Alt 28.12.2012, 08:21   #1
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Hallo zusammen,

ich habe mir gestern wohl was eingefangen. Während ich im www unterwegs war, schlossen sich auf einmal alle Fenster und ich hatte einen bluescreen ohne weiter shortcut Abbildungen. Ich habe Win7 Home Premium.

Ich habe mir jetzt die Antivir-Rescue CD runtergeladen und damit gebootet. Programm startet läuft auch durch, allerdings bekomme ich die Meldung, dasseine Verbindung zum Internet nicht möglich ist und somit keine Aktualisierung vorgenommen werden kann.

Ich habe den Rechner zudem im abgesicherten Modus gestartet und Spybot (ohne Fund) durchlaufen lassen.

Was kann ich tun?? Bitte helft mir.

Danke und Gruß


Alt 28.12.2012, 11:02   #2
/// TB-Ausbilder
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich.
Regeln für die Bereinigung
Damit die Bereinigung funktioniert bitte ich dich, die folgenden Punkte aufmerksam zu lesen:
  • Bitte arbeite alle Schritte der Reihe nach ab. Gib mir bitte zu jedem Schritt Rückmeldung (Logfile oder Antwort) und zwar gesammelt, wenn du alles erledigt hast.
  • Nur Scanns durchführen zu denen Du aufgefordert wirst.
  • Bitte kein Crossposting (posten in mehreren Foren).
  • Installiere oder Deinstalliere während der Bereinigung keine Software, ausser Du wurdest dazu aufgefordert.
  • Lese Dir die Anleitung zuerst vollständig durch. Sollte etwas unklar sein, frage bevor Du beginnst.
  • Poste die Logfiles direkt in deinen Thread (möglichst in Code-Tags - #-Symbol im Editor). Nicht anhängen ausser ich fordere Dich dazu auf, oder das Logfile wäre zu gross. Erschwert mir nämlich das Auswerten.
  • Mache deinen Namen nur dann unkenntlich, wenn es unbedingt sein muss.
  • Beim ersten Anzeichen illegal genutzer Software (Cracks, Patches und Co) wird der Support ohne Diskussion eingestellt.
  • Sollte ich nicht nach 3 Tagen geantwortet haben, dann (und nur dann) schicke mir bitte eine PM.
  • Ich werde dir ganz deutlich mitteilen, dass du "sauber" bist. Bis dahin arbeite bitte gut mit.
  • Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der schnellere und immer der sicherste Weg.
Wir fangen erst an zu bereinigen, wenn du mir das hier bestätigst und dich anschliessend daran hälst.
Gelesen und verstanden?

Schritt 1:
Laufwerksemulationen abschalten mit Defogger
Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop und starte es:
  • Klicke nun auf den Disable Button, um die Treiber gewisser Emulatoren zu deaktivieren.
  • Defogger wird dich fragen "Defogger will forcefully ... Continue?" bestätige dies mit Ja.
  • Wenn der Scan beendet wurde (Finished), klicke auf OK.
  • Defogger fordert gegebenfalls zum Neustart auf. Bestätige dies mit OK.
Poste bitte die defogger_disable.txt von deinem Desktop.
Klicke den Re-enable Button nicht ohne Anweisung.

Schritt 2:
Scan mit aswMBR

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Vista und Win7 User mit Rechtsklick "als Admininstartor starten"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. ( Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).

Schritt 3:
Scan mit dem TDSS-Killer

Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen.

Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe
  • Klicke auf Change parameters, setze einen Haken bei Detect TDLFS file system und bestätige mit OK.
  • Drücke Start Scan
  • Warnung:
    Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und speichere das Logfile.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern ( Meistens C:\ )
    Als Beispiel: C:\TDSSKiller.<version_date_time>log.txt
Poste den Inhalt bitte hier in deinen Thread (bitte dringend in CODE-Tags mit dem #-Symbol im Editor).

Schritt 4:
Scan mit DDS (+ attach)
Downloade dir bitte DDS (von sUBs) von einem der folgenden Downloadspiegel und speichere die Datei auf deinem Desktop.

dds.com | dds.scr | dds.pif
  • Schließe alle laufenden Programme und starte DDS mit Doppelklick.
  • Der Desktop wird verschwinden, das ist normal.
  • Stelle folgendes ein:

    [X] dds.txt
    [X] attach.txt
    [ ] options for dds.txt

  • Ändere keine Einstellung ohne Anweisung.
  • Klicke auf Start.
  • Es werden 2 Logfiles auf deinem Desktop erstellt.
    • dds.txt
    • attach.txt
  • Poste die beiden Logfile hier, möglichst in CODE-Tags.


Alt 28.12.2012, 11:28   #3
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Erstmal Danke und gleich ein Sorry hinterher, ich bin nicht so bewandert, deshalb meine Frage:
Ich mache das alles im abgesicherten Modus? Weil sonst ja kein Zugriff auf Desktop etc ...

Kann ich das auch alles auf einen Stick zihen und dann auf dem "abgesicherten Modus Desktop" installieren?

Alt 28.12.2012, 11:47   #4
/// TB-Ausbilder
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Ja abgesicherter Modus und notfalls mit Stick.
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
Digitale Freibeuter gegen Malware!
Keine Hilfe per PM!

Alt 28.12.2012, 19:50   #5
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Hallo ryder,

mit Spybot und ANtiVir hab ich es irgendwie wieder hinbekommen. Ich kann wieder auf alles zugreifen, ich weiß allerdings nicht wie ich das geschafft habe.

Möchte mich aber sehr für die Bereitschaft mir zu helfen bedanken.

Danke und guten Rutsch,


Alt 29.12.2012, 11:30   #6
/// TB-Ausbilder
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Die ist schon klar, dass "irgendwie" geschafft nicht funkionieren wird?
--> Blauer Screen nach booten , kein Zugriff auf Desktop etc

Alt 29.12.2012, 13:29   #7
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

ok, wie sollen wir dann weiter verfahren?
Wie oben angegeben?

Alt 29.12.2012, 13:33   #8
/// TB-Ausbilder
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Ja, aber nur wenn du willst!
Digitale Freibeuter gegen Malware!
Keine Hilfe per PM!

Alt 29.12.2012, 13:57   #9
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

defogger_disable by jpshortstuff (
Log created at 13:55 on 29/12/2012 (Dennis)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


Alt 29.12.2012, 13:59   #10
/// TB-Ausbilder
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

... und du liest meine Regeln nochmal!
Digitale Freibeuter gegen Malware!
Keine Hilfe per PM!

Alt 30.12.2012, 12:20   #11
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Hallo rayder,

ich hoffe ich habe jetzt alles richtig gemacht. Hier als sämtliche Protokolle:

defogger_disable by jpshortstuff (
Log created at 13:55 on 29/12/2012 (Dennis)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


---------Schritt 2-------------------------

aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2012-12-29 14:01:20
14:01:20.855    OS Version: Windows x64 6.1.7601 Service Pack 1
14:01:20.855    Number of processors: 4 586 0x2505
14:01:20.855    ComputerName: DENNIS-PC  UserName: Dennis
14:01:22.087    Initialize success
14:02:52.864    AVAST engine defs: 12122900
14:03:21.116    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
14:03:21.116    Disk 0 Vendor: SAMSUNG_ 2AJ1 Size: 305245MB BusType: 3
14:03:21.131    Disk 0 MBR read successfully
14:03:21.131    Disk 0 MBR scan
14:03:21.147    Disk 0 unknown MBR code
14:03:21.162    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
14:03:21.178    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        73728 MB offset 206848
14:03:21.194    Disk 0 Partition - 00     0F Extended LBA            209673 MB offset 

14:03:21.240    Disk 0 Partition 3 00     27 Hidden NTFS WinRE NTFS        21741 MB offset 

14:03:21.287    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS       209672 MB offset 

14:03:21.318    Disk 0 scanning C:\Windows\system32\drivers
14:03:38.946    Service scanning
14:04:10.569    Modules scanning
14:04:11.084    Disk 0 trace - called modules:
14:04:11.115    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
14:04:11.115    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80045cd060]
14:04:11.115    3 CLASSPNP.SYS[fffff8800181743f] -> nt!IofCallDriver -> \Device\Ide

14:04:11.536    AVAST engine scan C:\Windows
14:04:15.311    AVAST engine scan C:\Windows\system32
14:08:29.155    AVAST engine scan C:\Windows\system32\drivers
14:08:45.098    AVAST engine scan C:\Users\Dennis
14:11:47.650    AVAST engine scan C:\ProgramData
14:14:50.373    Scan finished successfully
10:57:06.350    Disk 0 MBR has been saved successfully to "C:\Users\Dennis\Desktop\MBR.dat"
10:57:06.662    The log file has been saved successfully to "C:\Users\Dennis\Desktop

-------------------------SCHRITT 3------------------------------------


10:59:20.0432 5036  TDSS rootkit removing tool Oct 31 2012 21:47:35
10:59:20.0541 5036  ============================================================
10:59:20.0541 5036  Current date / time: 2012/12/30 10:59:20.0541
10:59:20.0541 5036  SystemInfo:
10:59:20.0541 5036  
10:59:20.0541 5036  OS Version: 6.1.7601 ServicePack: 1.0
10:59:20.0541 5036  Product type: Workstation
10:59:20.0541 5036  ComputerName: DENNIS-PC
10:59:20.0541 5036  UserName: Dennis
10:59:20.0541 5036  Windows directory: C:\Windows
10:59:20.0541 5036  System windows directory: C:\Windows
10:59:20.0541 5036  Running under WOW64
10:59:20.0541 5036  Processor architecture: Intel x64
10:59:20.0541 5036  Number of processors: 4
10:59:20.0541 5036  Page size: 0x1000
10:59:20.0541 5036  Boot type: Normal boot
10:59:20.0541 5036  ============================================================
10:59:21.0415 5036  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), 

SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 

'K0', Flags 0x00000040
10:59:21.0430 5036  ============================================================
10:59:21.0430 5036  \Device\Harddisk0\DR0:
10:59:21.0430 5036  MBR partitions:
10:59:21.0430 5036  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, 

BlocksNum 0x32000
10:59:21.0430 5036  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, 

BlocksNum 0x9000000
10:59:21.0446 5036  \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x9033000, 

