Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: PC hängt nach Start immer ein paar Minuten oder länger

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 15.06.2013, 16:44   #1
Unbekannter
 
PC hängt nach Start immer ein paar Minuten oder länger - Ausrufezeichen

PC hängt nach Start immer ein paar Minuten oder länger



Hi Leute ich habe seit kurzem das Problem dass mein PC (WIN 7 64 bit)
manchmal hängt. Wenn ich auf ein Programm nach PC Start gehe dauert es ewig und es gibt einen Freeze.
Ich habe mal hier den hijack Post. Ist mein erster Eintrag also nicht böse sein, wenn ich was falsch mache

Zitat:
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 17:33:09, on 15.06.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
CHROME: 27.0.1453.110
FIREFOX: 19.0 (de)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
P:\iTunes\iTunesHelper.exe
C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
P:\Mozilla Firefox\firefox.exe
P:\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
H:\Firefox\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~4\Office15\GROOVEEX.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "P:\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "P:\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [EPSON BX525WD Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGAU.EXE /FU "C:\Users\Tobias\AppData\Local\Temp\E_SEC61.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [EPSON BX525WD Series (Kopie 1)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGAU.EXE /FU "C:\Users\Tobias\AppData\Local\Temp\E_SD4F3.tmp" /EF "HKCU"
O8 - Extra context menu item: An OneNote s&enden - res://P:\MICROS~2\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://P:\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://P:\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: &Virtuelle Tastatur - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Lync: Anruf per Mausklick - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync: Anruf per Mausklick - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - P:\SuperSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - P:\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - P:\TeamviewerVersion8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD Backup (WDBackup) - Western Digital - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
O23 - Service: WD Rules (WDRulesService) - Western Digital - C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 11386 bytes

Alt 15.06.2013, 16:45   #2
markusg
/// Malware-holic
 
PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Hi
anleitungen bitte lesen, hjt Logs wollen wir nicht.

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
  • Starte bitte die
    OTL.exe
    .
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Kopiere nun den Inhalt in die
    Textbox.
Code:
ATTFilter
activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT
         
  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread
__________________

__________________

Alt 16.06.2013, 15:22   #3
Unbekannter
 
PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Logs siehe Anhang.
__________________

Alt 16.06.2013, 18:45   #4
Unbekannter
 
PC hängt nach Start immer ein paar Minuten oder länger - Ausrufezeichen

PC hängt nach Start immer ein paar Minuten oder länger



Sorry habe die EXE falsch abgespeichert. Hier nochmal vom Desktop.

Alt 17.06.2013, 11:28   #5
markusg
/// Malware-holic
 
PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Hi,
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 17.06.2013, 19:16   #6
Unbekannter
 
PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Code:
ATTFilter
20:14:12.0375 4772  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:14:12.0680 4772  ============================================================
20:14:12.0680 4772  Current date / time: 2013/06/17 20:14:12.0680
20:14:12.0680 4772  SystemInfo:
20:14:12.0680 4772  
20:14:12.0680 4772  OS Version: 6.1.7601 ServicePack: 1.0
20:14:12.0680 4772  Product type: Workstation
20:14:12.0681 4772  ComputerName: GAMING
20:14:12.0681 4772  UserName: Tobias
20:14:12.0681 4772  Windows directory: C:\Windows
20:14:12.0681 4772  System windows directory: C:\Windows
20:14:12.0681 4772  Running under WOW64
20:14:12.0681 4772  Processor architecture: Intel x64
20:14:12.0681 4772  Number of processors: 8
20:14:12.0681 4772  Page size: 0x1000
20:14:12.0681 4772  Boot type: Normal boot
20:14:12.0681 4772  ============================================================
20:14:13.0567 4772  Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3F161, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
20:14:13.0572 4772  Drive \Device\Harddisk1\DR1 - Size: 0x1D1BF100000 (1862.99 Gb), SectorSize: 0x200, Cylinders: 0x3B5FD, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:14:13.0576 4772  ============================================================
20:14:13.0576 4772  \Device\Harddisk0\DR0:
20:14:13.0576 4772  MBR partitions:
20:14:13.0576 4772  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:14:13.0576 4772  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1D49F000
20:14:13.0576 4772  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x1D4D1800, BlocksNum 0x124F8000
20:14:13.0602 4772  \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0x2F9CA800, BlocksNum 0x5B8D8000
20:14:13.0618 4772  \Device\Harddisk0\DR0\Partition5: MBR, Type 0x7, StartLBA 0x8B2A3800, BlocksNum 0x4F575000
20:14:13.0638 4772  \Device\Harddisk0\DR0\Partition6: MBR, Type 0x7, StartLBA 0xDA819800, BlocksNum 0xCA96000
20:14:13.0649 4772  \Device\Harddisk0\DR0\Partition7: MBR, Type 0x7, StartLBA 0xE72B0000, BlocksNum 0x1B58000
20:14:13.0649 4772  ============================================================
20:14:13.0681 4772  C: <-> \Device\Harddisk0\DR0\Partition2
20:14:13.0726 4772  P: <-> \Device\Harddisk0\DR0\Partition3
20:14:13.0761 4772  H: <-> \Device\Harddisk0\DR0\Partition6
20:14:13.0852 4772  M: <-> \Device\Harddisk0\DR0\Partition7
20:14:13.0894 4772  S: <-> \Device\Harddisk0\DR0\Partition4
20:14:13.0922 4772  G: <-> \Device\Harddisk0\DR0\Partition5
20:14:13.0922 4772  ============================================================
20:14:13.0922 4772  Initialize success
20:14:13.0922 4772  ============================================================
20:14:40.0559 3640  ============================================================
20:14:40.0559 3640  Scan started
20:14:40.0559 3640  Mode: Manual; SigCheck; TDLFS; 
20:14:40.0559 3640  ============================================================
20:14:41.0195 3640  ================ Scan system memory ========================
20:14:41.0195 3640  System memory - ok
20:14:41.0196 3640  ================ Scan services =============================
20:14:41.0252 3640  [ B7603B1B3A188C79DE7E087F11E324FB ] !SASCORE        P:\SuperSpyware\SASCORE64.EXE
20:14:41.0294 3640  !SASCORE - ok
20:14:41.0406 3640  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
20:14:41.0437 3640  1394ohci - ok
20:14:41.0455 3640  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
20:14:41.0468 3640  ACPI - ok
20:14:41.0482 3640  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
20:14:41.0506 3640  AcpiPmi - ok
20:14:41.0557 3640  [ 8B46D5A1D3EF08232C04D0EAFB871FB2 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
20:14:41.0562 3640  Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
20:14:41.0562 3640  Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
20:14:41.0633 3640  [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:14:41.0643 3640  AdobeARMservice - ok
20:14:41.0740 3640  [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:14:41.0750 3640  AdobeFlashPlayerUpdateSvc - ok
20:14:41.0770 3640  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
20:14:41.0787 3640  adp94xx - ok
20:14:41.0804 3640  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
20:14:41.0819 3640  adpahci - ok
20:14:41.0825 3640  [ E109549C90F62FB570B9540C4B148E54 ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
20:14:41.0837 3640  adpu320 - ok
20:14:41.0858 3640  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
20:14:41.0893 3640  AeLookupSvc - ok
20:14:41.0920 3640  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD             C:\Windows\system32\drivers\afd.sys
20:14:41.0947 3640  AFD - ok
20:14:41.0966 3640  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
20:14:41.0976 3640  agp440 - ok
20:14:41.0993 3640  [ 3290D6946B5E30E70414990574883DDB ] ALG             C:\Windows\System32\alg.exe
20:14:42.0017 3640  ALG - ok
20:14:42.0027 3640  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
20:14:42.0037 3640  aliide - ok
20:14:42.0040 3640  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
20:14:42.0049 3640  amdide - ok
20:14:42.0068 3640  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
20:14:42.0085 3640  AmdK8 - ok
20:14:42.0095 3640  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
20:14:42.0121 3640  AmdPPM - ok
20:14:42.0129 3640  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
20:14:42.0140 3640  amdsata - ok
20:14:42.0150 3640  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
20:14:42.0162 3640  amdsbs - ok
20:14:42.0165 3640  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
20:14:42.0174 3640  amdxata - ok
20:14:42.0190 3640  [ 89A69C3F2F319B43379399547526D952 ] AppID           C:\Windows\system32\drivers\appid.sys
20:14:42.0224 3640  AppID - ok
20:14:42.0233 3640  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
20:14:42.0264 3640  AppIDSvc - ok
20:14:42.0282 3640  [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo         C:\Windows\System32\appinfo.dll
20:14:42.0306 3640  Appinfo - ok
20:14:42.0349 3640  [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:14:42.0359 3640  Apple Mobile Device - ok
20:14:42.0377 3640  [ C484F8CEB1717C540242531DB7845C4E ] arc             C:\Windows\system32\DRIVERS\arc.sys
20:14:42.0388 3640  arc - ok
20:14:42.0399 3640  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
20:14:42.0410 3640  arcsas - ok
20:14:42.0480 3640  [ 108FB6DDB69E537A2EA53F425363FAE5 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
20:14:42.0493 3640  aspnet_state - ok
20:14:42.0511 3640  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
20:14:42.0548 3640  AsyncMac - ok
20:14:42.0555 3640  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi           C:\Windows\system32\drivers\atapi.sys
20:14:42.0564 3640  atapi - ok
20:14:42.0614 3640  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:14:42.0658 3640  AudioEndpointBuilder - ok
20:14:42.0666 3640  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
20:14:42.0697 3640  AudioSrv - ok
20:14:42.0728 3640  AVP - ok
20:14:42.0750 3640  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
20:14:42.0789 3640  AxInstSV - ok
20:14:42.0805 3640  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbda.sys
20:14:42.0827 3640  b06bdrv - ok
20:14:42.0852 3640  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
20:14:42.0866 3640  b57nd60a - ok
20:14:42.0900 3640  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
20:14:42.0922 3640  BDESVC - ok
20:14:42.0931 3640  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
20:14:42.0969 3640  Beep - ok
20:14:42.0997 3640  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE             C:\Windows\System32\bfe.dll
20:14:43.0031 3640  BFE - ok
20:14:43.0057 3640  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\System32\qmgr.dll
20:14:43.0099 3640  BITS - ok
20:14:43.0113 3640  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
20:14:43.0132 3640  blbdrive - ok
20:14:43.0185 3640  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
20:14:43.0197 3640  Bonjour Service - ok
20:14:43.0217 3640  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
20:14:43.0229 3640  bowser - ok
20:14:43.0244 3640  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:14:43.0260 3640  BrFiltLo - ok
20:14:43.0271 3640  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:14:43.0284 3640  BrFiltUp - ok
20:14:43.0303 3640  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser         C:\Windows\System32\browser.dll
20:14:43.0316 3640  Browser - ok
20:14:43.0339 3640  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
20:14:43.0361 3640  Brserid - ok
20:14:43.0371 3640  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
20:14:43.0386 3640  BrSerWdm - ok
20:14:43.0393 3640  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
20:14:43.0417 3640  BrUsbMdm - ok
20:14:43.0423 3640  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
20:14:43.0434 3640  BrUsbSer - ok
20:14:43.0443 3640  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
20:14:43.0464 3640  BTHMODEM - ok
20:14:43.0490 3640  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv         C:\Windows\system32\bthserv.dll
20:14:43.0523 3640  bthserv - ok
20:14:43.0546 3640  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
20:14:43.0585 3640  cdfs - ok
20:14:43.0631 3640  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
20:14:43.0644 3640  cdrom - ok
20:14:43.0670 3640  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc     C:\Windows\System32\certprop.dll
20:14:43.0697 3640  CertPropSvc - ok
20:14:43.0702 3640  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
20:14:43.0714 3640  circlass - ok
20:14:43.0725 3640  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
20:14:43.0739 3640  CLFS - ok
20:14:43.0770 3640  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:14:43.0782 3640  clr_optimization_v2.0.50727_32 - ok
20:14:43.0819 3640  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:14:43.0831 3640  clr_optimization_v2.0.50727_64 - ok
20:14:44.0036 3640  [ 6D7C8A951AF6AD6835C029B3CB88D333 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:14:44.0048 3640  clr_optimization_v4.0.30319_32 - ok
20:14:44.0057 3640  [ 86329C35FF23CFEF0FB6C0023BA06BCE ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:14:44.0069 3640  clr_optimization_v4.0.30319_64 - ok
20:14:44.0089 3640  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
20:14:44.0104 3640  CmBatt - ok
20:14:44.0107 3640  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
20:14:44.0117 3640  cmdide - ok
20:14:44.0143 3640  [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG             C:\Windows\system32\Drivers\cng.sys
20:14:44.0166 3640  CNG - ok
20:14:44.0173 3640  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
20:14:44.0183 3640  Compbatt - ok
20:14:44.0212 3640  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
20:14:44.0235 3640  CompositeBus - ok
20:14:44.0257 3640  COMSysApp - ok
20:14:44.0334 3640  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
20:14:44.0344 3640  crcdisk - ok
20:14:44.0402 3640  [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc        C:\Windows\system32\cryptsvc.dll
20:14:44.0439 3640  CryptSvc - ok
20:14:44.0469 3640  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
20:14:44.0509 3640  DcomLaunch - ok
20:14:44.0540 3640  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc       C:\Windows\System32\defragsvc.dll
20:14:44.0570 3640  defragsvc - ok
20:14:44.0596 3640  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
20:14:44.0638 3640  DfsC - ok
20:14:44.0653 3640  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
20:14:44.0681 3640  Dhcp - ok
20:14:44.0699 3640  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
