Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7: McAfee findet Artemis

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 17.04.2015, 19:48   #1
kittyhawk
 
Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Hallo liebes Trojaner-Board-Team,

McAfee hat heute bei einem Scan einen Artemis Trojaner gefunden.
Der PC hatte heute Morgen Probleme beim Installieren von verschiedenen Updates.
Gmer stürzt ab, sobald es zu "harddisk volume shadow copy" kommt. Auch im abgesicherten Modus.

Bin für jede Hilfe dankbar.

Hier die logs:

Mc Afee:
Code:
ATTFilter
17.04.2015	09:44:44		Modulversion                            =	5700.7163
17.04.2015	09:44:44		AntiVirus-DAT-Version                   =	7773.0
17.04.2015	09:44:44		Anzahl an Entdeckungssignaturen in EXTRA.DAT=	Kein
17.04.2015	09:44:44		Namen der Entdeckungssignaturen in EXTRA.DAT=	Kein
17.04.2015	09:44:44	Scanvorgang wurde gestartet	-\Admin	Vollständiger Scan
17.04.2015	11:31:56	Gelöscht 	Admin	ODS[4320](Vollständiger Scan)	c:\Users\Admin\AppData\Local\Temp\13072434260007418133.exe	Artemis!B3737CCF8B6E (Trojanisches Pferd)
17.04.2015	11:32:04	Gelöscht 	Admin	ODS[4320](Vollständiger Scan)	c:\Users\Admin\AppData\Local\Temp\13072434392056970935.exe	Artemis!B3737CCF8B6E (Trojanisches Pferd)
17.04.2015	11:33:05	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_09\Data1.cab	
17.04.2015	11:33:06	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_11\Data1.cab	
17.04.2015	11:33:28	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_21\Data1.cab	
17.04.2015	11:33:30	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_25\Data1.cab	
17.04.2015	11:33:52	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab	
17.04.2015	11:33:57	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Admin\AppData\LocalLow\Sun\Java\jre1.7.0_67\Data1.cab	
17.04.2015	12:22:02	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Marci\AppData\Local\Mozilla\Firefox\Profiles\oc8xtaiy.default\cache2\entries\5F3C62B90583B630831A1F19278D7C587DEEC909	
17.04.2015	12:30:29	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Marci\Local Settings\Mozilla\Firefox\Profiles\oc8xtaiy.default\cache2\entries\5F3C62B90583B630831A1F19278D7C587DEEC909	
17.04.2015	12:35:58	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\2A50ECF1604771AFA8F5D970C854B732F5EF1AD7	
17.04.2015	12:36:31	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\448817BCF02275C2AF6F755A2D24B82E8455AAE9	
17.04.2015	12:37:35	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\7B3F5C5B8F76EFE5BFC367BD9669ABD8E4A0E0E3	
17.04.2015	12:38:08	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\9A8BB03D78043B3C7F10F43A637D0CA064DC4EF7	
17.04.2015	12:39:01	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\AppData\Local\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\CA46ADFC793D0200DAAF21B4AB458051B061E74A	
17.04.2015	13:27:15	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\2A50ECF1604771AFA8F5D970C854B732F5EF1AD7	
17.04.2015	13:27:37	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\448817BCF02275C2AF6F755A2D24B82E8455AAE9	
17.04.2015	13:28:26	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\7B3F5C5B8F76EFE5BFC367BD9669ABD8E4A0E0E3	
17.04.2015	13:28:53	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\9A8BB03D78043B3C7F10F43A637D0CA064DC4EF7	
17.04.2015	13:29:37	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\Local Settings\Mozilla\Firefox\Profiles\u7c5wv5h.default\cache2\entries\CA46ADFC793D0200DAAF21B4AB458051B061E74A	
17.04.2015	13:54:28	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Users\Standard User\Music\iTunes\iTunes Media\Mobile Applications\MadSkillsBMX 1.4.0.ipa	
17.04.2015	15:03:25	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Windows\Installer\84178.msp	
17.04.2015	15:51:26	Nicht gescannt (Die Datei ist verschlüsselt) 	c:\Windows\SoftwareDistribution\Download\acf67ef40852dc4544e261cb35f05219\BITB0CA.tmp	
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Scan-Zusammenfassung
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gescannte Prozesse: 78
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Entdeckte Prozesse: 0
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gesäuberte Prozesse: 0
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gescannte Boot-Sektoren: 2
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Entdeckte Boot-Sektoren: 0
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gesäuberte Boot-Sektoren: 0
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gescannte Dateien: 703562
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Dateien mit Entdeckungen: 2
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	DateiEntdeckungen: 2
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gesäuberte Dateien: 0
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gelöschte Dateien: 2
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Nicht gescannte Dateien: 145
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Scan-Zusammenfassung (Scannen der Registrierung)
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gescannte Schlüssel: 86527
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Entdeckte Schlüssel: 0
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gesäuberte Schlüssel: 0
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Gelöschte Schlüssel         : 0
17.04.2015	16:18:56	Scan-Zusammenfassung	-\Admin	Laufzeit: 6:34:11
17.04.2015	16:18:56	Scanvorgang wurde beendet	-\Admin	Vollständiger Scan
         
FRST:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04
Ran by Standard User (ATTENTION: The logged in user is not administrator) on - on 17-04-2015 19:51:52
Running from C:\Users\Standard User\AppData\Local\Temp\mozOpenDownload
Loaded Profiles: Admin & Standard User &  (Available profiles: Admin & Standard User & Marci)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> winlogon.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> atiesrxx.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> UMVPFSrv.exe
Failed to access process -> CTAudSvc.exe
Failed to access process -> svchost.exe
Failed to access process -> atieclxx.exe
Failed to access process -> vpnagent.exe
Failed to access process -> svchost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> armsvc.exe
Failed to access process -> AppleMobileDeviceService.exe
Failed to access process -> mDNSResponder.exe
Failed to access process -> svchost.exe
Failed to access process -> FrameworkService.exe
Failed to access process -> VsTskMgr.exe
Failed to access process -> mfevtps.exe
Failed to access process -> nlssrv32.exe
Failed to access process -> mfeann.exe
Failed to access process -> conhost.exe
Failed to access process -> naPrdMgr.exe
Failed to access process -> RosettaStoneDaemon.exe
Failed to access process -> psia.exe
Failed to access process -> svchost.exe
Failed to access process -> mcshield.exe
Failed to access process -> svchost.exe
Failed to access process -> sua.exe
Failed to access process -> USBVaccine.exe
(McAfee, Inc.) C:\Program Files\McAfee\Common Framework\UdaterUI.exe
(McAfee, Inc.) C:\Program Files\McAfee\Common Framework\McTray.exe
(Spotify Ltd) C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
() C:\Program Files\SWITCHdrive\SWITCHdrive.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> svchost.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\scan32.exe
Failed to access process -> FNPLicensingService.exe
() C:\Program Files\FileHippo.com\FileHippo.AppManager.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
Failed to access process -> dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
Failed to access process -> WmiPrvSE.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [McAfeeUpdaterUI] => C:\Program Files\McAfee\Common Framework\udaterui.exe [337440 2013-06-25] (McAfee, Inc.)
HKLM\...\Run: [ShStatEXE] => C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [243560 2014-01-15] (McAfee, Inc.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM\...\RunOnce: [NSIS.Library.RegTool.v3] => C:\Program Files\SWITCHdrive\shellext\NSIS.Library.RegTool.v3.{B6CC7347-25B5-45E2-83AF-3195401C8860}.exe [6656 2014-09-22] ()
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SandboxieControl] => "C:\Program Files\Sandboxie\SbieCtrl.exe"
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [Spotify Web Helper] => C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-04-02] (Spotify Ltd)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [AppleIEDAV] => C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [1080104 2014-09-19] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SWITCHdrive] => C:\Program Files\SWITCHdrive\SWITCHdrive.exe [23271459 2014-11-10] ()
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SandboxieControl] => "C:\Program Files\Sandboxie\SbieCtrl.exe"
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-04-02] (Spotify Ltd)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AppleIEDAV] => C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [1080104 2014-09-19] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SWITCHdrive] => C:\Program Files\SWITCHdrive\SWITCHdrive.exe [23271459 2014-11-10] ()
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
ShellIconOverlayIdentifiers: [  OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll (ownCloud Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-3271901242-2791666843-1555295335-1003] => 127.0.0.1:4001
ProxyServer: [S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] => 127.0.0.1:4001
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
URLSearchHook: [S-1-5-21-3271901242-2791666843-1555295335-1000] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-21-3271901242-2791666843-1555295335-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-21-3271901242-2791666843-1555295335-1263-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] ATTENTION ==> Default URLSearchHook is missing.
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20141013204033.dll [2014-10-13] (McAfee, Inc.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3271901242-2791666843-1555295335-1003 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL No File [ ]
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60

