Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 23.08.2012, 19:26   #16
t'john
/// Helfer-Team
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Malware-Scan mit Emsisoft Anti-Malware

Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm.
Lade über Jetzt Updaten die aktuellen Signaturen herunter.
Wähle den Freeware-Modus aus.

Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers.
Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten.

Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
__________________
Mfg, t'john
Das TB unterstützen

Alt 23.08.2012, 19:33   #17
magix1
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



für den betrieb mit windows 7 ist service pack 1 erforderlich
__________________


Alt 23.08.2012, 23:38   #18
t'john
/// Helfer-Team
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Alles Windows Updates einspielen, inkl. Service Pack!
__________________
__________________

Alt 24.08.2012, 12:46   #19
magix1
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



so, da habe ich dann nochmal nen brandaktuellen bericht

Code:
ATTFilter
Emsisoft Anti-Malware - Version 6.6
Letztes Update: 23.08.2012 22:26:46

Scan Einstellungen:

Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\
Archiv Scan: An
ADS Scan: An

Scan Beginn:	24.08.2012 11:53:21

c:\program files (x86)\freerip3 	gefunden: Trace.File.freerip v3.0!E1
c:\users\marcel\appdata\roaming\microsoft\internet explorer\quick launch\freerip.lnk 	gefunden: Trace.File.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> allowmultipleinstances 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> autochecknewversion 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> autosearchfreedb 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> beepafterrip 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> cddevice 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> converterusesfilenames 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> defaulttargetformat 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> ejectafterrip 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> encodedbypreset 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> filenameformat 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> flacenc_channels 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> flacenc_level 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> forceaspi 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freedbautochoose1 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freedbemail 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freedbserver 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freedbtimeout 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freeripdbautosearch 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> language 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> lastregreminderdate 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> lyricswindow_dx 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_bitrate 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_channels 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mainwndcy 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> lyricswindow_dy 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mainwndcx 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_mode 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_vbrquality 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> optionswindow_dy 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_writeid3 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> optionswindow_dx 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_writecrcs 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> proxyserver 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> proxyuser 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> proxypwd 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> outputpath 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> regname 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> regreminderdays 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> regcode 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> proxyport 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> runscounter 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> showfullfilename 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> showsplash 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> slowspeedmode 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> uselocaldb 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> runathigherpriority 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> vorbisenc_channels 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> vorbisenc_quality 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wavenc_bitspersample 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wavenc_channels 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wavenc_writeinfotags 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wmaenc_mode 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wndcloseafterrip 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> writecdplayerini 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> useproxy 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> readcdtext 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> ripvolume 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate --> version 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar0 --> barid 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate --> barsize_32772 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> writelrcfile 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> bar#1 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> bar#2 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> bar#0 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> writeplaylist 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> barid 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> docking 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudockbottompos 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudockid 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> barid 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudockrightpos 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudocktoppos 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudockleftpos 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrufloatxpos 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrufloatypos 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> xpos 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> ypos 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-summary --> bars 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-summary --> screencx 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-summary --> screency 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthconv --> n 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 0 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 1 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 2 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 3 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 4 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> n 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrufloatstyle 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> bars 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 2 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 3 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 4 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> n 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\freedbserverlist --> n 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> displayicon 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> displayname 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> displayversion 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> inno setup: app path 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> inno setup: icon group 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> inno setup: setup version 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> inno setup: user 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> installdate 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> installlocation 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 1 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> norepair 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> publisher 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> nomodify 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar1 --> barid 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 0 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> quietuninstallstring 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> uninstallstring 	gefunden: Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> urlinfoabout 	gefunden: Trace.Registry.freerip v3.0!E1
C:\_OTL\MovedFiles\08232012_004956\C_Users\Marcel\AppData\Local\{52bde81c-418a-f651-b260-dca8cdaeb747}\U\00000001.@ 	gefunden: Trojan.Crypt.EFC!E2
C:\Users\Marcel\Videos\Filme\OO Software CleverCache Professional v7 1 2737 Incl Keygen\keygen.exe 	gefunden: Trojan-Proxy.Win32.Agent!E2

Gescannt	638436
Gefunden	116

Scan Ende:	24.08.2012 13:34:08
Scan Zeit:	1:40:47

C:\Users\Marcel\Videos\Filme\OO Software CleverCache Professional v7 1 2737 Incl Keygen\keygen.exe	Quarantäne Trojan-Proxy.Win32.Agent!E2
C:\_OTL\MovedFiles\08232012_004956\C_Users\Marcel\AppData\Local\{52bde81c-418a-f651-b260-dca8cdaeb747}\U\00000001.@	Quarantäne Trojan.Crypt.EFC!E2
Value: hkey_current_user\software\mgshareware\freerip3 --> allowmultipleinstances	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> autochecknewversion	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> autosearchfreedb	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> beepafterrip	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> cddevice	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> converterusesfilenames	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> defaulttargetformat	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> ejectafterrip	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> encodedbypreset	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> filenameformat	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> flacenc_channels	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> flacenc_level	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> forceaspi	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freedbautochoose1	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freedbemail	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freedbserver	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freedbtimeout	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> freeripdbautosearch	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> language	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> lastregreminderdate	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> lyricswindow_dx	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_bitrate	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_channels	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mainwndcy	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> lyricswindow_dy	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mainwndcx	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_mode	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_vbrquality	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> optionswindow_dy	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_writeid3	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> optionswindow_dx	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> mp3enc_writecrcs	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> proxyserver	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> proxyuser	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> proxypwd	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> outputpath	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> regname	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> regreminderdays	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> regcode	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> proxyport	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> runscounter	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> showfullfilename	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> showsplash	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> slowspeedmode	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> uselocaldb	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> runathigherpriority	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> vorbisenc_channels	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> vorbisenc_quality	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wavenc_bitspersample	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wavenc_channels	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wavenc_writeinfotags	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wmaenc_mode	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> wndcloseafterrip	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> writecdplayerini	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> useproxy	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> readcdtext	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> ripvolume	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate --> version	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar0 --> barid	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate --> barsize_32772	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> writelrcfile	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> bar#1	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> bar#2	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> bar#0	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3 --> writeplaylist	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> barid	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> docking	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudockbottompos	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudockid	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> barid	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudockrightpos	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudocktoppos	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrudockleftpos	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrufloatxpos	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrufloatypos	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> xpos	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> ypos	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-summary --> bars	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-summary --> screencx	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-summary --> screency	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthconv --> n	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 0	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 1	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 2	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 3	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> 4	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\cdgridcolumnwidthrip --> n	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar3 --> mrufloatstyle	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar2 --> bars	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 2	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 3	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 4	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> n	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\freedbserverlist --> n	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> displayicon	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> displayname	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> displayversion	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> inno setup: app path	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> inno setup: icon group	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> inno setup: setup version	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> inno setup: user	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> installdate	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> installlocation	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 1	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> norepair	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> publisher	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> nomodify	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\barsstate-bar1 --> barid	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_current_user\software\mgshareware\freerip3\filenamedefs --> 0	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> quietuninstallstring	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> uninstallstring	Quarantäne Trace.Registry.freerip v3.0!E1
Value: hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{501451de-5808-4599-b544-8bd0915b6b24}_is1 --> urlinfoabout	Quarantäne Trace.Registry.freerip v3.0!E1
c:\program files (x86)\freerip3	Quarantäne Trace.File.freerip v3.0!E1
c:\users\marcel\appdata\roaming\microsoft\internet explorer\quick launch\freerip.lnk	Quarantäne Trace.File.freerip v3.0!E1

Quarantäne	116
         

Alt 24.08.2012, 15:07   #20
t'john
/// Helfer-Team
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Sehr gut!



Deinstalliere:
Emsisoft Anti-Malware


ESET Online Scanner

Vorbereitung

  • Schließe evtl. vorhandene externe Festplatten und/oder sonstigen Wechselmedien (z. B. evtl. vorhandene USB-Sticks) an den Rechner an.
  • Bitte während des Online-Scans Anti-Virus-Programm und Firewall deaktivieren.
  • Vista/Win7-User: Bitte den Browser unbedingt als Administrator starten.
Los geht's

  • Lade und starte Eset Smartinstaller
  • Haken setzen bei YES, I accept the Terms of Use.
  • Klick auf Start.
  • Haken setzen bei Remove found threads und Scan archives.
  • Klick auf Start.
  • Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Finish drücken.
  • Browser schließen.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (manchmal auch C:\Programme\Eset\log.txt) suchen und mit Deinem Editor öffnen.
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

__________________
Mfg, t'john
Das TB unterstützen

Alt 25.08.2012, 00:36   #21
magix1
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



einmal ESET


Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6226b4ee95f46146aff5fb161ea326fe
# end=stopped
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-08-24 04:56:18
# local_time=2012-08-24 06:56:18 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1797 16775165 100 94 377196 82361283 172711 0
# compatibility_mode=5121 16776637 100 82 79355431 98186775 0 0
# compatibility_mode=5893 16776573 100 94 10758 97454277 0 0
# compatibility_mode=8192 67108863 100 0 83 83 0 0
# scanned=89025
# found=0
# cleaned=0
# scan_time=2951
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6226b4ee95f46146aff5fb161ea326fe
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-08-24 11:27:25
# local_time=2012-08-25 01:27:25 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=1797 16775165 100 94 380291 82364378 175806 0
# compatibility_mode=5121 16776637 100 82 79358526 98189870 0 0
# compatibility_mode=5893 16776573 100 94 13853 97457372 0 0
# compatibility_mode=8192 67108863 100 0 3178 3178 0 0
# scanned=198314
# found=1
# cleaned=1
# scan_time=23322
C:\Windows\Installer\841ea65.msi	a variant of Win32/Toolbar.Widgi application (deleted - quarantined)	00000000000000000000000000000000	C
         