20:14:44.0725 3640  discache - ok
20:14:44.0751 3640  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\DRIVERS\disk.sys
20:14:44.0761 3640  Disk - ok
20:14:44.0786 3640  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
20:14:44.0804 3640  Dnscache - ok
20:14:44.0823 3640  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc         C:\Windows\System32\dot3svc.dll
20:14:44.0858 3640  dot3svc - ok
20:14:44.0877 3640  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS             C:\Windows\system32\dps.dll
20:14:44.0906 3640  DPS - ok
20:14:44.0932 3640  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
20:14:44.0949 3640  drmkaud - ok
20:14:44.0976 3640  [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
20:14:45.0001 3640  DXGKrnl - ok
20:14:45.0019 3640  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost         C:\Windows\System32\eapsvc.dll
20:14:45.0051 3640  EapHost - ok
20:14:45.0094 3640  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv           C:\Windows\system32\DRIVERS\evbda.sys
20:14:45.0140 3640  ebdrv - ok
20:14:45.0162 3640  [ C118A82CD78818C29AB228366EBF81C3 ] EFS             C:\Windows\System32\lsass.exe
20:14:45.0187 3640  EFS - ok
20:14:45.0221 3640  [ A05FC7ECA0966EBB70E4D17B855A853B ] ElbyCDIO        C:\Windows\system32\Drivers\ElbyCDIO.sys
20:14:45.0233 3640  ElbyCDIO - ok
20:14:45.0263 3640  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
20:14:45.0279 3640  elxstor - ok
20:14:45.0336 3640  [ ABDD5AD016AFFD34AD40E944CE94BF59 ] EpsonBidirectionalService C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
20:14:45.0347 3640  EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - warning
20:14:45.0347 3640  EpsonBidirectionalService - detected UnsignedFile.Multi.Generic (1)
20:14:45.0385 3640  [ 7DB097F4F6786307168C0DDDEC43A565 ] EPSON_EB_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
20:14:45.0403 3640  EPSON_EB_RPCV4_04 - ok
20:14:45.0415 3640  [ 258AA65A0862E19B7DE6981FDA3758AD ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
20:14:45.0435 3640  EPSON_PM_RPCV4_04 - ok
20:14:45.0453 3640  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
20:14:45.0474 3640  ErrDev - ok
20:14:45.0509 3640  [ 932C05033053ADA2404FD836C9AB2C70 ] EuMusDesignVirtualAudioCableWdm C:\Windows\system32\DRIVERS\vrtaucbl.sys
20:14:45.0518 3640  EuMusDesignVirtualAudioCableWdm - ok
20:14:45.0536 3640  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem     C:\Windows\system32\es.dll
20:14:45.0573 3640  EventSystem - ok
20:14:45.0616 3640  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat           C:\Windows\system32\drivers\exfat.sys
20:14:45.0645 3640  exfat - ok
20:14:45.0653 3640  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat         C:\Windows\system32\drivers\fastfat.sys
20:14:45.0690 3640  fastfat - ok
20:14:45.0710 3640  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax             C:\Windows\system32\fxssvc.exe
20:14:45.0728 3640  Fax - ok
20:14:45.0745 3640  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
20:14:45.0757 3640  fdc - ok
20:14:45.0775 3640  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost         C:\Windows\system32\fdPHost.dll
20:14:45.0807 3640  fdPHost - ok
20:14:45.0820 3640  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
20:14:45.0848 3640  FDResPub - ok
20:14:45.0859 3640  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
20:14:45.0869 3640  FileInfo - ok
20:14:45.0880 3640  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
20:14:45.0910 3640  Filetrace - ok
20:14:45.0923 3640  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
20:14:45.0935 3640  flpydisk - ok
20:14:45.0961 3640  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
20:14:45.0973 3640  FltMgr - ok
20:14:46.0053 3640  [ C4C183E6551084039EC862DA1C945E3D ] FontCache       C:\Windows\system32\FntCache.dll
20:14:46.0089 3640  FontCache - ok
20:14:46.0125 3640  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:14:46.0135 3640  FontCache3.0.0.0 - ok
20:14:46.0148 3640  [ D43703496149971890703B4B1B723EAC ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
20:14:46.0158 3640  FsDepends - ok
20:14:46.0177 3640  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
20:14:46.0193 3640  Fs_Rec - ok
20:14:46.0223 3640  [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
20:14:46.0237 3640  fvevol - ok
20:14:46.0252 3640  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
20:14:46.0262 3640  gagp30kx - ok
20:14:46.0273 3640  [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:14:46.0281 3640  GEARAspiWDM - ok
20:14:46.0308 3640  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc           C:\Windows\System32\gpsvc.dll
20:14:46.0349 3640  gpsvc - ok
20:14:46.0405 3640  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:14:46.0414 3640  gupdate - ok
20:14:46.0417 3640  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:14:46.0424 3640  gupdatem - ok
20:14:46.0441 3640  [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi         C:\Windows\system32\DRIVERS\hamachi.sys
20:14:46.0449 3640  hamachi - ok
20:14:46.0471 3640  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
20:14:46.0483 3640  hcw85cir - ok
20:14:46.0514 3640  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:14:46.0530 3640  HdAudAddService - ok
20:14:46.0538 3640  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
20:14:46.0558 3640  HDAudBus - ok
20:14:46.0562 3640  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
20:14:46.0577 3640  HidBatt - ok
20:14:46.0587 3640  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
20:14:46.0619 3640  HidBth - ok
20:14:46.0635 3640  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
20:14:46.0661 3640  HidIr - ok
20:14:46.0681 3640  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv         C:\Windows\system32\hidserv.dll
20:14:46.0716 3640  hidserv - ok
20:14:46.0735 3640  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
20:14:46.0747 3640  HidUsb - ok
20:14:46.0767 3640  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
20:14:46.0804 3640  hkmsvc - ok
20:14:46.0829 3640  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
20:14:46.0843 3640  HomeGroupListener - ok
20:14:46.0865 3640  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
20:14:46.0885 3640  HomeGroupProvider - ok
20:14:46.0898 3640  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
20:14:46.0909 3640  HpSAMD - ok
20:14:46.0935 3640  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
20:14:46.0973 3640  HTTP - ok
20:14:46.0986 3640  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
20:14:46.0995 3640  hwpolicy - ok
20:14:47.0013 3640  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
20:14:47.0026 3640  i8042prt - ok
20:14:47.0040 3640  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
20:14:47.0055 3640  iaStorV - ok
20:14:47.0078 3640  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:14:47.0098 3640  idsvc - ok
20:14:47.0119 3640  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
20:14:47.0129 3640  iirsp - ok
20:14:47.0146 3640  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
20:14:47.0192 3640  IKEEXT - ok
20:14:47.0265 3640  [ ACACD1B925D448558C1C9D0258749451 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
20:14:47.0317 3640  IntcAzAudAddService - ok
20:14:47.0321 3640  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
20:14:47.0330 3640  intelide - ok
20:14:47.0344 3640  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
20:14:47.0356 3640  intelppm - ok
20:14:47.0379 3640  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
20:14:47.0416 3640  IPBusEnum - ok
20:14:47.0436 3640  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:14:47.0473 3640  IpFilterDriver - ok
20:14:47.0501 3640  [ 08C2957BB30058E663720C5606885653 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
20:14:47.0518 3640  iphlpsvc - ok
20:14:47.0537 3640  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
20:14:47.0555 3640  IPMIDRV - ok
20:14:47.0565 3640  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
20:14:47.0606 3640  IPNAT - ok
20:14:47.0645 3640  [ 0FF335D687C85097725A53458160E81E ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
20:14:47.0659 3640  iPod Service - ok
20:14:47.0671 3640  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
20:14:47.0687 3640  IRENUM - ok
20:14:47.0696 3640  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
20:14:47.0707 3640  isapnp - ok
20:14:47.0721 3640  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
20:14:47.0734 3640  iScsiPrt - ok
20:14:47.0797 3640  [ 0D2DA1C6D8ED85F51E3758EAE22455F2 ] JMB36X          C:\Windows\SysWOW64\XSrvSetup.exe
20:14:47.0823 3640  JMB36X - ok
20:14:47.0844 3640  [ 50DE7DD7EDB1B512B13666588AEFBF6F ] JRAID           C:\Windows\system32\DRIVERS\jraid.sys
20:14:47.0853 3640  JRAID - ok
20:14:47.0865 3640  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
20:14:47.0876 3640  kbdclass - ok
20:14:47.0881 3640  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
20:14:47.0893 3640  kbdhid - ok
20:14:47.0896 3640  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
20:14:47.0907 3640  KeyIso - ok
20:14:47.0939 3640  [ 549F9D454E9E6697B108F16C569B505A ] KL1             C:\Windows\system32\DRIVERS\kl1.sys
20:14:47.0954 3640  KL1 - ok
20:14:47.0973 3640  [ 08DF1B7A82837B92096EC7597C00889A ] KLIF            C:\Windows\system32\DRIVERS\klif.sys
20:14:47.0987 3640  KLIF - ok
20:14:47.0999 3640  [ A7DFA9A2554143667E830E8ABE452D70 ] KLIM6           C:\Windows\system32\DRIVERS\klim6.sys
20:14:48.0008 3640  KLIM6 - ok
20:14:48.0041 3640  [ E6FAA395058F7BAF0F3529CDBA9B7133 ] klkbdflt        C:\Windows\system32\DRIVERS\klkbdflt.sys
20:14:48.0051 3640  klkbdflt - ok
20:14:48.0068 3640  [ D398DABD44FDDDBED305442BB7BCDB29 ] klmouflt        C:\Windows\system32\DRIVERS\klmouflt.sys
20:14:48.0077 3640  klmouflt - ok
20:14:48.0080 3640  [ B9B2AEEE5E17B2CEBC034FF2748577A0 ] kltdi           C:\Windows\system32\DRIVERS\kltdi.sys
20:14:48.0089 3640  kltdi - ok
20:14:48.0102 3640  [ 8E880E08D7453DB58DAC36C2C48FFD45 ] kneps           C:\Windows\system32\DRIVERS\kneps.sys
20:14:48.0112 3640  kneps - ok
20:14:48.0125 3640  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
20:14:48.0135 3640  KSecDD - ok
20:14:48.0157 3640  [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
20:14:48.0175 3640  KSecPkg - ok
20:14:48.0203 3640  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
20:14:48.0236 3640  ksthunk - ok
20:14:48.0259 3640  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm           C:\Windows\system32\msdtckrm.dll
20:14:48.0296 3640  KtmRm - ok
20:14:48.0331 3640  [ 305BB2AC00D46542E0A653AB63F4ABB1 ] LADF_CaptureOnly C:\Windows\system32\DRIVERS\ladfGSCamd64.sys
20:14:48.0343 3640  LADF_CaptureOnly - ok
20:14:48.0357 3640  [ 28CDDC7D478A6313F55077416DCBD0DE ] LADF_RenderOnly C:\Windows\system32\DRIVERS\ladfGSRamd64.sys
20:14:48.0366 3640  LADF_RenderOnly - ok
20:14:48.0385 3640  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
20:14:48.0424 3640  LanmanServer - ok
20:14:48.0444 3640  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:14:48.0484 3640  LanmanWorkstation - ok
20:14:48.0511 3640  [ FA529FB35694C24BF98A9EF67C1CD9D0 ] LGBusEnum       C:\Windows\system32\drivers\LGBusEnum.sys
20:14:48.0519 3640  LGBusEnum - ok
20:14:48.0554 3640  [ CDDC07D414B08FECD48E4940C29F483F ] LGSHidFilt      C:\Windows\system32\DRIVERS\LGSHidFilt.Sys
20:14:48.0564 3640  LGSHidFilt - ok
20:14:48.0571 3640  [ 94B29CE153765E768F004FB3440BE2B0 ] LGVirHid        C:\Windows\system32\drivers\LGVirHid.sys
20:14:48.0578 3640  LGVirHid - ok
20:14:48.0594 3640  [ 241F2648ADF090E2A10095BD6D6F5DCB ] LHidFilt        C:\Windows\system32\DRIVERS\LHidFilt.Sys
20:14:48.0604 3640  LHidFilt - ok
20:14:48.0626 3640  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
20:14:48.0662 3640  lltdio - ok