FireFox:
========
FF ProfilePath: C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default
FF Homepage: https://news.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-29] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-11-04] (Apple Inc.)
FF Extension: OpenDownload² - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{210249CE-F888-11DD-B868-4CB456D89593} [2015-01-12]
FF Extension: WOT - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-06-23]
FF Extension: Ghostery - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\firefox@ghostery.com.xpi [2014-06-23]
FF Extension: Zoom Page - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\zoompage@DW-dev.xpi [2015-03-30]
FF Extension: 瀏覽頁組管理員 - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2014-08-28]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2014-06-23]
FF Extension: NoScript - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-08-28]
FF Extension: Simple RSS Reader (SRR) - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{A5475360-A7EA-437b-9A79-29208F476940}.xpi [2014-08-04]
FF Extension: Right Links - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{B5F5E8D3-AE31-49A1-AC42-78B7B1CC5CDC}.xpi [2014-06-23]
FF Extension: Image Preview - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{D0A81AC1-3B12-4cec-AA8D-40EBDC4241EA}.xpi [2014-06-23]
FF Extension: Adblock Plus - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-23]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-06-28]
FF HKLM\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files\Common Files\McAfee\SystemCore
FF Extension: McAfee ScriptScan for Firefox - C:\Program Files\Common Files\McAfee\SystemCore [2014-10-13]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-04-03]

Chrome: 
=======
CHR Profile: C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-29]
CHR Extension: (Google Drive) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-29]
CHR Extension: (YouTube) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-29]
CHR Extension: (Google Search) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-29]
CHR Extension: (Google Wallet) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-29]
CHR Extension: (Gmail) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-29]
CHR HKLM\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - No Path Or update_url value
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-12-03]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [Not Found]
CHR HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bckipplcmnfhblnpibpbehenelnkpecd] - C:\Program Files\OkayFreedom\okayfreedom.crx [Not Found]
CHR HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bckipplcmnfhblnpibpbehenelnkpecd] - C:\Program Files\OkayFreedom\okayfreedom.crx [Not Found]

Opera: 
=======
OPR Extension: (WOT) - C:\Users\Standard User\AppData\Roaming\Opera Software\Opera Stable\Extensions\eeokceolphhfjdfcibaiiopmekmcbedp [2013-07-12]
OPR Extension: (Image Autosizer) - C:\Users\Standard User\AppData\Roaming\Opera Software\Opera Stable\Extensions\iikighlpichfheooodpapakdheilalcj [2013-07-12]
OPR Extension: (Adblock Plus) - C:\Users\Standard User\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2013-07-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-09-23] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-23] (Creative Technology Ltd) [File not signed]
R2 lmhosts; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 McAfeeFramework; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [130080 2013-06-25] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [204320 2014-10-13] (McAfee, Inc.)
R2 McTaskManager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [208416 2014-01-15] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [174968 2014-10-13] (McAfee, Inc.)
R2 NlaSvc; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nlsX86cc; C:\Windows\system32\nlssrv32.exe [66560 2011-02-15] (Nalpeiron Ltd.) [File not signed]
R2 nsi; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [1646056 2011-03-31] (Rosetta Stone Ltd.)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [563112 2014-08-15] (Cisco Systems, Inc.)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 FreemakeVideoCapture; "C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 acsock; C:\Windows\System32\DRIVERS\acsock.sys [92528 2014-08-15] (Cisco Systems, Inc.)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [63464 2013-05-29] (FTDI Ltd.)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [57112 2011-03-28] (Paragon Software Group)
R1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [82168 2013-11-21] (EZB Systems, Inc.)
R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [65640 2010-07-13] (ITE Tech. Inc. )
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-07-20] (ManyCam LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-04-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [25088 2012-07-20] (ManyCam LLC)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [134472 2014-10-13] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [236480 2014-10-13] (McAfee, Inc.)
R3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [66408 2014-10-13] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [573136 2014-10-13] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93144 2014-10-13] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [213872 2014-10-13] (McAfee, Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia)
S3 t3; C:\Windows\System32\drivers\t3.sys [413208 2009-05-06] (Creative Technology Ltd.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [40824 2011-03-28] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [381032 2011-03-28] (Paragon)
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva-6.sys [43888 2014-08-15] (Cisco Systems, Inc.)
U3 pxldapow; C:\Users\Admin\AppData\Local\Temp\pxldapow.sys [104960 2015-04-17] (GMER) [File not signed]
S3 ALSysIO; \??\C:\Users\Admin\AppData\Local\Temp\ALSysIO.sys [X]
U3 mfeavfk01; No ImagePath
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP5c\WNt500x86\Sandra.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-17 19:51 - 2015-04-17 19:52 - 00000000 ____D () C:\FRST
2015-04-17 11:31 - 2015-04-17 19:37 - 00000000 ____D () C:\QUARANTINE
2015-04-17 09:47 - 2015-04-17 09:47 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-04-15 19:49 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 19:49 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 19:49 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 19:49 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 19:49 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 19:49 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 19:49 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 19:49 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 19:48 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 19:48 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 19:48 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 19:48 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 19:48 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 19:48 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 19:48 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 19:48 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 19:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 19:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 19:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 19:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 19:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 19:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 19:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 19:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 19:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 19:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 19:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 19:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 19:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 19:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 19:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 19:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 19:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 19:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 19:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 19:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 19:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 19:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 19:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 19:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 19:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 19:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 19:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 19:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 19:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 19:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 19:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 19:41 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 19:38 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 19:14 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 19:14 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-11 11:58 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\Program Files\iTunes
2015-04-11 11:55 - 2015-04-11 11:55 - 00000000 ____D () C:\Program Files\iPod
2015-04-11 11:40 - 2015-04-11 11:40 - 00000000 ____D () C:\Users\Standard User\Tracing
2015-04-11 11:22 - 2015-04-11 11:25 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-11 09:10 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-11 09:10 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-11 09:10 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-11 09:10 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-11 09:09 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-11 09:09 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-02 12:02 - 2015-04-02 12:02 - 00000000 ____D () C:\Users\Standard User\Downloads\Manu Chao - La Radiolina
2015-04-02 11:54 - 2015-04-02 12:25 - 00000000 ____D () C:\Users\Standard User\Downloads\Siberie m etait conteee
2015-04-02 11:47 - 2015-04-02 12:27 - 00000000 ____D () C:\Users\Standard User\Downloads\Manu Chao and Friends - Manu Chao and Friends (2011)
2015-04-02 09:03 - 2015-04-02 09:03 - 00000678 _____ () C:\Windows\PFRO.log
2015-03-29 13:00 - 2015-03-29 13:00 - 00000000 __RSH () C:\MSDOS.SYS
2015-03-29 13:00 - 2015-03-29 13:00 - 00000000 __RSH () C:\IO.SYS
2015-03-23 08:57 - 2015-04-11 10:21 - 00000000 ____D () C:\Program Files\Mozilla Firefox

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-17 19:31 - 2014-07-12 14:12 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-17 19:25 - 2015-03-01 21:12 - 00005568 _____ () C:\Windows\setupact.log
2015-04-17 19:21 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-17 19:18 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-17 19:18 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-17 19:11 - 2014-11-05 22:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\Spotify
2015-04-17 19:07 - 2012-06-04 18:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-17 10:42 - 2012-06-04 11:35 - 01619570 _____ () C:\Windows\WindowsUpdate.log
2015-04-17 10:40 - 2014-05-14 11:59 - 00000000 ____D () C:\Users\Standard User\AppData\Local\C6B895D1-C4F4-4AA5-B457-2F5A43379524.aplzod
2015-04-17 10:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-17 09:59 - 2012-06-04 12:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-17 09:49 - 2013-11-19 16:42 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-04-17 09:47 - 2014-08-28 15:08 - 00000000 ____D () C:\Program Files\Java
2015-04-17 09:44 - 2015-03-06 18:56 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-04-17 09:39 - 2015-03-13 23:29 - 00003890 _____ () C:\Windows\SecuniaPackage.log
2015-04-17 09:36 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-17 09:20 - 2012-06-04 11:46 - 00785866 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-17 09:08 - 2013-11-05 22:16 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Spotify
2015-04-17 09:07 - 2014-12-17 21:11 - 00000000 ____D () C:\Users\Standard User\SWITCHdrive
2015-04-17 08:57 - 2012-07-06 19:26 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Adobe
2015-04-17 08:56 - 2013-11-05 22:15 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Spotify
2015-04-17 08:56 - 2012-06-04 18:13 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-17 08:56 - 2012-06-04 17:40 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-17 08:52 - 2014-08-31 14:31 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe
2015-04-17 07:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-15 20:53 - 2014-10-10 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-15 20:52 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-04-15 20:47 - 2013-07-14 13:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 20:42 - 2012-06-04 11:42 - 00000000 ____D () C:\Users\Admin
2015-04-15 20:31 - 2012-06-04 12:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-11 11:55 - 2012-06-04 18:50 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-04-11 11:41 - 2012-09-15 15:28 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Skype
2015-04-11 11:39 - 2012-09-15 15:27 - 00000000 ____D () C:\ProgramData\Skype
2015-04-11 11:32 - 2012-06-05 09:18 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\foobar2000
2015-04-11 11:32 - 2012-06-04 17:33 - 00001035 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2015-04-11 11:32 - 2012-06-04 17:33 - 00000000 ____D () C:\Program Files\foobar2000
2015-04-11 11:24 - 2014-05-15 18:56 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-11 11:22 - 2014-12-12 14:03 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-11 11:22 - 2014-05-06 10:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-02 16:02 - 2015-01-24 17:19 - 00001838 _____ () C:\Users\Standard User\Desktop\Spotify.lnk
2015-04-02 16:02 - 2013-11-05 22:16 - 00001824 _____ () C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-04-02 09:51 - 2012-06-26 10:44 - 00000000 ____D () C:\Program Files\JDownloader
2015-04-01 20:11 - 2015-02-15 16:25 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Popcorn-Time
2015-04-01 20:11 - 2012-09-03 14:36 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\vlc
2015-04-01 10:17 - 2012-06-04 19:28 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-30 08:32 - 2014-06-29 20:22 - 00000000 ____D () C:\Users\Standard User\Downloads\navigon
2015-03-29 14:26 - 2012-08-26 20:54 - 00000000 ____D () C:\ProgramData\boost_interprocess
2015-03-23 21:36 - 2014-07-12 14:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-03-23 21:36 - 2014-07-12 14:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-03-23 17:03 - 2014-10-06 15:28 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\Skype
2015-03-20 22:41 - 2014-09-08 21:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\vlc