Alt 25.08.2012, 15:36   #22
t'john
/// Helfer-Team
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Konrolle:

1. Schritt

Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Malwarebytes Anti-Malware
- Anwendbar auf Windows 2000, XP, Vista und 7.
- Installiere das Programm in den vorgegebenen Pfad.
- Aktualisiere die Datenbank!
- Aktiviere "Komplett Scan durchführen" => Scan.
- Wähle alle verfügbaren Laufwerke (ausser CD/DVD) aus und starte den Scan.
- Funde bitte löschen lassen oder in Quarantäne.
- Wenn der Scan beendet ist, klicke auf "Zeige Resultate".


dann:


TDSSKiller von Kaspersky
- Lade den TDSSKiller und entpacke das Archiv auf Deinen Desktop.
- Vergewissere Dich, dass die TDSSKiller.exe direkt auf dem Desktop liegt (nicht in einem Ordner auf dem Desktop).
- deaktiviere vorübergehend dein AntiVirus-Programm
- Starte die TDSSKiller.exe durch Doppelklick.
- Nach Beendigung der Arbeit schlägt das Tool vor, das System neu zu starten.
- Bestätige das ggfs. mit Y(es).
- Beim Hochfahren des Systems führt der Treiber alle geplanten Operationen aus löscht sich danach.
- Poste den Inhalt von C:\TDSSKiller.txt hier in den Thread.
Hier findest Du eine ausführlichere TDSSKiller Anleitung.
__________________
Mfg, t'john
Das TB unterstützen

Alt 25.08.2012, 18:50   #23
magix1
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



du wirst es nicht glauben, aber während Malwarebytes gerade durchläuft meldet sich avira mit TR/Sirefef.P.35 gefunden :-(

aktueller malwarebytes

Code:
ATTFilter
 Malwarebytes Anti-Malware  (Test) 1.62.0.1300
www.malwarebytes.org

Datenbank Version: v2012.08.25.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Marcel :: MARCEL-PC [Administrator]

Schutz: Aktiviert

25.08.2012 19:08:32
mbam-log-2012-08-25 (19-08-32).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 388340
Laufzeit: 1 Stunde(n), 45 Minute(n), 44 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
und tdss