BlocksNum 0x19984000
10:59:21.0446 5036  ============================================================
10:59:21.0493 5036  C: <-> \Device\Harddisk0\DR0\Partition2
10:59:21.0555 5036  D: <-> \Device\Harddisk0\DR0\Partition3
10:59:21.0649 5036  ============================================================
10:59:21.0649 5036  Initialize success
10:59:21.0649 5036  ============================================================
11:00:19.0416 4960  ============================================================
11:00:19.0416 4960  Scan started
11:00:19.0416 4960  Mode: Manual; TDLFS; 
11:00:19.0416 4960  ============================================================
11:00:20.0601 4960  ================ Scan system memory ========================
11:00:20.0601 4960  System memory - ok
11:00:20.0601 4960  ================ Scan services =============================
11:00:20.0788 4960  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows

11:00:20.0788 4960  1394ohci - ok
11:00:20.0866 4960  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows

11:00:20.0866 4960  ACPI - ok
11:00:20.0898 4960  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi         C:\Windows

11:00:20.0898 4960  AcpiPmi - ok
11:00:20.0944 4960  [ 2F0683FD2DF1D92E891CACA14B45A8C1 ] adfs            C:\Windows

11:00:20.0944 4960  adfs - ok
11:00:21.0054 4960  [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:

11:00:21.0054 4960  AdobeFlashPlayerUpdateSvc - ok
11:00:21.0116 4960  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx         C:\Windows

11:00:21.0116 4960  adp94xx - ok
11:00:21.0163 4960  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci         C:\Windows

11:00:21.0163 4960  adpahci - ok
11:00:21.0178 4960  [ E109549C90F62FB570B9540C4B148E54 ] adpu320         C:\Windows

11:00:21.0178 4960  adpu320 - ok
11:00:21.0210 4960  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc     C:\Windows

11:00:21.0225 4960  AeLookupSvc - ok
11:00:21.0256 4960  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD             C:\Windows

11:00:21.0272 4960  AFD - ok
11:00:21.0334 4960  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows

11:00:21.0334 4960  agp440 - ok
11:00:21.0366 4960  [ 3290D6946B5E30E70414990574883DDB ] ALG             C:\Windows

11:00:21.0366 4960  ALG - ok
11:00:21.0397 4960  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows

11:00:21.0397 4960  aliide - ok
11:00:21.0428 4960  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows

11:00:21.0428 4960  amdide - ok
11:00:21.0459 4960  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8           C:\Windows

11:00:21.0459 4960  AmdK8 - ok
11:00:21.0475 4960  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows

11:00:21.0475 4960  AmdPPM - ok
11:00:21.0537 4960  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata         C:\Windows

11:00:21.0537 4960  amdsata - ok
11:00:21.0568 4960  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows

11:00:21.0568 4960  amdsbs - ok
11:00:21.0584 4960  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata         C:\Windows

11:00:21.0584 4960  amdxata - ok
11:00:21.0678 4960  [ 0FA2D8304ECA29CA0AB7E3EE50FD585A ] AntiVirSchedulerService C:\Program 

Files (x86)\Avira\AntiVir Desktop\sched.exe
11:00:21.0678 4960  AntiVirSchedulerService - ok
11:00:21.0740 4960  [ 5C69AAC8A59207DA9710FF2E42D6F80F ] AntiVirService  C:\Program Files 

(x86)\Avira\AntiVir Desktop\avguard.exe
11:00:21.0756 4960  AntiVirService - ok
11:00:21.0787 4960  [ 89A69C3F2F319B43379399547526D952 ] AppID           C:\Windows

11:00:21.0802 4960  AppID - ok
11:00:21.0818 4960  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows

11:00:21.0834 4960  AppIDSvc - ok
11:00:21.0880 4960  [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo         C:\Windows

11:00:21.0880 4960  Appinfo - ok
11:00:21.0912 4960  [ C484F8CEB1717C540242531DB7845C4E ] arc             C:\Windows

11:00:21.0912 4960  arc - ok
11:00:21.0943 4960  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows

11:00:21.0943 4960  arcsas - ok
11:00:21.0958 4960  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows

11:00:21.0958 4960  AsyncMac - ok
11:00:22.0021 4960  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi           C:\Windows

11:00:22.0021 4960  atapi - ok
11:00:22.0068 4960  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows

11:00:22.0083 4960  AudioEndpointBuilder - ok
11:00:22.0099 4960  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows

11:00:22.0099 4960  AudioSrv - ok
11:00:22.0146 4960  [ BFE9598EBC3934CF8D876A303849C896 ] avgntflt        C:\Windows

11:00:22.0146 4960  avgntflt - ok
11:00:22.0208 4960  [ F74D86A9FB35FA5F24627B8DBBF3A9A4 ] avipbb          C:\Windows

11:00:22.0208 4960  avipbb - ok
11:00:22.0239 4960  [ CD0E732347BF09717E0BDDC0C66699AB ] avkmgr          C:\Windows

11:00:22.0239 4960  avkmgr - ok
11:00:22.0286 4960  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows

11:00:22.0302 4960  AxInstSV - ok
11:00:22.0333 4960  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv         C:\Windows

11:00:22.0333 4960  b06bdrv - ok
11:00:22.0395 4960  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows

11:00:22.0395 4960  b57nd60a - ok
11:00:22.0489 4960  [ 63DD9C990883709053DD2C427DF0DB6F ] BCM43XX         C:\Windows

11:00:22.0520 4960  BCM43XX - ok
11:00:22.0536 4960  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows

11:00:22.0551 4960  BDESVC - ok
11:00:22.0598 4960  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows

11:00:22.0598 4960  Beep - ok
11:00:22.0660 4960  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows

11:00:22.0676 4960  BITS - ok
11:00:22.0707 4960  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows

11:00:22.0707 4960  blbdrive - ok
11:00:22.0754 4960  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows

11:00:22.0754 4960  bowser - ok
11:00:22.0785 4960  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows

11:00:22.0785 4960  BrFiltLo - ok
11:00:22.0801 4960  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows

11:00:22.0801 4960  BrFiltUp - ok
11:00:22.0832 4960  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser         C:\Windows

11:00:22.0848 4960  Browser - ok
11:00:22.0988 4960  [ 9FCD0930616714A752F48DDBA54F3109 ] Browser Manager C:\ProgramData

\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
11:00:23.0019 4960  Browser Manager - ok
11:00:23.0035 4960  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid         C:\Windows

11:00:23.0035 4960  Brserid - ok
11:00:23.0066 4960  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows

11:00:23.0066 4960  BrSerWdm - ok
11:00:23.0082 4960  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows

11:00:23.0082 4960  BrUsbMdm - ok
11:00:23.0082 4960  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows

11:00:23.0082 4960  BrUsbSer - ok
11:00:23.0144 4960  [ CF98190A94F62E405C8CB255018B2315 ] BthEnum         C:\Windows

11:00:23.0144 4960  BthEnum - ok
11:00:23.0160 4960  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows

11:00:23.0160 4960  BTHMODEM - ok
11:00:23.0191 4960  [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan          C:\Windows

11:00:23.0191 4960  BthPan - ok
11:00:23.0269 4960  [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT         C:\Windows

11:00:23.0269 4960  BTHPORT - ok
11:00:23.0316 4960  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv         C:\Windows

11:00:23.0316 4960  bthserv - ok
11:00:23.0347 4960  [ F188B7394D81010767B6DF3178519A37 ] BTHUSB          C:\Windows

11:00:23.0347 4960  BTHUSB - ok
11:00:23.0409 4960  [ 72CC5DCC4E67E7927F94801166CFDCDA ] BTWAMPFL        C:\Windows

11:00:23.0425 4960  BTWAMPFL - ok
11:00:23.0456 4960  [ F6135859A582A7294BA7A3336E08BAA1 ] btwaudio        C:\Windows

11:00:23.0472 4960  btwaudio - ok
11:00:23.0487 4960  [ 3DEF2370E414B4E299673558BA171A51 ] btwavdt         C:\Windows

11:00:23.0503 4960  btwavdt - ok
11:00:23.0596 4960  [ F0AF04A96CA48B869284B5DC4CDB8CBB ] btwdins         C:\Program Files

\WIDCOMM\Bluetooth Software\btwdins.exe
11:00:23.0612 4960  btwdins - ok
11:00:23.0643 4960  [ 07096D2BC22CCB6CEA5A532DF0BE8A75 ] btwl2cap        C:\Windows

11:00:23.0643 4960  btwl2cap - ok
11:00:23.0659 4960  [ 9937E0E4DFC0030560A6DFE9D3A94B39 ] btwrchid        C:\Windows

11:00:23.0659 4960  btwrchid - ok
11:00:23.0690 4960  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows

11:00:23.0706 4960  cdfs - ok
11:00:23.0737 4960  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom           C:\Windows

11:00:23.0752 4960  cdrom - ok
11:00:23.0784 4960  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc     C:\Windows

11:00:23.0799 4960  CertPropSvc - ok
11:00:23.0815 4960  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows

11:00:23.0815 4960  circlass - ok
11:00:23.0846 4960  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows

11:00:23.0862 4960  CLFS - ok
11:00:23.0924 4960  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:

11:00:23.0940 4960  clr_optimization_v2.0.50727_32 - ok
11:00:24.0002 4960  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:

11:00:24.0002 4960  clr_optimization_v2.0.50727_64 - ok
11:00:24.0064 4960  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:

11:00:24.0080 4960  clr_optimization_v4.0.30319_32 - ok
11:00:24.0127 4960  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:

11:00:24.0127 4960  clr_optimization_v4.0.30319_64 - ok
11:00:24.0174 4960  [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd           C:\Windows

11:00:24.0174 4960  clwvd - ok
11:00:24.0205 4960  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows

11:00:24.0205 4960  CmBatt - ok
11:00:24.0236 4960  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows

11:00:24.0236 4960  cmdide - ok
11:00:24.0267 4960  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG             C:\Windows

11:00:24.0283 4960  CNG - ok
11:00:24.0298 4960  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows

11:00:24.0298 4960  Compbatt - ok
11:00:24.0361 4960  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows

11:00:24.0376 4960  CompositeBus - ok
11:00:24.0392 4960  COMSysApp - ok
11:00:24.0408 4960  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk         C:\Windows