==================== Files in the root of some directories =======

2012-06-05 10:35 - 2014-08-14 13:16 - 0000363 _____ () C:\Users\Standard User\AppData\Roaming\burnaware.ini
2012-10-23 03:23 - 2012-09-04 08:44 - 11624448 _____ () C:\Users\Standard User\AppData\Roaming\Sandra.mdb
2013-12-27 13:41 - 2014-02-18 23:18 - 0017408 _____ () C:\Users\Standard User\AppData\Local\WebpageIcons.db
2014-08-13 12:21 - 2014-08-13 12:21 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Standard User\AppData\Local\Temp\i4jdel0.exe
C:\Users\Standard User\AppData\Local\Temp\proxy_vole9193411994646851775.dll
C:\Users\Standard User\AppData\Local\Temp\SkypeSetup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


ATTENTION: ==> Could not access BCD. Check to make sure user is administrator or see Addition.txt for additional information.

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---


Addition:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-04-2015 04
Ran by Standard User at 2015-04-17 19:55:03
Running from C:\Users\Standard User\AppData\Local\Temp\mozOpenDownload
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: McAfee VirusScan Enterprise (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AS: McAfee VirusScan Enterprise Antispyware Module (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - )
Adobe Acrobat XI Pro (HKLM\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.10 - Adobe Systems)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 17.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM\...\{F1410A0A-8205-4D45-BF2B-9C7ACB2F4B24}) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM\...\{8C901387-B304-404D-93C0-E2E0C2D53D90}) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 3.6 (HKLM\...\{D0ACE207-0F90-402C-8CFA-2CB3D44CE689}) (Version: 3.6.1 - Adobe)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AGEIA PhysX v7.09.13 (HKLM\...\{45235788-142C-44BE-8A4D-DDE9A84492E5}) (Version: 7.09.13 - AGEIA Technologies, Inc.)
Apple Application Support (32-Bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo Burning Studio 2014 v.12.0.5 (HKLM\...\{91B33C97-280F-B76D-E27B-E712D7041B76}_is1) (Version: 12.0.5 - Ashampoo GmbH & Co. KG)
Biet-O-Matic v2.14.8 (HKLM\...\Biet-O-Matic v2.14.8) (Version: 2.14.8 - BOM Development Team)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (Version: 13.31.1038.0 - Logitech) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform)
Cisco AnyConnect Secure Mobility Client  (HKLM\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05182 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (Version: 3.1.05182 - Cisco Systems, Inc.) Hidden
Color Efex Pro 3.0 Complete (HKLM\...\Color Efex Pro 3.0 Complete Stand-Alone) (Version: 3.1.1.0 - Nik Software, Inc.)
Creative Audio-Systemsteuerung (HKLM\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Defraggler (HKLM\...\Defraggler) (Version: 2.19 - Piriform)
Dfine 2.0 (HKLM\...\Dfine 2.0 Stand-Alone) (Version: 2.1.0.7 - Nik Software, Inc.)
Eigenschaften von Creative Sound Blaster (HKLM\...\Creative Sound Blaster Properties) (Version: 1.02 - Creative Technology Limited)
EndNote X7 (HKLM\...\{86B3F2D6-AC2B-0017-8AE1-F2F77F781B0C}) (Version: 17.0.2.7390 - Thomson Reuters)
erLT (Version: 1.20.138.34 - Logitech, Inc.) Hidden
FileHippo App Manager (HKLM\...\FileHippo.com) (Version:  - FileHippo.com)
foobar2000 v1.3.8 (HKLM\...\foobar2000) (Version: 1.3.8 - Peter Pawlowski)
GoodSync (HKLM\...\{B26B00DA-2E5D-4CF2-83C5-911198C0F009}) (Version: 9.9.9.9 - Siber Systems)
GraphPad Prism 5 (HKLM\...\{35B73650-6899-11DA-6784-00232A9018BE}) (Version: 5.04 - GraphPad Software)
Host OpenAL (HKLM\...\Host OpenAL) (Version: 1.00 - Creative Technology Limited)
HP Officejet Pro 8600 Basic Device Software (HKLM\...\{8EAB4100-B343-41AE-A880-418746998209}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
I.R.I.S. OCR (HKLM\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
IBM SPSS Statistics 21 (HKLM\...\{1E26B9C2-ED08-4EEA-83C8-A786502B41E5}) (Version: 21.0.0.0 - IBM Corp)
iCloud (HKLM\...\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.)
iTunes (HKLM\...\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Logitech Webcam Software (HKLM\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.)
Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
McAfee Agent (HKLM\...\{1FDB8EC6-BAF1-42F9-8E09-4D9AB369F1B5}) (Version: 4.8.0.887 - McAfee, Inc.)
McAfee VirusScan Enterprise (HKLM\...\{CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}) (Version: 8.8.04001 - McAfee, Inc.)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM\...\{95140000-0081-0407-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Moveslink for Movestick Mini (HKLM\...\{4D036ACA-DFDF-41B2-A680-E0D736F3E947}) (Version: 1.2.40 - Suunto)
Mozilla Firefox 37.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 37.0.1 (x86 en-US)) (Version: 37.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Panda USB Vaccine 1.0.1.4 (HKLM\...\{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1) (Version:  - Panda Security)
Paragon Backup & Recovery™ 2011 Free (HKLM\...\{C268B5E1-A5DA-11DF-A289-005056C00008}) (Version: 90.00.0003 - Paragon Software)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
R for Windows 3.0.2 (HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\R for Windows 3.0.2_is1) (Version: 3.0.2 - R Core Team)
R for Windows 3.0.2 (HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\R for Windows 3.0.2_is1) (Version: 3.0.2 - R Core Team)
ResearchSoft Direct Export Helper (HKLM\...\ResearchSoft Direct Export Helper) (Version:  - Thomson Reuters)
Rosetta Stone Ltd Services (HKLM\...\{7BB2EF8A-5376-4BAE-96D0-38BE49501F40}) (Version: 3.2.17 - Rosetta Stone Ltd.)
Rosetta Stone TOTALe (HKLM\...\com.rosettastone.rosettastonetotale) (Version: 4.1.15.1 - Rosetta Stone, Ltd)
Rosetta Stone TOTALe (Version: 4.1.1 - Rosetta Stone, Ltd) Hidden
Rosetta Stone TOTALe (Version: 4.1.15.1 - Rosetta Stone, Ltd) Hidden
RStudio (HKLM\...\RStudio) (Version: 0.98.501 - RStudio)
Secunia PSI (3.0.0.9016) (HKLM\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version:  - Microsoft)
Sharpener Pro 3.0 (HKLM\...\Sharpener Pro 3.0 Stand-Alone) (Version: 3.0.0.5 - Nik Software, Inc.)
SIGMA Photo Pro 5 (HKLM\...\{B99C3D18-BA4B-4D65-A500-D364E3D2A8A3}) (Version: 5.2.1 - SIGMA)
Silver Efex Pro 2 (HKLM\...\Silver Efex Pro 2) (Version: 2.0.0.0 - Nik Software, Inc.)
Skype™ 7.3 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Spotify) (Version: 1.0.3.101.gbfa97dfe - Spotify AB)
Spotify (HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Spotify) (Version: 1.0.3.101.gbfa97dfe - Spotify AB)
Stata 13 (HKLM\...\{217BE429-022D-4094-960F-0376E1CBE13E}) (Version: 13.0 - StataCorp LP)
SWITCHdrive (HKLM\...\SWITCHdrive) (Version: 1.7.0.4198 - SWITCH)
UltraISO Premium V9.62 (HKLM\...\UltraISO_is1) (Version:  - )
Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{0C5B0539-7EDE-4297-947E-48890971B557}) (Version:  - Microsoft)
Viveza 2 (HKLM\...\Viveza 2) (Version: 2.0.0.4 - Nik Software, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - Suunto (libusb0) Suunto  (10/02/2010 1.2.2.0) (HKLM\...\4E5E6491582172E255196D3F11B77725E6681767) (Version: 10/02/2010 1.2.2.0 - Suunto)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

ATTENTION: System Restore is disabled.
Check "winmgmt" service or repair WMI.