Code:
ATTFilter
21:06:27.0963 4752  TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
21:06:27.0995 4752  ============================================================
21:06:27.0995 4752  Current date / time: 2012/08/25 21:06:27.0995
21:06:27.0995 4752  SystemInfo:
21:06:27.0995 4752  
21:06:27.0995 4752  OS Version: 6.1.7601 ServicePack: 1.0
21:06:27.0995 4752  Product type: Workstation
21:06:27.0995 4752  ComputerName: MARCEL-PC
21:06:27.0995 4752  UserName: Marcel
21:06:27.0995 4752  Windows directory: C:\Windows
21:06:27.0995 4752  System windows directory: C:\Windows
21:06:27.0995 4752  Running under WOW64
21:06:27.0995 4752  Processor architecture: Intel x64
21:06:27.0995 4752  Number of processors: 4
21:06:27.0995 4752  Page size: 0x1000
21:06:27.0995 4752  Boot type: Normal boot
21:06:27.0995 4752  ============================================================
21:06:28.0806 4752  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:06:28.0806 4752  ============================================================
21:06:28.0806 4752  \Device\Harddisk0\DR0:
21:06:28.0806 4752  MBR partitions:
21:06:28.0806 4752  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1964800, BlocksNum 0x32000
21:06:28.0806 4752  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1996800, BlocksNum 0x23A97AB0
21:06:28.0806 4752  ============================================================
21:06:28.0837 4752  C: <-> \Device\Harddisk0\DR0\Partition2
21:06:28.0837 4752  ============================================================
21:06:28.0837 4752  Initialize success
21:06:28.0837 4752  ============================================================
21:06:39.0882 6836  ============================================================
21:06:39.0882 6836  Scan started
21:06:39.0882 6836  Mode: Manual; 
21:06:39.0882 6836  ============================================================
21:06:40.0147 6836  ================ Scan system memory ========================
21:06:40.0147 6836  System memory - ok
21:06:40.0147 6836  ================ Scan services =============================
21:06:40.0365 6836  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
21:06:40.0365 6836  1394ohci - ok
21:06:40.0412 6836  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
21:06:40.0412 6836  ACPI - ok
21:06:40.0459 6836  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
21:06:40.0459 6836  AcpiPmi - ok
21:06:40.0615 6836  [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:06:40.0615 6836  AdobeFlashPlayerUpdateSvc - ok
21:06:40.0693 6836  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
21:06:40.0709 6836  adp94xx - ok
21:06:40.0771 6836  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
21:06:40.0771 6836  adpahci - ok
21:06:40.0802 6836  [ E109549C90F62FB570B9540C4B148E54 ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
21:06:40.0802 6836  adpu320 - ok
21:06:40.0849 6836  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
21:06:40.0865 6836  AeLookupSvc - ok
21:06:40.0896 6836  [ 65F8D71074FCE72B6C491F63535FEDC6 ] AF9035BDA       C:\Windows\system32\DRIVERS\AF15BDA.sys
21:06:40.0911 6836  AF9035BDA - ok
21:06:40.0974 6836  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD             C:\Windows\system32\drivers\afd.sys
21:06:40.0989 6836  AFD - ok
21:06:41.0083 6836  [ B65F8DBA54F251906BBE8611B5A0E7AB ] AgereModemAudio C:\Program Files\LSI SoftModem\agr64svc.exe
21:06:41.0083 6836  AgereModemAudio - ok
21:06:41.0130 6836  [ A6AB6F0ACE87DA76B4C401813D18BE95 ] AgereSoftModem  C:\Windows\system32\DRIVERS\agrsm64.sys
21:06:41.0145 6836  AgereSoftModem - ok
21:06:41.0192 6836  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
21:06:41.0192 6836  agp440 - ok
21:06:41.0208 6836  [ 3290D6946B5E30E70414990574883DDB ] ALG             C:\Windows\System32\alg.exe
21:06:41.0208 6836  ALG - ok
21:06:41.0255 6836  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
21:06:41.0255 6836  aliide - ok
21:06:41.0286 6836  [ 41A0813F22D3330C0CA71CE5BBD42B12 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
21:06:41.0301 6836  AMD External Events Utility - ok
21:06:41.0333 6836  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
21:06:41.0333 6836  amdide - ok
21:06:41.0348 6836  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
21:06:41.0348 6836  AmdK8 - ok
21:06:41.0379 6836  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
21:06:41.0379 6836  AmdPPM - ok
21:06:41.0426 6836  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
21:06:41.0442 6836  amdsata - ok
21:06:41.0489 6836  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
21:06:41.0489 6836  amdsbs - ok
21:06:41.0504 6836  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
21:06:41.0504 6836  amdxata - ok
21:06:41.0551 6836  [ 391887990CDAA83DE5C56C3FDE966DA1 ] AmUStor         C:\Windows\system32\drivers\AmUStor.SYS
21:06:41.0551 6836  AmUStor - ok
21:06:41.0645 6836  [ C27D46B06D340293670450FCE9DFB166 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
21:06:41.0660 6836  AntiVirSchedulerService - ok
21:06:41.0691 6836  [ 72D90E56563165984224493069C69ED4 ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
21:06:41.0691 6836  AntiVirService - ok
21:06:41.0769 6836  [ 89A69C3F2F319B43379399547526D952 ] AppID           C:\Windows\system32\drivers\appid.sys
21:06:41.0769 6836  AppID - ok
21:06:41.0785 6836  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
21:06:41.0785 6836  AppIDSvc - ok
21:06:41.0816 6836  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo         C:\Windows\System32\appinfo.dll
21:06:41.0816 6836  Appinfo - ok
21:06:41.0925 6836  [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
21:06:41.0925 6836  Apple Mobile Device - ok
21:06:41.0957 6836  [ C484F8CEB1717C540242531DB7845C4E ] arc             C:\Windows\system32\DRIVERS\arc.sys
21:06:41.0972 6836  arc - ok
21:06:42.0003 6836  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
21:06:42.0003 6836  arcsas - ok
21:06:42.0035 6836  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
21:06:42.0035 6836  AsyncMac - ok
21:06:42.0081 6836  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi           C:\Windows\system32\drivers\atapi.sys
21:06:42.0081 6836  atapi - ok
21:06:42.0144 6836  [ D6CAD7E5B05055BB8226BDCB1644DA27 ] athr            C:\Windows\system32\DRIVERS\athrx.sys
21:06:42.0175 6836  athr - ok
21:06:42.0378 6836  [ 37456BE85384E4CC38DC899F07F88C45 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
21:06:42.0612 6836  atikmdag - ok
21:06:42.0674 6836  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:06:42.0690 6836  AudioEndpointBuilder - ok
21:06:42.0705 6836  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
21:06:42.0705 6836  AudioSrv - ok
21:06:42.0752 6836  [ B1224E6B086CD6548315B04AB575A23E ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
21:06:42.0752 6836  avgntflt - ok
21:06:42.0768 6836  [ ED45F12CFA62B83765C9C1496758CC87 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
21:06:42.0768 6836  avipbb - ok
21:06:42.0830 6836  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
21:06:42.0846 6836  AxInstSV - ok
21:06:42.0877 6836  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbda.sys
21:06:42.0893 6836  b06bdrv - ok
21:06:42.0924 6836  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
21:06:42.0924 6836  b57nd60a - ok
21:06:43.0033 6836  [ 825F81A6F7DD073509DB101F0BA6DC59 ] BBSvc           C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
21:06:43.0033 6836  BBSvc - ok
21:06:43.0095 6836  [ 9E84A931DBEE0292E38ED672F6293A99 ] BCM43XX         C:\Windows\system32\DRIVERS\bcmwl664.sys
21:06:43.0111 6836  BCM43XX - ok
21:06:43.0142 6836  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
21:06:43.0142 6836  BDESVC - ok
21:06:43.0173 6836  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
21:06:43.0173 6836  Beep - ok
21:06:43.0236 6836  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE             C:\Windows\System32\bfe.dll
21:06:43.0251 6836  BFE - ok
21:06:43.0314 6836  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\system32\qmgr.dll
21:06:43.0345 6836  BITS - ok
21:06:43.0376 6836  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
21:06:43.0376 6836  blbdrive - ok
21:06:43.0454 6836  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
21:06:43.0454 6836  Bonjour Service - ok
21:06:43.0517 6836  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
21:06:43.0517 6836  bowser - ok
21:06:43.0548 6836  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
21:06:43.0548 6836  BrFiltLo - ok
21:06:43.0563 6836  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
21:06:43.0563 6836  BrFiltUp - ok
21:06:43.0579 6836  [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
21:06:43.0579 6836  BridgeMP - ok
21:06:43.0626 6836  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser         C:\Windows\System32\browser.dll
21:06:43.0626 6836  Browser - ok
21:06:43.0657 6836  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
21:06:43.0657 6836  Brserid - ok
21:06:43.0673 6836  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
21:06:43.0673 6836  BrSerWdm - ok
21:06:43.0704 6836  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
21:06:43.0704 6836  BrUsbMdm - ok
21:06:43.0719 6836  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
21:06:43.0719 6836  BrUsbSer - ok
21:06:43.0735 6836  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
21:06:43.0735 6836  BTHMODEM - ok
21:06:43.0782 6836  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv         C:\Windows\system32\bthserv.dll
21:06:43.0782 6836  bthserv - ok
21:06:43.0782 6836  catchme - ok
21:06:43.0813 6836  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
21:06:43.0829 6836  cdfs - ok
21:06:43.0860 6836  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom           C:\Windows\system32\drivers\cdrom.sys
21:06:43.0875 6836  cdrom - ok
21:06:43.0922 6836  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc     C:\Windows\System32\certprop.dll
21:06:43.0922 6836  CertPropSvc - ok
21:06:43.0938 6836  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
21:06:43.0938 6836  circlass - ok
21:06:43.0969 6836  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
21:06:43.0969 6836  CLFS - ok
21:06:44.0047 6836  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:06:44.0047 6836  clr_optimization_v2.0.50727_32 - ok
21:06:44.0094 6836  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:06:44.0094 6836  clr_optimization_v2.0.50727_64 - ok
21:06:44.0187 6836  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:06:44.0203 6836  clr_optimization_v4.0.30319_32 - ok
21:06:44.0250 6836  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:06:44.0250 6836  clr_optimization_v4.0.30319_64 - ok
21:06:44.0265 6836  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
21:06:44.0281 6836  CmBatt - ok
21:06:44.0297 6836  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
21:06:44.0297 6836  cmdide - ok
21:06:44.0343 6836  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG             C:\Windows\system32\Drivers\cng.sys
21:06:44.0343 6836  CNG - ok
21:06:44.0390 6836  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
21:06:44.0390 6836  Compbatt - ok
21:06:44.0421 6836  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
21:06:44.0421 6836  CompositeBus - ok
21:06:44.0437 6836  COMSysApp - ok
21:06:44.0453 6836  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
21:06:44.0453 6836  crcdisk - ok
21:06:44.0515 6836  [ 4F5414602E2544A4554D95517948B705 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
21:06:44.0515 6836  CryptSvc - ok