20:14:48.0677 3640  [ C1185803384AB3FEED115F79F109427F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
20:14:48.0709 3640  lltdsvc - ok
20:14:48.0723 3640  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts         C:\Windows\System32\lmhsvc.dll
20:14:48.0761 3640  lmhosts - ok
20:14:48.0774 3640  [ 342ED5A4B3326014438F36D22D803737 ] LMouFilt        C:\Windows\system32\DRIVERS\LMouFilt.Sys
20:14:48.0783 3640  LMouFilt - ok
20:14:48.0800 3640  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
20:14:48.0811 3640  LSI_FC - ok
20:14:48.0829 3640  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
20:14:48.0841 3640  LSI_SAS - ok
20:14:48.0847 3640  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:14:48.0857 3640  LSI_SAS2 - ok
20:14:48.0870 3640  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:14:48.0881 3640  LSI_SCSI - ok
20:14:48.0889 3640  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv           C:\Windows\system32\drivers\luafv.sys
20:14:48.0916 3640  luafv - ok
20:14:48.0950 3640  [ 922CBAC7B992B9614CAB7122F4BF9406 ] ManyCam         C:\Windows\system32\DRIVERS\mcvidrv_x64.sys
20:14:48.0969 3640  ManyCam - ok
20:14:48.0994 3640  [ 34A42DD7CF525D0D2C5232916496E4B8 ] mcaudrv_simple  C:\Windows\system32\drivers\mcaudrv_x64.sys
20:14:49.0014 3640  mcaudrv_simple - ok
20:14:49.0023 3640  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
20:14:49.0034 3640  megasas - ok
20:14:49.0057 3640  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
20:14:49.0087 3640  MegaSR - ok
20:14:49.0110 3640  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS           C:\Windows\system32\mmcss.dll
20:14:49.0162 3640  MMCSS - ok
20:14:49.0176 3640  [ 800BA92F7010378B09F9ED9270F07137 ] Modem           C:\Windows\system32\drivers\modem.sys
20:14:49.0207 3640  Modem - ok
20:14:49.0223 3640  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
20:14:49.0241 3640  monitor - ok
20:14:49.0263 3640  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
20:14:49.0274 3640  mouclass - ok
20:14:49.0280 3640  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
20:14:49.0299 3640  mouhid - ok
20:14:49.0330 3640  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
20:14:49.0340 3640  mountmgr - ok
20:14:49.0362 3640  [ 4CA71F8820469C6FA8AC82381CDA3EFC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:14:49.0374 3640  MozillaMaintenance - ok
20:14:49.0392 3640  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
20:14:49.0404 3640  mpio - ok
20:14:49.0414 3640  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
20:14:49.0448 3640  mpsdrv - ok
20:14:49.0476 3640  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
20:14:49.0513 3640  MpsSvc - ok
20:14:49.0533 3640  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
20:14:49.0556 3640  MRxDAV - ok
20:14:49.0571 3640  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
20:14:49.0592 3640  mrxsmb - ok
20:14:49.0614 3640  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:14:49.0634 3640  mrxsmb10 - ok
20:14:49.0643 3640  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:14:49.0655 3640  mrxsmb20 - ok
20:14:49.0661 3640  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
20:14:49.0672 3640  msahci - ok
20:14:49.0682 3640  [ DB801A638D011B9633829EB6F663C900 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
20:14:49.0693 3640  msdsm - ok
20:14:49.0706 3640  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC           C:\Windows\System32\msdtc.exe
20:14:49.0728 3640  MSDTC - ok
20:14:49.0747 3640  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
20:14:49.0776 3640  Msfs - ok
20:14:49.0778 3640  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
20:14:49.0810 3640  mshidkmdf - ok
20:14:49.0816 3640  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
20:14:49.0826 3640  msisadrv - ok
20:14:49.0856 3640  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
20:14:49.0890 3640  MSiSCSI - ok
20:14:49.0893 3640  msiserver - ok
20:14:49.0910 3640  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
20:14:49.0937 3640  MSKSSRV - ok
20:14:49.0949 3640  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
20:14:49.0982 3640  MSPCLOCK - ok
20:14:49.0989 3640  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
20:14:50.0022 3640  MSPQM - ok
20:14:50.0045 3640  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
20:14:50.0059 3640  MsRPC - ok
20:14:50.0078 3640  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
20:14:50.0088 3640  mssmbios - ok
20:14:50.0091 3640  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
20:14:50.0129 3640  MSTEE - ok
20:14:50.0143 3640  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
20:14:50.0154 3640  MTConfig - ok
20:14:50.0162 3640  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup             C:\Windows\system32\Drivers\mup.sys
20:14:50.0172 3640  Mup - ok
20:14:50.0187 3640  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
20:14:50.0225 3640  napagent - ok
20:14:50.0259 3640  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
20:14:50.0288 3640  NativeWifiP - ok
20:14:50.0345 3640  [ E0E4A1F81A7D69C595A8A9DDAD084C19 ] NAUpdate        C:\Program Files (x86)\Nero\Update\NASvc.exe
20:14:50.0363 3640  NAUpdate - ok
20:14:50.0366 3640  Nbdrv - ok
20:14:50.0394 3640  [ 760E38053BF56E501D562B70AD796B88 ] NDIS            C:\Windows\system32\drivers\ndis.sys
20:14:50.0417 3640  NDIS - ok
20:14:50.0425 3640  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
20:14:50.0453 3640  NdisCap - ok
20:14:50.0470 3640  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
20:14:50.0498 3640  NdisTapi - ok
20:14:50.0512 3640  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
20:14:50.0539 3640  Ndisuio - ok
20:14:50.0552 3640  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
20:14:50.0584 3640  NdisWan - ok
20:14:50.0612 3640  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
20:14:50.0643 3640  NDProxy - ok
20:14:50.0656 3640  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
20:14:50.0692 3640  NetBIOS - ok
20:14:50.0712 3640  [ 09594D1089C523423B32A4229263F068 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
20:14:50.0750 3640  NetBT - ok
20:14:50.0753 3640  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
20:14:50.0765 3640  Netlogon - ok
20:14:50.0788 3640  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
20:14:50.0831 3640  Netman - ok
20:14:50.0875 3640  [ 5243CFC2E7161C91C2B355240035B9E4 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:14:50.0888 3640  NetMsmqActivator - ok
20:14:50.0891 3640  [ 5243CFC2E7161C91C2B355240035B9E4 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:14:50.0904 3640  NetPipeActivator - ok
20:14:50.0910 3640  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
20:14:50.0954 3640  netprofm - ok
20:14:50.0957 3640  [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:14:50.0969 3640  NetTcpActivator - ok
20:14:50.0972 3640  [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:14:50.0985 3640  NetTcpPortSharing - ok
20:14:51.0014 3640  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
20:14:51.0025 3640  nfrd960 - ok
20:14:51.0050 3640  [ 8AD77806D336673F270DB31645267293 ] NlaSvc          C:\Windows\System32\nlasvc.dll
20:14:51.0066 3640  NlaSvc - ok
20:14:51.0076 3640  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
20:14:51.0102 3640  Npfs - ok
20:14:51.0127 3640  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi             C:\Windows\system32\nsisvc.dll
20:14:51.0164 3640  nsi - ok
20:14:51.0175 3640  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
20:14:51.0209 3640  nsiproxy - ok
20:14:51.0242 3640  [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
20:14:51.0273 3640  Ntfs - ok
20:14:51.0281 3640  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
20:14:51.0320 3640  Null - ok
20:14:51.0331 3640  [ A7127E86F9FFE2A53E271B56B2C4CEDF ] nusb3hub        C:\Windows\system32\DRIVERS\nusb3hub.sys
20:14:51.0341 3640  nusb3hub - ok
20:14:51.0353 3640  [ 49BBEC6F48D5F9284B03ABF3A959B19B ] nusb3xhc        C:\Windows\system32\DRIVERS\nusb3xhc.sys
20:14:51.0365 3640  nusb3xhc - ok
20:14:51.0402 3640  [ 805F0C2B9C07E4C0F74D0EF70E9E827A ] NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
20:14:51.0413 3640  NVHDA - ok
20:14:51.0554 3640  [ 7A711D08F1FD1AB8149B6199F84A0EB7 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:14:51.0673 3640  nvlddmkm - ok
20:14:51.0691 3640  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
20:14:51.0702 3640  nvraid - ok
20:14:51.0722 3640  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
20:14:51.0734 3640  nvstor - ok
20:14:51.0770 3640  [ B9F3591981D761A5CA1D24C369764D96 ] nvsvc           C:\Windows\system32\nvvsvc.exe
20:14:51.0788 3640  nvsvc - ok
20:14:51.0851 3640  [ A9AFE5B0648C8D7A411A72D8222F7F6E ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
20:14:51.0885 3640  nvUpdatusService - ok
20:14:51.0898 3640  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
20:14:51.0909 3640  nv_agp - ok
20:14:51.0917 3640  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
20:14:51.0936 3640  ohci1394 - ok
20:14:51.0974 3640  [ B9C125314A025127FE562C116D614AA3 ] ose64           C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:14:51.0986 3640  ose64 - ok
20:14:52.0083 3640  [ FE9C0029E1AF26350D9985D00520E5C8 ] osppsvc         C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
20:14:52.0163 3640  osppsvc - ok
20:14:52.0184 3640  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
20:14:52.0204 3640  p2pimsvc - ok
20:14:52.0215 3640  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
20:14:52.0230 3640  p2psvc - ok
20:14:52.0255 3640  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
20:14:52.0267 3640  Parport - ok
20:14:52.0286 3640  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr         C:\Windows\system32\drivers\partmgr.sys
20:14:52.0297 3640  partmgr - ok
20:14:52.0307 3640  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
20:14:52.0331 3640  PcaSvc - ok
20:14:52.0352 3640  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci             C:\Windows\system32\drivers\pci.sys
20:14:52.0363 3640  pci - ok
20:14:52.0369 3640  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
20:14:52.0378 3640  pciide - ok
20:14:52.0393 3640  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
20:14:52.0406 3640  pcmcia - ok
20:14:52.0412 3640  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw             C:\Windows\system32\drivers\pcw.sys
20:14:52.0422 3640  pcw - ok
20:14:52.0436 3640  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
20:14:52.0481 3640  PEAUTH - ok
20:14:52.0505 3640  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
20:14:52.0523 3640  PerfHost - ok
20:14:52.0559 3640  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla             C:\Windows\system32\pla.dll
20:14:52.0612 3640  pla - ok
20:14:52.0641 3640  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
20:14:52.0658 3640  PlugPlay - ok
20:14:52.0664 3640  PnkBstrA - ok
20:14:52.0680 3640  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
20:14:52.0700 3640  PNRPAutoReg - ok
20:14:52.0709 3640  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
20:14:52.0722 3640  PNRPsvc - ok
20:14:52.0745 3640  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
20:14:52.0777 3640  PolicyAgent - ok
20:14:52.0796 3640  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power           C:\Windows\system32\umpo.dll
20:14:52.0829 3640  Power - ok
20:14:52.0861 3640  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
20:14:52.0898 3640  PptpMiniport - ok
20:14:52.0921 3640  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor       C:\Windows\system32\DRIVERS\processr.sys
20:14:52.0935 3640  Processor - ok
20:14:52.0963 3640  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc         C:\Windows\system32\profsvc.dll