11:00:24.0408 4960  crcdisk - ok
11:00:24.0439 4960  [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc        C:\Windows

11:00:24.0439 4960  CryptSvc - ok
11:00:24.0486 4960  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows

11:00:24.0501 4960  DcomLaunch - ok
11:00:24.0532 4960  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc       C:\Windows

11:00:24.0532 4960  defragsvc - ok
11:00:24.0579 4960  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows

11:00:24.0579 4960  DfsC - ok
11:00:24.0626 4960  dgderdrv - ok
11:00:24.0657 4960  [ B9430166FEB246F6070A62B3554932C9 ] dg_ssudbus      C:\Windows

11:00:24.0657 4960  dg_ssudbus - ok
11:00:24.0735 4960  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows

11:00:24.0735 4960  Dhcp - ok
11:00:24.0766 4960  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows

11:00:24.0766 4960  discache - ok
11:00:24.0798 4960  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows

11:00:24.0798 4960  Disk - ok
11:00:24.0829 4960  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows

11:00:24.0829 4960  Dnscache - ok
11:00:24.0876 4960  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc         C:\Windows

11:00:24.0891 4960  dot3svc - ok
11:00:24.0938 4960  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS             C:\Windows

11:00:24.0938 4960  DPS - ok
11:00:24.0969 4960  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud         C:\Windows

11:00:24.0969 4960  drmkaud - ok
11:00:25.0016 4960  [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl         C:\Windows

11:00:25.0032 4960  DXGKrnl - ok
11:00:25.0063 4960  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost         C:\Windows

11:00:25.0078 4960  EapHost - ok
11:00:25.0156 4960  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv           C:\Windows

11:00:25.0203 4960  ebdrv - ok
11:00:25.0234 4960  [ C118A82CD78818C29AB228366EBF81C3 ] EFS             C:\Windows

11:00:25.0234 4960  EFS - ok
11:00:25.0312 4960  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr         C:\Windows\ehome

11:00:25.0328 4960  ehRecvr - ok
11:00:25.0359 4960  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched         C:\Windows\ehome

11:00:25.0375 4960  ehSched - ok
11:00:25.0500 4960  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor         C:\Windows

11:00:25.0500 4960  elxstor - ok
11:00:25.0609 4960  [ ABDD5AD016AFFD34AD40E944CE94BF59 ] EpsonBidirectionalService C:

\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
11:00:25.0609 4960  EpsonBidirectionalService - ok
11:00:25.0656 4960  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows

11:00:25.0656 4960  ErrDev - ok
11:00:25.0702 4960  [ 0C8324462B9791A1ECE2A329A7378A55 ] ETD             C:\Windows

11:00:25.0718 4960  ETD - ok
11:00:25.0749 4960  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem     C:\Windows

11:00:25.0765 4960  EventSystem - ok
11:00:25.0812 4960  [ 334C907536E815E56CD13108A6D5FB9D ] ewusbmbb        C:\Windows

11:00:25.0827 4960  ewusbmbb - ok
11:00:25.0843 4960  ewusbnet - ok
11:00:25.0858 4960  [ 86F7951BBCEE4A86E79A97306BD14318 ] ew_hwusbdev     C:\Windows

11:00:25.0858 4960  ew_hwusbdev - ok
11:00:25.0890 4960  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat           C:\Windows

11:00:25.0890 4960  exfat - ok
11:00:25.0921 4960  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat         C:\Windows

11:00:25.0921 4960  fastfat - ok
11:00:25.0983 4960  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax             C:\Windows

11:00:25.0999 4960  Fax - ok
11:00:26.0030 4960  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc             C:\Windows

11:00:26.0030 4960  fdc - ok
11:00:26.0061 4960  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost         C:\Windows

11:00:26.0061 4960  fdPHost - ok
11:00:26.0077 4960  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows

11:00:26.0092 4960  FDResPub - ok
11:00:26.0108 4960  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows

11:00:26.0108 4960  FileInfo - ok
11:00:26.0124 4960  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace       C:\Windows

11:00:26.0124 4960  Filetrace - ok
11:00:26.0170 4960  [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service C:

\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher

11:00:26.0202 4960  FLEXnet Licensing Service - ok
11:00:26.0264 4960  [ 1C3FB052A0BB72EDAED90785C34D6EED ] FLEXnet Licensing Service 64 C:

\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
11:00:26.0280 4960  FLEXnet Licensing Service 64 - ok
11:00:26.0311 4960  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows

11:00:26.0311 4960  flpydisk - ok
11:00:26.0373 4960  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows

11:00:26.0373 4960  FltMgr - ok
11:00:26.0436 4960  [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache       C:\Windows

11:00:26.0451 4960  FontCache - ok
11:00:26.0498 4960  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows

11:00:26.0498 4960  FontCache3.0.0.0 - ok
11:00:26.0529 4960  [ D43703496149971890703B4B1B723EAC ] FsDepends       C:\Windows

11:00:26.0529 4960  FsDepends - ok
11:00:26.0576 4960  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows

11:00:26.0576 4960  Fs_Rec - ok
11:00:26.0607 4960  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows

11:00:26.0623 4960  fvevol - ok
11:00:26.0638 4960  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows

11:00:26.0638 4960  gagp30kx - ok
11:00:26.0716 4960  [ 521A469CAF61F00E1DE081CC2099C1D6 ] GameConsoleService C:\Program Files 

(x86)\WildGames\Game Console - WildGames\GameConsoleService.exe
11:00:26.0716 4960  GameConsoleService - ok
11:00:26.0763 4960  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc           C:\Windows

11:00:26.0779 4960  gpsvc - ok
11:00:26.0857 4960  [ F02A533F517EB38333CB12A9E8963773 ] gupdate         C:\Program Files 

11:00:26.0888 4960  gupdate - ok
11:00:26.0919 4960  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files 

11:00:26.0919 4960  gupdatem - ok
11:00:26.0950 4960  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows

11:00:26.0950 4960  hcw85cir - ok
11:00:26.0997 4960  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows

11:00:26.0997 4960  HdAudAddService - ok
11:00:27.0028 4960  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows

11:00:27.0028 4960  HDAudBus - ok
11:00:27.0060 4960  [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64         C:\Windows

11:00:27.0060 4960  HECIx64 - ok
11:00:27.0075 4960  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt         C:\Windows

11:00:27.0075 4960  HidBatt - ok
11:00:27.0091 4960  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows

11:00:27.0091 4960  HidBth - ok
11:00:27.0122 4960  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr           C:\Windows

11:00:27.0122 4960  HidIr - ok
11:00:27.0138 4960  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv         C:\Windows

11:00:27.0138 4960  hidserv - ok
11:00:27.0184 4960  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows

11:00:27.0184 4960  HidUsb - ok
11:00:27.0231 4960  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows

11:00:27.0231 4960  hkmsvc - ok
11:00:27.0278 4960  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows

11:00:27.0294 4960  HomeGroupListener - ok
11:00:27.0340 4960  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows

11:00:27.0356 4960  HomeGroupProvider - ok
11:00:27.0387 4960  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows

11:00:27.0387 4960  HpSAMD - ok
11:00:27.0434 4960  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows

11:00:27.0450 4960  HTTP - ok
11:00:27.0481 4960  [ F572B7467B5CB4FA8FB6319575902E41 ] Huawei          C:\Windows

11:00:27.0496 4960  Huawei - ok
11:00:27.0512 4960  [ 1642C62F1FD5E1FF44608283994A7BB8 ] huawei_enumerator C:\Windows

11:00:27.0528 4960  huawei_enumerator - ok
11:00:27.0574 4960  [ 4B80AF36EE9F31361C1DCB2EE563719A ] hwdatacard      C:\Windows

11:00:27.0574 4960  hwdatacard - ok
11:00:27.0637 4960  [ E90DA42B87D684DEBFB73B38A718A006 ] HWDeviceService64.exe C:

11:00:27.0637 4960  HWDeviceService64.exe - ok
11:00:27.0699 4960  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows

11:00:27.0699 4960  hwpolicy - ok
11:00:27.0730 4960  hwusbdev - ok
11:00:27.0793 4960  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows

11:00:27.0793 4960  i8042prt - ok
11:00:27.0840 4960  [ A5F72BB0D024E7E463344105BE613AE4 ] iaStor          C:\Windows

11:00:27.0840 4960  iaStor - ok
11:00:27.0886 4960  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV         C:\Windows

11:00:27.0902 4960  iaStorV - ok
11:00:27.0949 4960  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc           C:\Windows

\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
11:00:27.0996 4960  idsvc - ok
11:00:28.0230 4960  [ 677AA5991026A65ADA128C4B59CF2BAD ] igfx            C:\Windows

11:00:28.0432 4960  igfx - ok
11:00:28.0464 4960  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp           C:\Windows

11:00:28.0464 4960  iirsp - ok
11:00:28.0542 4960  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows

11:00:28.0557 4960  IKEEXT - ok
11:00:28.0604 4960  [ DD587A55390ED2295BCE6D36AD567DA9 ] Impcd           C:\Windows

11:00:28.0604 4960  Impcd - ok
11:00:28.0713 4960  [ A0C2C3D4C03C4FB896CFC53873784178 ] IntcAzAudAddService C:\Windows

11:00:28.0744 4960  IntcAzAudAddService - ok
11:00:28.0791 4960  [ C6C1F19205DA83C801BE7C25F4E2EE07 ] IntcDAud        C:\Windows

11:00:28.0791 4960  IntcDAud - ok
11:00:28.0838 4960  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows

11:00:28.0838 4960  intelide - ok
11:00:28.0885 4960  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows

11:00:28.0885 4960  intelppm - ok
11:00:28.0916 4960  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum       C:\Windows

11:00:28.0932 4960  IPBusEnum - ok
11:00:28.0963 4960  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows

11:00:28.0963 4960  IpFilterDriver - ok
11:00:29.0010 4960  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV         C:\Windows

11:00:29.0010 4960  IPMIDRV - ok
11:00:29.0025 4960  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT           C:\Windows

11:00:29.0025 4960  IPNAT - ok
11:00:29.0056 4960  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows

11:00:29.0056 4960  IRENUM - ok
11:00:29.0072 4960  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows

11:00:29.0072 4960  isapnp - ok
11:00:29.0088 4960  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows

11:00:29.0103 4960  iScsiPrt - ok
11:00:29.0134 4960  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows

11:00:29.0150 4960  kbdclass - ok
11:00:29.0197 4960  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows

11:00:29.0197 4960  kbdhid - ok
11:00:29.0212 4960  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows

11:00:29.0212 4960  KeyIso - ok
11:00:29.0244 4960  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows

11:00:29.0244 4960  KSecDD - ok
11:00:29.0259 4960  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg         C:\Windows

11:00:29.0259 4960  KSecPkg - ok
11:00:29.0290 4960  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk         C:\Windows

11:00:29.0290 4960  ksthunk - ok
11:00:29.0322 4960  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm           C:\Windows

11:00:29.0353 4960  KtmRm - ok
11:00:29.0384 4960  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows

11:00:29.0384 4960  LanmanServer - ok
11:00:29.0431 4960  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows

11:00:29.0431 4960  LanmanWorkstation - ok
11:00:29.0478 4960  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows

11:00:29.0478 4960  lltdio - ok
11:00:29.0509 4960  [ C1185803384AB3FEED115F79F109427F ] lltdsvc         C:\Windows

11:00:29.0509 4960  lltdsvc - ok
11:00:29.0540 4960  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts         C:\Windows

11:00:29.0540 4960  lmhosts - ok
11:00:29.0602 4960  [ 23D990150D56B670A62B21B9ABDD45EE ] LMS             C:\Program Files 

(x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:00:29.0602 4960  LMS - ok
11:00:29.0649 4960  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows

11:00:29.0649 4960  LSI_FC - ok
11:00:29.0665 4960  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS         C:\Windows

11:00:29.0665 4960  LSI_SAS - ok
11:00:29.0680 4960  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows

11:00:29.0680 4960  LSI_SAS2 - ok
11:00:29.0696 4960  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows

11:00:29.0696 4960  LSI_SCSI - ok
11:00:29.0727 4960  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv           C:\Windows

11:00:29.0727 4960  luafv - ok
11:00:29.0774 4960  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc         C:\Windows

11:00:29.0790 4960  Mcx2Svc - ok
11:00:29.0790 4960  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas         C:\Windows

11:00:29.0805 4960  megasas - ok
11:00:29.0821 4960  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows

11:00:29.0821 4960  MegaSR - ok
11:00:29.0914 4960  [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit 

Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
11:00:29.0914 4960  Microsoft Office Groove Audit Service - ok
11:00:29.0946 4960  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS           C:\Windows

11:00:29.0946 4960  MMCSS - ok
11:00:30.0039 4960  [ 1CE0621B591913C12BECAA5B50E88BB2 ] Mobile Partner. RunOuc C:\Program 

Files (x86)\Mobile Partner\UpdateDog\ouc.exe
11:00:30.0055 4960  Mobile Partner. RunOuc - ok
11:00:30.0102 4960  [ 15E399875C850B54FC253A2323AD8021 ] mod7700         C:\Windows

11:00:30.0117 4960  mod7700 - ok
11:00:30.0133 4960  [ 800BA92F7010378B09F9ED9270F07137 ] Modem           C:\Windows

11:00:30.0133 4960  Modem - ok
11:00:30.0180 4960  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor         C:\Windows

11:00:30.0180 4960  monitor - ok
11:00:30.0226 4960  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows

11:00:30.0226 4960  mouclass - ok
11:00:30.0258 4960  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows

11:00:30.0258 4960  mouhid - ok
11:00:30.0289 4960  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows

11:00:30.0289 4960  mountmgr - ok
11:00:30.0382 4960  [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files 

(x86)\Mozilla Maintenance Service\maintenanceservice.exe
11:00:30.0382 4960  MozillaMaintenance - ok
11:00:30.0398 4960  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows

11:00:30.0414 4960  mpio - ok
11:00:30.0429 4960  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows

11:00:30.0429 4960  mpsdrv - ok
11:00:30.0460 4960  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows

11:00:30.0476 4960  MRxDAV - ok
11:00:30.0507 4960  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows

11:00:30.0523 4960  mrxsmb - ok
11:00:30.0554 4960  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows

11:00:30.0570 4960  mrxsmb10 - ok
11:00:30.0585 4960  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows

11:00:30.0585 4960  mrxsmb20 - ok
11:00:30.0632 4960  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows

11:00:30.0632 4960  msahci - ok
11:00:30.0663 4960  [ DB801A638D011B9633829EB6F663C900 ] msdsm           C:\Windows

11:00:30.0663 4960  msdsm - ok
11:00:30.0679 4960  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC           C:\Windows

11:00:30.0694 4960  MSDTC - ok
11:00:30.0741 4960  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows

11:00:30.0741 4960  Msfs - ok
11:00:30.0772 4960  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf       C:\Windows

11:00:30.0772 4960  mshidkmdf - ok
11:00:30.0788 4960  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows

11:00:30.0788 4960  msisadrv - ok
11:00:30.0819 4960  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI         C:\Windows

11:00:30.0835 4960  MSiSCSI - ok
11:00:30.0835 4960  msiserver - ok
11:00:30.0866 4960  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV         C:\Windows

11:00:30.0866 4960  MSKSSRV - ok
11:00:30.0882 4960  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows

11:00:30.0882 4960  MSPCLOCK - ok
11:00:30.0897 4960  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM           C:\Windows

11:00:30.0897 4960  MSPQM - ok
11:00:30.0944 4960  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC           C:\Windows

11:00:30.0960 4960  MsRPC - ok
11:00:31.0006 4960  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows

11:00:31.0006 4960  mssmbios - ok
11:00:31.0022 4960  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE           C:\Windows

11:00:31.0022 4960  MSTEE - ok
11:00:31.0038 4960  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows

11:00:31.0038 4960  MTConfig - ok
11:00:31.0053 4960  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup             C:\Windows

11:00:31.0053 4960  Mup - ok
11:00:31.0100 4960  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows

11:00:31.0116 4960  napagent - ok
11:00:31.0162 4960  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP     C:\Windows

11:00:31.0162 4960  NativeWifiP - ok
11:00:31.0240 4960  [ 760E38053BF56E501D562B70AD796B88 ] NDIS            C:\Windows

11:00:31.0256 4960  NDIS - ok
11:00:31.0287 4960  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap         C:\Windows

11:00:31.0287 4960  NdisCap - ok
11:00:31.0334 4960  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows

11:00:31.0334 4960  NdisTapi - ok
11:00:31.0381 4960  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio         C:\Windows

11:00:31.0381 4960  Ndisuio - ok
11:00:31.0428 4960  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan         C:\Windows

11:00:31.0428 4960  NdisWan - ok
11:00:31.0474 4960  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy         C:\Windows

11:00:31.0474 4960  NDProxy - ok
11:00:31.0521 4960  [ 6F4607E2333FE21E9E3FF8133A88B35B ] Netaapl         C:\Windows

11:00:31.0521 4960  Netaapl - ok
11:00:31.0568 4960  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS         C:\Windows

11:00:31.0568 4960  NetBIOS - ok
11:00:31.0615 4960  [ 09594D1089C523423B32A4229263F068 ] NetBT           C:\Windows

11:00:31.0615 4960  NetBT - ok
11:00:31.0630 4960  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows

11:00:31.0630 4960  Netlogon - ok
11:00:31.0677 4960  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows

11:00:31.0677 4960  Netman - ok
11:00:31.0693 4960  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows

11:00:31.0708 4960  netprofm - ok
11:00:31.0724 4960  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows

\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:00:31.0740 4960  NetTcpPortSharing - ok
11:00:31.0771 4960  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960         C:\Windows

11:00:31.0771 4960  nfrd960 - ok
11:00:31.0818 4960  [ 8AD77806D336673F270DB31645267293 ] NlaSvc          C:\Windows

11:00:31.0818 4960  NlaSvc - ok
11:00:31.0864 4960  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows

11:00:31.0864 4960  Npfs - ok
11:00:31.0896 4960  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi             C:\Windows

11:00:31.0896 4960  nsi - ok
11:00:31.0911 4960  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows

11:00:31.0911 4960  nsiproxy - ok
11:00:31.0974 4960  [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs            C:\Windows

11:00:31.0989 4960  Ntfs - ok
11:00:32.0005 4960  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows

11:00:32.0005 4960  Null - ok
11:00:32.0020 4960  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows

11:00:32.0036 4960  nvraid - ok
11:00:32.0067 4960  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows

11:00:32.0067 4960  nvstor - ok
11:00:32.0098 4960  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows

11:00:32.0114 4960  nv_agp - ok
11:00:32.0161 4960  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files 

(x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
11:00:32.0176 4960  odserv - ok
11:00:32.0223 4960  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows

11:00:32.0223 4960  ohci1394 - ok
11:00:32.0254 4960  [ 5A432A042DAE460ABE7199B758E8606C ] ose             C:\Program Files 

(x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:00:32.0270 4960  ose - ok
11:00:32.0301 4960  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows

11:00:32.0301 4960  p2pimsvc - ok
11:00:32.0348 4960  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows

11:00:32.0364 4960  p2psvc - ok
11:00:32.0379 4960  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport         C:\Windows

11:00:32.0379 4960  Parport - ok
11:00:32.0410 4960  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr         C:\Windows

11:00:32.0410 4960  partmgr - ok
11:00:32.0426 4960  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows

11:00:32.0442 4960  PcaSvc - ok
11:00:32.0457 4960  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci             C:\Windows

11:00:32.0457 4960  pci - ok
11:00:32.0488 4960  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows

11:00:32.0488 4960  pciide - ok
11:00:32.0520 4960  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows

11:00:32.0520 4960  pcmcia - ok
11:00:32.0535 4960  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw             C:\Windows

11:00:32.0535 4960  pcw - ok
11:00:32.0566 4960  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows

11:00:32.0582 4960  PEAUTH - ok
11:00:32.0660 4960  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows

11:00:32.0676 4960  PerfHost - ok
11:00:32.0738 4960  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla             C:\Windows

