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
20:01:41.0092 1568 TCPIP6 - ok
20:01:41.0128 1568 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
20:01:41.0134 1568 tcpipreg - ok
20:01:41.0143 1568 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
20:01:41.0149 1568 TDPIPE - ok
20:01:41.0173 1568 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
20:01:41.0178 1568 TDTCP - ok
20:01:41.0215 1568 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
20:01:41.0236 1568 tdx - ok
20:01:41.0248 1568 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
20:01:41.0255 1568 TermDD - ok
20:01:41.0292 1568 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
20:01:41.0318 1568 TermService - ok
20:01:41.0331 1568 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
20:01:41.0341 1568 Themes - ok
20:01:41.0368 1568 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
20:01:41.0390 1568 THREADORDER - ok
20:01:41.0417 1568 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
20:01:41.0440 1568 TrkWks - ok
20:01:41.0470 1568 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:01:41.0492 1568 TrustedInstaller - ok
20:01:41.0531 1568 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
20:01:41.0551 1568 tssecsrv - ok
20:01:41.0574 1568 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
20:01:41.0580 1568 TsUsbFlt - ok
20:01:41.0621 1568 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
20:01:41.0642 1568 tunnel - ok
20:01:41.0656 1568 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
20:01:41.0663 1568 uagp35 - ok
20:01:41.0698 1568 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
20:01:41.0720 1568 udfs - ok
20:01:41.0736 1568 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
20:01:41.0744 1568 UI0Detect - ok
20:01:41.0755 1568 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
20:01:41.0762 1568 uliagpkx - ok
20:01:41.0774 1568 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
20:01:41.0780 1568 umbus - ok
20:01:41.0793 1568 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
20:01:41.0799 1568 UmPass - ok
20:01:41.0824 1568 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
20:01:41.0848 1568 upnphost - ok
20:01:41.0911 1568 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
20:01:41.0917 1568 USBAAPL64 - ok
20:01:41.0950 1568 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
20:01:41.0958 1568 usbaudio - ok
20:01:41.0992 1568 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
20:01:41.0998 1568 usbccgp - ok
20:01:42.0031 1568 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
20:01:42.0039 1568 usbcir - ok
20:01:42.0051 1568 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
20:01:42.0057 1568 usbehci - ok
20:01:42.0098 1568 [ 2C780746DC44A28FE67004DC58173F05 ] usbfilter C:\Windows\system32\DRIVERS\usbfilter.sys
20:01:42.0104 1568 usbfilter - ok
20:01:42.0123 1568 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
20:01:42.0131 1568 usbhub - ok
20:01:42.0144 1568 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
20:01:42.0150 1568 usbohci - ok
20:01:42.0178 1568 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
20:01:42.0185 1568 usbprint - ok
20:01:42.0214 1568 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
20:01:42.0222 1568 usbscan - ok
20:01:42.0230 1568 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:01:42.0236 1568 USBSTOR - ok
20:01:42.0247 1568 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
20:01:42.0254 1568 usbuhci - ok
20:01:42.0299 1568 [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx C:\Windows\system32\drivers\usb8023x.sys
20:01:42.0305 1568 usb_rndisx - ok
20:01:42.0317 1568 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
20:01:42.0339 1568 UxSms - ok
20:01:42.0349 1568 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
20:01:42.0356 1568 VaultSvc - ok
20:01:42.0364 1568 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
20:01:42.0370 1568 vdrvroot - ok
20:01:42.0401 1568 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
20:01:42.0417 1568 vds - ok
20:01:42.0432 1568 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
20:01:42.0432 1568 vga - ok
20:01:42.0448 1568 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
20:01:42.0463 1568 VgaSave - ok
20:01:42.0479 1568 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
20:01:42.0495 1568 vhdmp - ok
20:01:42.0526 1568 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
20:01:42.0526 1568 viaide - ok
20:01:42.0541 1568 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
20:01:42.0541 1568 volmgr - ok
20:01:42.0573 1568 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
20:01:42.0588 1568 volmgrx - ok
20:01:42.0604 1568 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
20:01:42.0604 1568 volsnap - ok
20:01:42.0635 1568 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
20:01:42.0635 1568 vsmraid - ok
20:01:42.0682 1568 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
20:01:42.0713 1568 VSS - ok
20:01:42.0729 1568 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
20:01:42.0729 1568 vwifibus - ok
20:01:42.0744 1568 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
20:01:42.0775 1568 W32Time - ok
20:01:42.0775 1568 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
20:01:42.0791 1568 WacomPen - ok
20:01:42.0822 1568 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
20:01:42.0838 1568 WANARP - ok
20:01:42.0853 1568 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
20:01:42.0869 1568 Wanarpv6 - ok
20:01:42.0900 1568 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
20:01:42.0916 1568 wbengine - ok
20:01:42.0931 1568 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
20:01:42.0947 1568 WbioSrvc - ok
20:01:42.0994 1568 [ 8BDA6DB43AA54E8BB5E0794541DDC209 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
20:01:42.0994 1568 WcesComm - ok
20:01:43.0009 1568 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
20:01:43.0025 1568 wcncsvc - ok
20:01:43.0056 1568 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:01:43.0056 1568 WcsPlugInService - ok
20:01:43.0056 1568 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
20:01:43.0072 1568 Wd - ok
20:01:43.0103 1568 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
20:01:43.0119 1568 Wdf01000 - ok
20:01:43.0134 1568 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
20:01:43.0134 1568 WdiServiceHost - ok
20:01:43.0134 1568 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
20:01:43.0150 1568 WdiSystemHost - ok
20:01:43.0181 1568 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
20:01:43.0197 1568 WebClient - ok
20:01:43.0197 1568 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
20:01:43.0228 1568 Wecsvc - ok
20:01:43.0228 1568 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
20:01:43.0259 1568 wercplsupport - ok
20:01:43.0275 1568 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
20:01:43.0290 1568 WerSvc - ok
20:01:43.0306 1568 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
20:01:43.0321 1568 WfpLwf - ok
20:01:43.0337 1568 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
20:01:43.0353 1568 WIMMount - ok
20:01:43.0353 1568 WinDefend - ok
20:01:43.0368 1568 WinHttpAutoProxySvc - ok
20:01:43.0399 1568 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
20:01:43.0431 1568 Winmgmt - ok
20:01:43.0509 1568 [ 0C0195C48B6B8582FA6F6373032118DA ] WinRing0_1_2_0 C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys
20:01:43.0524 1568 WinRing0_1_2_0 - ok
20:01:43.0540 1568 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
20:01:43.0571 1568 WinRM - ok
20:01:43.0618 1568 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
20:01:43.0633 1568 WinUsb - ok
20:01:43.0665 1568 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
20:01:43.0680 1568 Wlansvc - ok
20:01:43.0758 1568 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:01:43.0789 1568 wlidsvc - ok
20:01:43.0805 1568 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
20:01:43.0821 1568 WmiAcpi - ok
20:01:43.0836 1568 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
20:01:43.0836 1568 wmiApSrv - ok
20:01:43.0852 1568 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
20:01:43.0852 1568 WPCSvc - ok
20:01:43.0883 1568 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
20:01:43.0883 1568 WPDBusEnum - ok
20:01:43.0899 1568 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
20:01:43.0930 1568 ws2ifsl - ok
20:01:43.0930 1568 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
20:01:43.0945 1568 wscsvc - ok
20:01:44.0008 1568 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
20:01:44.0039 1568 wuauserv - ok
20:01:44.0055 1568 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
20:01:44.0070 1568 WudfPf - ok
20:01:44.0101 1568 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
20:01:44.0101 1568 WUDFRd - ok
20:01:44.0133 1568 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
20:01:44.0133 1568 wudfsvc - ok
20:01:44.0148 1568 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
20:01:44.0148 1568 WwanSvc - ok
20:01:44.0164 1568 ================ Scan global ===============================
20:01:44.0195 1568 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
20:01:44.0226 1568 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
20:01:44.0226 1568 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
20:01:44.0242 1568 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
20:01:44.0257 1568 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
20:01:44.0273 1568 [Global] - ok
20:01:44.0273 1568 ================ Scan MBR ==================================
20:01:44.0273 1568 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
20:01:44.0320 1568 \Device\Harddisk0\DR0 - ok
20:01:44.0335 1568 [ 3F217AA00F5333EE4FC0F117341604AE ] \Device\Harddisk1\DR1
20:01:44.0504 1568 \Device\Harddisk1\DR1 ( TDSS File System ) - warning
20:01:44.0504 1568 \Device\Harddisk1\DR1 - detected TDSS File System (1)
20:01:44.0505 1568 ================ Scan VBR ==================================
20:01:44.0506 1568 [ 16B3F20A8E4DA619376AB550FDD8FAFA ] \Device\Harddisk0\DR0\Partition1
20:01:44.0507 1568 \Device\Harddisk0\DR0\Partition1 - ok
20:01:44.0509 1568 [ DD9154D684E6B5DF850E4C2312795C00 ] \Device\Harddisk0\DR0\Partition2
20:01:44.0510 1568 \Device\Harddisk0\DR0\Partition2 - ok
20:01:44.0537 1568 [ 3AFB5538021C88D7E1F82354EDC288CC ] \Device\Harddisk1\DR1\Partition1
20:01:44.0538 1568 \Device\Harddisk1\DR1\Partition1 - ok
20:01:44.0538 1568 ============================================================
20:01:44.0538 1568 Scan finished
20:01:44.0538 1568 ============================================================
20:01:44.0544 1004 Detected object count: 2
20:01:44.0544 1004 Actual detected object count: 2
20:03:10.0210 1004 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
20:03:10.0210 1004 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
20:03:10.0210 1004 \Device\Harddisk1\DR1 ( TDSS File System ) - skipped by user
20:03:10.0210 1004 \Device\Harddisk1\DR1 ( TDSS File System ) - User select action: Skip

Alt 07.01.2013, 20:14   #8
markusg
/// Malware-holic
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Hab ich mir fast gedacht...