20:14:52.0978 3640  ProfSvc - ok
20:14:52.0988 3640  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
20:14:52.0999 3640  ProtectedStorage - ok
20:14:53.0028 3640  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
20:14:53.0061 3640  Psched - ok
20:14:53.0081 3640  [ DD3FD48D69F5FBBB21D46D1514C1C2DB ] PSI             C:\Windows\system32\DRIVERS\psi_mf_amd64.sys
20:14:53.0089 3640  PSI - ok
20:14:53.0095 3640  pwdrvio - ok
20:14:53.0102 3640  pwdspio - ok
20:14:53.0131 3640  [ BC08F7F3C53CBEE68670ED1314E290FD ] PxHlpa64        C:\Windows\system32\Drivers\PxHlpa64.sys
20:14:53.0139 3640  PxHlpa64 - ok
20:14:53.0173 3640  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
20:14:53.0204 3640  ql2300 - ok
20:14:53.0211 3640  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
20:14:53.0222 3640  ql40xx - ok
20:14:53.0241 3640  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE           C:\Windows\system32\qwave.dll
20:14:53.0260 3640  QWAVE - ok
20:14:53.0272 3640  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
20:14:53.0298 3640  QWAVEdrv - ok
20:14:53.0310 3640  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
20:14:53.0338 3640  RasAcd - ok
20:14:53.0352 3640  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
20:14:53.0378 3640  RasAgileVpn - ok
20:14:53.0396 3640  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto         C:\Windows\System32\rasauto.dll
20:14:53.0424 3640  RasAuto - ok
20:14:53.0449 3640  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
20:14:53.0481 3640  Rasl2tp - ok
20:14:53.0501 3640  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
20:14:53.0533 3640  RasMan - ok
20:14:53.0551 3640  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
20:14:53.0579 3640  RasPppoe - ok
20:14:53.0595 3640  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
20:14:53.0629 3640  RasSstp - ok
20:14:53.0653 3640  [ 77F665941019A1594D887A74F301FA2F ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
20:14:53.0681 3640  rdbss - ok
20:14:53.0693 3640  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
20:14:53.0706 3640  rdpbus - ok
20:14:53.0725 3640  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
20:14:53.0751 3640  RDPCDD - ok
20:14:53.0762 3640  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
20:14:53.0799 3640  RDPENCDD - ok
20:14:53.0802 3640  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
20:14:53.0828 3640  RDPREFMP - ok
20:14:53.0876 3640  [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
20:14:53.0892 3640  RdpVideoMiniport - ok
20:14:53.0911 3640  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
20:14:53.0929 3640  RDPWD - ok
20:14:53.0971 3640  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
20:14:53.0983 3640  rdyboost - ok
20:14:54.0008 3640  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
20:14:54.0054 3640  RemoteAccess - ok
20:14:54.0074 3640  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
20:14:54.0114 3640  RemoteRegistry - ok
20:14:54.0126 3640  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
20:14:54.0161 3640  RpcEptMapper - ok
20:14:54.0180 3640  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
20:14:54.0202 3640  RpcLocator - ok
20:14:54.0219 3640  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs           C:\Windows\system32\rpcss.dll
20:14:54.0248 3640  RpcSs - ok
20:14:54.0269 3640  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
20:14:54.0296 3640  rspndr - ok
20:14:54.0332 3640  [ 7F4F11527AF5A7E4526CB6A146B3E40C ] RTL8167         C:\Windows\system32\DRIVERS\Rt64win7.sys
20:14:54.0346 3640  RTL8167 - ok
20:14:54.0348 3640  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs           C:\Windows\system32\lsass.exe
20:14:54.0359 3640  SamSs - ok
20:14:54.0385 3640  [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV        P:\SuperSpyware\SASDIFSV64.SYS
20:14:54.0392 3640  SASDIFSV - ok
20:14:54.0445 3640  [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL        P:\SuperSpyware\SASKUTIL64.SYS
20:14:54.0453 3640  SASKUTIL - ok
20:14:54.0499 3640  [ CCBF62280DAF6D94A4C73E391CDAC68C ] SbieDrv         P:\Sandboxie\SbieDrv.sys
20:14:54.0511 3640  SbieDrv - ok
20:14:54.0522 3640  [ 8A1F63C6EC01C56C9EC4C681E593FE34 ] SbieSvc         P:\Sandboxie\SbieSvc.exe
20:14:54.0532 3640  SbieSvc - ok
20:14:54.0549 3640  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
20:14:54.0560 3640  sbp2port - ok
20:14:54.0570 3640  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
20:14:54.0601 3640  SCardSvr - ok
20:14:54.0620 3640  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
20:14:54.0658 3640  scfilter - ok
20:14:54.0687 3640  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
20:14:54.0744 3640  Schedule - ok
20:14:54.0769 3640  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc     C:\Windows\System32\certprop.dll
20:14:54.0794 3640  SCPolicySvc - ok
20:14:54.0814 3640  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
20:14:54.0839 3640  SDRSVC - ok
20:14:54.0872 3640  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
20:14:54.0899 3640  secdrv - ok
20:14:54.0910 3640  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
20:14:54.0944 3640  seclogon - ok
20:14:54.0999 3640  [ E43C0D32FF2D9A72F2D975B83B916964 ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
20:14:55.0019 3640  Secunia PSI Agent - ok
20:14:55.0049 3640  [ CB2D183E27D1443F7D4CF10665B2BDED ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
20:14:55.0064 3640  Secunia Update Agent - ok
20:14:55.0083 3640  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
20:14:55.0116 3640  SENS - ok
20:14:55.0128 3640  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
20:14:55.0141 3640  SensrSvc - ok
20:14:55.0156 3640  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
20:14:55.0174 3640  Serenum - ok
20:14:55.0194 3640  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
20:14:55.0206 3640  Serial - ok
20:14:55.0232 3640  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
20:14:55.0256 3640  sermouse - ok
20:14:55.0281 3640  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
20:14:55.0310 3640  SessionEnv - ok
20:14:55.0329 3640  [ A554811BCD09279536440C964AE35BBF ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
20:14:55.0346 3640  sffdisk - ok
20:14:55.0357 3640  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
20:14:55.0377 3640  sffp_mmc - ok
20:14:55.0390 3640  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
20:14:55.0407 3640  sffp_sd - ok
20:14:55.0430 3640  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
20:14:55.0448 3640  sfloppy - ok
20:14:55.0476 3640  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
20:14:55.0514 3640  SharedAccess - ok
20:14:55.0528 3640  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:14:55.0566 3640  ShellHWDetection - ok
20:14:55.0592 3640  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:14:55.0603 3640  SiSRaid2 - ok
20:14:55.0611 3640  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
20:14:55.0622 3640  SiSRaid4 - ok
20:14:55.0634 3640  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
20:14:55.0662 3640  Smb - ok
20:14:55.0690 3640  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
20:14:55.0703 3640  SNMPTRAP - ok
20:14:55.0708 3640  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr           C:\Windows\system32\drivers\spldr.sys
20:14:55.0717 3640  spldr - ok
20:14:55.0737 3640  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler         C:\Windows\System32\spoolsv.exe
20:14:55.0754 3640  Spooler - ok
20:14:55.0806 3640  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
20:14:55.0873 3640  sppsvc - ok
20:14:55.0880 3640  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
20:14:55.0915 3640  sppuinotify - ok
20:14:55.0935 3640  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv             C:\Windows\system32\DRIVERS\srv.sys
20:14:55.0951 3640  srv - ok
20:14:55.0965 3640  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
20:14:55.0985 3640  srv2 - ok
20:14:56.0001 3640  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
20:14:56.0021 3640  srvnet - ok
20:14:56.0046 3640  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
20:14:56.0086 3640  SSDPSRV - ok
20:14:56.0097 3640  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc         C:\Windows\system32\sstpsvc.dll
20:14:56.0125 3640  SstpSvc - ok
20:14:56.0146 3640  Steam Client Service - ok
20:14:56.0158 3640  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
20:14:56.0168 3640  stexstor - ok
20:14:56.0199 3640  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
20:14:56.0221 3640  stisvc - ok
20:14:56.0238 3640  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\drivers\swenum.sys
20:14:56.0248 3640  swenum - ok
20:14:56.0317 3640  [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard     C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
20:14:56.0337 3640  SwitchBoard ( UnsignedFile.Multi.Generic ) - warning
20:14:56.0337 3640  SwitchBoard - detected UnsignedFile.Multi.Generic (1)
20:14:56.0354 3640  [ E08E46FDD841B7184194011CA1955A0B ] swprv           C:\Windows\System32\swprv.dll
20:14:56.0386 3640  swprv - ok
20:14:56.0420 3640  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain         C:\Windows\system32\sysmain.dll
20:14:56.0471 3640  SysMain - ok
20:14:56.0489 3640  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:14:56.0518 3640  TabletInputService - ok
20:14:56.0537 3640  [ F9BE29D5E097F03F81D3CD12B794CB66 ] tap0901         C:\Windows\system32\DRIVERS\tap0901.sys
20:14:56.0547 3640  tap0901 - ok
20:14:56.0575 3640  [ 8B9FD32C71F29DF235A27CE9FF4F19DC ] taphss6         C:\Windows\system32\DRIVERS\taphss6.sys
20:14:56.0584 3640  taphss6 - ok
20:14:56.0611 3640  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv         C:\Windows\System32\tapisrv.dll
20:14:56.0646 3640  TapiSrv - ok
20:14:56.0661 3640  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS             C:\Windows\System32\tbssvc.dll
20:14:56.0689 3640  TBS - ok
20:14:56.0731 3640  [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
20:14:56.0761 3640  Tcpip - ok
20:14:56.0781 3640  [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
20:14:56.0808 3640  TCPIP6 - ok
20:14:56.0834 3640  [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
20:14:56.0846 3640  tcpipreg - ok
20:14:56.0858 3640  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
20:14:56.0875 3640  TDPIPE - ok
20:14:56.0897 3640  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
20:14:56.0908 3640  TDTCP - ok
20:14:56.0928 3640  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
20:14:56.0961 3640  tdx - ok
20:14:57.0096 3640  [ 7C8DD5576695B3362202EF09B20C425E ] TeamViewer8     P:\TeamviewerVersion8\TeamViewer_Service.exe
20:14:57.0137 3640  TeamViewer8 - ok
20:14:57.0168 3640  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\drivers\termdd.sys
20:14:57.0178 3640  TermDD - ok
20:14:57.0197 3640  [ 2E648163254233755035B46DD7B89123 ] TermService     C:\Windows\System32\termsrv.dll
20:14:57.0238 3640  TermService - ok
20:14:57.0251 3640  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
20:14:57.0276 3640  Themes - ok
20:14:57.0293 3640  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER     C:\Windows\system32\mmcss.dll
20:14:57.0320 3640  THREADORDER - ok
20:14:57.0351 3640  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
20:14:57.0393 3640  TrkWks - ok
20:14:57.0417 3640  [ 370A6907DDF79532A39319492B1FA38A ] truecrypt       C:\Windows\system32\drivers\truecrypt.sys
20:14:57.0429 3640  truecrypt - ok
20:14:57.0470 3640  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:14:57.0498 3640  TrustedInstaller - ok
20:14:57.0513 3640  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
20:14:57.0544 3640  tssecsrv - ok