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2014-06-28 19:15 - 00000896 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => 

==================== Loaded Modules (whitelisted) ==============

2014-11-04 02:30 - 2014-11-04 02:30 - 00045568 _____ () C:\Program Files\SWITCHdrive\shellext\OCUtil_x86.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-11-10 11:39 - 2014-11-10 11:39 - 23271459 _____ () C:\Program Files\SWITCHdrive\SWITCHdrive.exe
2014-11-10 11:38 - 2014-11-10 11:38 - 03044905 _____ () C:\Program Files\SWITCHdrive\libocsync.dll
2014-09-24 10:23 - 2014-09-24 10:23 - 00158048 _____ () C:\Program Files\SWITCHdrive\libneon-27.dll
2014-09-22 00:32 - 2014-09-22 00:32 - 00084012 _____ () C:\Program Files\SWITCHdrive\zlib1.dll
2014-09-22 03:45 - 2014-09-22 03:45 - 00095790 _____ () C:\Program Files\SWITCHdrive\libgcc_s_sjlj-1.dll
2014-09-22 03:13 - 2014-09-22 03:13 - 00172695 _____ () C:\Program Files\SWITCHdrive\libproxy.dll
2014-09-22 03:11 - 2014-09-22 03:11 - 00042626 _____ () C:\Program Files\SWITCHdrive\libmodman.dll
2014-09-22 03:45 - 2014-09-22 03:45 - 00847430 _____ () C:\Program Files\SWITCHdrive\libstdc++-6.dll
2014-09-22 02:05 - 2014-09-22 02:05 - 01150984 _____ () C:\Program Files\SWITCHdrive\libxml2-2.dll
2014-09-22 02:10 - 2014-09-22 02:10 - 02164003 _____ () C:\Program Files\SWITCHdrive\icui18n53.dll
2014-09-22 02:10 - 2014-09-22 02:10 - 01288240 _____ () C:\Program Files\SWITCHdrive\icuuc53.dll
2014-09-22 02:10 - 2014-09-22 02:10 - 21540519 _____ () C:\Program Files\SWITCHdrive\icudata53.dll
2014-09-22 02:16 - 2014-09-22 02:16 - 00144533 _____ () C:\Program Files\SWITCHdrive\libpcre16-0.dll
2014-09-22 02:15 - 2014-09-22 02:15 - 01345629 _____ () C:\Program Files\SWITCHdrive\libGLESv2.dll
2014-09-22 01:58 - 2014-09-22 01:58 - 00203567 _____ () C:\Program Files\SWITCHdrive\libpng16-16.dll
2014-11-10 11:39 - 2014-11-10 11:39 - 15897518 _____ () C:\Program Files\SWITCHdrive\libSWITCHdrivesync.dll
2014-09-22 02:15 - 2014-09-22 02:15 - 00150916 _____ () C:\Program Files\SWITCHdrive\libEGL.dll
2014-09-22 02:08 - 2014-09-22 02:08 - 00197062 _____ () C:\Program Files\SWITCHdrive\libjpeg-8.dll
2014-09-22 02:13 - 2014-09-22 02:13 - 00646511 _____ () C:\Program Files\SWITCHdrive\libsqlite3-0.dll
2014-09-22 03:28 - 2014-09-22 03:28 - 00247028 _____ () C:\Program Files\SWITCHdrive\libwebp-4.dll
2014-09-22 04:24 - 2014-09-22 04:24 - 00228655 _____ () C:\Program Files\SWITCHdrive\libxslt-1.dll
2014-09-24 09:38 - 2014-09-24 09:38 - 00052119 _____ () C:\Program Files\SWITCHdrive\libqt5keychain.dll
2014-09-22 12:25 - 2014-09-22 12:25 - 00702136 _____ () C:\Program Files\SWITCHdrive\platforms\qwindows.dll
2014-09-22 12:25 - 2014-09-22 12:25 - 00032568 _____ () C:\Program Files\SWITCHdrive\imageformats\qgif.dll
2014-09-22 12:25 - 2014-09-22 12:25 - 00035173 _____ () C:\Program Files\SWITCHdrive\imageformats\qico.dll
2014-09-22 12:25 - 2014-09-22 12:25 - 00048436 _____ () C:\Program Files\SWITCHdrive\imageformats\qjpeg.dll
2014-09-22 12:25 - 2014-09-22 12:25 - 00172128 _____ () C:\Program Files\SWITCHdrive\accessible\qtaccessiblewidgets.dll
2015-01-27 14:18 - 2015-01-27 14:18 - 02926800 _____ () C:\Program Files\FileHippo.com\FileHippo.AppManager.exe
2015-04-17 08:56 - 2015-04-17 08:56 - 16863920 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows:nlsPreferences

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 62.2.24.162 - 62.2.17.61

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Moveslink for Movestick Mini.lnk => C:\Windows\pss\Moveslink for Movestick Mini.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk => C:\Windows\pss\Logitech . Produktregistrierung.lnk.Startup
MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BrMfcWnd => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: Cisco AnyConnect Secure Mobility Agent for Windows => "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
MSCONFIG\startupreg: ControlCenter3 => C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
MSCONFIG\startupreg: Logitech Vid => "C:\Program Files\Logitech\Vid\Vid.exe" -bootmode
MSCONFIG\startupreg: LWS => C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: QuickTime Plugin Install => C:\Program Files\QuickTime\Plugins\DeleteMe1.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SPIRunE => Rundll32 SPIRunE.dll,RunDLLEntry
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: VirtualCloneDrive => "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s

==================== Accounts: =============================

Admin (S-1-5-21-3271901242-2791666843-1555295335-1000 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-3271901242-2791666843-1555295335-500 - Administrator - Disabled)
Guest (S-1-5-21-3271901242-2791666843-1555295335-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3271901242-2791666843-1555295335-1261 - Limited - Enabled)
Marci (S-1-5-21-3271901242-2791666843-1555295335-1263 - Limited - Enabled) => C:\Users\Marci
Standard User (S-1-5-21-3271901242-2791666843-1555295335-1003 - Limited - Enabled) => C:\Users\Standard User

==================== Faulty Device Manager Devices =============

Name: Base System Device
Description: Base System Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Base System Device
Description: Base System Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/17/2015 04:18:56 PM) (Source: McLogEvent) (EventID: 259) (User: -)
Description: Der Scan hat Entdeckungen gefunden. Scan-Modul der Version 5700.7163 DAT-Version 7773.

Error: (04/17/2015 09:44:09 AM) (Source: MsiInstaller) (EventID: 11704) (User: -)
Description: Product: Java 8 Update 45 -- Error 1704. An installation for Adobe Flash Player 15 Plugin is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?

Error: (04/17/2015 09:40:00 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program psi.exe version 3.0.0.9016 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: b18

Start Time: 01d078e18213cc2d

Termination Time: 16

Application Path: C:\Program Files\Secunia\PSI\psi.exe

Report Id: f06fc799-e4d4-11e4-b74e-002170820736

Error: (04/17/2015 09:15:22 AM) (Source: MsiInstaller) (EventID: 11705) (User: NT AUTHORITY)
Description: Product: Adobe Flash Player 15 Plugin -- Error 1705.A previous installation for this product is in progress.  You must undo the changes made by that installation to continue.  Do you want to undo those changes?

Error: (04/17/2015 08:59:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 6.1.7601.17567, time stamp: 0x4d6727a7
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0006f447
Faulting process id: 0x2cdc
Faulting application start time: 0xexplorer.exe0
Faulting application path: explorer.exe1
Faulting module path: explorer.exe2
Report Id: explorer.exe3

Error: (04/17/2015 07:58:27 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154

Error: (04/15/2015 06:52:00 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location G:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).