11:00:32.0754 4960  pla - ok
11:00:32.0800 4960  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows

11:00:32.0800 4960  PlugPlay - ok
11:00:32.0894 4960  [ AFA7A2192F0E52ACC715637227AB360F ] PMBDeviceInfoProvider C:\Program 

Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
11:00:32.0925 4960  PMBDeviceInfoProvider - ok
11:00:32.0956 4960  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg     C:\Windows

11:00:32.0956 4960  PNRPAutoReg - ok
11:00:32.0972 4960  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc         C:\Windows

11:00:32.0988 4960  PNRPsvc - ok
11:00:33.0019 4960  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent     C:\Windows

11:00:33.0034 4960  PolicyAgent - ok
11:00:33.0081 4960  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power           C:\Windows

11:00:33.0081 4960  Power - ok
11:00:33.0128 4960  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows

11:00:33.0128 4960  PptpMiniport - ok
11:00:33.0144 4960  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor       C:\Windows

11:00:33.0144 4960  Processor - ok
11:00:33.0190 4960  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc         C:\Windows

11:00:33.0206 4960  ProfSvc - ok
11:00:33.0222 4960  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows

11:00:33.0222 4960  ProtectedStorage - ok
11:00:33.0268 4960  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows

11:00:33.0268 4960  Psched - ok
11:00:33.0315 4960  [ 46851BC18322DA70F3F2299A1007C479 ] PxHlpa64        C:\Windows

11:00:33.0315 4960  PxHlpa64 - ok
11:00:33.0362 4960  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows

11:00:33.0378 4960  ql2300 - ok
11:00:33.0409 4960  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows

11:00:33.0409 4960  ql40xx - ok
11:00:33.0440 4960  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE           C:\Windows

11:00:33.0456 4960  QWAVE - ok
11:00:33.0471 4960  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows

11:00:33.0471 4960  QWAVEdrv - ok
11:00:33.0487 4960  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows

11:00:33.0487 4960  RasAcd - ok
11:00:33.0518 4960  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn     C:\Windows

11:00:33.0518 4960  RasAgileVpn - ok
11:00:33.0534 4960  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto         C:\Windows

11:00:33.0549 4960  RasAuto - ok
11:00:33.0580 4960  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp         C:\Windows

11:00:33.0580 4960  Rasl2tp - ok
11:00:33.0627 4960  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows

11:00:33.0643 4960  RasMan - ok
11:00:33.0674 4960  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows

11:00:33.0674 4960  RasPppoe - ok
11:00:33.0690 4960  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp         C:\Windows

11:00:33.0690 4960  RasSstp - ok
11:00:33.0721 4960  [ 77F665941019A1594D887A74F301FA2F ] rdbss           C:\Windows

11:00:33.0721 4960  rdbss - ok
11:00:33.0736 4960  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows

11:00:33.0736 4960  rdpbus - ok
11:00:33.0768 4960  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows

11:00:33.0768 4960  RDPCDD - ok
11:00:33.0799 4960  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows

11:00:33.0799 4960  RDPENCDD - ok
11:00:33.0799 4960  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows

11:00:33.0799 4960  RDPREFMP - ok
11:00:33.0830 4960  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD           C:\Windows

11:00:33.0830 4960  RDPWD - ok
11:00:33.0877 4960  [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost        C:\Windows

11:00:33.0877 4960  rdyboost - ok
11:00:33.0924 4960  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows

11:00:33.0924 4960  RemoteAccess - ok
11:00:33.0955 4960  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows

11:00:33.0955 4960  RemoteRegistry - ok
11:00:34.0002 4960  [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM          C:\Windows

11:00:34.0017 4960  RFCOMM - ok
11:00:34.0080 4960  [ F12A68ED55053940CADD59CA5E3468DD ] RichVideo       C:\Program Files 

(x86)\CyberLink\Shared files\RichVideo.exe
11:00:34.0095 4960  RichVideo - ok
11:00:34.0126 4960  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows

11:00:34.0126 4960  RpcEptMapper - ok
11:00:34.0189 4960  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows

11:00:34.0189 4960  RpcLocator - ok
11:00:34.0220 4960  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs           C:\Windows

11:00:34.0236 4960  RpcSs - ok
11:00:34.0267 4960  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows

11:00:34.0267 4960  rspndr - ok
11:00:34.0314 4960  [ BFE0EF0C4C15820698F50AD73AF5E35F ] RTL8167         C:\Windows

11:00:34.0314 4960  RTL8167 - ok
11:00:34.0392 4960  [ 4CA0DBA9E224473D664C25E411F5A3BD ] rtport          C:\Windows

11:00:34.0392 4960  rtport - ok
11:00:34.0423 4960  [ 62DB6CC4B0818F1B5F3441241B098F12 ] SABI            C:\Windows

11:00:34.0423 4960  SABI - ok
11:00:34.0438 4960  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs           C:\Windows

11:00:34.0438 4960  SamSs - ok
11:00:34.0470 4960  [ D641337B75B9A9D5AE10687AA1097755 ] Samsung UPD Service C:\Windows

11:00:34.0470 4960  Samsung UPD Service - ok
11:00:34.0516 4960  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows

11:00:34.0516 4960  sbp2port - ok
11:00:34.0610 4960  [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService  C:\Program Files 

(x86)\Spybot - Search & Destroy\SDWinSec.exe
11:00:34.0641 4960  SBSDWSCService - ok
11:00:34.0657 4960  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows

11:00:34.0657 4960  SCardSvr - ok
11:00:34.0688 4960  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows

11:00:34.0688 4960  scfilter - ok
11:00:34.0750 4960  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows

11:00:34.0766 4960  Schedule - ok
11:00:34.0797 4960  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc     C:\Windows

11:00:34.0813 4960  SCPolicySvc - ok
11:00:34.0844 4960  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows

11:00:34.0844 4960  SDRSVC - ok
11:00:34.0891 4960  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows

11:00:34.0891 4960  secdrv - ok
11:00:34.0922 4960  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows

11:00:34.0922 4960  seclogon - ok
11:00:34.0953 4960  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows

11:00:34.0953 4960  SENS - ok
11:00:34.0984 4960  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows

11:00:34.0984 4960  SensrSvc - ok
11:00:35.0031 4960  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum         C:\Windows

11:00:35.0031 4960  Serenum - ok
11:00:35.0062 4960  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows

11:00:35.0062 4960  Serial - ok
11:00:35.0109 4960  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows

11:00:35.0109 4960  sermouse - ok
11:00:35.0172 4960  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows

11:00:35.0172 4960  SessionEnv - ok
11:00:35.0203 4960  [ A554811BCD09279536440C964AE35BBF ] sffdisk         C:\Windows

11:00:35.0218 4960  sffdisk - ok
11:00:35.0234 4960  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows

11:00:35.0234 4960  sffp_mmc - ok
11:00:35.0250 4960  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd         C:\Windows

11:00:35.0250 4960  sffp_sd - ok
11:00:35.0281 4960  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy         C:\Windows

11:00:35.0281 4960  sfloppy - ok
11:00:35.0343 4960  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows

11:00:35.0343 4960  ShellHWDetection - ok
11:00:35.0374 4960  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows

11:00:35.0374 4960  SiSRaid2 - ok
11:00:35.0390 4960  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows

11:00:35.0390 4960  SiSRaid4 - ok
11:00:35.0484 4960  [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate     C:\Program Files 

11:00:35.0499 4960  SkypeUpdate - ok
11:00:35.0515 4960  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb             C:\Windows

11:00:35.0515 4960  Smb - ok
11:00:35.0577 4960  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows

11:00:35.0577 4960  SNMPTRAP - ok
11:00:35.0608 4960  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr           C:\Windows

11:00:35.0608 4960  spldr - ok
11:00:35.0671 4960  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler         C:\Windows

11:00:35.0671 4960  Spooler - ok
11:00:35.0811 4960  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows

11:00:35.0905 4960  sppsvc - ok
11:00:35.0936 4960  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify     C:\Windows

11:00:35.0952 4960  sppuinotify - ok
11:00:35.0983 4960  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv             C:\Windows

11:00:35.0998 4960  srv - ok
11:00:36.0014 4960  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows

11:00:36.0014 4960  srv2 - ok
11:00:36.0030 4960  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows

11:00:36.0030 4960  srvnet - ok
11:00:36.0061 4960  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV         C:\Windows

11:00:36.0076 4960  SSDPSRV - ok
11:00:36.0092 4960  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc         C:\Windows

11:00:36.0092 4960  SstpSvc - ok
11:00:36.0139 4960  [ C692C94FE55CAD0633440236022C27B3 ] ssudmdm         C:\Windows

11:00:36.0139 4960  ssudmdm - ok
11:00:36.0201 4960  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows

11:00:36.0201 4960  stexstor - ok
11:00:36.0232 4960  [ DECACB6921DED1A38642642685D77DAC ] StillCam        C:\Windows

11:00:36.0248 4960  StillCam - ok
11:00:36.0310 4960  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows

11:00:36.0326 4960  stisvc - ok
11:00:36.0357 4960  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows

11:00:36.0357 4960  swenum - ok
11:00:36.0388 4960  [ E08E46FDD841B7184194011CA1955A0B ] swprv           C:\Windows

11:00:36.0404 4960  swprv - ok
11:00:36.0466 4960  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain         C:\Windows

11:00:36.0482 4960  SysMain - ok
11:00:36.0513 4960  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows

11:00:36.0529 4960  TabletInputService - ok
11:00:36.0560 4960  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv         C:\Windows

11:00:36.0576 4960  TapiSrv - ok
11:00:36.0607 4960  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS             C:\Windows

11:00:36.0607 4960  TBS - ok
11:00:36.0685 4960  [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip           C:\Windows

11:00:36.0716 4960  Tcpip - ok
11:00:36.0747 4960  [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6          C:\Windows

11:00:36.0763 4960  TCPIP6 - ok
11:00:36.0794 4960  [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg        C:\Windows

11:00:36.0794 4960  tcpipreg - ok
11:00:36.0825 4960  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows

11:00:36.0825 4960  TDPIPE - ok
11:00:36.0841 4960  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP           C:\Windows