bitte starte den TDSS killer mit den Parametern von oben.
bei dem Eintrag:
TDSS File System
wähle cure bzw delete.
Starte neu, starte den TDSS killer mit den Parametern von oben, und erstelle und poste ein neues Log
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.01.2013, 20:20   #9
herbcyy
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Neuer Post:

Zitat:
20:19:14.0492 1536 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
20:19:14.0664 1536 ============================================================
20:19:14.0664 1536 Current date / time: 2013/01/07 20:19:14.0664
20:19:14.0664 1536 SystemInfo:
20:19:14.0664 1536
20:19:14.0664 1536 OS Version: 6.1.7601 ServicePack: 1.0
20:19:14.0664 1536 Product type: Workstation
20:19:14.0664 1536 ComputerName: JONAS-PC
20:19:14.0664 1536 UserName: jonas
20:19:14.0664 1536 Windows directory: C:\Windows
20:19:14.0664 1536 System windows directory: C:\Windows
20:19:14.0664 1536 Running under WOW64
20:19:14.0664 1536 Processor architecture: Intel x64
20:19:14.0664 1536 Number of processors: 6
20:19:14.0664 1536 Page size: 0x1000
20:19:14.0664 1536 Boot type: Safe boot with network
20:19:14.0664 1536 ============================================================
20:19:15.0693 1536 Drive \Device\Harddisk0\DR0 - Size: 0xEE8156000 (59.63 Gb), SectorSize: 0x200, Cylinders: 0x1E67, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:19:15.0693 1536 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:19:15.0693 1536 ============================================================
20:19:15.0693 1536 \Device\Harddisk0\DR0:
20:19:15.0709 1536 MBR partitions:
20:19:15.0709 1536 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:19:15.0709 1536 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x770D000
20:19:15.0709 1536 \Device\Harddisk1\DR1:
20:19:15.0709 1536 MBR partitions:
20:19:15.0709 1536 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
20:19:15.0709 1536 ============================================================
20:19:15.0724 1536 C: <-> \Device\Harddisk1\DR1\Partition1
20:19:15.0724 1536 D: <-> \Device\Harddisk0\DR0\Partition2
20:19:15.0724 1536 ============================================================
20:19:15.0724 1536 Initialize success
20:19:15.0724 1536 ============================================================
20:19:30.0127 1888 ============================================================
20:19:30.0127 1888 Scan started
20:19:30.0127 1888 Mode: Manual;
20:19:30.0127 1888 ============================================================
20:19:30.0867 1888 ================ Scan system memory ========================
20:19:30.0867 1888 System memory - ok
20:19:30.0867 1888 ================ Scan services =============================
20:19:31.0164 1888 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
20:19:31.0164 1888 1394ohci - ok
20:19:31.0211 1888 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
20:19:31.0211 1888 ACPI - ok
20:19:31.0211 1888 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
20:19:31.0211 1888 AcpiPmi - ok
20:19:31.0320 1888 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:19:31.0320 1888 AdobeARMservice - ok
20:19:31.0351 1888 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
20:19:31.0351 1888 adp94xx - ok
20:19:31.0367 1888 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
20:19:31.0367 1888 adpahci - ok
20:19:31.0382 1888 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
20:19:31.0382 1888 adpu320 - ok
20:19:31.0398 1888 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
20:19:31.0398 1888 AeLookupSvc - ok
20:19:31.0429 1888 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
20:19:31.0445 1888 AFD - ok
20:19:31.0445 1888 Scan interrupted by user!
20:19:31.0445 1888 ================ Scan global ===============================
20:19:31.0445 1888 Scan interrupted by user!
20:19:31.0445 1888 ================ Scan MBR ==================================
20:19:31.0445 1888 Scan interrupted by user!
20:19:31.0445 1888 ================ Scan VBR ==================================
20:19:31.0445 1888 Scan interrupted by user!