21:06:44.0562 6836  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
21:06:44.0562 6836  DcomLaunch - ok
21:06:44.0609 6836  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc       C:\Windows\System32\defragsvc.dll
21:06:44.0609 6836  defragsvc - ok
21:06:44.0671 6836  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
21:06:44.0671 6836  DfsC - ok
21:06:44.0702 6836  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
21:06:44.0702 6836  Dhcp - ok
21:06:44.0733 6836  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
21:06:44.0733 6836  discache - ok
21:06:44.0796 6836  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\DRIVERS\disk.sys
21:06:44.0796 6836  Disk - ok
21:06:44.0889 6836  [ D5BCB77BE83CF99F508943945D46343D ] DKbFltr         C:\Windows\syswow64\Drivers\DKbFltr.sys
21:06:44.0889 6836  DKbFltr - ok
21:06:44.0936 6836  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
21:06:44.0936 6836  Dnscache - ok
21:06:44.0983 6836  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc         C:\Windows\System32\dot3svc.dll
21:06:44.0983 6836  dot3svc - ok
21:06:45.0014 6836  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS             C:\Windows\system32\dps.dll
21:06:45.0030 6836  DPS - ok
21:06:45.0061 6836  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
21:06:45.0061 6836  drmkaud - ok
21:06:45.0123 6836  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
21:06:45.0139 6836  DXGKrnl - ok
21:06:45.0170 6836  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost         C:\Windows\System32\eapsvc.dll
21:06:45.0170 6836  EapHost - ok
21:06:45.0264 6836  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv           C:\Windows\system32\DRIVERS\evbda.sys
21:06:45.0357 6836  ebdrv - ok
21:06:45.0404 6836  [ C118A82CD78818C29AB228366EBF81C3 ] EFS             C:\Windows\System32\lsass.exe
21:06:45.0404 6836  EFS - ok
21:06:45.0498 6836  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
21:06:45.0513 6836  ehRecvr - ok
21:06:45.0529 6836  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched         C:\Windows\ehome\ehsched.exe
21:06:45.0529 6836  ehSched - ok
21:06:45.0576 6836  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
21:06:45.0576 6836  elxstor - ok
21:06:45.0685 6836  [ FB67AA8AC61B9365ADD546139A21BED6 ] ePowerSvc       C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
21:06:45.0701 6836  ePowerSvc - ok
21:06:45.0716 6836  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
21:06:45.0716 6836  ErrDev - ok
21:06:45.0779 6836  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem     C:\Windows\system32\es.dll
21:06:45.0779 6836  EventSystem - ok
21:06:45.0810 6836  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat           C:\Windows\system32\drivers\exfat.sys
21:06:45.0810 6836  exfat - ok
21:06:45.0841 6836  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat         C:\Windows\system32\drivers\fastfat.sys
21:06:45.0841 6836  fastfat - ok
21:06:45.0903 6836  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax             C:\Windows\system32\fxssvc.exe
21:06:45.0903 6836  Fax - ok
21:06:45.0919 6836  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
21:06:45.0919 6836  fdc - ok
21:06:45.0950 6836  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost         C:\Windows\system32\fdPHost.dll
21:06:45.0950 6836  fdPHost - ok
21:06:45.0966 6836  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
21:06:45.0966 6836  FDResPub - ok
21:06:45.0997 6836  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
21:06:45.0997 6836  FileInfo - ok
21:06:45.0997 6836  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
21:06:46.0013 6836  Filetrace - ok
21:06:46.0028 6836  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
21:06:46.0028 6836  flpydisk - ok
21:06:46.0059 6836  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
21:06:46.0059 6836  FltMgr - ok
21:06:46.0122 6836  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache       C:\Windows\system32\FntCache.dll
21:06:46.0137 6836  FontCache - ok
21:06:46.0200 6836  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:06:46.0200 6836  FontCache3.0.0.0 - ok
21:06:46.0231 6836  [ D43703496149971890703B4B1B723EAC ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
21:06:46.0231 6836  FsDepends - ok
21:06:46.0293 6836  [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr         C:\Windows\system32\DRIVERS\fssfltr.sys
21:06:46.0293 6836  fssfltr - ok
21:06:46.0403 6836  [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc          C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
21:06:46.0418 6836  fsssvc - ok
21:06:46.0465 6836  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
21:06:46.0465 6836  Fs_Rec - ok
21:06:46.0512 6836  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
21:06:46.0512 6836  fvevol - ok
21:06:46.0559 6836  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
21:06:46.0559 6836  gagp30kx - ok
21:06:46.0605 6836  [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:06:46.0605 6836  GEARAspiWDM - ok
21:06:46.0668 6836  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc           C:\Windows\System32\gpsvc.dll
21:06:46.0683 6836  gpsvc - ok
21:06:46.0761 6836  [ 816FD5A6F3C2F3D600900096632FC60E ] Greg_Service    C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
21:06:46.0777 6836  Greg_Service - ok
21:06:46.0824 6836  [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:06:46.0824 6836  gupdate - ok
21:06:46.0855 6836  [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:06:46.0871 6836  gupdatem - ok
21:06:46.0886 6836  [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc           C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
21:06:46.0902 6836  gusvc - ok
21:06:46.0917 6836  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
21:06:46.0917 6836  hcw85cir - ok
21:06:46.0980 6836  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:06:46.0980 6836  HdAudAddService - ok
21:06:47.0011 6836  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
21:06:47.0027 6836  HDAudBus - ok
21:06:47.0042 6836  [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64         C:\Windows\system32\DRIVERS\HECIx64.sys
21:06:47.0058 6836  HECIx64 - ok
21:06:47.0089 6836  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
21:06:47.0105 6836  HidBatt - ok
21:06:47.0136 6836  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
21:06:47.0136 6836  HidBth - ok
21:06:47.0167 6836  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
21:06:47.0167 6836  HidIr - ok
21:06:47.0183 6836  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv         C:\Windows\System32\hidserv.dll
21:06:47.0183 6836  hidserv - ok
21:06:47.0229 6836  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\drivers\hidusb.sys
21:06:47.0229 6836  HidUsb - ok
21:06:47.0276 6836  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
21:06:47.0276 6836  hkmsvc - ok
21:06:47.0339 6836  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:06:47.0339 6836  HomeGroupListener - ok
21:06:47.0385 6836  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:06:47.0385 6836  HomeGroupProvider - ok
21:06:47.0417 6836  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
21:06:47.0417 6836  HpSAMD - ok
21:06:47.0463 6836  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
21:06:47.0479 6836  HTTP - ok
21:06:47.0510 6836  hwdatacard - ok
21:06:47.0557 6836  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
21:06:47.0557 6836  hwpolicy - ok
21:06:47.0619 6836  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
21:06:47.0619 6836  i8042prt - ok
21:06:47.0697 6836  [ 7548066DF68A8A1A56B043359F915F37 ] IAANTMON        C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
21:06:47.0697 6836  IAANTMON - ok
21:06:47.0760 6836  [ 1D004CB1DA6323B1F55CAEF7F94B61D9 ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
21:06:47.0760 6836  iaStor - ok
21:06:47.0838 6836  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
21:06:47.0838 6836  iaStorV - ok
21:06:47.0931 6836  [ 848EDEBB3C1D6FEC50E09EDA95C21E84 ] ICQ Service     C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
21:06:47.0931 6836  ICQ Service - ok
21:06:48.0025 6836  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:06:48.0041 6836  idsvc - ok
21:06:48.0212 6836  [ A87261EF1546325B559374F5689CF5BC ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
21:06:48.0384 6836  igfx - ok
21:06:48.0431 6836  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
21:06:48.0431 6836  iirsp - ok
21:06:48.0477 6836  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
21:06:48.0493 6836  IKEEXT - ok
21:06:48.0524 6836  [ 36FDF367A1DABFF903E2214023D71368 ] Impcd           C:\Windows\system32\DRIVERS\Impcd.sys
21:06:48.0524 6836  Impcd - ok
21:06:48.0618 6836  [ 42943BB3AB7A405B30EFF7C8283CC129 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
21:06:48.0649 6836  IntcAzAudAddService - ok
21:06:48.0665 6836  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
21:06:48.0680 6836  intelide - ok
21:06:48.0711 6836  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
21:06:48.0711 6836  intelppm - ok
21:06:48.0711 6836  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
21:06:48.0727 6836  IPBusEnum - ok
21:06:48.0774 6836  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:06:48.0774 6836  IpFilterDriver - ok
21:06:48.0836 6836  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
21:06:48.0836 6836  iphlpsvc - ok
21:06:48.0867 6836  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
21:06:48.0867 6836  IPMIDRV - ok
21:06:48.0899 6836  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
21:06:48.0899 6836  IPNAT - ok
21:06:49.0070 6836  [ 4472C8825B5E41D8697D5962F47AB1C9 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
21:06:49.0070 6836  iPod Service - ok
21:06:49.0133 6836  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
21:06:49.0133 6836  IRENUM - ok
21:06:49.0164 6836  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
21:06:49.0164 6836  isapnp - ok
21:06:49.0195 6836  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
21:06:49.0211 6836  iScsiPrt - ok
21:06:49.0257 6836  [ D85F3F18E44F7447B5F1BA5C85BAEB7C ] k57nd60a        C:\Windows\system32\DRIVERS\k57nd60a.sys
21:06:49.0273 6836  k57nd60a - ok
21:06:49.0289 6836  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\drivers\kbdclass.sys
21:06:49.0289 6836  kbdclass - ok
21:06:49.0320 6836  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
21:06:49.0320 6836  kbdhid - ok
21:06:49.0351 6836  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
21:06:49.0351 6836  KeyIso - ok
21:06:49.0382 6836  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
21:06:49.0382 6836  KSecDD - ok
21:06:49.0413 6836  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
21:06:49.0413 6836  KSecPkg - ok
21:06:49.0429 6836  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
21:06:49.0429 6836  ksthunk - ok
21:06:49.0460 6836  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm           C:\Windows\system32\msdtckrm.dll
21:06:49.0476 6836  KtmRm - ok
21:06:49.0491 6836  [ 2AC603C3188C704CFCE353659AA7AD71 ] L1E             C:\Windows\system32\DRIVERS\L1E62x64.sys
21:06:49.0507 6836  L1E - ok
21:06:49.0523 6836  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\System32\srvsvc.dll
21:06:49.0523 6836  LanmanServer - ok
21:06:49.0569 6836  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:06:49.0569 6836  LanmanWorkstation - ok
21:06:49.0616 6836  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
21:06:49.0616 6836  lltdio - ok
21:06:49.0632 6836  [ C1185803384AB3FEED115F79F109427F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