11:00:36.0841 4960  TDTCP - ok
11:00:36.0888 4960  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx             C:\Windows

11:00:36.0888 4960  tdx - ok
11:00:36.0919 4960  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows

11:00:36.0919 4960  TermDD - ok
11:00:36.0966 4960  [ 2E648163254233755035B46DD7B89123 ] TermService     C:\Windows

11:00:36.0981 4960  TermService - ok
11:00:37.0012 4960  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows

11:00:37.0012 4960  Themes - ok
11:00:37.0044 4960  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER     C:\Windows

11:00:37.0044 4960  THREADORDER - ok
11:00:37.0059 4960  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows

11:00:37.0075 4960  TrkWks - ok
11:00:37.0137 4960  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows

11:00:37.0137 4960  TrustedInstaller - ok
11:00:37.0215 4960  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows

11:00:37.0215 4960  tssecsrv - ok
11:00:37.0262 4960  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows

11:00:37.0262 4960  TsUsbFlt - ok
11:00:37.0309 4960  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows

11:00:37.0309 4960  tunnel - ok
11:00:37.0356 4960  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows

11:00:37.0356 4960  uagp35 - ok
11:00:37.0418 4960  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows

11:00:37.0418 4960  udfs - ok
11:00:37.0449 4960  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect       C:\Windows

11:00:37.0449 4960  UI0Detect - ok
11:00:37.0480 4960  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows

11:00:37.0480 4960  uliagpkx - ok
11:00:37.0543 4960  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus           C:\Windows

11:00:37.0543 4960  umbus - ok
11:00:37.0558 4960  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows

11:00:37.0558 4960  UmPass - ok
11:00:37.0683 4960  [ CBDEE152D73200EE49031A26310B9D3E ] UNS             C:\Program Files 

(x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
11:00:37.0714 4960  UNS - ok
11:00:37.0746 4960  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows

11:00:37.0761 4960  upnphost - ok
11:00:37.0792 4960  [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64       C:\Windows

11:00:37.0808 4960  USBAAPL64 - ok
11:00:37.0839 4960  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp         C:\Windows

11:00:37.0839 4960  usbccgp - ok
11:00:37.0870 4960  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows

11:00:37.0870 4960  usbcir - ok
11:00:37.0902 4960  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci         C:\Windows

11:00:37.0902 4960  usbehci - ok
11:00:37.0933 4960  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows

11:00:37.0933 4960  usbhub - ok
11:00:37.0964 4960  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci         C:\Windows

11:00:37.0964 4960  usbohci - ok
11:00:38.0011 4960  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows

11:00:38.0011 4960  usbprint - ok
11:00:38.0058 4960  [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan         C:\Windows

11:00:38.0073 4960  usbscan - ok
11:00:38.0089 4960  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR         C:\Windows

11:00:38.0089 4960  USBSTOR - ok
11:00:38.0136 4960  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci         C:\Windows

11:00:38.0136 4960  usbuhci - ok
11:00:38.0198 4960  [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo        C:\Windows

11:00:38.0198 4960  usbvideo - ok
11:00:38.0229 4960  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms           C:\Windows

11:00:38.0229 4960  UxSms - ok
11:00:38.0245 4960  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows

11:00:38.0245 4960  VaultSvc - ok
11:00:38.0307 4960  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows

11:00:38.0307 4960  vdrvroot - ok
11:00:38.0338 4960  [ 8D6B481601D01A456E75C3210F1830BE ] vds             C:\Windows

11:00:38.0354 4960  vds - ok
11:00:38.0385 4960  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga             C:\Windows

11:00:38.0385 4960  vga - ok
11:00:38.0416 4960  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave         C:\Windows

11:00:38.0416 4960  VgaSave - ok
11:00:38.0463 4960  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp           C:\Windows

11:00:38.0463 4960  vhdmp - ok
11:00:38.0494 4960  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows

11:00:38.0494 4960  viaide - ok
11:00:38.0526 4960  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows

11:00:38.0526 4960  volmgr - ok
11:00:38.0541 4960  [ A255814907C89BE58B79EF2F189B843B ] volmgrx         C:\Windows

11:00:38.0557 4960  volmgrx - ok
11:00:38.0572 4960  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap         C:\Windows

11:00:38.0572 4960  volsnap - ok
11:00:38.0619 4960  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid         C:\Windows

11:00:38.0619 4960  vsmraid - ok
11:00:38.0682 4960  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS             C:\Windows

11:00:38.0697 4960  VSS - ok
11:00:38.0728 4960  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows

11:00:38.0728 4960  vwifibus - ok
11:00:38.0728 4960  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows

11:00:38.0728 4960  vwififlt - ok
11:00:38.0760 4960  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time         C:\Windows

11:00:38.0775 4960  W32Time - ok
11:00:38.0791 4960  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows

11:00:38.0806 4960  WacomPen - ok
11:00:38.0853 4960  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows

11:00:38.0853 4960  WANARP - ok
11:00:38.0853 4960  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows

11:00:38.0869 4960  Wanarpv6 - ok
11:00:38.0947 4960  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc     C:\Windows

11:00:38.0994 4960  WatAdminSvc - ok
11:00:39.0072 4960  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows

11:00:39.0087 4960  wbengine - ok
11:00:39.0118 4960  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows

11:00:39.0118 4960  WbioSrvc - ok
11:00:39.0150 4960  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc         C:\Windows

11:00:39.0165 4960  wcncsvc - ok
11:00:39.0165 4960  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows

11:00:39.0165 4960  WcsPlugInService - ok
11:00:39.0196 4960  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows

11:00:39.0196 4960  Wd - ok
11:00:39.0243 4960  [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000        C:\Windows

11:00:39.0259 4960  Wdf01000 - ok
11:00:39.0274 4960  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows

11:00:39.0274 4960  WdiServiceHost - ok
11:00:39.0290 4960  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost   C:\Windows

11:00:39.0290 4960  WdiSystemHost - ok
11:00:39.0337 4960  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient       C:\Windows

11:00:39.0337 4960  WebClient - ok
11:00:39.0352 4960  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows

11:00:39.0368 4960  Wecsvc - ok
11:00:39.0384 4960  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport   C:\Windows

11:00:39.0384 4960  wercplsupport - ok
11:00:39.0415 4960  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows

11:00:39.0415 4960  WerSvc - ok
11:00:39.0462 4960  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows

11:00:39.0462 4960  WfpLwf - ok
11:00:39.0477 4960  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows

11:00:39.0477 4960  WIMMount - ok
11:00:39.0477 4960  WinHttpAutoProxySvc - ok
11:00:39.0540 4960  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt         C:\Windows

11:00:39.0540 4960  Winmgmt - ok
11:00:39.0618 4960  [ BCB1310604AA415C4508708975B3931E ] WinRM           C:\Windows

11:00:39.0664 4960  WinRM - ok
11:00:39.0727 4960  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows

11:00:39.0727 4960  WinUsb - ok
11:00:39.0774 4960  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc         C:\Windows

11:00:39.0789 4960  Wlansvc - ok
11:00:39.0883 4960  [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc        C:\Program Files

\Windows Live\Mesh\wlcrasvc.exe
11:00:39.0883 4960  wlcrasvc - ok
11:00:39.0961 4960  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc         C:\Program Files

\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
11:00:39.0992 4960  wlidsvc - ok
11:00:40.0023 4960  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi         C:\Windows

11:00:40.0023 4960  WmiAcpi - ok
11:00:40.0054 4960  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows

11:00:40.0070 4960  wmiApSrv - ok
11:00:40.0101 4960  WMPNetworkSvc - ok
11:00:40.0132 4960  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows

11:00:40.0132 4960  WPCSvc - ok
11:00:40.0179 4960  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows

11:00:40.0179 4960  WPDBusEnum - ok
11:00:40.0210 4960  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl         C:\Windows

11:00:40.0210 4960  ws2ifsl - ok
11:00:40.0210 4960  WSearch - ok
11:00:40.0304 4960  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows

11:00:40.0335 4960  wuauserv - ok
11:00:40.0366 4960  [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf          C:\Windows

11:00:40.0366 4960  WudfPf - ok
11:00:40.0398 4960  [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd          C:\Windows

11:00:40.0398 4960  WUDFRd - ok
11:00:40.0429 4960  [ B20F051B03A966392364C83F009F7D17 ] wudfsvc         C:\Windows

11:00:40.0429 4960  wudfsvc - ok
11:00:40.0460 4960  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc         C:\Windows

11:00:40.0460 4960  WwanSvc - ok
11:00:40.0522 4960  ================ Scan global ===============================
11:00:40.0554 4960  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
11:00:40.0585 4960  [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
11:00:40.0600 4960  [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
11:00:40.0632 4960  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
11:00:40.0663 4960  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
11:00:40.0663 4960  [Global] - ok
11:00:40.0663 4960  ================ Scan MBR ==================================
11:00:40.0678 4960  [ 2E5DEBB2116B3417023E0D6562D7ED07 ] \Device\Harddisk0\DR0
11:00:41.0131 4960  \Device\Harddisk0\DR0 - ok
11:00:41.0131 4960  ================ Scan VBR ==================================
11:00:41.0131 4960  [ 703B8AC6B5FE574C87C48C3485F56A04 ] \Device\Harddisk0\DR0\Partition1
11:00:41.0131 4960  \Device\Harddisk0\DR0\Partition1 - ok
11:00:41.0162 4960  [ B153CE70F7F4DB238AB04040FBDF79E8 ] \Device\Harddisk0\DR0\Partition2
11:00:41.0162 4960  \Device\Harddisk0\DR0\Partition2 - ok
11:00:41.0193 4960  [ 6ACE0DBD7489536CF8BB5C1EF33C45EB ] \Device\Harddisk0\DR0\Partition3
11:00:41.0193 4960  \Device\Harddisk0\DR0\Partition3 - ok
11:00:41.0193 4960  ============================================================
11:00:41.0193 4960  Scan finished
11:00:41.0193 4960  ============================================================
11:00:41.0209 2280  Detected object count: 0
11:00:41.0209 2280  Actual detected object count: 0