20:19:31.0445 1888 ============================================================
20:19:31.0445 1888 Scan finished
20:19:31.0445 1888 ============================================================
20:19:31.0445 0144 Detected object count: 0
20:19:31.0445 0144 Actual detected object count: 0
20:19:36.0452 1876 ============================================================
20:19:36.0452 1876 Scan started
20:19:36.0452 1876 Mode: Manual; SigCheck; TDLFS;
20:19:36.0452 1876 ============================================================
20:19:36.0733 1876 ================ Scan system memory ========================
20:19:36.0733 1876 System memory - ok
20:19:36.0733 1876 ================ Scan services =============================
20:19:36.0764 1876 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
20:19:37.0014 1876 1394ohci - ok
20:19:37.0014 1876 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
20:19:37.0029 1876 ACPI - ok
20:19:37.0029 1876 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
20:19:37.0092 1876 AcpiPmi - ok
20:19:37.0092 1876 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:19:37.0092 1876 AdobeARMservice - ok
20:19:37.0107 1876 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
20:19:37.0107 1876 adp94xx - ok
20:19:37.0123 1876 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
20:19:37.0123 1876 adpahci - ok
20:19:37.0139 1876 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
20:19:37.0139 1876 adpu320 - ok
20:19:37.0154 1876 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
20:19:37.0232 1876 AeLookupSvc - ok
20:19:37.0248 1876 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
20:19:37.0295 1876 AFD - ok
20:19:37.0295 1876 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
20:19:37.0310 1876 agp440 - ok
20:19:37.0326 1876 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
20:19:37.0373 1876 ALG - ok
20:19:37.0388 1876 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
20:19:37.0388 1876 aliide - ok
20:19:37.0419 1876 [ DCEEE24E57E8176115207312F827C130 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
20:19:37.0497 1876 AMD External Events Utility - ok
20:19:37.0497 1876 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
20:19:37.0513 1876 amdide - ok
20:19:37.0529 1876 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
20:19:37.0575 1876 AmdK8 - ok
20:19:37.0700 1876 [ F6640D83AF0FD74C50E23E68548EA9A0 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
20:19:37.0809 1876 amdkmdag - ok
20:19:37.0825 1876 [ 20B63276A1920B41E1C56720B395049B ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
20:19:37.0856 1876 amdkmdap - ok
20:19:37.0872 1876 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
20:19:37.0903 1876 AmdPPM - ok
20:19:37.0950 1876 [ 53D8D46D51D390ABDB54ECA623165CB7 ] amdsata C:\Windows\system32\DRIVERS\amdsata.sys
20:19:37.0950 1876 amdsata - ok
20:19:37.0981 1876 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
20:19:37.0997 1876 amdsbs - ok
20:19:37.0997 1876 [ 75C51148154E34EB3D7BB84749A758D5 ] amdxata C:\Windows\system32\DRIVERS\amdxata.sys
20:19:37.0997 1876 amdxata - ok
20:19:38.0075 1876 [ C27D46B06D340293670450FCE9DFB166 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
20:19:38.0075 1876 AntiVirSchedulerService - ok
20:19:38.0121 1876 [ 72D90E56563165984224493069C69ED4 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
20:19:38.0137 1876 AntiVirService - ok
20:19:38.0184 1876 AODDriver - ok
20:19:38.0231 1876 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
20:19:38.0324 1876 AppID - ok
20:19:38.0340 1876 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
20:19:38.0387 1876 AppIDSvc - ok
20:19:38.0402 1876 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
20:19:38.0433 1876 Appinfo - ok
20:19:38.0527 1876 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:19:38.0543 1876 Apple Mobile Device - ok
20:19:38.0574 1876 [ 301AA64F9643BC453D90A66C4C0E7204 ] AppleCharger C:\Windows\system32\DRIVERS\AppleCharger.sys
20:19:38.0574 1876 AppleCharger - ok
20:19:38.0589 1876 [ 95EF7247C50C7241FDAE39A9B3AFF4AE ] AppleChargerSrv C:\Windows\system32\AppleChargerSrv.exe
20:19:38.0589 1876 AppleChargerSrv - ok
20:19:38.0605 1876 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
20:19:38.0621 1876 arc - ok
20:19:38.0621 1876 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
20:19:38.0636 1876 arcsas - ok
20:19:38.0730 1876 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
20:19:38.0792 1876 aspnet_state - ok
20:19:38.0808 1876 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
20:19:38.0839 1876 AsyncMac - ok
20:19:38.0886 1876 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
20:19:38.0901 1876 atapi - ok
20:19:38.0933 1876 [ 7C5D273E29DCC5505469B299C6F29163 ] AtiPcie C:\Windows\system32\DRIVERS\AtiPcie.sys
20:19:38.0933 1876 AtiPcie - ok
20:19:38.0964 1876 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:19:39.0011 1876 AudioEndpointBuilder - ok
20:19:39.0026 1876 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
20:19:39.0057 1876 AudioSrv - ok
20:19:39.0073 1876 [ B1224E6B086CD6548315B04AB575A23E ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
20:19:39.0073 1876 avgntflt - ok
20:19:39.0104 1876 [ ED45F12CFA62B83765C9C1496758CC87 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
20:19:39.0120 1876 avipbb - ok
20:19:39.0151 1876 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
20:19:39.0213 1876 AxInstSV - ok
20:19:39.0245 1876 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
20:19:39.0291 1876 b06bdrv - ok
20:19:39.0307 1876 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
20:19:39.0323 1876 b57nd60a - ok
20:19:39.0354 1876 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
20:19:39.0369 1876 BDESVC - ok
20:19:39.0385 1876 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
20:19:39.0432 1876 Beep - ok
20:19:39.0479 1876 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
20:19:39.0510 1876 BFE - ok
20:19:39.0541 1876 BITCOMET_HELPER_SERVICE - ok
20:19:39.0572 1876 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
20:19:39.0603 1876 BITS - ok
20:19:39.0635 1876 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
20:19:39.0650 1876 blbdrive - ok
20:19:39.0728 1876 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
20:19:39.0744 1876 Bonjour Service - ok
20:19:39.0775 1876 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
20:19:39.0806 1876 bowser - ok
20:19:39.0837 1876 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:19:39.0884 1876 BrFiltLo - ok
20:19:39.0900 1876 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:19:39.0900 1876 BrFiltUp - ok
20:19:39.0931 1876 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
20:19:39.0947 1876 Browser - ok
20:19:40.0071 1876 [ 52BE156F6C23B2995AFACE7091D18493 ] Browser Manager C:\ProgramData\Browser Manager\2.3.796.11\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
20:19:40.0103 1876 Browser Manager - ok
20:19:40.0118 1876 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
20:19:40.0165 1876 Brserid - ok
20:19:40.0165 1876 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
20:19:40.0181 1876 BrSerWdm - ok
20:19:40.0212 1876 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
20:19:40.0227 1876 BrUsbMdm - ok
20:19:40.0243 1876 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
20:19:40.0259 1876 BrUsbSer - ok
20:19:40.0274 1876 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
20:19:40.0305 1876 BTHMODEM - ok
20:19:40.0321 1876 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
20:19:40.0352 1876 bthserv - ok
20:19:40.0368 1876 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
20:19:40.0399 1876 cdfs - ok
20:19:40.0461 1876 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
20:19:40.0477 1876 cdrom - ok
20:19:40.0524 1876 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
20:19:40.0539 1876 CertPropSvc - ok
20:19:40.0571 1876 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
20:19:40.0571 1876 circlass - ok
20:19:40.0602 1876 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
20:19:40.0602 1876 CLFS - ok
20:19:40.0649 1876 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:19:40.0649 1876 clr_optimization_v2.0.50727_32 - ok
20:19:40.0680 1876 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:19:40.0695 1876 clr_optimization_v2.0.50727_64 - ok
20:19:40.0758 1876 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:19:40.0836 1876 clr_optimization_v4.0.30319_32 - ok
20:19:40.0851 1876 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:19:40.0898 1876 clr_optimization_v4.0.30319_64 - ok
20:19:40.0929 1876 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
20:19:40.0945 1876 CmBatt - ok
20:19:40.0961 1876 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
20:19:40.0976 1876 cmdide - ok
20:19:41.0007 1876 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
20:19:41.0039 1876 CNG - ok
20:19:41.0054 1876 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
20:19:41.0070 1876 Compbatt - ok
20:19:41.0085 1876 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
20:19:41.0117 1876 CompositeBus - ok
20:19:41.0117 1876 COMSysApp - ok
20:19:41.0132 1876 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
20:19:41.0132 1876 crcdisk - ok
20:19:41.0179 1876 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
20:19:41.0226 1876 CryptSvc - ok
20:19:41.0257 1876 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
20:19:41.0288 1876 DcomLaunch - ok