21:06:49.0647 6836  lltdsvc - ok
21:06:49.0663 6836  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts         C:\Windows\System32\lmhsvc.dll
21:06:49.0663 6836  lmhosts - ok
21:06:49.0710 6836  [ 7485FBCEF9136F530953575E2977859D ] LMS             C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
21:06:49.0725 6836  LMS - ok
21:06:49.0757 6836  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
21:06:49.0757 6836  LSI_FC - ok
21:06:49.0772 6836  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
21:06:49.0772 6836  LSI_SAS - ok
21:06:49.0772 6836  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
21:06:49.0772 6836  LSI_SAS2 - ok
21:06:49.0803 6836  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
21:06:49.0803 6836  LSI_SCSI - ok
21:06:49.0819 6836  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv           C:\Windows\system32\drivers\luafv.sys
21:06:49.0819 6836  luafv - ok
21:06:49.0850 6836  lxcz_device - ok
21:06:49.0881 6836  [ DC8490812A3B72811AE534F423B4C206 ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
21:06:49.0881 6836  MBAMProtector - ok
21:06:49.0928 6836  [ 43683E970F008C93C9429EF428147A54 ] MBAMService     C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
21:06:49.0928 6836  MBAMService - ok
21:06:50.0006 6836  [ B891E3920F24FF1A3BEAD6CD2B42ED99 ] McAfee SiteAdvisor Service C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
21:06:50.0006 6836  McAfee SiteAdvisor Service - ok
21:06:50.0115 6836  [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
21:06:50.0115 6836  McComponentHostService - ok
21:06:50.0178 6836  [ 0FC36E77D779F8D021D338BDC7368181 ] mcmscsvc        C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe
21:06:50.0178 6836  mcmscsvc - ok
21:06:50.0303 6836  [ 2988E515570E4F8B9D9B256137F8E8F4 ] McNASvc         c:\PROGRA~2\COMMON~1\mcafee\mna\mcnasvc.exe
21:06:50.0334 6836  McNASvc - ok
21:06:50.0396 6836  [ 504C0AF387549FAB2F3E867E5043851D ] McODS           C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
21:06:50.0412 6836  McODS - ok
21:06:50.0459 6836  [ C85968D24449E37653B891B03188140C ] McProxy         c:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe
21:06:50.0459 6836  McProxy - ok
21:06:50.0490 6836  [ C833BCEE15F6F489D57748514C4DE8B8 ] McShield        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
21:06:50.0490 6836  McShield - ok
21:06:50.0552 6836  [ F2A433E0EA959028E349FB1D5BAE01E7 ] McSysmon        C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe
21:06:50.0552 6836  McSysmon - ok
21:06:50.0599 6836  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
21:06:50.0599 6836  Mcx2Svc - ok
21:06:50.0630 6836  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
21:06:50.0630 6836  megasas - ok
21:06:50.0661 6836  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
21:06:50.0661 6836  MegaSR - ok
21:06:50.0693 6836  [ 4A1C21576FB7F96F4DBDEA627FFDA775 ] mfeavfk         C:\Windows\system32\drivers\mfeavfk.sys
21:06:50.0693 6836  mfeavfk - ok
21:06:50.0724 6836  [ 9E0AC52B3232FF8DC65FEE1A9C2FE8D1 ] mfehidk         C:\Windows\system32\drivers\mfehidk.sys
21:06:50.0724 6836  mfehidk - ok
21:06:50.0755 6836  [ 624D717B11E5004F68442B5740F17F21 ] mferkdk         C:\Windows\system32\drivers\mferkdk.sys
21:06:50.0755 6836  mferkdk - ok
21:06:50.0771 6836  [ 0CD9DE7B96735F33F078C4EA044E8B34 ] mfesmfk         C:\Windows\system32\drivers\mfesmfk.sys
21:06:50.0771 6836  mfesmfk - ok
21:06:50.0802 6836  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS           C:\Windows\system32\mmcss.dll
21:06:50.0802 6836  MMCSS - ok
21:06:50.0833 6836  [ 800BA92F7010378B09F9ED9270F07137 ] Modem           C:\Windows\system32\drivers\modem.sys
21:06:50.0833 6836  Modem - ok
21:06:50.0864 6836  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
21:06:50.0864 6836  monitor - ok
21:06:50.0895 6836  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\drivers\mouclass.sys
21:06:50.0895 6836  mouclass - ok
21:06:50.0927 6836  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
21:06:50.0927 6836  mouhid - ok
21:06:50.0973 6836  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
21:06:50.0973 6836  mountmgr - ok
21:06:51.0036 6836  [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:06:51.0036 6836  MozillaMaintenance - ok
21:06:51.0067 6836  [ AE2E68527013EB4F761ECCC630F7F1A3 ] MPFP            C:\Windows\system32\Drivers\Mpfp.sys
21:06:51.0067 6836  MPFP - ok
21:06:51.0129 6836  [ DB4D0DFE069E995B3F45CE4623ABFDD9 ] MpfService      C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe
21:06:51.0129 6836  MpfService - ok
21:06:51.0176 6836  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
21:06:51.0176 6836  mpio - ok
21:06:51.0207 6836  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
21:06:51.0207 6836  mpsdrv - ok
21:06:51.0270 6836  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
21:06:51.0270 6836  MpsSvc - ok
21:06:51.0301 6836  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
21:06:51.0301 6836  MRxDAV - ok
21:06:51.0332 6836  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
21:06:51.0332 6836  mrxsmb - ok
21:06:51.0348 6836  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:06:51.0363 6836  mrxsmb10 - ok
21:06:51.0379 6836  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:06:51.0379 6836  mrxsmb20 - ok
21:06:51.0410 6836  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
21:06:51.0410 6836  msahci - ok
21:06:51.0426 6836  [ DB801A638D011B9633829EB6F663C900 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
21:06:51.0426 6836  msdsm - ok
21:06:51.0441 6836  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC           C:\Windows\System32\msdtc.exe
21:06:51.0441 6836  MSDTC - ok
21:06:51.0488 6836  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
21:06:51.0488 6836  Msfs - ok
21:06:51.0504 6836  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
21:06:51.0504 6836  mshidkmdf - ok
21:06:51.0535 6836  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
21:06:51.0535 6836  msisadrv - ok
21:06:51.0551 6836  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
21:06:51.0566 6836  MSiSCSI - ok
21:06:51.0566 6836  msiserver - ok
21:06:51.0644 6836  [ CF3C267356F458BE85C5034BFC382022 ] MSK80Service    C:\Program Files (x86)\McAfee\MSK\MskSrver.exe
21:06:51.0644 6836  MSK80Service - ok
21:06:51.0675 6836  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
21:06:51.0675 6836  MSKSSRV - ok
21:06:51.0691 6836  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
21:06:51.0707 6836  MSPCLOCK - ok
21:06:51.0707 6836  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
21:06:51.0707 6836  MSPQM - ok
21:06:51.0738 6836  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
21:06:51.0753 6836  MsRPC - ok
21:06:51.0769 6836  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
21:06:51.0785 6836  mssmbios - ok
21:06:51.0785 6836  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
21:06:51.0785 6836  MSTEE - ok
21:06:51.0800 6836  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
21:06:51.0800 6836  MTConfig - ok
21:06:51.0816 6836  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup             C:\Windows\system32\Drivers\mup.sys
21:06:51.0816 6836  Mup - ok
21:06:51.0847 6836  [ 6FFECC25B39DC7652A0CEC0ADA9DB589 ] mwlPSDFilter    C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
21:06:51.0847 6836  mwlPSDFilter - ok
21:06:51.0878 6836  [ 0BEFE32CA56D6EE89D58175725596A85 ] mwlPSDNServ     C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
21:06:51.0878 6836  mwlPSDNServ - ok
21:06:51.0909 6836  [ D43BC633B8660463E446E28E14A51262 ] mwlPSDVDisk     C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
21:06:51.0909 6836  mwlPSDVDisk - ok
21:06:52.0003 6836  [ 2F139207F618EC2933830227EEFFDDB4 ] MWLService      C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
21:06:52.0003 6836  MWLService - ok
21:06:52.0065 6836  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
21:06:52.0065 6836  napagent - ok
21:06:52.0128 6836  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
21:06:52.0128 6836  NativeWifiP - ok
21:06:52.0175 6836  [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS            C:\Windows\system32\drivers\ndis.sys
21:06:52.0190 6836  NDIS - ok
21:06:52.0221 6836  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
21:06:52.0237 6836  NdisCap - ok
21:06:52.0253 6836  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
21:06:52.0268 6836  NdisTapi - ok
21:06:52.0284 6836  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
21:06:52.0299 6836  Ndisuio - ok
21:06:52.0315 6836  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
21:06:52.0315 6836  NdisWan - ok
21:06:52.0362 6836  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
21:06:52.0362 6836  NDProxy - ok
21:06:52.0409 6836  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
21:06:52.0409 6836  NetBIOS - ok
21:06:52.0455 6836  [ 09594D1089C523423B32A4229263F068 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
21:06:52.0455 6836  NetBT - ok
21:06:52.0487 6836  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
21:06:52.0487 6836  Netlogon - ok
21:06:52.0518 6836  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
21:06:52.0533 6836  Netman - ok
21:06:52.0565 6836  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
21:06:52.0565 6836  netprofm - ok
21:06:52.0596 6836  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:06:52.0596 6836  NetTcpPortSharing - ok
21:06:52.0658 6836  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
21:06:52.0658 6836  nfrd960 - ok
21:06:52.0721 6836  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
21:06:52.0721 6836  NlaSvc - ok
21:06:52.0799 6836  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
21:06:52.0799 6836  Npfs - ok
21:06:52.0830 6836  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi             C:\Windows\system32\nsisvc.dll
21:06:52.0830 6836  nsi - ok
21:06:52.0845 6836  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
21:06:52.0845 6836  nsiproxy - ok
21:06:52.0923 6836  [ A2F74975097F52A00745F9637451FDD8 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
21:06:52.0939 6836  Ntfs - ok
21:06:53.0017 6836  [ 14E66F603FB187713AEB02AD3B0390CF ] NTI IScheduleSvc C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
21:06:53.0017 6836  NTI IScheduleSvc - ok
21:06:53.0064 6836  [ FD324CCE1D4D5BB5AF65F8E55B462C7E ] NTIBackupSvc    C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
21:06:53.0064 6836  NTIBackupSvc - ok
21:06:53.0095 6836  [ 64DDD0DEE976302F4BD93E5EFCC2F013 ] NTIDrvr         C:\Windows\system32\drivers\NTIDrvr.sys
21:06:53.0095 6836  NTIDrvr - ok
21:06:53.0126 6836  [ 3F6268A2EC33CD38CF75C880AF8DED42 ] NTISchedulerSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
21:06:53.0126 6836  NTISchedulerSvc - ok
21:06:53.0157 6836  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
21:06:53.0157 6836  Null - ok
21:06:53.0204 6836  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
21:06:53.0204 6836  nvraid - ok
21:06:53.0220 6836  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
21:06:53.0235 6836  nvstor - ok
21:06:53.0267 6836  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
21:06:53.0267 6836  nv_agp - ok
21:06:53.0360 6836  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
21:06:53.0360 6836  odserv - ok
21:06:53.0391 6836  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
21:06:53.0391 6836  ohci1394 - ok
21:06:53.0454 6836  [ 5A432A042DAE460ABE7199B758E8606C ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:06:53.0454 6836  ose - ok