Error: (04/15/2015 06:50:20 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154

Error: (04/11/2015 09:15:11 AM) (Source: Microsoft Office 15) (EventID: 2001) (User: )
Description: Microsoft Outlook: Rejected Safe Mode action : Outlook konnte beim letzten Mal nicht gestartet werden. Der abgesicherte Modus kann Ihnen bei der Problembehandlung behilflich sein. Einige Features sind aber in diesem Modus möglicherweise nicht verfügbar.

Möchten Sie im abgesicherten Modus starten?.
Rejected Safe Mode action : Microsoft Outlook.

Error: (04/11/2015 08:55:50 AM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location G:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).


System errors:
=============
Error: (04/17/2015 07:25:26 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (04/17/2015 07:25:02 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (04/17/2015 11:10:37 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (04/17/2015 11:10:13 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (04/17/2015 10:38:19 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (04/17/2015 09:55:50 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (04/17/2015 09:42:41 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.

Error: (04/17/2015 09:37:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The FreemakeVideoCapture service failed to start due to the following error: 
%%2

Error: (04/17/2015 09:36:46 AM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active

Error: (04/17/2015 09:36:46 AM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter


Microsoft Office Sessions:
=========================
Error: (04/17/2015 04:18:56 PM) (Source: McLogEvent) (EventID: 259) (User: -)
Description: Der Scan hat Entdeckungen gefunden. Scan-Modul der Version 5700.7163 DAT-Version 7773.

Error: (04/17/2015 09:44:09 AM) (Source: MsiInstaller) (EventID: 11704) (User: -)
Description: Product: Java 8 Update 45 -- Error 1704. An installation for Adobe Flash Player 15 Plugin is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (04/17/2015 09:40:00 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: psi.exe3.0.0.9016b1801d078e18213cc2d16C:\Program Files\Secunia\PSI\psi.exef06fc799-e4d4-11e4-b74e-002170820736

Error: (04/17/2015 09:15:22 AM) (Source: MsiInstaller) (EventID: 11705) (User: NT AUTHORITY)
Description: Product: Adobe Flash Player 15 Plugin -- Error 1705.A previous installation for this product is in progress.  You must undo the changes made by that installation to continue.  Do you want to undo those changes?(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (04/17/2015 08:59:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: explorer.exe6.1.7601.175674d6727a7unknown0.0.0.000000000c00000050006f4472cdc01d078dbd3a0afdbC:\Windows\explorer.exeunknown493f9d43-e4cf-11e4-8544-002170820736

Error: (04/17/2015 07:58:27 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154

Error: (04/15/2015 06:52:00 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: G:\The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006)

Error: (04/15/2015 06:50:20 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154

Error: (04/11/2015 09:15:11 AM) (Source: Microsoft Office 15) (EventID: 2001) (User: )
Description: Microsoft OutlookOutlook konnte beim letzten Mal nicht gestartet werden. Der abgesicherte Modus kann Ihnen bei der Problembehandlung behilflich sein. Einige Features sind aber in diesem Modus möglicherweise nicht verfügbar.

Möchten Sie im abgesicherten Modus starten?

Error: (04/11/2015 08:55:50 AM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: G:\The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006)


CodeIntegrity Errors:
===================================
  Date: 2014-06-03 14:16:00.398
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:16:00.153
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:15:59.903
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tpm-driver-wmi_31bf3856ad364e35_6.0.6001.18000_none_6f8d0e60c043c672\Win32_Tpm.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:15:47.017
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6001.18000_none_34daa5e8f21ef8d2\fveapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:15:46.767
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6001.18000_none_34daa5e8f21ef8d2\fveapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:15:46.539
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6001.18000_none_34daa5e8f21ef8d2\fveapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:14:48.042
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:14:47.802
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:14:47.568
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\bcrypt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 14:13:49.467
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\Backup\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f_bcrypt.dll_e2f091ac because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz
Percentage of memory in use: 57%
Total physical RAM: 3581.98 MB
Available physical RAM: 1518.06 MB
Total Pagefile: 8830.27 MB
Available Pagefile: 6449.47 MB
Total Virtual: 2047.88 MB
Available Virtual: 1898.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:287.95 GB) (Free:33.95 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:4.97 GB) NTFS

==================== MBR & Partition Table ==================

==================== End Of Log ============================
         

Geändert von kittyhawk (17.04.2015 um 20:05 Uhr)

Alt 17.04.2015, 19:54   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



hi,

unsere Tools brauchen immer Adminrechte!



Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.
__________________

__________________

Alt 17.04.2015, 20:51   #3
kittyhawk
 
Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Danke für die schnelle Antwort.

Hier die Logs:

Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.09.1.1004
www.malwarebytes.org

Database version:
  main:    v2015.04.17.05
  rootkit: v2015.03.31.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17728
Admin :: - [administrator]