20:19:41.0351 1876 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
20:19:41.0413 1876 defragsvc - ok
20:19:41.0585 1876 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
20:19:41.0631 1876 DfsC - ok
20:19:41.0959 1876 [ 113212D25D0C9BB8901A9833774DA97F ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
20:19:41.0959 1876 dg_ssudbus - ok
20:19:41.0975 1876 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
20:19:42.0006 1876 Dhcp - ok
20:19:42.0021 1876 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
20:19:42.0053 1876 discache - ok
20:19:42.0068 1876 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
20:19:42.0084 1876 Disk - ok
20:19:42.0115 1876 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
20:19:42.0146 1876 Dnscache - ok
20:19:42.0177 1876 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
20:19:42.0209 1876 dot3svc - ok
20:19:42.0240 1876 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
20:19:42.0271 1876 DPS - ok
20:19:42.0349 1876 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
20:19:42.0396 1876 drmkaud - ok
20:19:42.0567 1876 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
20:19:42.0583 1876 DXGKrnl - ok
20:19:42.0677 1876 EagleX64 - ok
20:19:42.0692 1876 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
20:19:42.0755 1876 EapHost - ok
20:19:43.0285 1876 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
20:19:43.0347 1876 ebdrv - ok
20:19:43.0363 1876 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
20:19:43.0410 1876 EFS - ok
20:19:43.0425 1876 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
20:19:43.0441 1876 elxstor - ok
20:19:43.0457 1876 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
20:19:43.0472 1876 ErrDev - ok
20:19:43.0503 1876 [ B8FA96995726D1FA58476E352C02AD82 ] ES lite Service C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
20:19:43.0519 1876 ES lite Service - ok
20:19:43.0535 1876 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
20:19:43.0581 1876 EventSystem - ok
20:19:43.0597 1876 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
20:19:43.0628 1876 exfat - ok
20:19:43.0644 1876 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
20:19:43.0675 1876 fastfat - ok
20:19:43.0706 1876 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
20:19:43.0722 1876 fdc - ok
20:19:43.0737 1876 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
20:19:43.0769 1876 fdPHost - ok
20:19:43.0784 1876 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
20:19:43.0831 1876 FDResPub - ok
20:19:43.0847 1876 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
20:19:43.0847 1876 FileInfo - ok
20:19:43.0862 1876 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
20:19:43.0893 1876 Filetrace - ok
20:19:43.0925 1876 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
20:19:43.0925 1876 flpydisk - ok
20:19:43.0956 1876 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
20:19:43.0971 1876 FltMgr - ok
20:19:44.0018 1876 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
20:19:44.0065 1876 FontCache - ok
20:19:44.0112 1876 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:19:44.0112 1876 FontCache3.0.0.0 - ok
20:19:44.0127 1876 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
20:19:44.0143 1876 FsDepends - ok
20:19:44.0174 1876 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
20:19:44.0174 1876 Fs_Rec - ok
20:19:44.0221 1876 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
20:19:44.0237 1876 fvevol - ok
20:19:44.0252 1876 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
20:19:44.0252 1876 gagp30kx - ok
20:19:44.0283 1876 [ 7907E14F9BCF3A4689C9A74A1A873CB6 ] gdrv C:\Windows\gdrv.sys
20:19:44.0283 1876 gdrv - ok
20:19:44.0330 1876 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:19:44.0330 1876 GEARAspiWDM - ok
20:19:44.0361 1876 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
20:19:44.0408 1876 gpsvc - ok
20:19:44.0424 1876 [ 8126331FBD4ED29EB3B356F9C905064D ] GVTDrv64 C:\Windows\GVTDrv64.sys
20:19:44.0424 1876 GVTDrv64 - ok
20:19:44.0439 1876 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
20:19:44.0471 1876 hcw85cir - ok
20:19:44.0517 1876 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:19:44.0533 1876 HdAudAddService - ok
20:19:44.0564 1876 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
20:19:44.0564 1876 HDAudBus - ok
20:19:44.0580 1876 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
20:19:44.0595 1876 HidBatt - ok
20:19:44.0611 1876 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
20:19:44.0627 1876 HidBth - ok
20:19:44.0642 1876 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
20:19:44.0642 1876 HidIr - ok
20:19:44.0658 1876 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
20:19:44.0689 1876 hidserv - ok
20:19:44.0751 1876 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
20:19:44.0751 1876 HidUsb - ok
20:19:44.0767 1876 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
20:19:44.0783 1876 hkmsvc - ok
20:19:44.0814 1876 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
20:19:44.0829 1876 HomeGroupListener - ok
20:19:44.0861 1876 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
20:19:44.0876 1876 HomeGroupProvider - ok
20:19:44.0923 1876 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
20:19:44.0939 1876 HpSAMD - ok
20:19:44.0970 1876 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
20:19:45.0001 1876 HTTP - ok
20:19:45.0017 1876 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
20:19:45.0017 1876 hwpolicy - ok
20:19:45.0063 1876 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
20:19:45.0063 1876 i8042prt - ok
20:19:45.0079 1876 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
20:19:45.0095 1876 iaStorV - ok
20:19:45.0141 1876 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
20:19:45.0157 1876 IDriverT ( UnsignedFile.Multi.Generic ) - warning
20:19:45.0157 1876 IDriverT - detected UnsignedFile.Multi.Generic (1)
20:19:45.0188 1876 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:19:45.0204 1876 idsvc - ok
20:19:45.0235 1876 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
20:19:45.0235 1876 iirsp - ok
20:19:45.0266 1876 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
20:19:45.0297 1876 IKEEXT - ok
20:19:45.0360 1876 [ 0ADF714079AE174A39D69036143E4C50 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
20:19:45.0391 1876 IntcAzAudAddService - ok
20:19:45.0407 1876 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
20:19:45.0407 1876 intelide - ok
20:19:45.0422 1876 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
20:19:45.0453 1876 intelppm - ok
20:19:45.0469 1876 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
20:19:45.0500 1876 IPBusEnum - ok
20:19:45.0531 1876 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:19:45.0578 1876 IpFilterDriver - ok
20:19:45.0609 1876 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
20:19:45.0641 1876 iphlpsvc - ok
20:19:45.0672 1876 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
20:19:45.0687 1876 IPMIDRV - ok
20:19:45.0687 1876 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
20:19:45.0734 1876 IPNAT - ok
20:19:45.0797 1876 [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
20:19:45.0812 1876 iPod Service - ok
20:19:45.0812 1876 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
20:19:45.0859 1876 IRENUM - ok
20:19:45.0875 1876 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
20:19:45.0875 1876 isapnp - ok
20:19:45.0906 1876 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
20:19:45.0921 1876 iScsiPrt - ok
20:19:45.0984 1876 [ F3A41EC4C6506E76E07A219B3A1DF8D2 ] JMB36X C:\Windows\SysWOW64\XSrvSetup.exe
20:19:45.0984 1876 JMB36X - ok
20:19:46.0015 1876 [ 1C368C1A2733DCC5B8E15420AA2B0F6D ] JRAID C:\Windows\system32\DRIVERS\jraid.sys
20:19:46.0031 1876 JRAID - ok
20:19:46.0062 1876 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
20:19:46.0077 1876 kbdclass - ok
20:19:46.0077 1876 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
20:19:46.0093 1876 kbdhid - ok
20:19:46.0093 1876 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
20:19:46.0109 1876 KeyIso - ok
20:19:46.0140 1876 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
20:19:46.0140 1876 KSecDD - ok
20:19:46.0171 1876 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
20:19:46.0187 1876 KSecPkg - ok
20:19:46.0202 1876 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
20:19:46.0233 1876 ksthunk - ok
20:19:46.0249 1876 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
20:19:46.0280 1876 KtmRm - ok
20:19:46.0327 1876 [ 86DCBF8A41C78561A1DA07AB5E7B1CCC ] LADF_DHP2 C:\Windows\system32\DRIVERS\ladfDHP2amd64.sys
20:19:46.0327 1876 LADF_DHP2 - ok
20:19:46.0343 1876 [ 175C04C7813CE64616B5CB046E5E1383 ] LADF_SBVM C:\Windows\system32\DRIVERS\ladfSBVMamd64.sys
20:19:46.0358 1876 LADF_SBVM - ok
20:19:46.0389 1876 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
20:19:46.0436 1876 LanmanServer - ok
20:19:46.0452 1876 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:19:46.0483 1876 LanmanWorkstation - ok
20:19:46.0514 1876 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
20:19:46.0530 1876 lltdio - ok
20:19:46.0561 1876 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
20:19:46.0592 1876 lltdsvc - ok
20:19:46.0608 1876 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
20:19:46.0623 1876 lmhosts - ok
20:19:46.0655 1876 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
20:19:46.0655 1876 LSI_FC - ok