21:06:53.0485 6836  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
21:06:53.0485 6836  p2pimsvc - ok
21:06:53.0516 6836  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
21:06:53.0532 6836  p2psvc - ok
21:06:53.0547 6836  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
21:06:53.0547 6836  Parport - ok
21:06:53.0594 6836  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr         C:\Windows\system32\drivers\partmgr.sys
21:06:53.0594 6836  partmgr - ok
21:06:53.0625 6836  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
21:06:53.0625 6836  PcaSvc - ok
21:06:53.0657 6836  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci             C:\Windows\system32\drivers\pci.sys
21:06:53.0657 6836  pci - ok
21:06:53.0703 6836  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
21:06:53.0735 6836  pciide - ok
21:06:53.0781 6836  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
21:06:53.0797 6836  pcmcia - ok
21:06:53.0844 6836  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw             C:\Windows\system32\drivers\pcw.sys
21:06:53.0844 6836  pcw - ok
21:06:53.0891 6836  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
21:06:53.0906 6836  PEAUTH - ok
21:06:54.0031 6836  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
21:06:54.0031 6836  PerfHost - ok
21:06:54.0109 6836  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla             C:\Windows\system32\pla.dll
21:06:54.0140 6836  pla - ok
21:06:54.0203 6836  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
21:06:54.0218 6836  PlugPlay - ok
21:06:54.0234 6836  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
21:06:54.0234 6836  PNRPAutoReg - ok
21:06:54.0249 6836  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
21:06:54.0249 6836  PNRPsvc - ok
21:06:54.0296 6836  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
21:06:54.0312 6836  PolicyAgent - ok
21:06:54.0343 6836  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power           C:\Windows\system32\umpo.dll
21:06:54.0343 6836  Power - ok
21:06:54.0405 6836  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
21:06:54.0405 6836  PptpMiniport - ok
21:06:54.0437 6836  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor       C:\Windows\system32\DRIVERS\processr.sys
21:06:54.0437 6836  Processor - ok
21:06:54.0483 6836  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc         C:\Windows\system32\profsvc.dll
21:06:54.0499 6836  ProfSvc - ok
21:06:54.0499 6836  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
21:06:54.0499 6836  ProtectedStorage - ok
21:06:54.0561 6836  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
21:06:54.0561 6836  Psched - ok
21:06:54.0639 6836  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
21:06:54.0655 6836  ql2300 - ok
21:06:54.0702 6836  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
21:06:54.0702 6836  ql40xx - ok
21:06:54.0717 6836  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE           C:\Windows\system32\qwave.dll
21:06:54.0733 6836  QWAVE - ok
21:06:54.0733 6836  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
21:06:54.0733 6836  QWAVEdrv - ok
21:06:54.0764 6836  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
21:06:54.0764 6836  RasAcd - ok
21:06:54.0795 6836  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
21:06:54.0795 6836  RasAgileVpn - ok
21:06:54.0827 6836  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto         C:\Windows\System32\rasauto.dll
21:06:54.0842 6836  RasAuto - ok
21:06:54.0873 6836  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
21:06:54.0889 6836  Rasl2tp - ok
21:06:54.0920 6836  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
21:06:54.0936 6836  RasMan - ok
21:06:54.0967 6836  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
21:06:54.0967 6836  RasPppoe - ok
21:06:54.0983 6836  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
21:06:54.0983 6836  RasSstp - ok
21:06:55.0014 6836  [ 77F665941019A1594D887A74F301FA2F ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
21:06:55.0014 6836  rdbss - ok
21:06:55.0029 6836  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
21:06:55.0029 6836  rdpbus - ok
21:06:55.0076 6836  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
21:06:55.0076 6836  RDPCDD - ok
21:06:55.0092 6836  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
21:06:55.0092 6836  RDPENCDD - ok
21:06:55.0107 6836  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
21:06:55.0107 6836  RDPREFMP - ok
21:06:55.0154 6836  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
21:06:55.0154 6836  RDPWD - ok
21:06:55.0217 6836  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
21:06:55.0217 6836  rdyboost - ok
21:06:55.0248 6836  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
21:06:55.0248 6836  RemoteAccess - ok
21:06:55.0279 6836  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
21:06:55.0279 6836  RemoteRegistry - ok
21:06:55.0295 6836  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
21:06:55.0310 6836  RpcEptMapper - ok
21:06:55.0326 6836  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
21:06:55.0326 6836  RpcLocator - ok
21:06:55.0357 6836  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs           C:\Windows\system32\rpcss.dll
21:06:55.0357 6836  RpcSs - ok
21:06:55.0388 6836  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
21:06:55.0388 6836  rspndr - ok
21:06:55.0435 6836  [ 7421A35C45484B95E83B5E9E107CEFC2 ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys
21:06:55.0435 6836  RTHDMIAzAudService - ok
21:06:55.0451 6836  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs           C:\Windows\system32\lsass.exe
21:06:55.0451 6836  SamSs - ok
21:06:55.0482 6836  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
21:06:55.0482 6836  sbp2port - ok
21:06:55.0513 6836  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
21:06:55.0513 6836  SCardSvr - ok
21:06:55.0560 6836  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
21:06:55.0560 6836  scfilter - ok
21:06:55.0622 6836  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
21:06:55.0638 6836  Schedule - ok
21:06:55.0685 6836  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc     C:\Windows\System32\certprop.dll
21:06:55.0685 6836  SCPolicySvc - ok
21:06:55.0716 6836  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
21:06:55.0716 6836  SDRSVC - ok
21:06:55.0809 6836  [ CC781378E7EDA615D2CDCA3B17829FA4 ] SeaPort         C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
21:06:55.0809 6836  SeaPort - ok
21:06:55.0841 6836  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
21:06:55.0856 6836  secdrv - ok
21:06:55.0872 6836  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
21:06:55.0872 6836  seclogon - ok
21:06:55.0934 6836  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\system32\sens.dll
21:06:55.0934 6836  SENS - ok
21:06:55.0965 6836  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
21:06:55.0965 6836  SensrSvc - ok
21:06:55.0997 6836  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
21:06:55.0997 6836  Serenum - ok
21:06:56.0028 6836  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
21:06:56.0028 6836  Serial - ok
21:06:56.0075 6836  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
21:06:56.0075 6836  sermouse - ok
21:06:56.0121 6836  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
21:06:56.0137 6836  SessionEnv - ok
21:06:56.0153 6836  [ A554811BCD09279536440C964AE35BBF ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
21:06:56.0153 6836  sffdisk - ok
21:06:56.0168 6836  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
21:06:56.0168 6836  sffp_mmc - ok
21:06:56.0184 6836  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
21:06:56.0199 6836  sffp_sd - ok
21:06:56.0215 6836  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
21:06:56.0215 6836  sfloppy - ok
21:06:56.0246 6836  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
21:06:56.0246 6836  SharedAccess - ok
21:06:56.0309 6836  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:06:56.0309 6836  ShellHWDetection - ok
21:06:56.0340 6836  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
21:06:56.0340 6836  SiSRaid2 - ok
21:06:56.0371 6836  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
21:06:56.0371 6836  SiSRaid4 - ok
21:06:56.0402 6836  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
21:06:56.0402 6836  Smb - ok
21:06:56.0449 6836  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
21:06:56.0449 6836  SNMPTRAP - ok
21:06:56.0480 6836  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr           C:\Windows\system32\drivers\spldr.sys
21:06:56.0480 6836  spldr - ok
21:06:56.0527 6836  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler         C:\Windows\System32\spoolsv.exe
21:06:56.0527 6836  Spooler - ok
21:06:56.0667 6836  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
21:06:56.0792 6836  sppsvc - ok
21:06:56.0839 6836  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
21:06:56.0839 6836  sppuinotify - ok
21:06:56.0886 6836  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv             C:\Windows\system32\DRIVERS\srv.sys
21:06:56.0886 6836  srv - ok
21:06:56.0917 6836  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
21:06:56.0917 6836  srv2 - ok
21:06:56.0933 6836  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
21:06:56.0933 6836  srvnet - ok
21:06:56.0979 6836  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
21:06:56.0979 6836  SSDPSRV - ok
21:06:57.0011 6836  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc         C:\Windows\system32\sstpsvc.dll
21:06:57.0011 6836  SstpSvc - ok
21:06:57.0042 6836  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
21:06:57.0042 6836  stexstor - ok
21:06:57.0089 6836  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
21:06:57.0104 6836  stisvc - ok
21:06:57.0120 6836  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\drivers\swenum.sys
21:06:57.0120 6836  swenum - ok
21:06:57.0260 6836  [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard     C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
21:06:57.0276 6836  SwitchBoard - ok
21:06:57.0323 6836  [ E08E46FDD841B7184194011CA1955A0B ] swprv           C:\Windows\System32\swprv.dll
21:06:57.0323 6836  swprv - ok
21:06:57.0385 6836  [ ED6D1424E5B0C21A57B28DD8508D6843 ] SynTP           C:\Windows\system32\DRIVERS\SynTP.sys
21:06:57.0385 6836  SynTP - ok
21:06:57.0463 6836  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain         C:\Windows\system32\sysmain.dll
21:06:57.0479 6836  SysMain - ok
21:06:57.0525 6836  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:06:57.0525 6836  TabletInputService - ok
21:06:57.0557 6836  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv         C:\Windows\System32\tapisrv.dll
21:06:57.0557 6836  TapiSrv - ok
21:06:57.0603 6836  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS             C:\Windows\System32\tbssvc.dll
21:06:57.0603 6836  TBS - ok
21:06:57.0713 6836  [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
21:06:57.0728 6836  Tcpip - ok
21:06:57.0791 6836  [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
21:06:57.0806 6836  TCPIP6 - ok
21:06:57.0853 6836  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
21:06:57.0853 6836  tcpipreg - ok
21:06:57.0869 6836  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
21:06:57.0869 6836  TDPIPE - ok
21:06:57.0915 6836  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
21:06:57.0915 6836  TDTCP - ok
21:06:57.0962 6836  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
21:06:57.0962 6836  tdx - ok