20:14:57.0561 3640  [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
20:14:57.0582 3640  TsUsbFlt - ok
20:14:57.0634 3640  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
20:14:57.0668 3640  tunnel - ok
20:14:57.0687 3640  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
20:14:57.0697 3640  uagp35 - ok
20:14:57.0708 3640  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
20:14:57.0735 3640  udfs - ok
20:14:57.0748 3640  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
20:14:57.0768 3640  UI0Detect - ok
20:14:57.0780 3640  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
20:14:57.0790 3640  uliagpkx - ok
20:14:57.0809 3640  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus           C:\Windows\system32\drivers\umbus.sys
20:14:57.0831 3640  umbus - ok
20:14:57.0841 3640  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
20:14:57.0853 3640  UmPass - ok
20:14:57.0873 3640  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
20:14:57.0908 3640  upnphost - ok
20:14:57.0931 3640  [ C9E9D59C0099A9FF51697E9306A44240 ] USBAAPL64       C:\Windows\system32\Drivers\usbaapl64.sys
20:14:57.0943 3640  USBAAPL64 - ok
20:14:57.0956 3640  [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
20:14:57.0978 3640  usbaudio - ok
20:14:58.0004 3640  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
20:14:58.0027 3640  usbccgp - ok
20:14:58.0037 3640  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
20:14:58.0051 3640  usbcir - ok
20:14:58.0071 3640  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci         C:\Windows\system32\drivers\usbehci.sys
20:14:58.0089 3640  usbehci - ok
20:14:58.0114 3640  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
20:14:58.0139 3640  usbhub - ok
20:14:58.0147 3640  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
20:14:58.0158 3640  usbohci - ok
20:14:58.0179 3640  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
20:14:58.0192 3640  usbprint - ok
20:14:58.0217 3640  [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
20:14:58.0237 3640  usbscan - ok
20:14:58.0248 3640  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:14:58.0269 3640  USBSTOR - ok
20:14:58.0279 3640  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
20:14:58.0290 3640  usbuhci - ok
20:14:58.0293 3640  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms           C:\Windows\System32\uxsms.dll
20:14:58.0324 3640  UxSms - ok
20:14:58.0337 3640  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
20:14:58.0348 3640  VaultSvc - ok
20:14:58.0375 3640  [ FD911873C0BB6945FA38C16E9A2B58F9 ] VClone          C:\Windows\system32\DRIVERS\VClone.sys
20:14:58.0390 3640  VClone - ok
20:14:58.0392 3640  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
20:14:58.0402 3640  vdrvroot - ok
20:14:58.0427 3640  [ 8D6B481601D01A456E75C3210F1830BE ] vds             C:\Windows\System32\vds.exe
20:14:58.0460 3640  vds - ok
20:14:58.0474 3640  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
20:14:58.0487 3640  vga - ok
20:14:58.0498 3640  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave         C:\Windows\System32\drivers\vga.sys
20:14:58.0524 3640  VgaSave - ok
20:14:58.0549 3640  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
20:14:58.0561 3640  vhdmp - ok
20:14:58.0571 3640  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
20:14:58.0582 3640  viaide - ok
20:14:58.0595 3640  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
20:14:58.0604 3640  volmgr - ok
20:14:58.0619 3640  [ A255814907C89BE58B79EF2F189B843B ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
20:14:58.0633 3640  volmgrx - ok
20:14:58.0644 3640  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
20:14:58.0657 3640  volsnap - ok
20:14:58.0686 3640  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
20:14:58.0698 3640  vsmraid - ok
20:14:58.0722 3640  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS             C:\Windows\system32\vssvc.exe
20:14:58.0769 3640  VSS - ok
20:14:58.0777 3640  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
20:14:58.0799 3640  vwifibus - ok
20:14:58.0822 3640  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time         C:\Windows\system32\w32time.dll
20:14:58.0854 3640  W32Time - ok
20:14:58.0867 3640  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
20:14:58.0882 3640  WacomPen - ok
20:14:58.0896 3640  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
20:14:58.0927 3640  WANARP - ok
20:14:58.0929 3640  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
20:14:58.0955 3640  Wanarpv6 - ok
20:14:58.0976 3640  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
20:14:59.0006 3640  wbengine - ok
20:14:59.0014 3640  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
20:14:59.0039 3640  WbioSrvc - ok
20:14:59.0067 3640  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc         C:\Windows\System32\wcncsvc.dll
20:14:59.0085 3640  wcncsvc - ok
20:14:59.0090 3640  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:14:59.0101 3640  WcsPlugInService - ok
20:14:59.0116 3640  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\DRIVERS\wd.sys
20:14:59.0126 3640  Wd - ok
20:14:59.0241 3640  [ 96C4C98FE4866C16FC64E4578A0AA975 ] WDBackup        C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
20:14:59.0283 3640  WDBackup - ok
20:14:59.0309 3640  [ A3D04EBF5227886029B4532F20D026F7 ] WDC_SAM         C:\Windows\system32\DRIVERS\wdcsam64.sys
20:14:59.0340 3640  WDC_SAM - ok
20:14:59.0419 3640  [ 80F8944EA183004D6EDCBBDCEC166404 ] WDDriveService  C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
20:14:59.0429 3640  WDDriveService - ok
20:14:59.0461 3640  [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
20:14:59.0482 3640  Wdf01000 - ok
20:14:59.0488 3640  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
20:14:59.0510 3640  WdiServiceHost - ok
20:14:59.0513 3640  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost   C:\Windows\system32\wdi.dll
20:14:59.0529 3640  WdiSystemHost - ok
20:14:59.0563 3640  [ FD2D1C60CDBDFAB63EF182539D8FFC2D ] WDRulesService  C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
20:14:59.0583 3640  WDRulesService - ok
20:14:59.0617 3640  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient       C:\Windows\System32\webclnt.dll
20:14:59.0649 3640  WebClient - ok
20:14:59.0669 3640  [ D5BA7D43FA2EF656BF7E98A188391E40 ] Wecsvc          C:\Windows\system32\wecsvc.dll
20:14:59.0691 3640  Wecsvc - ok
20:14:59.0703 3640  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
20:14:59.0740 3640  wercplsupport - ok
20:14:59.0759 3640  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
20:14:59.0788 3640  WerSvc - ok
20:14:59.0804 3640  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
20:14:59.0830 3640  WfpLwf - ok
20:14:59.0840 3640  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
20:14:59.0849 3640  WIMMount - ok
20:14:59.0862 3640  WinDefend - ok
20:14:59.0867 3640  WinHttpAutoProxySvc - ok
20:14:59.0899 3640  [ 136760C1E9697BAF4ECDEAE5590A0806 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
20:14:59.0922 3640  Winmgmt - ok
20:14:59.0970 3640  [ 3BB6B401A780BF434C8F58137DE10BF7 ] WinRM           C:\Windows\system32\WsmSvc.dll
20:15:00.0025 3640  WinRM - ok
20:15:00.0048 3640  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
20:15:00.0062 3640  WinUsb - ok
20:15:00.0088 3640  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc         C:\Windows\System32\wlansvc.dll
20:15:00.0125 3640  Wlansvc - ok
20:15:00.0180 3640  [ 357CABBF155AFD1D3926E62539D2A3A7 ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:15:00.0220 3640  wlidsvc - ok
20:15:00.0239 3640  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
20:15:00.0260 3640  WmiAcpi - ok
20:15:00.0272 3640  [ 4DF841632B62A7CF19A79A05046A8AB1 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
20:15:00.0286 3640  wmiApSrv - ok
20:15:00.0298 3640  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
20:15:00.0311 3640  WPCSvc - ok
20:15:00.0325 3640  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
20:15:00.0341 3640  WPDBusEnum - ok
20:15:00.0362 3640  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
20:15:00.0393 3640  ws2ifsl - ok
20:15:00.0406 3640  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\System32\wscsvc.dll
20:15:00.0430 3640  wscsvc - ok
20:15:00.0432 3640  WSearch - ok
20:15:00.0473 3640  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
20:15:00.0517 3640  wuauserv - ok
20:15:00.0534 3640  [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
20:15:00.0547 3640  WudfPf - ok
20:15:00.0569 3640  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
20:15:00.0594 3640  WUDFRd - ok
20:15:00.0618 3640  [ B20F051B03A966392364C83F009F7D17 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
20:15:00.0641 3640  wudfsvc - ok
20:15:00.0660 3640  [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc         C:\Windows\System32\wwansvc.dll
20:15:00.0676 3640  WwanSvc - ok
20:15:00.0711 3640  [ 4A5CE13408945E525503B5F73D29B9C5 ] xnacc           C:\Windows\system32\DRIVERS\xnacc.sys
20:15:00.0734 3640  xnacc - ok
20:15:00.0758 3640  [ 2EE48CFCE7CA8E0DB4C44C7476C0943B ] xusb21          C:\Windows\system32\DRIVERS\xusb21.sys
20:15:00.0780 3640  xusb21 - ok
20:15:00.0786 3640  ================ Scan global ===============================
20:15:00.0803 3640  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
20:15:00.0823 3640  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
20:15:00.0829 3640  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
20:15:00.0852 3640  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
20:15:00.0863 3640  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
20:15:00.0867 3640  [Global] - ok
20:15:00.0868 3640  ================ Scan MBR ==================================
20:15:00.0873 3640  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
20:15:01.0122 3640  \Device\Harddisk0\DR0 - ok
20:15:01.0123 3640  ================ Scan VBR ==================================
20:15:01.0123 3640  [ 630A212140F0C7FCEACE74CDA6143FF7 ] \Device\Harddisk0\DR0\Partition1
20:15:01.0124 3640  \Device\Harddisk0\DR0\Partition1 - ok
20:15:01.0150 3640  [ BD3B76ACDA945781B9271B5ED2E0FA04 ] \Device\Harddisk0\DR0\Partition2
20:15:01.0152 3640  \Device\Harddisk0\DR0\Partition2 - ok
20:15:01.0169 3640  [ 6583BE889808E371630DAAF92918FCEC ] \Device\Harddisk0\DR0\Partition3
20:15:01.0170 3640  \Device\Harddisk0\DR0\Partition3 - ok
20:15:01.0171 3640  [ A78EEBDCF2C6D2317AAC74FBCA9C4527 ] \Device\Harddisk0\DR0\Partition4
20:15:01.0172 3640  \Device\Harddisk0\DR0\Partition4 - ok
20:15:01.0190 3640  [ 93B738BE8F7221D77524ABF55BB7ED16 ] \Device\Harddisk0\DR0\Partition5
20:15:01.0191 3640  \Device\Harddisk0\DR0\Partition5 - ok
20:15:01.0210 3640  [ 1508834C195201F3896E79BB3B1EC06C ] \Device\Harddisk0\DR0\Partition6
20:15:01.0212 3640  \Device\Harddisk0\DR0\Partition6 - ok
20:15:01.0221 3640  [ AEA818AA631D4149FED30B665024A7AA ] \Device\Harddisk0\DR0\Partition7
20:15:01.0222 3640  \Device\Harddisk0\DR0\Partition7 - ok
20:15:01.0223 3640  ============================================================
20:15:01.0223 3640  Scan finished
20:15:01.0223 3640  ============================================================
20:15:01.0229 5076  Detected object count: 3
20:15:01.0229 5076  Actual detected object count: 3
20:15:51.0694 5076  Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user
20:15:51.0694 5076  Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 
20:15:51.0695 5076  EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - skipped by user
20:15:51.0695 5076  EpsonBidirectionalService ( UnsignedFile.Multi.Generic ) - User select action: Skip 
20:15:51.0696 5076  SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user
20:15:51.0696 5076  SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip 
20:15:59.0587 2716  Deinitialize success
         