20:19:46.0670 1876 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
20:19:46.0686 1876 LSI_SAS - ok
20:19:46.0701 1876 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:19:46.0701 1876 LSI_SAS2 - ok
20:19:46.0717 1876 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:19:46.0717 1876 LSI_SCSI - ok
20:19:46.0733 1876 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
20:19:46.0748 1876 luafv - ok
20:19:46.0779 1876 [ A401CFF74982D8DF851F20307C806073 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys
20:19:46.0795 1876 LVRS64 - ok
20:19:46.0857 1876 [ 13384CB5F5813E65F31078D6ABFAAF38 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys
20:19:46.0935 1876 LVUVC64 - ok
20:19:46.0951 1876 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
20:19:46.0951 1876 megasas - ok
20:19:46.0967 1876 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
20:19:46.0982 1876 MegaSR - ok
20:19:46.0998 1876 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
20:19:47.0045 1876 MMCSS - ok
20:19:47.0060 1876 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
20:19:47.0091 1876 Modem - ok
20:19:47.0107 1876 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
20:19:47.0123 1876 monitor - ok
20:19:47.0169 1876 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
20:19:47.0169 1876 mouclass - ok
20:19:47.0185 1876 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
20:19:47.0201 1876 mouhid - ok
20:19:47.0232 1876 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
20:19:47.0247 1876 mountmgr - ok
20:19:47.0263 1876 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
20:19:47.0279 1876 mpio - ok
20:19:47.0279 1876 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
20:19:47.0310 1876 mpsdrv - ok
20:19:47.0341 1876 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
20:19:47.0388 1876 MpsSvc - ok
20:19:47.0419 1876 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
20:19:47.0419 1876 MRxDAV - ok
20:19:47.0450 1876 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
20:19:47.0466 1876 mrxsmb - ok
20:19:47.0513 1876 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:19:47.0528 1876 mrxsmb10 - ok
20:19:47.0544 1876 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:19:47.0559 1876 mrxsmb20 - ok
20:19:47.0591 1876 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
20:19:47.0591 1876 msahci - ok
20:19:47.0606 1876 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
20:19:47.0606 1876 msdsm - ok
20:19:47.0622 1876 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
20:19:47.0622 1876 MSDTC - ok
20:19:47.0653 1876 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
20:19:47.0669 1876 Msfs - ok
20:19:47.0684 1876 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
20:19:47.0715 1876 mshidkmdf - ok
20:19:47.0731 1876 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
20:19:47.0747 1876 msisadrv - ok
20:19:47.0762 1876 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
20:19:47.0793 1876 MSiSCSI - ok
20:19:47.0793 1876 msiserver - ok
20:19:47.0825 1876 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
20:19:47.0856 1876 MSKSSRV - ok
20:19:47.0871 1876 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
20:19:47.0887 1876 MSPCLOCK - ok
20:19:47.0903 1876 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
20:19:47.0934 1876 MSPQM - ok
20:19:47.0965 1876 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
20:19:47.0981 1876 MsRPC - ok
20:19:47.0981 1876 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
20:19:47.0981 1876 mssmbios - ok
20:19:47.0996 1876 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
20:19:48.0043 1876 MSTEE - ok
20:19:48.0059 1876 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
20:19:48.0074 1876 MTConfig - ok
20:19:48.0090 1876 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
20:19:48.0090 1876 Mup - ok
20:19:48.0121 1876 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
20:19:48.0168 1876 napagent - ok
20:19:48.0183 1876 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
20:19:48.0215 1876 NativeWifiP - ok
20:19:48.0277 1876 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
20:19:48.0293 1876 NDIS - ok
20:19:48.0308 1876 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
20:19:48.0324 1876 NdisCap - ok
20:19:48.0339 1876 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
20:19:48.0371 1876 NdisTapi - ok
20:19:48.0402 1876 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
20:19:48.0417 1876 Ndisuio - ok
20:19:48.0449 1876 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
20:19:48.0480 1876 NdisWan - ok
20:19:48.0495 1876 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
20:19:48.0527 1876 NDProxy - ok
20:19:48.0527 1876 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
20:19:48.0558 1876 NetBIOS - ok
20:19:48.0605 1876 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
20:19:48.0636 1876 NetBT - ok
20:19:48.0651 1876 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
20:19:48.0651 1876 Netlogon - ok
20:19:48.0683 1876 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
20:19:48.0729 1876 Netman - ok
20:19:48.0807 1876 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:19:48.0823 1876 NetMsmqActivator - ok
20:19:48.0854 1876 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:19:48.0854 1876 NetPipeActivator - ok
20:19:48.0870 1876 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
20:19:48.0901 1876 netprofm - ok
20:19:48.0917 1876 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:19:48.0932 1876 NetTcpActivator - ok
20:19:48.0932 1876 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:19:48.0932 1876 NetTcpPortSharing - ok
20:19:48.0948 1876 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
20:19:48.0963 1876 nfrd960 - ok
20:19:48.0995 1876 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
20:19:49.0010 1876 NlaSvc - ok
20:19:49.0041 1876 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
20:19:49.0057 1876 Npfs - ok
20:19:49.0073 1876 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
20:19:49.0104 1876 nsi - ok
20:19:49.0119 1876 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
20:19:49.0151 1876 nsiproxy - ok
20:19:49.0197 1876 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
20:19:49.0229 1876 Ntfs - ok
20:19:49.0244 1876 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
20:19:49.0275 1876 Null - ok
20:19:49.0307 1876 [ 785298579B5F9B4032152DFBB992FDB6 ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
20:19:49.0353 1876 nusb3hub - ok
20:19:49.0369 1876 [ DF2750481B4964814467C974F2B0EEF1 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
20:19:49.0385 1876 nusb3xhc - ok
20:19:49.0416 1876 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
20:19:49.0431 1876 nvraid - ok
20:19:49.0447 1876 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
20:19:49.0447 1876 nvstor - ok
20:19:49.0478 1876 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
20:19:49.0494 1876 nv_agp - ok
20:19:49.0509 1876 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
20:19:49.0525 1876 ohci1394 - ok
20:19:49.0572 1876 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:19:49.0587 1876 ose - ok
20:19:49.0603 1876 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
20:19:49.0619 1876 p2pimsvc - ok
20:19:49.0634 1876 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
20:19:49.0650 1876 p2psvc - ok
20:19:49.0665 1876 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
20:19:49.0665 1876 Parport - ok
20:19:49.0697 1876 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
20:19:49.0697 1876 partmgr - ok
20:19:49.0712 1876 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
20:19:49.0728 1876 PcaSvc - ok
20:19:49.0743 1876 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
20:19:49.0759 1876 pci - ok
20:19:49.0759 1876 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
20:19:49.0775 1876 pciide - ok
20:19:49.0775 1876 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
20:19:49.0790 1876 pcmcia - ok
20:19:49.0806 1876 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
20:19:49.0806 1876 pcw - ok
20:19:49.0821 1876 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
20:19:49.0868 1876 PEAUTH - ok
20:19:49.0884 1876 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
20:19:49.0915 1876 PerfHost - ok
20:19:49.0962 1876 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
20:19:50.0009 1876 pla - ok
20:19:50.0040 1876 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
20:19:50.0055 1876 PlugPlay - ok
20:19:50.0071 1876 PnkBstrA - ok
20:19:50.0102 1876 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
20:19:50.0102 1876 PNRPAutoReg - ok
20:19:50.0102 1876 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
20:19:50.0118 1876 PNRPsvc - ok
20:19:50.0133 1876 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
20:19:50.0180 1876 PolicyAgent - ok
20:19:50.0211 1876 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
20:19:50.0243 1876 Power - ok
20:19:50.0289 1876 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
20:19:50.0321 1876 PptpMiniport - ok
20:19:50.0336 1876 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
20:19:50.0352 1876 Processor - ok
20:19:50.0399 1876 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
20:19:50.0445 1876 ProfSvc - ok
20:19:50.0461 1876 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
20:19:50.0461 1876 ProtectedStorage - ok
20:19:50.0492 1876 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
20:19:50.0539 1876 Psched - ok