21:06:58.0009 6836  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\drivers\termdd.sys
21:06:58.0009 6836  TermDD - ok
21:06:58.0056 6836  [ 2E648163254233755035B46DD7B89123 ] TermService     C:\Windows\System32\termsrv.dll
21:06:58.0071 6836  TermService - ok
21:06:58.0087 6836  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
21:06:58.0087 6836  Themes - ok
21:06:58.0118 6836  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER     C:\Windows\system32\mmcss.dll
21:06:58.0118 6836  THREADORDER - ok
21:06:58.0134 6836  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
21:06:58.0149 6836  TrkWks - ok
21:06:58.0212 6836  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:06:58.0212 6836  TrustedInstaller - ok
21:06:58.0243 6836  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
21:06:58.0243 6836  tssecsrv - ok
21:06:58.0274 6836  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
21:06:58.0274 6836  TsUsbFlt - ok
21:06:58.0321 6836  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
21:06:58.0321 6836  tunnel - ok
21:06:58.0352 6836  [ 825E7A1F48FB8BCFBA27C178AAB4E275 ] TurboB          C:\Windows\system32\DRIVERS\TurboB.sys
21:06:58.0352 6836  TurboB - ok
21:06:58.0399 6836  [ B206BE1174D5964D49A56BB6C4E0524A ] TurboBoost      C:\Program Files\Intel\TurboBoost\TurboBoost.exe
21:06:58.0399 6836  TurboBoost - ok
21:06:58.0446 6836  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
21:06:58.0446 6836  uagp35 - ok
21:06:58.0477 6836  [ 2E22C1FD397A5A9FFEF55E9D1FC96C00 ] UBHelper        C:\Windows\system32\drivers\UBHelper.sys
21:06:58.0477 6836  UBHelper - ok
21:06:58.0524 6836  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
21:06:58.0539 6836  udfs - ok
21:06:58.0571 6836  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
21:06:58.0571 6836  UI0Detect - ok
21:06:58.0617 6836  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
21:06:58.0617 6836  uliagpkx - ok
21:06:58.0649 6836  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus           C:\Windows\system32\drivers\umbus.sys
21:06:58.0649 6836  umbus - ok
21:06:58.0664 6836  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
21:06:58.0680 6836  UmPass - ok
21:06:58.0805 6836  [ 765F2DD351BA064F657751D8D75E58C0 ] UNS             C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
21:06:58.0836 6836  UNS - ok
21:06:58.0914 6836  [ 70DDE3A86DBEB1D6C3C30AD687B1877A ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
21:06:58.0914 6836  Updater Service - ok
21:06:58.0945 6836  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
21:06:58.0961 6836  upnphost - ok
21:06:58.0992 6836  [ AA33FC47ED58C34E6E9261E4F850B7EB ] USBAAPL64       C:\Windows\system32\Drivers\usbaapl64.sys
21:06:58.0992 6836  USBAAPL64 - ok
21:06:59.0023 6836  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
21:06:59.0023 6836  usbccgp - ok
21:06:59.0070 6836  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
21:06:59.0070 6836  usbcir - ok
21:06:59.0101 6836  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci         C:\Windows\system32\drivers\usbehci.sys
21:06:59.0101 6836  usbehci - ok
21:06:59.0148 6836  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
21:06:59.0148 6836  usbhub - ok
21:06:59.0179 6836  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
21:06:59.0179 6836  usbohci - ok
21:06:59.0210 6836  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
21:06:59.0210 6836  usbprint - ok
21:06:59.0273 6836  [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
21:06:59.0273 6836  usbscan - ok
21:06:59.0304 6836  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR         C:\Windows\system32\drivers\USBSTOR.SYS
21:06:59.0304 6836  USBSTOR - ok
21:06:59.0319 6836  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
21:06:59.0319 6836  usbuhci - ok
21:06:59.0382 6836  [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo        C:\Windows\System32\Drivers\usbvideo.sys
21:06:59.0382 6836  usbvideo - ok
21:06:59.0444 6836  [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx      C:\Windows\system32\DRIVERS\usb8023x.sys
21:06:59.0444 6836  usb_rndisx - ok
21:06:59.0491 6836  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms           C:\Windows\System32\uxsms.dll
21:06:59.0491 6836  UxSms - ok
21:06:59.0522 6836  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
21:06:59.0522 6836  VaultSvc - ok
21:06:59.0538 6836  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
21:06:59.0553 6836  vdrvroot - ok
21:06:59.0585 6836  [ 8D6B481601D01A456E75C3210F1830BE ] vds             C:\Windows\System32\vds.exe
21:06:59.0600 6836  vds - ok
21:06:59.0631 6836  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
21:06:59.0631 6836  vga - ok
21:06:59.0663 6836  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave         C:\Windows\System32\drivers\vga.sys
21:06:59.0663 6836  VgaSave - ok
21:06:59.0678 6836  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
21:06:59.0694 6836  vhdmp - ok
21:06:59.0709 6836  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
21:06:59.0709 6836  viaide - ok
21:06:59.0741 6836  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
21:06:59.0741 6836  volmgr - ok
21:06:59.0803 6836  [ A255814907C89BE58B79EF2F189B843B ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
21:06:59.0803 6836  volmgrx - ok
21:06:59.0834 6836  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
21:06:59.0834 6836  volsnap - ok
21:06:59.0881 6836  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
21:06:59.0881 6836  vsmraid - ok
21:06:59.0959 6836  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS             C:\Windows\system32\vssvc.exe
21:06:59.0975 6836  VSS - ok
21:07:00.0021 6836  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
21:07:00.0021 6836  vwifibus - ok
21:07:00.0037 6836  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
21:07:00.0037 6836  vwififlt - ok
21:07:00.0068 6836  [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp         C:\Windows\system32\DRIVERS\vwifimp.sys
21:07:00.0068 6836  vwifimp - ok
21:07:00.0115 6836  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time         C:\Windows\system32\w32time.dll
21:07:00.0131 6836  W32Time - ok
21:07:00.0146 6836  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
21:07:00.0146 6836  WacomPen - ok
21:07:00.0193 6836  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
21:07:00.0209 6836  WANARP - ok
21:07:00.0209 6836  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
21:07:00.0209 6836  Wanarpv6 - ok
21:07:00.0287 6836  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
21:07:00.0318 6836  wbengine - ok
21:07:00.0349 6836  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
21:07:00.0349 6836  WbioSrvc - ok
21:07:00.0411 6836  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc         C:\Windows\System32\wcncsvc.dll
21:07:00.0411 6836  wcncsvc - ok
21:07:00.0427 6836  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:07:00.0443 6836  WcsPlugInService - ok
21:07:00.0474 6836  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\DRIVERS\wd.sys
21:07:00.0474 6836  Wd - ok
21:07:00.0505 6836  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
21:07:00.0521 6836  Wdf01000 - ok
21:07:00.0536 6836  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
21:07:00.0536 6836  WdiServiceHost - ok
21:07:00.0552 6836  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost   C:\Windows\system32\wdi.dll
21:07:00.0552 6836  WdiSystemHost - ok
21:07:00.0599 6836  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient       C:\Windows\System32\webclnt.dll
21:07:00.0599 6836  WebClient - ok
21:07:00.0677 6836  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
21:07:00.0692 6836  Wecsvc - ok
21:07:00.0708 6836  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
21:07:00.0723 6836  wercplsupport - ok
21:07:00.0723 6836  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
21:07:00.0739 6836  WerSvc - ok
21:07:00.0755 6836  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
21:07:00.0755 6836  WfpLwf - ok
21:07:00.0770 6836  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
21:07:00.0770 6836  WIMMount - ok
21:07:00.0786 6836  WinDefend - ok
21:07:00.0786 6836  WinHttpAutoProxySvc - ok
21:07:00.0833 6836  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
21:07:00.0833 6836  Winmgmt - ok
21:07:00.0926 6836  [ BCB1310604AA415C4508708975B3931E ] WinRM           C:\Windows\system32\WsmSvc.dll
21:07:00.0957 6836  WinRM - ok
21:07:01.0020 6836  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
21:07:01.0020 6836  WinUsb - ok
21:07:01.0067 6836  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc         C:\Windows\System32\wlansvc.dll
21:07:01.0082 6836  Wlansvc - ok
21:07:01.0145 6836  [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
21:07:01.0160 6836  wlcrasvc - ok
21:07:01.0269 6836  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:07:01.0301 6836  wlidsvc - ok
21:07:01.0332 6836  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
21:07:01.0332 6836  WmiAcpi - ok
21:07:01.0363 6836  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
21:07:01.0363 6836  wmiApSrv - ok
21:07:01.0410 6836  WMPNetworkSvc - ok
21:07:01.0410 6836  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
21:07:01.0410 6836  WPCSvc - ok
21:07:01.0441 6836  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
21:07:01.0441 6836  WPDBusEnum - ok
21:07:01.0488 6836  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
21:07:01.0488 6836  ws2ifsl - ok
21:07:01.0519 6836  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\system32\wscsvc.dll
21:07:01.0535 6836  wscsvc - ok
21:07:01.0535 6836  WSearch - ok
21:07:01.0644 6836  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
21:07:01.0659 6836  wuauserv - ok
21:07:01.0691 6836  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
21:07:01.0691 6836  WudfPf - ok
21:07:01.0722 6836  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
21:07:01.0737 6836  WUDFRd - ok
21:07:01.0753 6836  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
21:07:01.0753 6836  wudfsvc - ok
21:07:01.0784 6836  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc         C:\Windows\System32\wwansvc.dll
21:07:01.0784 6836  WwanSvc - ok
21:07:01.0847 6836  ================ Scan global ===============================
21:07:01.0862 6836  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
21:07:01.0909 6836  [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
21:07:01.0925 6836  [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
21:07:01.0956 6836  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
21:07:01.0987 6836  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
21:07:01.0987 6836  [Global] - ok
21:07:01.0987 6836  ================ Scan MBR ==================================
21:07:02.0003 6836  [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
21:07:02.0221 6836  \Device\Harddisk0\DR0 - ok
21:07:02.0221 6836  ================ Scan VBR ==================================
21:07:02.0221 6836  [ 68F6694F27B92DE3B92FDAF34A438DD5 ] \Device\Harddisk0\DR0\Partition1
21:07:02.0221 6836  \Device\Harddisk0\DR0\Partition1 - ok
21:07:02.0237 6836  [ EAC1E4D51B7F6B20BE429E1EB50316D8 ] \Device\Harddisk0\DR0\Partition2
21:07:02.0237 6836  \Device\Harddisk0\DR0\Partition2 - ok
21:07:02.0237 6836  ============================================================
21:07:02.0237 6836  Scan finished
21:07:02.0237 6836  ============================================================
21:07:02.0252 6288  Detected object count: 0
21:07:02.0252 6288  Actual detected object count: 0
         