17.04.2015 21:02:16
mbar-log-2015-04-17 (21-02-16).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 415837
Time elapsed: 39 minute(s), 41 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         
Code:
ATTFilter
21:47:11.0985 0x0378  TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
21:47:18.0334 0x0378  ============================================================
21:47:18.0334 0x0378  Current date / time: 2015/04/17 21:47:18.0334
21:47:18.0334 0x0378  SystemInfo:
21:47:18.0334 0x0378  
21:47:18.0334 0x0378  OS Version: 6.1.7601 ServicePack: 1.0
21:47:18.0334 0x0378  Product type: Workstation
21:47:18.0334 0x0378  ComputerName: -
21:47:18.0334 0x0378  UserName: Admin
21:47:18.0334 0x0378  Windows directory: C:\Windows
21:47:18.0334 0x0378  System windows directory: C:\Windows
21:47:18.0334 0x0378  Processor architecture: Intel x86
21:47:18.0334 0x0378  Number of processors: 2
21:47:18.0334 0x0378  Page size: 0x1000
21:47:18.0334 0x0378  Boot type: Normal boot
21:47:18.0334 0x0378  ============================================================
21:47:20.0815 0x0378  KLMD registered as C:\Windows\system32\drivers\80691991.sys
21:47:21.0236 0x0378  System UUID: {7DC626DA-743E-8683-6C75-74A6DAB7817A}
21:47:21.0875 0x0378  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
21:47:21.0875 0x0378  ============================================================
21:47:21.0875 0x0378  \Device\Harddisk0\DR0:
21:47:21.0875 0x0378  MBR partitions:
21:47:21.0875 0x0378  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x47000, BlocksNum 0x1400000
21:47:21.0875 0x0378  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1447000, BlocksNum 0x23FE7000
21:47:21.0875 0x0378  ============================================================
21:47:21.0907 0x0378  C: <-> \Device\Harddisk0\DR0\Partition2
21:47:21.0938 0x0378  D: <-> \Device\Harddisk0\DR0\Partition1
21:47:21.0938 0x0378  ============================================================
21:47:21.0938 0x0378  Initialize success
21:47:21.0938 0x0378  ============================================================
21:48:10.0657 0x1660  ============================================================
21:48:10.0657 0x1660  Scan started
21:48:10.0657 0x1660  Mode: Manual; SigCheck; TDLFS; 
21:48:10.0657 0x1660  ============================================================
21:48:10.0657 0x1660  KSN ping started
21:48:24.0403 0x1660  KSN ping finished: true
21:48:27.0102 0x1660  ================ Scan system memory ========================
21:48:27.0102 0x1660  System memory - ok
21:48:27.0102 0x1660  ================ Scan services =============================
21:48:27.0477 0x1660  [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
21:48:27.0648 0x1660  1394ohci - ok
21:48:27.0695 0x1660  [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI            C:\Windows\system32\drivers\ACPI.sys
21:48:27.0726 0x1660  ACPI - ok
21:48:27.0773 0x1660  [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
21:48:27.0882 0x1660  AcpiPmi - ok
21:48:27.0960 0x1660  [ 27A563BEEFCE364823EAAA789A3F7EAE, 371EF141AEBDD00F9CCAD62B742B59A4D0C97EA449E9C14E3BE66EC7FFFF9D2C ] acsock          C:\Windows\system32\DRIVERS\acsock.sys
21:48:28.0007 0x1660  acsock - ok
21:48:28.0194 0x1660  [ 4C72FDD915D62EAEF149BD9C73AB9CF4, 8EA45A1B88DFD819F0ADA3AF36D464E1BF52574269592370E0CC8D0490680E1F ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
21:48:28.0225 0x1660  AdobeARMservice - ok
21:48:28.0366 0x1660  [ B04A4810C6CC205F9DC72DC22E4AB236, 547321F5C28C80D4818372D65E2A33D4BAC593015DD6613B24586FE4B4A95D5D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
21:48:28.0397 0x1660  AdobeFlashPlayerUpdateSvc - ok
21:48:28.0475 0x1660  [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
21:48:28.0537 0x1660  adp94xx - ok
21:48:28.0569 0x1660  [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
21:48:28.0584 0x1660  adpahci - ok
21:48:28.0615 0x1660  [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
21:48:28.0631 0x1660  adpu320 - ok
21:48:28.0693 0x1660  [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
21:48:28.0865 0x1660  AeLookupSvc - ok
21:48:28.0943 0x1660  [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD             C:\Windows\system32\drivers\afd.sys
21:48:29.0037 0x1660  AFD - ok
21:48:29.0083 0x1660  [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440          C:\Windows\system32\drivers\agp440.sys
21:48:29.0115 0x1660  agp440 - ok
21:48:29.0161 0x1660  [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx         C:\Windows\system32\DRIVERS\djsvs.sys
21:48:29.0177 0x1660  aic78xx - ok
21:48:29.0239 0x1660  [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG             C:\Windows\System32\alg.exe
21:48:29.0271 0x1660  ALG - ok
21:48:29.0317 0x1660  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide          C:\Windows\system32\drivers\aliide.sys
21:48:29.0349 0x1660  aliide - ok
21:48:29.0489 0x1660  ALSysIO - ok
21:48:29.0536 0x1660  [ B19505648F033393E907E2E419FDE8B3, BEF76AAD61FE0CA1F2B91C491FD94DE1BE67E776BBB7972D57ADFBE0333E9615 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
21:48:29.0614 0x1660  AMD External Events Utility - ok
21:48:29.0645 0x1660  [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
21:48:29.0676 0x1660  amdagp - ok
21:48:29.0739 0x1660  [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide          C:\Windows\system32\drivers\amdide.sys
21:48:29.0754 0x1660  amdide - ok
21:48:29.0817 0x1660  [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
21:48:29.0879 0x1660  AmdK8 - ok
21:48:29.0895 0x1660  [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
21:48:29.0941 0x1660  AmdPPM - ok
21:48:29.0988 0x1660  [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
21:48:30.0019 0x1660  amdsata - ok
21:48:30.0051 0x1660  [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
21:48:30.0066 0x1660  amdsbs - ok
21:48:30.0097 0x1660  [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
21:48:30.0113 0x1660  amdxata - ok
21:48:30.0191 0x1660  [ DD8D9C597AF7CD2F6B70A3D6A4A1ACEA, 834B397F365D930DA01D5189DDF06195CFE4C0F9249223C5A9004643F41BA6E4 ] androidusb      C:\Windows\system32\Drivers\ssadadb.sys
21:48:30.0269 0x1660  androidusb - ok
21:48:30.0347 0x1660  [ 81F97D8F8B3FB94A451CC6F7CF8B2965, 8DEBA4E47E1016D69740C0BB7CDD23852D86E0D42C1C1EA5A847ECB115C38CB1 ] AppID           C:\Windows\system32\drivers\appid.sys
21:48:30.0441 0x1660  AppID - ok
21:48:30.0503 0x1660  [ F5090F8FA6757C58E17BAEAA86093636, 5E14CF3032DF5801240F45C59AA93962EA41AA5648A0C6458D16D9B9D95A131F ] AppIDSvc        C:\Windows\System32\appidsvc.dll
21:48:30.0565 0x1660  AppIDSvc - ok
21:48:30.0612 0x1660  [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo         C:\Windows\System32\appinfo.dll
21:48:30.0659 0x1660  Appinfo - ok
21:48:30.0784 0x1660  [ D2B87FC03BE28CD0B33C2B5C1119FD8E, 97EB74CB7F62C0D06D45CB250E3A90657A0F107C2FC20738FF6B2C87B0240080 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
21:48:30.0815 0x1660  Apple Mobile Device - ok
21:48:30.0893 0x1660  [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt         C:\Windows\System32\appmgmts.dll
21:48:30.0955 0x1660  AppMgmt - ok
21:48:30.0987 0x1660  [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc             C:\Windows\system32\DRIVERS\arc.sys
21:48:31.0018 0x1660  arc - ok
21:48:31.0033 0x1660  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
21:48:31.0049 0x1660  arcsas - ok
21:48:31.0236 0x1660  [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
21:48:31.0267 0x1660  aspnet_state - ok
21:48:31.0314 0x1660  [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
21:48:31.0455 0x1660  AsyncMac - ok
21:48:31.0517 0x1660  [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi           C:\Windows\system32\drivers\atapi.sys
21:48:31.0548 0x1660  atapi - ok
21:48:31.0813 0x1660  [ 04F09923A393E4E0E8453A8F78361E73, B5C0B9D1195B87AF823887AD9355CD2B4C4F4DDF34103891EE48EA86F0F544E7 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
21:48:32.0079 0x1660  atikmdag - ok
21:48:32.0141 0x1660  [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:48:32.0203 0x1660  AudioEndpointBuilder - ok
21:48:32.0235 0x1660  [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
21:48:32.0266 0x1660  Audiosrv - ok
21:48:32.0344 0x1660  [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV        C:\Windows\System32\AxInstSV.dll
21:48:32.0406 0x1660  AxInstSV - ok
21:48:32.0469 0x1660  [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbdx.sys
21:48:32.0593 0x1660  b06bdrv - ok
21:48:32.0640 0x1660  [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
21:48:32.0749 0x1660  b57nd60x - ok
21:48:32.0905 0x1660  [ F9CE9B5E049EFC66B8E6C73C18EE8438, 8B43B84F59810DAFA961EEA13E354FF9A0796A185E2C8D6642D8660AAC1B96F4 ] BCM43XX         C:\Windows\system32\DRIVERS\bcmwl6.sys
21:48:33.0061 0x1660  BCM43XX - ok
21:48:33.0171 0x1660  [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC          C:\Windows\System32\bdesvc.dll
21:48:33.0202 0x1660  BDESVC - ok
21:48:33.0217 0x1660  [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep            C:\Windows\system32\drivers\Beep.sys
21:48:33.0280 0x1660  Beep - ok
21:48:33.0389 0x1660  [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE             C:\Windows\System32\bfe.dll
21:48:33.0498 0x1660  BFE - ok
21:48:33.0545 0x1660  [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS            C:\Windows\System32\qmgr.dll