20:19:50.0570 1876 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
20:19:50.0601 1876 ql2300 - ok
20:19:50.0617 1876 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
20:19:50.0617 1876 ql40xx - ok
20:19:50.0648 1876 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
20:19:50.0664 1876 QWAVE - ok
20:19:50.0679 1876 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
20:19:50.0695 1876 QWAVEdrv - ok
20:19:50.0820 1876 [ B40AA9BE30D62B288DBF4AAA83FB2A49 ] Radio.fx C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe
20:19:50.0882 1876 Radio.fx - ok
20:19:50.0929 1876 [ A55E7D0D873B2C97585B3B5926AC6ADE ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
20:19:50.0929 1876 RapiMgr - ok
20:19:50.0945 1876 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
20:19:50.0960 1876 RasAcd - ok
20:19:50.0991 1876 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
20:19:51.0007 1876 RasAgileVpn - ok
20:19:51.0038 1876 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
20:19:51.0132 1876 RasAuto - ok
20:19:51.0163 1876 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
20:19:51.0210 1876 Rasl2tp - ok
20:19:51.0241 1876 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
20:19:51.0272 1876 RasMan - ok
20:19:51.0288 1876 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
20:19:51.0319 1876 RasPppoe - ok
20:19:51.0350 1876 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
20:19:51.0366 1876 RasSstp - ok
20:19:51.0397 1876 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
20:19:51.0428 1876 rdbss - ok
20:19:51.0444 1876 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
20:19:51.0475 1876 rdpbus - ok
20:19:51.0475 1876 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
20:19:51.0491 1876 RDPCDD - ok
20:19:51.0522 1876 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
20:19:51.0553 1876 RDPENCDD - ok
20:19:51.0584 1876 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
20:19:51.0600 1876 RDPREFMP - ok
20:19:51.0631 1876 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
20:19:51.0662 1876 RDPWD - ok
20:19:51.0709 1876 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
20:19:51.0709 1876 rdyboost - ok
20:19:51.0725 1876 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
20:19:51.0756 1876 RemoteAccess - ok
20:19:51.0787 1876 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
20:19:51.0818 1876 RemoteRegistry - ok
20:19:51.0849 1876 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
20:19:51.0881 1876 RpcEptMapper - ok
20:19:51.0896 1876 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
20:19:51.0912 1876 RpcLocator - ok
20:19:51.0927 1876 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
20:19:51.0959 1876 RpcSs - ok
20:19:51.0974 1876 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
20:19:52.0005 1876 rspndr - ok
20:19:52.0037 1876 [ D6D381B76056C668679723938F06F16C ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys
20:19:52.0052 1876 RTHDMIAzAudService - ok
20:19:52.0099 1876 [ 4FBDA07EF0A3097CE14C5CABF723B278 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
20:19:52.0099 1876 RTL8167 - ok
20:19:52.0115 1876 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
20:19:52.0115 1876 SamSs - ok
20:19:52.0146 1876 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
20:19:52.0161 1876 sbp2port - ok
20:19:52.0177 1876 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
20:19:52.0208 1876 SCardSvr - ok
20:19:52.0239 1876 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
20:19:52.0255 1876 scfilter - ok
20:19:52.0286 1876 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
20:19:52.0317 1876 Schedule - ok
20:19:52.0349 1876 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
20:19:52.0380 1876 SCPolicySvc - ok
20:19:52.0411 1876 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
20:19:52.0427 1876 SDRSVC - ok
20:19:52.0442 1876 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
20:19:52.0473 1876 secdrv - ok
20:19:52.0505 1876 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
20:19:52.0536 1876 seclogon - ok
20:19:52.0551 1876 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
20:19:52.0583 1876 SENS - ok
20:19:52.0614 1876 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
20:19:52.0629 1876 SensrSvc - ok
20:19:52.0645 1876 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
20:19:52.0645 1876 Serenum - ok
20:19:52.0661 1876 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
20:19:52.0676 1876 Serial - ok
20:19:52.0707 1876 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
20:19:52.0723 1876 sermouse - ok
20:19:52.0754 1876 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
20:19:52.0801 1876 SessionEnv - ok
20:19:52.0801 1876 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
20:19:52.0832 1876 sffdisk - ok
20:19:52.0848 1876 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
20:19:52.0863 1876 sffp_mmc - ok
20:19:52.0895 1876 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
20:19:52.0910 1876 sffp_sd - ok
20:19:52.0926 1876 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
20:19:52.0941 1876 sfloppy - ok
20:19:53.0004 1876 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
20:19:53.0051 1876 SharedAccess - ok
20:19:53.0113 1876 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:19:53.0144 1876 ShellHWDetection - ok
20:19:53.0160 1876 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:19:53.0175 1876 SiSRaid2 - ok
20:19:53.0191 1876 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
20:19:53.0207 1876 SiSRaid4 - ok
20:19:53.0347 1876 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
20:19:53.0363 1876 SkypeUpdate - ok
20:19:53.0378 1876 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
20:19:53.0425 1876 Smb - ok
20:19:53.0472 1876 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
20:19:53.0472 1876 SNMPTRAP - ok
20:19:53.0487 1876 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
20:19:53.0503 1876 spldr - ok
20:19:53.0550 1876 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
20:19:53.0581 1876 Spooler - ok
20:19:53.0643 1876 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
20:19:53.0721 1876 sppsvc - ok
20:19:53.0753 1876 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
20:19:53.0784 1876 sppuinotify - ok
20:19:53.0815 1876 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
20:19:53.0846 1876 srv - ok
20:19:53.0862 1876 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
20:19:53.0893 1876 srv2 - ok
20:19:53.0909 1876 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
20:19:53.0940 1876 srvnet - ok
20:19:53.0971 1876 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
20:19:54.0002 1876 SSDPSRV - ok
20:19:54.0033 1876 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
20:19:54.0065 1876 SstpSvc - ok
20:19:54.0096 1876 [ 78CD64791F8634CF7B582FD085E57C4B ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys
20:19:54.0111 1876 ssudmdm - ok
20:19:54.0143 1876 Steam Client Service - ok
20:19:54.0158 1876 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
20:19:54.0158 1876 stexstor - ok
20:19:54.0205 1876 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
20:19:54.0236 1876 stisvc - ok
20:19:54.0252 1876 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
20:19:54.0267 1876 swenum - ok
20:19:54.0299 1876 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
20:19:54.0330 1876 swprv - ok
20:19:54.0361 1876 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
20:19:54.0408 1876 SysMain - ok
20:19:54.0439 1876 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:19:54.0455 1876 TabletInputService - ok
20:19:54.0486 1876 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
20:19:54.0533 1876 TapiSrv - ok
20:19:54.0548 1876 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
20:19:54.0564 1876 TBS - ok
20:19:54.0626 1876 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
20:19:54.0657 1876 Tcpip - ok
20:19:54.0689 1876 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
20:19:54.0704 1876 TCPIP6 - ok
20:19:54.0751 1876 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
20:19:54.0751 1876 tcpipreg - ok
20:19:54.0767 1876 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
20:19:54.0798 1876 TDPIPE - ok
20:19:54.0829 1876 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
20:19:54.0845 1876 TDTCP - ok
20:19:54.0876 1876 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
20:19:54.0923 1876 tdx - ok
20:19:54.0938 1876 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
20:19:54.0938 1876 TermDD - ok
20:19:54.0969 1876 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
20:19:55.0016 1876 TermService - ok
20:19:55.0047 1876 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
20:19:55.0063 1876 Themes - ok
20:19:55.0079 1876 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
20:19:55.0110 1876 THREADORDER - ok
20:19:55.0125 1876 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
20:19:55.0157 1876 TrkWks - ok
20:19:55.0203 1876 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:19:55.0235 1876 TrustedInstaller - ok
20:19:55.0266 1876 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
20:19:55.0281 1876 tssecsrv - ok
20:19:55.0313 1876 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
20:19:55.0344 1876 TsUsbFlt - ok
20:19:55.0391 1876 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
20:19:55.0406 1876 tunnel - ok
20:19:55.0422 1876 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
20:19:55.0437 1876 uagp35 - ok