Alt 26.08.2012, 01:11   #24
t'john
/// Helfer-Team
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Java aktualisieren

Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 7 Update 6 ) herunter laden.
  • Wenn die Installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Hacken gesetzt ist und klicke OK.
  • Klicke erneut OK.


Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html

Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck
__________________
Mfg, t'john
Das TB unterstützen

Alt 26.08.2012, 08:20   #25
magix1
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



PluginCheck

Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen.
Überprüft wird: Browser, Flash, Java und Adobe Reader Version.

Firefox 14.0.1 ist aktuell

Flash 11,3,300,271 ist veraltet!
Aktualisieren Sie bitte auf die neueste Version!

Java (1,7,0,6) ist aktuell.

Adobe Reader 9,3,0,148 ist veraltet!
Aktualisieren Sie bitte auf die neueste Version: 10,1,3



Zurück

Tools:

StartSeite
PluginCheck
Secunia Online Scan

Weiterführendes:

Java Updaten und Einstellen

Secunia Personal Software Inspector (PSI)

Family:

TR/Agent

Alt 27.08.2012, 00:11   #26
t'john
/// Helfer-Team
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Sehr gut!

damit bist Du entlassen!

adwCleaner entfernen

  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Uninstall.
  • Bestätige mit Ja.




Tool-Bereinigung mit OTL


Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
  • Bitte lade Dir (falls noch nicht vorhanden) OTL von OldTimer herunter.
  • Speichere es auf Deinem Desktop.
  • Doppelklick auf OTL.exe um das Programm auszuführen.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Klicke auf den Button "Bereinigung"
  • OTL fragt eventuell nach einem Neustart.
    Sollte es dies tun, so lasse dies bitte zu.
Anmerkung: Nach dem Neustart werden OTL und andere Helferprogramme, die Du im Laufe der Bereinigung heruntergeladen hast, nicht mehr vorhanden sein. Sie wurden entfernt. Es ist daher Ok, wenn diese Programme nicht mehr vorhanden sind. Sollten noch welche übrig geblieben sein, lösche sie manuell.


Zurücksetzen der Sicherheitszonen

Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen.
Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html


Systemwiederherstellungen leeren

Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein:
Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7
Danach wieder aktivieren.


Aufräumen mit CCleaner

Lasse mit CCleaner (Download) (Anleitung) Fehler in der

  • Registry beheben (mehrmals, solange bis keine Fehler mehr gefunden werden) und
  • temporäre Dateien löschen.




Lektuere zum abarbeiten:
http://www.trojaner-board.de/90880-d...tallation.html
http://www.trojaner-board.de/105213-...tellungen.html
PluginCheck
http://www.trojaner-board.de/96344-a...-rechners.html
Secunia Online Software Inspector
http://www.trojaner-board.de/71715-k...iendungen.html
http://www.trojaner-board.de/83238-a...sschalten.html
PC wird immer langsamer - was tun?
__________________
Mfg, t'john
Das TB unterstützen

Alt 27.08.2012, 07:52   #27
magix1
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Ist der sirefef.p.35 den Avira mir gestern gemeldet hatte auch verschwunden ?

Alt 27.08.2012, 17:42   #28
t'john
/// Helfer-Team
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Poste das Log von Avira.
__________________
Mfg, t'john
Das TB unterstützen

Alt 27.08.2012, 20:16   #29
magix1
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Wo find ich den Avira Log?

Wo find ich den Avira Log?

das kam gerade beim download von cccleaner

Code:
ATTFilter
Typ:	Datei
Quelle:	C:\Users\Marcel\Downloads\DownloadAcceleratorSetup.exe
Status:	Infiziert
Quarantäne-Objekt:	55186e0c.qua
Wiederhergestellt:	NEIN
Zu Avira hochgeladen:	NEIN
Betriebssystem:	Windows 2000/XP/VISTA Workstation
Suchengine:	8.02.10.146
Virendefinitionsdatei:	7.11.40.250
Meldung:	Enthält Erkennungsmuster der Adware ADWARE/InstallCore.Gen
Datum/Uhrzeit:	27.08.2012, 21:43
         
und das ist der sirefef.P.35

Code:
ATTFilter
Typ:	Datei
Quelle:	C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{5355E1F0-09FC-237D-6F4D-3D6CD8015739}-71171649.exe
Status:	Infiziert
Quarantäne-Objekt:	553eb756.qua
Wiederhergestellt:	NEIN
Zu Avira hochgeladen:	NEIN
Betriebssystem:	Windows 2000/XP/VISTA Workstation
Suchengine:	8.02.10.146
Virendefinitionsdatei:	7.11.40.250
Meldung:	Ist das Trojanische Pferd TR/Sirefef.P.35
Datum/Uhrzeit:	25.08.2012, 20:15
         

Alt 28.08.2012, 16:17   #30
t'john
/// Helfer-Team
 
Trojaner geangelt   TR/ATRAPS.Gen2   TR/Sirefef.16896 - Standard

Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896



Das ist OK, das is die Quarantaene von Windows Defender.

Er ist also nicht aktiv.
__________________
Mfg, t'john
Das TB unterstützen

Antwort

Themen zu Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896
avira, compu, freue, heute, leicht, meldung, minute, minuten, nichts, tr/atraps.gen, tr/atraps.gen2, tr/sirefef.16896, troja, trojaner, verständliche, würde




Ähnliche Themen: Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896


  1. Trojaner TR/Sirefef.BC.57, TR/Sirefef.AG.9, TR/ATRAPS.Gen2, TR/Necurs.A.71 und SpyHunter 4 auf Rechner
    Log-Analyse und Auswertung - 07.05.2013 (7)
  2. Avira findet TR/Sirefef.16896 und TR/ATRAPS.Gen und TR/ATRAPS.Gen2 in Windows\Installer und W32/Patched.UA in Windows\System32\service.exe
    Plagegeister aller Art und deren Bekämpfung - 14.11.2012 (23)
  3. Antivir schickt Viren (TR/ATRAPS.Gen2 + TR/Sirefef.W.16896) in Quarantäne
    Plagegeister aller Art und deren Bekämpfung - 21.10.2012 (60)
  4. Trojaner Befall TR/ATRAPS.GEN ,TR/ATRAPS.GEN2 , TR/Cutwail.jhg , TR/ZAccess.H , TR/Sirefef.A.37
    Plagegeister aller Art und deren Bekämpfung - 08.10.2012 (17)
  5. tr/sirefef.16896 und tr/atraps.gen2; wie bekomme ich die weg?
    Plagegeister aller Art und deren Bekämpfung - 26.09.2012 (17)
  6. TR/Sirefef.16896 und TR/ATRAPS.Gen2 im Papierkorb-Verzeichnis (Win7 x64)
    Plagegeister aller Art und deren Bekämpfung - 23.09.2012 (5)
  7. TR/ATRAPS.Gen2 und TR/Sirefef.W.16896 in C:\$Recycle.Bin\S-1-5-18\......
    Plagegeister aller Art und deren Bekämpfung - 19.09.2012 (3)
  8. TR/Sirefef.16896 und TR/ATRAPS.Gen2 auf Laptop gefunden
    Plagegeister aller Art und deren Bekämpfung - 14.09.2012 (33)
  9. TR/ATRAPS.Gen2 und TR/Sirefef.16896 lässt sich nicht entfernen
    Log-Analyse und Auswertung - 06.09.2012 (33)
  10. TR/ATRAPS.Gen2, TR/Sirefef.16896 (in C:\Windows\Installer\...) und W32/Patched.UA (C:\Windows\System32\services.exe)
    Plagegeister aller Art und deren Bekämpfung - 04.09.2012 (5)
  11. multipler Befall: ATRAPS.Gen2, Sirefef.16896, BDS/ZeroAccess
    Log-Analyse und Auswertung - 29.08.2012 (13)
  12. TR/Winwebsec.AJ.14;BDS/ZAccess.W;EXP/JAVA.Teqwari.gen;TR/Agent.2049;TR/ATRAPS.gen2 und TR/sirefef.16896 von AVIRA gefunden
    Log-Analyse und Auswertung - 21.08.2012 (12)
  13. Trojaner TR/ATRAPS.Gen2 und TR/Sirefef.16896 lassen sich nicht entfernen
    Plagegeister aller Art und deren Bekämpfung - 20.08.2012 (5)
  14. Avira: Wiederholte Warnung zu TR/ATRAPS.Gen2 und TR/Sirefef.16896
    Log-Analyse und Auswertung - 15.08.2012 (1)
  15. TR/Sirefef.16896 und TR/ATRAPS.Gen2 wurden gefunden.
    Plagegeister aller Art und deren Bekämpfung - 15.08.2012 (1)
  16. Trojaner Atraps.Gen, Atraps.Gen2 und Sirefef.AB.20 - gelöscht, aber auch sicher?
    Log-Analyse und Auswertung - 14.07.2012 (23)
  17. Antivir findet 4 Trojaner: TR/ATRAPS.Gen, TR/ATRAPS.Gen2, Sirefef.P.342, Dldr.Phdet.E.41
    Log-Analyse und Auswertung - 11.07.2012 (1)

Zum Thema Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896 - Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail - Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896...
Archiv
Du betrachtest: Trojaner geangelt TR/ATRAPS.Gen2 TR/Sirefef.16896 auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.