Alt 18.06.2013, 16:46   #7
markusg
/// Malware-holic
 
PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Hi,
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 18.06.2013, 20:37   #8
Unbekannter
 
PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Code:
ATTFilter
ComboFix 13-06-18.02 - Tobias 18.06.2013  21:16:03.1.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.8187.5699 [GMT 2:00]
ausgeführt von:: c:\users\Tobias\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
FW: Kaspersky Internet Security *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
SP: Kaspersky Internet Security *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\CoolXPProgress.ocx
c:\windows\SysWow64\frapsvid.dll
c:\windows\SysWow64\User
c:\windows\UA000096.DLL
G:\install.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-05-18 bis 2013-06-18  ))))))))))))))))))))))))))))))
.
.
2013-06-18 19:24 . 2013-06-18 19:24	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-06-18 19:24 . 2013-06-18 19:24	--------	d-----w-	c:\users\Administrator\AppData\Local\temp
2013-06-18 18:34 . 2013-06-12 03:08	9552976	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{54A4F93F-8C2E-4E92-A82A-FA13F73F003A}\mpengine.dll
2013-06-11 20:40 . 2013-06-11 20:40	--------	d-----w-	c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-11 20:40 . 2013-06-11 20:40	--------	d-----w-	c:\program files\iTunes
2013-06-11 20:40 . 2013-06-11 20:40	--------	d-----w-	c:\program files\iPod
2013-06-11 19:05 . 2013-05-13 05:51	184320	----a-w-	c:\windows\system32\cryptsvc.dll
2013-06-11 19:04 . 2013-04-25 23:30	1505280	----a-w-	c:\windows\SysWow64\d3d11.dll
2013-06-11 19:04 . 2013-03-31 22:52	1887232	----a-w-	c:\windows\system32\d3d11.dll
2013-06-01 17:34 . 2013-06-01 17:34	--------	d-----w-	c:\users\Tobias\AppData\Roaming\SUPERAntiSpyware.com
2013-06-01 17:34 . 2013-06-01 17:34	--------	d-----w-	c:\programdata\SUPERAntiSpyware.com
2013-05-23 17:17 . 2013-05-23 17:17	--------	d-----w-	c:\users\Tobias\AppData\Local\NVIDIA
2013-05-23 17:12 . 2013-05-23 17:12	--------	d-----w-	c:\users\UpdatusUser
2013-05-23 17:09 . 2013-05-23 17:09	--------	d-----w-	C:\NVIDIA
2013-05-20 19:00 . 2013-05-20 19:00	5079256	----a-w-	c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe
2013-05-20 19:00 . 2013-05-20 19:00	4843712	----a-w-	c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\Csi.dll
2013-05-20 19:00 . 2013-05-20 19:00	25367232	----a-w-	c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2013-05-20 18:34 . 2013-05-20 18:34	6795992	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe
2013-05-20 18:34 . 2013-05-20 18:34	6572736	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\Csi.dll
2013-05-20 18:33 . 2013-05-20 18:33	3001536	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\1031\MSOINTL.DLL
2013-05-20 18:33 . 2013-05-20 18:33	35345600	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-15 15:55 . 2012-07-15 11:43	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-15 15:55 . 2012-07-15 11:43	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-11 19:09 . 2012-06-23 14:26	75825640	----a-w-	c:\windows\system32\MRT.exe
2013-05-29 16:45 . 2012-06-30 14:37	291328	----a-w-	c:\windows\SysWow64\PnkBstrB.xtr
2013-05-29 16:45 . 2012-06-24 14:33	291328	----a-w-	c:\windows\SysWow64\PnkBstrB.exe
2013-05-26 18:38 . 2012-06-24 14:33	291328	----a-w-	c:\windows\SysWow64\PnkBstrB.ex0
2013-05-19 19:10 . 2012-07-17 20:33	18960	----a-w-	c:\windows\system32\drivers\LNonPnP.sys
2013-05-16 18:12 . 2012-07-17 13:37	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-12 21:42 . 2013-04-27 13:14	2935696	----a-w-	c:\windows\system32\nvapi64.dll
2013-05-12 21:42 . 2013-04-27 13:14	27775776	----a-w-	c:\windows\system32\nvoglv64.dll
2013-05-12 21:42 . 2013-04-27 13:14	15910736	----a-w-	c:\windows\system32\nvwgf2umx.dll
2013-05-12 21:42 . 2013-04-27 13:14	13403168	----a-w-	c:\windows\SysWow64\nvwgf2um.dll
2013-05-12 21:42 . 2013-04-27 13:14	12426216	----a-w-	c:\windows\SysWow64\nvd3dum.dll
2013-05-12 21:42 . 2013-04-27 13:14	1059560	----a-w-	c:\windows\system32\nvumdshimx.dll
2013-05-12 21:42 . 2012-02-09 20:43	61216	----a-w-	c:\windows\system32\OpenCL.dll
2013-05-12 21:42 . 2012-02-09 20:43	53024	----a-w-	c:\windows\SysWow64\OpenCL.dll
2013-05-12 20:34 . 2013-04-27 13:21	6491936	----a-w-	c:\windows\system32\nvcpl.dll
2013-05-12 20:34 . 2013-04-27 13:21	3514656	----a-w-	c:\windows\system32\nvsvc64.dll
2013-05-12 20:34 . 2013-04-27 13:21	884512	----a-w-	c:\windows\system32\nvvsvc.exe
2013-05-12 20:34 . 2013-04-27 13:21	63776	----a-w-	c:\windows\system32\nvshext.dll
2013-05-12 20:34 . 2013-04-27 13:21	2555680	----a-w-	c:\windows\system32\nvsvcr.dll
2013-05-12 20:34 . 2013-04-27 13:21	237856	----a-w-	c:\windows\system32\nvmctray.dll
2013-05-10 07:57 . 2013-05-10 07:57	27208	----a-w-	c:\windows\system32\AdobePDFUI.dll
2013-05-10 07:57 . 2013-05-10 07:57	55872	----a-w-	c:\windows\system32\AdobePDF.dll
2013-05-08 14:13 . 2013-04-27 13:21	3165737	----a-w-	c:\windows\system32\nvcoproc.bin
2013-05-02 00:06 . 2012-06-23 14:15	278800	------w-	c:\windows\system32\MpSigStub.exe
2013-05-01 01:59 . 2013-05-01 01:59	94208	----a-w-	c:\windows\SysWow64\QuickTimeVR.qtx
2013-05-01 01:59 . 2013-05-01 01:59	69632	----a-w-	c:\windows\SysWow64\QuickTime.qts
2013-04-24 21:56 . 2013-04-24 21:56	77592	----a-w-	c:\windows\system32\ladfGSRCoinst_amd64.dll
2013-04-24 21:56 . 2013-04-24 21:56	410008	----a-w-	c:\windows\system32\drivers\ladfGSCamd64.sys
2013-04-24 21:56 . 2013-04-24 21:56	102808	----a-w-	c:\windows\system32\drivers\ladfGSRamd64.sys
2013-04-19 04:24 . 2013-04-27 13:14	1832224	----a-w-	c:\windows\system32\nvdispco6432000.dll
2013-04-19 04:24 . 2013-04-27 13:14	1511712	----a-w-	c:\windows\system32\nvdispgenco6432000.dll
2013-04-13 05:49 . 2013-05-14 19:03	135168	----a-w-	c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-14 19:03	350208	----a-w-	c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-14 19:03	308736	----a-w-	c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-14 19:03	111104	----a-w-	c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-14 19:03	474624	----a-w-	c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-14 19:03	2176512	----a-w-	c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-24 12:11	1656680	----a-w-	c:\windows\system32\drivers\ntfs.sys
2013-04-10 06:01 . 2013-05-14 19:03	265064	----a-w-	c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-14 19:03	983400	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-14 19:03	3153920	----a-w-	c:\windows\system32\win32k.sys
2013-04-04 03:35 . 2013-04-17 19:10	95648	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2013-05-20 19:00	1725128	----a-w-	c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2013-05-20 19:00	1725128	----a-w-	c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2013-05-20 19:00	1725128	----a-w-	c:\progra~2\MICROS~4\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [2012-05-31 218880]
"iTunesHelper"="p:\itunes\iTunesHelper.exe" [2013-05-31 152392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Acrobat Speed Launcher"="p:\adobe acrobat x pro\Acrobat\Acrobat_sl.exe"
"iTunesHelper"="p:\itunes\iTunesHelper.exe"
"QuickTime Task"="p:\quicktime\QTTask.exe" -atboottime
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe [x]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv_x64.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv_x64.sys [x]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x]
R3 Nbdrv;NetBalancer;c:\windows\system32\DRIVERS\nbdrv.sys;c:\windows\SYSNATIVE\DRIVERS\nbdrv.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys;c:\windows\SYSNATIVE\pwdrvio.sys [x]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys;c:\windows\SYSNATIVE\pwdspio.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S1 SASDIFSV;SASDIFSV;p:\superspyware\SASDIFSV64.SYS;p:\superspyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;p:\superspyware\SASKUTIL64.SYS;p:\superspyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;p:\superspyware\SASCORE64.EXE;p:\superspyware\SASCORE64.EXE [x]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [x]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x]
S2 TeamViewer8;TeamViewer 8;p:\teamviewerversion8\TeamViewer_Service.exe;p:\teamviewerversion8\TeamViewer_Service.exe [x]
S2 WDBackup;WD Backup;c:\program files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe;c:\program files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [x]
S2 WDDriveService;WD Drive Manager;c:\program files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe;c:\program files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [x]
S2 WDRulesService;WD Rules;c:\program files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe;c:\program files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSCamd64.sys [x]
S3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSRamd64.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf_amd64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 15:55]
.
2013-06-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-19 19:36]
.
2013-06-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-19 19:36]
.
2013-06-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3788861942-4145589557-749543772-1001Core.job
- c:\users\Tobias\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-25 19:27]
.
2013-06-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3788861942-4145589557-749543772-1001UA.job
- c:\users\Tobias\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-25 19:27]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-04-24 7477016]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
ustart page = about:blank
mStart Page = about:blank
IE: An OneNote s&enden - p:\micros~2\Office15\ONBttnIE.dll/105
IE: Hinzufügen zu Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
IE: Nach Microsoft E&xcel exportieren - p:\micros~2\Office15\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - p:\micros~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.178.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\788knjyq.default\
FF - prefs.js: network.proxy.http - www-proxy.t-online.de
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-04-21 00:03; {df4e4df5-5cb7-46b0-9aef-6c784c3249f8}; c:\users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\788knjyq.default\extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi
FF - ExtSQL: 2013-04-28 17:19; info@maltegoetz.de; c:\users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\788knjyq.default\extensions\info@maltegoetz.de.xpi
FF - ExtSQL: 2013-05-19 20:40; youtubeunblocker@unblocker.yt; c:\users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\788knjyq.default\extensions\youtubeunblocker@unblocker.yt.xpi
FF - ExtSQL: 2013-06-16 17:09; {02450914-cdd9-410f-b1da-db004e18c671}; c:\users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\788knjyq.default\extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
   1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}"=hex:51,66,7a,6c,4c,1d,38,12,da,39,34,
   5d,e1,a9,97,05,de,be,2c,e9,c9,ff,c2,38
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E33CF602-D945-461A-83F0-819F76A199F8}"=hex:51,66,7a,6c,4c,1d,38,12,6c,f5,2f,
   e7,77,97,74,03,fc,e6,c2,df,73,ff,dd,ec
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
   fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
   b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:ba,e2,10,bb,ad,6d,cd,01
.
[HKEY_USERS\S-1-5-21-3788861942-4145589557-749543772-1001\Software\SecuROM\License information*]
"datasecu"=hex:86,c6,58,50,60,c3,20,28,35,1d,06,3e,5a,bb,51,28,40,c3,bb,d9,2f,
   38,90,fe,8f,6d,c2,8b,44,54,06,55,8d,05,75,ad,bc,ea,c4,81,31,87,47,5e,5c,7a,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-06-18  21:36:10
ComboFix-quarantined-files.txt  2013-06-18 19:36
.
Vor Suchlauf: 12 Verzeichnis(se), 158.264.414.208 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 160.026.669.056 Bytes frei
.
- - End Of File - - 17D6C09FBB06C84BECB87A688BDDE6AE
A36C5E4F47E84449FF07ED3517B43A31
         