20:19:55.0469 1876 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
20:19:55.0500 1876 udfs - ok
20:19:55.0531 1876 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
20:19:55.0531 1876 UI0Detect - ok
20:19:55.0562 1876 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
20:19:55.0562 1876 uliagpkx - ok
20:19:55.0593 1876 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
20:19:55.0625 1876 umbus - ok
20:19:55.0640 1876 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
20:19:55.0640 1876 UmPass - ok
20:19:55.0656 1876 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
20:19:55.0687 1876 upnphost - ok
20:19:55.0749 1876 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
20:19:55.0781 1876 USBAAPL64 - ok
20:19:55.0812 1876 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
20:19:55.0812 1876 usbaudio - ok
20:19:55.0843 1876 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
20:19:55.0859 1876 usbccgp - ok
20:19:55.0890 1876 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
20:19:55.0905 1876 usbcir - ok
20:19:55.0921 1876 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
20:19:55.0952 1876 usbehci - ok
20:19:56.0015 1876 [ 2C780746DC44A28FE67004DC58173F05 ] usbfilter C:\Windows\system32\DRIVERS\usbfilter.sys
20:19:56.0015 1876 usbfilter - ok
20:19:56.0030 1876 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
20:19:56.0077 1876 usbhub - ok
20:19:56.0093 1876 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
20:19:56.0108 1876 usbohci - ok
20:19:56.0139 1876 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
20:19:56.0155 1876 usbprint - ok
20:19:56.0186 1876 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
20:19:56.0186 1876 usbscan - ok
20:19:56.0202 1876 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:19:56.0202 1876 USBSTOR - ok
20:19:56.0217 1876 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
20:19:56.0249 1876 usbuhci - ok
20:19:56.0295 1876 [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx C:\Windows\system32\drivers\usb8023x.sys
20:19:56.0295 1876 usb_rndisx - ok
20:19:56.0327 1876 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
20:19:56.0358 1876 UxSms - ok
20:19:56.0373 1876 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
20:19:56.0373 1876 VaultSvc - ok
20:19:56.0389 1876 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
20:19:56.0389 1876 vdrvroot - ok
20:19:56.0420 1876 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
20:19:56.0436 1876 vds - ok
20:19:56.0451 1876 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
20:19:56.0451 1876 vga - ok
20:19:56.0467 1876 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
20:19:56.0498 1876 VgaSave - ok
20:19:56.0514 1876 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
20:19:56.0529 1876 vhdmp - ok
20:19:56.0529 1876 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
20:19:56.0545 1876 viaide - ok
20:19:56.0545 1876 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
20:19:56.0545 1876 volmgr - ok
20:19:56.0592 1876 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
20:19:56.0607 1876 volmgrx - ok
20:19:56.0607 1876 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
20:19:56.0623 1876 volsnap - ok
20:19:56.0639 1876 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
20:19:56.0654 1876 vsmraid - ok
20:19:56.0701 1876 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
20:19:56.0748 1876 VSS - ok
20:19:56.0763 1876 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
20:19:56.0779 1876 vwifibus - ok
20:19:56.0826 1876 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
20:19:56.0841 1876 W32Time - ok
20:19:56.0857 1876 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
20:19:56.0873 1876 WacomPen - ok
20:19:56.0888 1876 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
20:19:56.0919 1876 WANARP - ok
20:19:56.0919 1876 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
20:19:56.0935 1876 Wanarpv6 - ok
20:19:56.0982 1876 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
20:19:57.0013 1876 wbengine - ok
20:19:57.0029 1876 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
20:19:57.0044 1876 WbioSrvc - ok
20:19:57.0091 1876 [ 8BDA6DB43AA54E8BB5E0794541DDC209 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
20:19:57.0091 1876 WcesComm - ok
20:19:57.0122 1876 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
20:19:57.0153 1876 wcncsvc - ok
20:19:57.0169 1876 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:19:57.0185 1876 WcsPlugInService - ok
20:19:57.0185 1876 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
20:19:57.0200 1876 Wd - ok
20:19:57.0231 1876 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
20:19:57.0247 1876 Wdf01000 - ok
20:19:57.0263 1876 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
20:19:57.0325 1876 WdiServiceHost - ok
20:19:57.0341 1876 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
20:19:57.0341 1876 WdiSystemHost - ok
20:19:57.0372 1876 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
20:19:57.0403 1876 WebClient - ok
20:19:57.0419 1876 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
20:19:57.0450 1876 Wecsvc - ok
20:19:57.0465 1876 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
20:19:57.0512 1876 wercplsupport - ok
20:19:57.0528 1876 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
20:19:57.0559 1876 WerSvc - ok
20:19:57.0575 1876 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
20:19:57.0606 1876 WfpLwf - ok
20:19:57.0621 1876 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
20:19:57.0621 1876 WIMMount - ok
20:19:57.0637 1876 WinDefend - ok
20:19:57.0637 1876 WinHttpAutoProxySvc - ok
20:19:57.0684 1876 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
20:19:57.0699 1876 Winmgmt - ok
20:19:57.0793 1876 [ 0C0195C48B6B8582FA6F6373032118DA ] WinRing0_1_2_0 C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys
20:19:57.0793 1876 WinRing0_1_2_0 - ok
20:19:57.0855 1876 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
20:19:57.0887 1876 WinRM - ok
20:19:57.0933 1876 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
20:19:57.0949 1876 WinUsb - ok
20:19:57.0996 1876 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
20:19:58.0011 1876 Wlansvc - ok
20:19:58.0105 1876 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:19:58.0136 1876 wlidsvc - ok
20:19:58.0167 1876 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
20:19:58.0167 1876 WmiAcpi - ok
20:19:58.0183 1876 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
20:19:58.0199 1876 wmiApSrv - ok
20:19:58.0230 1876 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
20:19:58.0230 1876 WPCSvc - ok
20:19:58.0261 1876 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
20:19:58.0292 1876 WPDBusEnum - ok
20:19:58.0308 1876 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
20:19:58.0323 1876 ws2ifsl - ok
20:19:58.0339 1876 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
20:19:58.0355 1876 wscsvc - ok
20:19:58.0417 1876 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
20:19:58.0448 1876 wuauserv - ok
20:19:58.0479 1876 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
20:19:58.0511 1876 WudfPf - ok
20:19:58.0542 1876 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
20:19:58.0542 1876 WUDFRd - ok
20:19:58.0573 1876 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
20:19:58.0604 1876 wudfsvc - ok
20:19:58.0620 1876 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
20:19:58.0620 1876 WwanSvc - ok
20:19:58.0635 1876 ================ Scan global ===============================
20:19:58.0667 1876 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
20:19:58.0698 1876 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
20:19:58.0698 1876 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
20:19:58.0713 1876 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
20:19:58.0729 1876 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
20:19:58.0745 1876 [Global] - ok
20:19:58.0745 1876 ================ Scan MBR ==================================
20:19:58.0745 1876 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
20:19:58.0791 1876 \Device\Harddisk0\DR0 - ok
20:19:58.0807 1876 [ 3F217AA00F5333EE4FC0F117341604AE ] \Device\Harddisk1\DR1
20:19:58.0979 1876 \Device\Harddisk1\DR1 - ok
20:19:58.0979 1876 ================ Scan VBR ==================================
20:19:58.0979 1876 [ 16B3F20A8E4DA619376AB550FDD8FAFA ] \Device\Harddisk0\DR0\Partition1
20:19:58.0979 1876 \Device\Harddisk0\DR0\Partition1 - ok
20:19:58.0979 1876 [ DD9154D684E6B5DF850E4C2312795C00 ] \Device\Harddisk0\DR0\Partition2
20:19:58.0979 1876 \Device\Harddisk0\DR0\Partition2 - ok
20:19:59.0010 1876 [ 3AFB5538021C88D7E1F82354EDC288CC ] \Device\Harddisk1\DR1\Partition1
20:19:59.0010 1876 \Device\Harddisk1\DR1\Partition1 - ok
20:19:59.0010 1876 ============================================================
20:19:59.0010 1876 Scan finished
20:19:59.0010 1876 ============================================================
20:19:59.0025 1948 Detected object count: 1
20:19:59.0025 1948 Actual detected object count: 1
20:20:04.0392 1948 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
20:20:04.0392 1948 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip

Alt 07.01.2013, 20:21   #10
markusg
/// Malware-holic
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Hi
nutzt du dieses System für Onlinebanking, zum einkaufen, für sonstige Zahlungsabwicklungen, oder ähnlich wichtigem, wie beruflichem?