21:48:33.0607 0x1660  BITS - ok
21:48:33.0623 0x1660  [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
21:48:33.0639 0x1660  blbdrive - ok
21:48:33.0732 0x1660  [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A, 10F21999FF6B1D410EBF280F7F27DEACA5289739CF12F4293B614B8FC6C88DCC ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
21:48:33.0763 0x1660  Bonjour Service - ok
21:48:33.0826 0x1660  [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
21:48:33.0904 0x1660  bowser - ok
21:48:33.0919 0x1660  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
21:48:34.0029 0x1660  BrFiltLo - ok
21:48:34.0044 0x1660  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
21:48:34.0107 0x1660  BrFiltUp - ok
21:48:34.0153 0x1660  [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser         C:\Windows\System32\browser.dll
21:48:34.0231 0x1660  Browser - ok
21:48:34.0263 0x1660  [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
21:48:34.0341 0x1660  Brserid - ok
21:48:34.0356 0x1660  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
21:48:34.0387 0x1660  BrSerWdm - ok
21:48:34.0403 0x1660  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
21:48:34.0450 0x1660  BrUsbMdm - ok
21:48:34.0465 0x1660  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
21:48:34.0497 0x1660  BrUsbSer - ok
21:48:34.0528 0x1660  [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
21:48:34.0559 0x1660  BTHMODEM - ok
21:48:34.0606 0x1660  [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv         C:\Windows\system32\bthserv.dll
21:48:34.0653 0x1660  bthserv - ok
21:48:34.0684 0x1660  [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
21:48:34.0746 0x1660  cdfs - ok
21:48:34.0809 0x1660  [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
21:48:34.0840 0x1660  cdrom - ok
21:48:34.0902 0x1660  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc     C:\Windows\System32\certprop.dll
21:48:34.0965 0x1660  CertPropSvc - ok
21:48:35.0011 0x1660  [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
21:48:35.0043 0x1660  circlass - ok
21:48:35.0105 0x1660  [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS            C:\Windows\system32\CLFS.sys
21:48:35.0136 0x1660  CLFS - ok
21:48:35.0245 0x1660  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:48:35.0277 0x1660  clr_optimization_v2.0.50727_32 - ok
21:48:35.0355 0x1660  [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:48:35.0386 0x1660  clr_optimization_v4.0.30319_32 - ok
21:48:35.0401 0x1660  [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
21:48:35.0433 0x1660  CmBatt - ok
21:48:35.0464 0x1660  [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
21:48:35.0479 0x1660  cmdide - ok
21:48:35.0542 0x1660  [ 3051724F223EA48968B19567DE2A81F4, DCC27DE1B2B35866FC6DBDE95A368E7D0D346B6C3F31D0BACA63DD39B0A8874E ] CNG             C:\Windows\system32\Drivers\cng.sys
21:48:35.0589 0x1660  CNG - ok
21:48:35.0620 0x1660  [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
21:48:35.0635 0x1660  Compbatt - ok
21:48:35.0667 0x1660  [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
21:48:35.0713 0x1660  CompositeBus - ok
21:48:35.0729 0x1660  COMSysApp - ok
21:48:35.0745 0x1660  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
21:48:35.0760 0x1660  crcdisk - ok
21:48:35.0823 0x1660  [ C0EAD9F8AB83D41FF07303C75589C2B8, C89CAC39BCD2FA2DCC56D7EE84FF66127BCECCAE400E119FE41BF4C4D769504B ] Creative Audio Engine Licensing Service C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
21:48:35.0854 0x1660  Creative Audio Engine Licensing Service - detected UnsignedFile.Multi.Generic ( 1 )
21:48:38.0584 0x1660  Detect skipped due to KSN trusted
21:48:38.0584 0x1660  Creative Audio Engine Licensing Service - ok
21:48:38.0693 0x1660  [ 49474B3E37969AF4B5C076F42B623AFF, BDA6B57E9B60EF1B67C74099263D33A367AAA035667239F76AB8B268FD3E8F23 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
21:48:38.0755 0x1660  CryptSvc - ok
21:48:38.0818 0x1660  [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC             C:\Windows\system32\drivers\csc.sys
21:48:38.0896 0x1660  CSC - ok
21:48:38.0943 0x1660  [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService      C:\Windows\System32\cscsvc.dll
21:48:39.0005 0x1660  CscService - ok
21:48:39.0114 0x1660  [ 07BA6D17E66879018B30B6C3F976EBED, 1759CE25519358A47E1B1FA02A415DB5D3F6B511AD3820D0AE8A1533B5DC83CD ] CTAudSvcService C:\Program Files\Creative\Shared Files\CTAudSvc.exe
21:48:39.0161 0x1660  CTAudSvcService - detected UnsignedFile.Multi.Generic ( 1 )
21:48:41.0891 0x1660  Detect skipped due to KSN trusted
21:48:41.0891 0x1660  CTAudSvcService - ok
21:48:41.0969 0x1660  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch      C:\Windows\system32\rpcss.dll
21:48:42.0078 0x1660  DcomLaunch - ok
21:48:42.0141 0x1660  [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc       C:\Windows\System32\defragsvc.dll
21:48:42.0187 0x1660  defragsvc - ok
21:48:42.0219 0x1660  [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
21:48:42.0281 0x1660  DfsC - ok
21:48:42.0328 0x1660  [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp            C:\Windows\system32\dhcpcore.dll
21:48:42.0406 0x1660  Dhcp - ok
21:48:42.0421 0x1660  [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache        C:\Windows\system32\drivers\discache.sys
21:48:42.0515 0x1660  discache - ok
21:48:42.0577 0x1660  [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
21:48:42.0609 0x1660  Disk - ok
21:48:42.0640 0x1660  [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache        C:\Windows\System32\dnsrslvr.dll
21:48:42.0718 0x1660  Dnscache - ok
21:48:42.0796 0x1660  [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc         C:\Windows\System32\dot3svc.dll
21:48:42.0874 0x1660  dot3svc - ok
21:48:42.0921 0x1660  [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS             C:\Windows\system32\dps.dll
21:48:42.0999 0x1660  DPS - ok
21:48:43.0045 0x1660  [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
21:48:43.0108 0x1660  drmkaud - ok
21:48:43.0201 0x1660  [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
21:48:43.0295 0x1660  DXGKrnl - ok
21:48:43.0357 0x1660  [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost         C:\Windows\System32\eapsvc.dll
21:48:43.0404 0x1660  EapHost - ok
21:48:43.0607 0x1660  [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv           C:\Windows\system32\DRIVERS\evbdx.sys
21:48:43.0825 0x1660  ebdrv - ok
21:48:43.0903 0x1660  [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] EFS             C:\Windows\System32\lsass.exe
21:48:43.0981 0x1660  EFS - ok
21:48:44.0075 0x1660  [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
21:48:44.0215 0x1660  ehRecvr - ok
21:48:44.0309 0x1660  [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched         C:\Windows\ehome\ehsched.exe
21:48:44.0387 0x1660  ehSched - ok
21:48:44.0434 0x1660  [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
21:48:44.0481 0x1660  elxstor - ok
21:48:44.0512 0x1660  [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
21:48:44.0543 0x1660  ErrDev - ok
21:48:44.0637 0x1660  [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem     C:\Windows\system32\es.dll
21:48:44.0699 0x1660  EventSystem - ok
21:48:44.0715 0x1660  [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat           C:\Windows\system32\drivers\exfat.sys
21:48:44.0808 0x1660  exfat - ok
21:48:44.0839 0x1660  [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
21:48:44.0902 0x1660  fastfat - ok
21:48:44.0980 0x1660  [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax             C:\Windows\system32\fxssvc.exe
21:48:45.0058 0x1660  Fax - ok
21:48:45.0073 0x1660  [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
21:48:45.0120 0x1660  fdc - ok
21:48:45.0167 0x1660  [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost         C:\Windows\system32\fdPHost.dll
21:48:45.0245 0x1660  fdPHost - ok
21:48:45.0292 0x1660  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub        C:\Windows\system32\fdrespub.dll
21:48:45.0323 0x1660  FDResPub - ok
21:48:45.0370 0x1660  [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
21:48:45.0401 0x1660  FileInfo - ok
21:48:45.0417 0x1660  [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
21:48:45.0448 0x1660  Filetrace - ok
21:48:45.0588 0x1660  [ 8669BE94F63944E4F899C3950B520241, 9991E57B3C366D59BD186CEAA78D4590EDB2BC127250CF4D1522CBE413453E72 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
21:48:45.0651 0x1660  FLEXnet Licensing Service - ok
21:48:45.0713 0x1660  [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
21:48:45.0760 0x1660  flpydisk - ok
21:48:45.0807 0x1660  [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
21:48:45.0822 0x1660  FltMgr - ok
21:48:45.0900 0x1660  [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache       C:\Windows\system32\FntCache.dll
21:48:46.0041 0x1660  FontCache - ok
21:48:46.0181 0x1660  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
21:48:46.0212 0x1660  FontCache3.0.0.0 - ok
21:48:46.0243 0x1660  FreemakeVideoCapture - ok
21:48:46.0259 0x1660  [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
21:48:46.0275 0x1660  FsDepends - ok
21:48:46.0306 0x1660  [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
21:48:46.0321 0x1660  Fs_Rec - ok
21:48:46.0384 0x1660  [ 8C89DAB1061E3D04E902404754D3FA29, 43249B36BCDB6A684ED709CCCE06380BEE92734EA7B2ACE2190B2F699E8E28D4 ] FTDIBUS         C:\Windows\system32\drivers\ftdibus.sys