----------------SCHRITT 4 dds.txt------------------------

DDS Logfile:
DDS Logfile:
DDS Logfile:
DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 8.0.7601.17514  BrowserJavaVersion: 10.9.2
Run by Dennis at 12:02:44 on 2012-12-30
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3893.3039 [GMT 1:00]
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uDefault_Page_URL = hxxp://samsung.msn.com
mStart Page = hxxp://samsung.msn.com
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - <orphaned>
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: An vorhandene PDF-Datei anfügen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Bild an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Free YouTube to MP3 Converter - C:\Users\Dennis\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: In Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Linkziel an vorhandene PDF-Datei anhängen - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Linkziel in Adobe PDF konvertieren - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Nach Microsoft E&xel exportieren - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://active.macromedia.com/flash2/cabs/swflash.cab
TCP: NameServer =
TCP: Interfaces\{02A037B1-9057-4233-8DCE-5270B2219720} : DHCPNameServer =
TCP: Interfaces\{02A037B1-9057-4233-8DCE-5270B2219720}\5416379724F687D2641373143383 : DHCPNameServer =
TCP: Interfaces\{02A037B1-9057-4233-8DCE-5270B2219720}\75C414E4D2030313144364936393733433 : DHCPNameServer =
TCP: Interfaces\{177BEB8A-FE68-4DA3-B29A-15B7438D4351} : NameServer =
TCP: Interfaces\{44237ED6-4043-4B5B-BA86-E0AF28C91C19} : NameServer =
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll c:\progra~3\browse~1\22643~1.41\{16cdf~1\browse~1.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\ly0anwrd.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\ly0anwrd.default\extensions\{213c8ed6-1d78-4d8f-8729-25006aa86a76}\plugins\np-mswmp.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-12-13 18:32; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\ly0anwrd.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF - ExtSQL: 2012-12-27 10:48; {213c8ed6-1d78-4d8f-8729-25006aa86a76}; C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\ly0anwrd.default\extensions\{213c8ed6-1d78-4d8f-8729-25006aa86a76}
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-11-1 53488]
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2012-11-3 27800]
R1 SABI;SAMSUNG Kernel Driver For Windows 7;C:\Windows\System32\drivers\SABI.sys [2010-12-30 13824]
R2 AntiVirSchedulerService;Avira Planer;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-11-3 85280]
R2 AntiVirService;Avira Echtzeit-Scanner;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-11-3 109344]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2012-11-3 99912]
R2 Browser Manager;Browser Manager;C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [2012-10-11 2309656]
R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [2012-9-25 474208]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-30 2533400]
R3 BTWAMPFL;BTWAMPFL;C:\Windows\System32\drivers\btwampfl.sys [2011-5-19 348712]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-5-19 39464]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-11-10 31088]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2012-4-25 258896]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-12-31 56344]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2012-4-5 86016]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-12-31 158976]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-12-31 289280]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-12-30 409192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 Mobile Partner. RunOuc;Mobile Partner. OUC;C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe [2012-4-5 246112]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-5-21 1153368]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2012-11-8 102368]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\System32\drivers\ew_hwusbdev.sys [2012-4-5 117248]
S3 ewusbmbb;HUAWEI USB-WWAN miniport;C:\Windows\System32\drivers\ewusbwwan.sys [2012-4-5 421376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-6-12 1038088]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;C:\Windows\System32\drivers\ewdcsc.sys [2012-11-18 32768]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2011-5-10 22528]
S3 Samsung UPD Service;Samsung UPD Service;C:\Windows\System32\SUPDSvc.exe [2011-5-19 166704]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2012-11-8 203104]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-26 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows-Aktivierungstechnologieservice;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-3-11 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
=============== Created Last 30 ================
2012-12-25 18:24:57	--------	d-----w-	C:\Program Files\CCleaner
2012-12-21 19:55:06	46080	----a-w-	C:\Windows\System32\atmlib.dll
2012-12-21 19:55:06	34304	----a-w-	C:\Windows\SysWow64\atmlib.dll
2012-12-21 19:55:05	367616	----a-w-	C:\Windows\System32\atmfd.dll
2012-12-21 19:55:05	295424	----a-w-	C:\Windows\SysWow64\atmfd.dll
2012-12-12 15:27:59	424960	----a-w-	C:\Windows\System32\KernelBase.dll
==================== Find3M  ====================
2012-12-11 19:23:15	73656	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-11 19:23:15	697272	----a-w-	C:\Windows\SysWow64\FlashPlayerApp.exe
2012-12-11 18:21:06	99912	----a-w-	C:\Windows\System32\drivers\avgntflt.sys
2012-11-22 03:26:40	3149824	----a-w-	C:\Windows\System32\win32k.sys
2012-11-12 12:28:37	1638912	----a-w-	C:\Windows\System32\mshtml.tlb
2012-11-12 11:52:18	1638912	----a-w-	C:\Windows\SysWow64\mshtml.tlb
2012-11-09 05:45:09	2048	----a-w-	C:\Windows\System32\tzres.dll
2012-11-09 04:42:49	2048	----a-w-	C:\Windows\SysWow64\tzres.dll
2012-11-02 05:59:11	478208	----a-w-	C:\Windows\System32\dpnet.dll
2012-11-02 05:11:31	376832	----a-w-	C:\Windows\SysWow64\dpnet.dll
2012-10-27 06:26:55	981504	----a-w-	C:\Windows\SysWow64\wininet.dll
2012-10-27 05:51:21	1188864	----a-w-	C:\Windows\System32\wininet.dll
2012-10-16 08:38:37	135168	----a-w-	C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38:34	350208	----a-w-	C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39:52	561664	----a-w-	C:\Windows\apppatch\AcLayers.dll
2012-10-09 18:17:13	55296	----a-w-	C:\Windows\System32\dhcpcsvc6.dll
2012-10-09 18:17:13	226816	----a-w-	C:\Windows\System32\dhcpcore6.dll
2012-10-09 17:40:31	44032	----a-w-	C:\Windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40:31	193536	----a-w-	C:\Windows\SysWow64\dhcpcore6.dll
2012-10-04 17:46:16	362496	----a-w-	C:\Windows\System32\wow64win.dll
2012-10-04 17:46:15	243200	----a-w-	C:\Windows\System32\wow64.dll
2012-10-04 17:46:15	13312	----a-w-	C:\Windows\System32\wow64cpu.dll
2012-10-04 17:45:55	215040	----a-w-	C:\Windows\System32\winsrv.dll
2012-10-04 17:43:28	16384	----a-w-	C:\Windows\System32\ntvdm64.dll
2012-10-04 16:47:41	5120	----a-w-	C:\Windows\SysWow64\wow32.dll
2012-10-04 16:47:41	274944	----a-w-	C:\Windows\SysWow64\KernelBase.dll
2012-10-04 15:21:55	338432	----a-w-	C:\Windows\System32\conhost.exe
2012-10-04 14:46:46	7680	----a-w-	C:\Windows\SysWow64\instnm.exe
2012-10-04 14:46:46	25600	----a-w-	C:\Windows\SysWow64\setup16.exe
2012-10-04 14:46:44	14336	----a-w-	C:\Windows\SysWow64\ntvdm64.dll
2012-10-04 14:46:43	2048	----a-w-	C:\Windows\SysWow64\user.exe
2012-10-04 14:41:50	6144	---ha-w-	C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-10-04 14:41:50	4608	---ha-w-	C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-10-04 14:41:50	3584	---ha-w-	C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-10-04 14:41:50	3072	---ha-w-	C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-10-03 17:56:54	1914248	----a-w-	C:\Windows\System32\drivers\tcpip.sys
2012-10-03 17:44:21	70656	----a-w-	C:\Windows\System32\nlaapi.dll
2012-10-03 17:44:21	303104	----a-w-	C:\Windows\System32\nlasvc.dll
2012-10-03 17:44:17	246272	----a-w-	C:\Windows\System32\netcorehc.dll
2012-10-03 17:44:17	18944	----a-w-	C:\Windows\System32\netevent.dll
2012-10-03 17:44:16	216576	----a-w-	C:\Windows\System32\ncsi.dll
2012-10-03 17:42:16	569344	----a-w-	C:\Windows\System32\iphlpsvc.dll
2012-10-03 16:42:24	18944	----a-w-	C:\Windows\SysWow64\netevent.dll
2012-10-03 16:42:24	175104	----a-w-	C:\Windows\SysWow64\netcorehc.dll
2012-10-03 16:42:23	156672	----a-w-	C:\Windows\SysWow64\ncsi.dll
2012-10-03 16:07:26	45568	----a-w-	C:\Windows\System32\drivers\tcpipreg.sys
============= FINISH: 12:03:17,92 ===============
--- --- ---
--- --- ---