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.01.2013, 20:25   #11
herbcyy
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Nein, nur hin und wieder für Einkäufe über Steam/ Amazon, wieso ?
UNd für Bewerbungen fürs Studium etc.

Alt 07.01.2013, 20:26   #12
markusg
/// Malware-holic
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Du hast das Rootkit.zero access + andere Schadsoftware, diesen PC können wir nicht mit 100 %iger sicherheit reinigen, dies ist aber nötig, da du über diesen einkaufst.
der pc muss neu aufgesetzt und dann abgesichert werden
1. Datenrettung:2. Formatieren, Windows neu instalieren:3. PC absichern: http://www.trojaner-board.de/96344-a...-rechners.html
ich werde außerdem noch weitere punkte dazu posten.
4. alle Passwörter ändern!
5. nach PC Absicherung, die gesicherten Daten prüfen und falls sauber: zurückspielen.
6. werde ich dann noch was zum absichern von Onlinebanking mit Chip Card Reader + Star Money sagen.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.01.2013, 20:33   #13
herbcyy
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Puh okey. Also ich selbst benutze den PC eigentlich nicht zum Online Banking. Weißt du wie lange ich diese Viren schon habe ?
Weil ich selbst benutze eigentlich kein online Banking und dass mein Dad hier was bestellt hat ist etwas her. Glaub der würds nicht so gut aufnehmen, wenn er erfährt dass er seine Passwörter ändern muss

Windows werde ich natürlich trotzdem neu aufsetzen. Geht eig nur ums Passwort ändern
Allerdings habe ich noch eine Frage zum Windows aufsetzten. Habe jetzt schon 2 mal meinen PC neu aufgesetzt und wenn ich meinen PC jetzt starte kommt immer eine Anzeige bei der ich unter 3 "Windows 7" auswählen kann. Kann man die anderen beiden endgültig löschen oder geht das nicht ?
Und möchte mich jetzt schonmal für deine Mühe danken !

Alt 07.01.2013, 21:14   #14
markusg
/// Malware-holic
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Hi
wie lange das Teil drauf ist, kann ich dir nicht sagen, PW's ändern ist ne gute Idee.
hast du denn ne normale Windows CD, oder ne Recovery cd? bzw ist das ein fertig pc, dann mal hersteller und typ posten.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 07.01.2013, 21:17   #15
herbcyy
 
Virus / unzählige Fenster öffnen sich - Standard

Virus / unzählige Fenster öffnen sich



Nein, der PC ist selbst zusammengestellt. Zur Neuinstallation benutze ich glaub die Windows 7 OEM Preinstallation Kit CD. Kann das hinkommen ?

Antwort

Themen zu Virus / unzählige Fenster öffnen sich
anklicken, arbeiten, desktop, einiger, fenster, fenster öffnen sich, kleines, klicke, klicken, modus, offen, pc normal, poste, posten, problem, schonmal, screenshot, sobald, starte, starten, versuche, virus, vordergrund, öffnen, öffnet




Ähnliche Themen: Virus / unzählige Fenster öffnen sich


  1. Virus oder so, Fenster in meinem browser öffnen sich alle paar minuten (adf.ly)
    Plagegeister aller Art und deren Bekämpfung - 22.02.2015 (7)
  2. Win 7: unzählige pop-up Fenster und Werbung in Internet Explorer und Firefox
    Log-Analyse und Auswertung - 22.03.2014 (11)
  3. Windows 7: FBDownloaderSearch macht sich zur Startseite im Browser, popup-Fenster öffnen sich
    Log-Analyse und Auswertung - 17.12.2013 (9)
  4. Hilfe Trojaner oder Virus - Internetexplorer öffnet unzählige Fenster....
    Log-Analyse und Auswertung - 10.11.2013 (1)
  5. Trojaner? doppelt unterstrichene Wörter und unzählige Pop up Fenster!
    Plagegeister aller Art und deren Bekämpfung - 12.10.2013 (23)
  6. Unzählige Browserfenster öffnen sich| www.traderush.com?
    Plagegeister aller Art und deren Bekämpfung - 31.07.2013 (3)
  7. Virus eingefangen und nun sind Pfade durcheinander, es öffnen sich unzählige Programme nicht mehr
    Plagegeister aller Art und deren Bekämpfung - 15.07.2011 (1)
  8. Fenster verkleinern/verstecken sich, lassen sich nicht mehr öffnen
    Plagegeister aller Art und deren Bekämpfung - 28.12.2010 (2)
  9. Explorer Fenster öffnen sich automatisch ...Trojaner oder virus..was kann ich tun?
    Log-Analyse und Auswertung - 12.09.2009 (1)
  10. Hilfe! Welcher Virus! Dll Dateien fehlen! Webe-fenster öffnen sich!
    Log-Analyse und Auswertung - 01.07.2009 (124)
  11. Firefox Fenster öffnen sich
    Log-Analyse und Auswertung - 22.12.2008 (4)
  12. Uhr verstellt sich, ungewollte Fenster öffnen sich während dem Surfen
    Log-Analyse und Auswertung - 20.09.2008 (0)
  13. Fenster öffnen sich automatisch im IE
    Log-Analyse und Auswertung - 21.02.2008 (4)
  14. fenster öffnen sich ständig...
    Plagegeister aller Art und deren Bekämpfung - 01.12.2006 (1)
  15. Fenster Öffnen sich!
    Log-Analyse und Auswertung - 22.12.2005 (1)
  16. IE öffnet unzählige Fenster
    Log-Analyse und Auswertung - 05.11.2005 (7)
  17. Fenster öffnen und schließen sich
    Plagegeister aller Art und deren Bekämpfung - 01.01.2005 (4)

Zum Thema Virus / unzählige Fenster öffnen sich - Hallo, ich habe ein Problem mit einem vermutlichem Virus. Sobald ich meinen PC starte, öffnet sich immer ein kleines Fenster.Eigentlich wollte ich einen Screenshot davon posten, allerdings geht dieses im - Virus / unzählige Fenster öffnen sich...
Archiv
Du betrachtest: Virus / unzählige Fenster öffnen sich auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.