Alt 18.06.2013, 20:54   #9
markusg
/// Malware-holic
 
PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Hi,
malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.
__________________
-Verdächtige mails bitte an uns zur Analyse weiterleiten:
markusg.trojaner-board@web.de
Weiterleiten
Anleitung:
http://markusg.trojaner-board.de
Mails bitte vorerst nach obiger Anleitung an
markusg.trojaner-board@web.de
Weiterleiten
Wenn Ihr uns unterstützen möchtet

Alt 19.06.2013, 21:24   #10
Unbekannter
 
PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Code:
ATTFilter
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.06.19.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Tobias :: GAMING [Administrator]

19.06.2013 21:29:42
mbam-log-2013-06-19 (21-29-42).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|G:\|H:\|M:\|P:\|S:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 494439
Laufzeit: 53 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         

Alt 21.06.2013, 10:50   #11
schrauber
/// the machine
/// TB-Ausbilder
 

PC hängt nach Start immer ein paar Minuten oder länger - Standard

PC hängt nach Start immer ein paar Minuten oder länger



Hi,

Markus ist im Urlaub. Gibt es noch irgendwelche Probleme mit dem System?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu PC hängt nach Start immer ein paar Minuten oder länger
acrobat update, adobe, bho, bonjour, computer, ebanking, explorer, google, hijack, hijackthis, hängt, internet, internet explorer, kaspersky, kaspersky internet security 2013, logfile, lsass.exe, microsoft, mozilla, nvidia, pdf, plug-in, problem, programm, security, software, tastatur, temp, usb, windows




Ähnliche Themen: PC hängt nach Start immer ein paar Minuten oder länger


  1. wenn ich das pc anschalte zeigt es nach paar minuten stand da "anzeigetriber wurde nach dem fehler wieder hergestellt" also so in der richtu
    Alles rund um Windows - 09.08.2015 (3)
  2. Windows 7 hängt sich nach paar Minuten auf.
    Log-Analyse und Auswertung - 28.07.2015 (6)
  3. Virus oder so, Fenster in meinem browser öffnen sich alle paar minuten (adf.ly)
    Plagegeister aller Art und deren Bekämpfung - 22.02.2015 (7)
  4. Windows 7: Schwarzer Bildschirm nach ein paar Minuten im Internet, dann geht nichts mehr
    Log-Analyse und Auswertung - 05.10.2014 (24)
  5. PC LANGSAM und Hängt sich nach paar minuten ins Unendlich auf
    Plagegeister aller Art und deren Bekämpfung - 12.07.2014 (14)
  6. Mein Computer geht immer erst nach länger zeit an, bzw.
    Log-Analyse und Auswertung - 17.03.2014 (16)
  7. Win 7 PC hängt sich nach 5 Minuten immer auf
    Alles rund um Windows - 02.12.2012 (9)
  8. pc hängt sich nach 10-20 minuten auf
    Log-Analyse und Auswertung - 19.06.2012 (1)
  9. Rechner hakt alle paar sekunden, Programme öffnen erst nach mehreren Minuten, JAVA/Stutter.I.1
    Log-Analyse und Auswertung - 01.08.2011 (1)
  10. laptop hängt sich nach paar minuten auf
    Plagegeister aller Art und deren Bekämpfung - 14.11.2009 (1)
  11. Soundkarte (X-Fi Extreme Music) fliegt plötzlich nach paar minuten immer ausm windows
    Netzwerk und Hardware - 01.06.2009 (0)
  12. Soundkarte (X-Fi Extreme Music) fliegt plötzlich nach paar minuten immer ausm windows
    Plagegeister aller Art und deren Bekämpfung - 01.06.2009 (28)
  13. nach ca. 2 Minuten hängt er sich auf
    Log-Analyse und Auswertung - 18.05.2009 (1)
  14. Pc friert ein nach paar Minuten.
    Log-Analyse und Auswertung - 02.03.2009 (0)
  15. Internet geht nach paar Minuten aus
    Netzwerk und Hardware - 27.01.2009 (2)
  16. Hochstarten dauert 10 minuten und länger
    Alles rund um Windows - 19.01.2009 (6)
  17. PC hängt sich nach 5 Minuten auf
    Mülltonne - 10.11.2008 (1)

Zum Thema PC hängt nach Start immer ein paar Minuten oder länger - Hi Leute ich habe seit kurzem das Problem dass mein PC (WIN 7 64 bit) manchmal hängt. Wenn ich auf ein Programm nach PC Start gehe dauert es ewig und - PC hängt nach Start immer ein paar Minuten oder länger...
Archiv
Du betrachtest: PC hängt nach Start immer ein paar Minuten oder länger auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.