--- --- ---


-----------------SCHRITT 5 attach.txt---------------------------------


DDS (Ver_2012-11-20.01)
Microsoft Windows 7 Home Premium 
Boot Device: \Device\HarddiskVolume1
Install Date: 19.05.2011 20:14:48
System Uptime: 30.12.2012 08:55:02 (4 hours ago)
Motherboard: SAMSUNG ELECTRONICS CO., LTD. |  | RV411/RV511/E3511/S3511    
Processor: Intel(R) Core(TM) i3 CPU       M 380  @ 2.53GHz | CPU 1 | 911/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 72 GiB total, 19,932 GiB free.
D: is FIXED (NTFS) - 205 GiB total, 94,647 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
 Update for Microsoft Office 2007 (KB2508958)
???? ??? Windows Live
???? Windows Live
????? Messenger
????? Windows Live
?????? ??????? ?? Windows Live
???????? ?? Messenger
???????? ?????????? Windows Live
????????? Messenger
?????????? Windows Live
??????????? ?? Windows Live
Adobe Acrobat 9 Pro - English, Français, Deutsch
Adobe Acrobat 9.5.2 - CPSID_83708
Adobe AIR
Adobe Anchor Service CS4
Adobe Anchor Service x64 CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe CMaps x64 CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Recommended Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Extra Settings CS4
Adobe Color Video Profiles CS CS4
Adobe Creative Suite 4 Design Premium
Adobe CSI CS4
Adobe CSI CS4 x64
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe Drive CS4 x64
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Fonts All
Adobe Fonts All x64
Adobe Linguistics CS4
Adobe Linguistics CS4 x64
Adobe Media Encoder CS4 Importer
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe PDF Library Files x64 CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 (64 Bit)
Adobe Photoshop CS4 Support
Adobe Reader 9.5.2 - Deutsch
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Type Support x64 CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe WinSoft Linguistics Plugin x64
Adobe XMP Panels CS4
Agatha Christie - Death on the Nile
„Messenger“ pagalbine priemone
Atheros Client Installation Program
Avira Free Antivirus
„Windows Live Essentials“
„Windows Live Mail“
„Windows Live Messenger“
„Windows Live“ fotogalerija
Bejeweled 2 Deluxe
Bing Rewards Client Installer
Broadcom 802.11 Network Adapter
Browser Manager
Canon MP Navigator EX 2.0
Chuzzle Deluxe
Complemento Messenger
Complément Messenger
CyberLink Media Suite
CyberLink Media+ Player10
CyberLink MediaShow
CyberLink Power2Go
CyberLink PowerDirector
CyberLink YouCam
Diner Dash 2 Restaurant Rescue
Doplnok programu Messenger
Easy Content Share
Easy Display Manager
Easy Migration
Easy Network Manager
Easy SpeedUp Manager
EPSON BX620FWD Series Handbuch
EPSON BX620FWD Series Netzwerk-Handbuch
EPSON BX620FWD Series Printer Uninstall
Epson Easy Photo Print 2
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
Epson Event Manager
Epson FAX Utility
EpsonNet Print
EpsonNet Setup 3.3
ETDWare PS/2-X64
Farm Frenzy
Fast Start
FileZilla Client
Fotogalerija Windows Live
Free YouTube to MP3 Converter version
Galeria de Fotografias do Windows Live
Galeria fotografii uslugi Windows Live
Galerie de photos Windows Live
Galerie foto Windows Live
Galería fotográfica de Windows Live
Google Earth
Google Update Helper
Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678)
Insaniquarium Deluxe
Intel(R) Control Center
Intel(R) Graphics Media Accelerator Driver
Intel(R) Management Engine Components
Intel(R) Rapid Storage Technology
IrfanView (remove only)
Java 7 Update 9
Java Auto Updater
John Deere Drive Green
Junk Mail filter update
MAGIX Screenshare
MAGIX Speed burnR (MSI)
Mesh Runtime
Messenger ??? ??
Messenger ????
Messenger ?????
Messenger Assistent
Messenger Companion
Messenger kíséro
Messenger Pratilac
Messenger Suradnik
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile DEU Language Pack
Microsoft Application Error Reporting
Microsoft Default Manager
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (German) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (German) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (German) 2007
Microsoft Office InfoPath MUI (German) 2007
Microsoft Office Live Add-in 1.5
Microsoft Office Office 64-bit Components 2007
Microsoft Office OneNote MUI (German) 2007
Microsoft Office Outlook MUI (German) 2007
Microsoft Office PowerPoint MUI (German) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Italian) 2007
Microsoft Office Proofing (German) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (German) 2007
Microsoft Office Shared 64-bit MUI (German) 2007
Microsoft Office Shared MUI (German) 2007
Microsoft Office Word MUI (German) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Mobile Partner
Movie Color Enhancer
Mozilla Firefox 17.0.1 (x86 de)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2721691)
MSXML 4.0 SP3 Parser (KB973685)
PDF Settings CS4
Phase 5 HTML-Editor
Photoshop Camera Raw
Photoshop Camera Raw_x64
Plants vs. Zombies
PlayMemories Home
Poczta uslugi Windows Live
Podstawowe programy Windows Live
Polar Golfer
Pomocnik Messenger
Pošta Windows Live
PriceGong 2.6.7
Raccolta foto di Windows Live
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
S?????? f?t???af??? t?? Windows Live
Samsung AnyWeb Print
Samsung Kies
Samsung Support Center 1.0
Samsung Universal Print Driver
Samsung Universal Scan Driver
Samsung Update Plus
SAMSUNG USB Driver for Mobile Phones
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition 
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition 
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition 
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition 
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition 
Skype™ 5.10
Spremljevalec Messenger
Spybot - Search & Destroy
SRS Premium Sound Control Panel
Suite Shared Configuration CS4
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Outlook 2007 Help (KB963677)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760573) 32-Bit Edition
User Guide
WIDCOMM Bluetooth Software
WildTangent Games
WildTangent ORB Game Console
Windows Live
Windows Live ??
Windows Live ?? ???
Windows Live ???
Windows Live ????
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotótár
Windows Live Foto-galerija
Windows Live fotoattelu galerija
Windows Live Fotogalerie
Windows Live Fotogalleri
Windows Live Fotogaléria
Windows Live Fotograf Galerisi
Windows Live Galeria de Fotos
Windows Live Galerija fotografija
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Pošta
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Temel Parçalar
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Liven asennustyökalu
Windows Liven sähköposti
Windows Liven valokuvavalikoima
WinRAR 4.20 (32-Bit)
Zuma Deluxe
==== End Of File ===========================

So ich glaube das wärs. Es ist noch ein Fenster vom defogger geöffenet.

Dieses fragt mich: Defogger is a tool .... mit Schaltfläche "Disable" oder "Re-enable"

Zitat von ryder Beitrag anzeigen
... und du liest meine Regeln nochmal!
.. ok hab. Ich hoffe ich hab sie auch verstanden .

Alt 30.12.2012, 16:50   #12
/// TB-Ausbilder
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Bevor es weiter geht:

Hast du irgendwie ein System bei dem man in mehrere Betriebssysteme booten kann?
Digitale Freibeuter gegen Malware!
Keine Hilfe per PM!

Alt 30.12.2012, 17:35   #13
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Ich glaube nicht, wäre mir nicht bekannt.

Alt 30.12.2012, 17:53   #14
/// TB-Ausbilder
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

Gut dannnnnnnn

Schritt 1:
aswMBR starten > fix MBR
dauert nur kurz

Schritt 2:

Schritt 3:
neues logfile mit aswmbr machen und posten
Digitale Freibeuter gegen Malware!
Keine Hilfe per PM!

Alt 30.12.2012, 19:24   #15
Blauer Screen nach booten , kein Zugriff auf Desktop etc - Standard

Blauer Screen nach booten , kein Zugriff auf Desktop etc

So, hier:

aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2012-12-30 19:08:37
19:08:37.122    OS Version: Windows x64 6.1.7601 Service Pack 1
19:08:37.122    Number of processors: 4 586 0x2505
19:08:37.122    ComputerName: DENNIS-PC  UserName: Dennis
19:08:37.434    Initialize success
19:08:44.844    AVAST engine defs: 12122900
19:09:01.801    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:09:01.801    Disk 0 Vendor: SAMSUNG_ 2AJ1 Size: 305245MB BusType: 3
19:09:01.817    Disk 0 MBR read successfully
19:09:01.832    Disk 0 MBR scan
19:09:01.832    Disk 0 Windows 7 default MBR code
19:09:01.848    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
19:09:01.879    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        73728 MB offset 206848
19:09:01.879    Disk 0 Partition - 00     0F Extended LBA            209673 MB offset 151201792
19:09:01.926    Disk 0 Partition 3 00     27 Hidden NTFS WinRE NTFS        21741 MB offset 580612096
19:09:01.973    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS       209672 MB offset 151203840
19:09:02.020    Disk 0 scanning C:\Windows\system32\drivers
19:09:22.986    Service scanning
19:09:54.560    Modules scanning
19:09:54.576    Disk 0 trace - called modules:
19:09:54.607    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
19:09:54.623    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800635f060]
19:09:54.623    3 CLASSPNP.SYS[fffff88001d4b43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004363050]
19:09:55.403    AVAST engine scan C:\Windows
19:09:58.913    AVAST engine scan C:\Windows\system32
19:15:05.219    AVAST engine scan C:\Windows\system32\drivers
19:15:24.517    AVAST engine scan C:\Users\Dennis
19:17:06.244    Disk 0 MBR has been saved successfully to "C:\Users\Dennis\Desktop\MBR.dat"
19:17:06.260    The log file has been saved successfully to "C:\Users\Dennis\Desktop\aswMBR_lv.txt"

aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2012-12-30 19:08:37
19:08:37.122    OS Version: Windows x64 6.1.7601 Service Pack 1
19:08:37.122    Number of processors: 4 586 0x2505
19:08:37.122    ComputerName: DENNIS-PC  UserName: Dennis
19:08:37.434    Initialize success
19:08:44.844    AVAST engine defs: 12122900
19:09:01.801    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
19:09:01.801    Disk 0 Vendor: SAMSUNG_ 2AJ1 Size: 305245MB BusType: 3
19:09:01.817    Disk 0 MBR read successfully
19:09:01.832    Disk 0 MBR scan
19:09:01.832    Disk 0 Windows 7 default MBR code
19:09:01.848    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
19:09:01.879    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        73728 MB offset 206848
19:09:01.879    Disk 0 Partition - 00     0F Extended LBA            209673 MB offset 151201792
19:09:01.926    Disk 0 Partition 3 00     27 Hidden NTFS WinRE NTFS        21741 MB offset 580612096
19:09:01.973    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS       209672 MB offset 151203840
19:09:02.020    Disk 0 scanning C:\Windows\system32\drivers
19:09:22.986    Service scanning
19:09:54.560    Modules scanning
19:09:54.576    Disk 0 trace - called modules:
19:09:54.607    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
19:09:54.623    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800635f060]
19:09:54.623    3 CLASSPNP.SYS[fffff88001d4b43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004363050]
19:09:55.403    AVAST engine scan C:\Windows
19:09:58.913    AVAST engine scan C:\Windows\system32
19:15:05.219    AVAST engine scan C:\Windows\system32\drivers
19:15:24.517    AVAST engine scan C:\Users\Dennis
19:17:06.244    Disk 0 MBR has been saved successfully to "C:\Users\Dennis\Desktop\MBR.dat"
19:17:06.260    The log file has been saved successfully to "C:\Users\Dennis\Desktop\aswMBR_lv.txt"
19:19:14.112    AVAST engine scan C:\ProgramData
19:22:17.787    Scan finished successfully
19:22:37.037    Disk 0 MBR has been saved successfully to "C:\Users\Dennis\Desktop\MBR.dat"
19:22:37.053    The log file has been saved successfully to "C:\Users\Dennis\Desktop\aswMBR_lv.txt"