21:48:46.0415 0x1660  FTDIBUS - ok
21:48:46.0477 0x1660  [ 63D72A4CF9F163B59DB0CEED940A7D76, A9CBBEC0F7D8170F410501734E7AFE475E2515D53753637C40C8F0F6B8ADE148 ] FTSER2K         C:\Windows\system32\drivers\ftser2k.sys
21:48:46.0493 0x1660  FTSER2K - ok
21:48:46.0540 0x1660  [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
21:48:46.0571 0x1660  fvevol - ok
21:48:46.0618 0x1660  [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
21:48:46.0633 0x1660  gagp30kx - ok
21:48:46.0696 0x1660  [ 185ADA973B5020655CEE342059A86CBB, D3E352DFAF30761505480A4C557D980083F65EC5BD46E2656B2114D47B272A89 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:48:46.0711 0x1660  GEARAspiWDM - ok
21:48:46.0774 0x1660  [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc           C:\Windows\System32\gpsvc.dll
21:48:46.0883 0x1660  gpsvc - ok
21:48:46.0930 0x1660  [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
21:48:46.0961 0x1660  hcw85cir - ok
21:48:47.0008 0x1660  [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:48:47.0055 0x1660  HdAudAddService - ok
21:48:47.0101 0x1660  [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
21:48:47.0148 0x1660  HDAudBus - ok
21:48:47.0179 0x1660  [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
21:48:47.0211 0x1660  HidBatt - ok
21:48:47.0242 0x1660  [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
21:48:47.0289 0x1660  HidBth - ok
21:48:47.0320 0x1660  [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
21:48:47.0351 0x1660  HidIr - ok
21:48:47.0398 0x1660  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv         C:\Windows\system32\hidserv.dll
21:48:47.0429 0x1660  hidserv - ok
21:48:47.0460 0x1660  [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
21:48:47.0538 0x1660  HidUsb - ok
21:48:47.0569 0x1660  [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc          C:\Windows\system32\kmsvc.dll
21:48:47.0616 0x1660  hkmsvc - ok
21:48:47.0647 0x1660  [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:48:47.0710 0x1660  HomeGroupListener - ok
21:48:47.0725 0x1660  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:48:47.0772 0x1660  HomeGroupProvider - ok
21:48:47.0819 0x1660  [ 8BE9369D385DC0FDF86A59F70D90AE79, CB5301009D85473AA51B88EA5ED103CB250FD36602267E261583E2ABE75B4067 ] hotcore3        C:\Windows\system32\DRIVERS\hotcore3.sys
21:48:47.0835 0x1660  hotcore3 - ok
21:48:47.0881 0x1660  [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
21:48:47.0897 0x1660  HpSAMD - ok
21:48:48.0037 0x1660  [ 487569E5DA56A5A432FF8AF6D3599CF9, 7C974D8379C60B4F69A20B01876C49181B0A63AC318C4BD0A21DABFF27A15C9D ] HTTP            C:\Windows\system32\drivers\HTTP.sys
21:48:48.0131 0x1660  HTTP - ok
21:48:48.0162 0x1660  [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
21:48:48.0178 0x1660  hwpolicy - ok
21:48:48.0271 0x1660  [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
21:48:48.0287 0x1660  i8042prt - ok
21:48:48.0318 0x1660  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
21:48:48.0365 0x1660  iaStorV - ok
21:48:48.0490 0x1660  [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
21:48:48.0552 0x1660  idsvc - ok
21:48:48.0583 0x1660  IEEtwCollectorService - ok
21:48:48.0615 0x1660  [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
21:48:48.0630 0x1660  iirsp - ok
21:48:48.0693 0x1660  [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT          C:\Windows\System32\ikeext.dll
21:48:48.0755 0x1660  IKEEXT - ok
21:48:48.0817 0x1660  [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide        C:\Windows\system32\drivers\intelide.sys
21:48:48.0849 0x1660  intelide - ok
21:48:48.0880 0x1660  [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
21:48:48.0911 0x1660  intelppm - ok
21:48:48.0958 0x1660  [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
21:48:49.0005 0x1660  IPBusEnum - ok
21:48:49.0036 0x1660  [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:48:49.0067 0x1660  IpFilterDriver - ok
21:48:49.0129 0x1660  [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
21:48:49.0192 0x1660  iphlpsvc - ok
21:48:49.0239 0x1660  [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
21:48:49.0285 0x1660  IPMIDRV - ok
21:48:49.0332 0x1660  [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
21:48:49.0395 0x1660  IPNAT - ok
21:48:49.0488 0x1660  [ FB7679FD086C60597F8C6929FF66FAC2, 6333339CB052D2A64CFBE5916D6D8F2A4D6CA84A31B549F70733A91F3C4D6EB8 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
21:48:49.0551 0x1660  iPod Service - ok
21:48:49.0582 0x1660  [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
21:48:49.0629 0x1660  IRENUM - ok
21:48:49.0660 0x1660  [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
21:48:49.0675 0x1660  isapnp - ok
21:48:49.0722 0x1660  [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
21:48:49.0753 0x1660  iScsiPrt - ok
21:48:49.0863 0x1660  [ 5645290B24D23612D8AE10BBE8BF03CE, 21DC0FFF80748CE3115658BD6CDFF9FC13711ED9E686D25233C3A73535157D0F ] ISODrive        C:\Program Files\UltraISO\drivers\ISODrive.sys
21:48:49.0894 0x1660  ISODrive - ok
21:48:49.0925 0x1660  [ 83A0305939E1D113A8D8BC2B2EA64774, 9DA55F3B8285467252B77BE887D4FC1E7194260470AE978F5EFD2E9F24F8F199 ] itecir          C:\Windows\system32\DRIVERS\itecir.sys
21:48:49.0941 0x1660  itecir - ok
21:48:49.0987 0x1660  [ C4C95805B85BCE1EB9D20F4A02FC5F9B, 0ED6A3004B0C5020223C2E1F70B7590C6772D5B272A0033679BC610E21EAE670 ] k57nd60x        C:\Windows\system32\DRIVERS\k57nd60x.sys
21:48:50.0065 0x1660  k57nd60x - ok
21:48:50.0112 0x1660  [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
21:48:50.0143 0x1660  kbdclass - ok
21:48:50.0175 0x1660  [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
21:48:50.0237 0x1660  kbdhid - ok
21:48:50.0253 0x1660  [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] KeyIso          C:\Windows\system32\lsass.exe
21:48:50.0284 0x1660  KeyIso - ok
21:48:50.0331 0x1660  [ 746F89CE0C6569C589E6AC4D3DA82D41, 6D41311CBA8BB7C9C09C1757D7947539B67FE3EFF6299502176C673809BAEAD8 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
21:48:50.0346 0x1660  KSecDD - ok
21:48:50.0377 0x1660  [ D800E1EAF33630A1636BB21E8256AA92, D07542A242E0D52B494BE63A6A141207D0A59CF66ABEBA9CE33877594BF7BA5D ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
21:48:50.0393 0x1660  KSecPkg - ok
21:48:50.0440 0x1660  [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm           C:\Windows\system32\msdtckrm.dll
21:48:50.0502 0x1660  KtmRm - ok
21:48:50.0549 0x1660  [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer    C:\Windows\system32\srvsvc.dll
21:48:50.0611 0x1660  LanmanServer - ok
21:48:50.0643 0x1660  [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:48:50.0689 0x1660  LanmanWorkstation - ok
21:48:50.0752 0x1660  [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
21:48:50.0830 0x1660  lltdio - ok
21:48:50.0877 0x1660  [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
21:48:50.0908 0x1660  lltdsvc - ok
21:48:50.0939 0x1660  [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts         C:\Windows\System32\lmhsvc.dll
21:48:50.0986 0x1660  lmhosts - ok
21:48:51.0033 0x1660  [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
21:48:51.0095 0x1660  LSI_FC - ok
21:48:51.0111 0x1660  [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
21:48:51.0126 0x1660  LSI_SAS - ok
21:48:51.0142 0x1660  [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
21:48:51.0173 0x1660  LSI_SAS2 - ok
21:48:51.0189 0x1660  [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
21:48:51.0220 0x1660  LSI_SCSI - ok
21:48:51.0267 0x1660  [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv           C:\Windows\system32\drivers\luafv.sys
21:48:51.0329 0x1660  luafv - ok
21:48:51.0376 0x1660  [ ED643E777BA3F7151EF3F0FB6BE4F7F0, 94B96367ECF2140299F36D93C00C9FE666953BEA6A1253EEEAAC439A682D38CA ] LVRS            C:\Windows\system32\DRIVERS\lvrs.sys
21:48:51.0407 0x1660  LVRS - ok
21:48:51.0610 0x1660  [ 5BC80451109A8DD7F2DDD35BCE2929A3, F97BAD2D43D1E199841BAE5707424B49B4451CD486F249646E898FC7CC7AB4C8 ] LVUVC           C:\Windows\system32\DRIVERS\lvuvc.sys
21:48:51.0828 0x1660  LVUVC - ok
21:48:51.0906 0x1660  [ D8C0B2EB928D57C928522EFF500C4BA8, B7261AB2DD262140489087C1A8F1A1DA5EE6373D453E5BC8A3F7B93A5540CE6C ] ManyCam         C:\Windows\system32\DRIVERS\mcvidrv.sys
21:48:51.0984 0x1660  ManyCam - ok
21:48:52.0031 0x1660  [ AB73A39A5E45F465B02C11C500BB0278, 6863B27DA7A0808F232B93CB74ACA09751B6F63FD9FB26EB3FA0282636CE9807 ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
21:48:52.0047 0x1660  MBAMProtector - ok
21:48:52.0218 0x1660  [ E27891A49DF92004041FEC5C3A2D4230, A4679A1F10F84935875E35A83FC7075499B8F4CBB543209A38C0D946347CD264 ] MBAMService     C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe
21:48:52.0296 0x1660  MBAMService - ok
21:48:52.0374 0x1660  [ 2A1B51A1FE8DC4DC0D52EC700CB02CEF, BF689A361F941F91B63D5F8E54925550333C068F65E59E4DBF0A7B66B8C7EDD6 ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
21:48:52.0390 0x1660  MBAMWebAccessControl - ok
21:48:52.0499 0x1660  [ 114061CEBEDB149971B70E3B31B0026A, F135084F6CF0BC1220CBCCAE3FA3FD14CBCD9E05D6E598B28FC22F6C53B5F1C3 ] McAfeeFramework C:\Program Files\McAfee\Common Framework\FrameworkService.exe
21:48:52.0530 0x1660  McAfeeFramework - ok
21:48:52.0577 0x1660  [ 964BD01FD77026F93F15040027F6F579, 7812F242A06F638094F63A1A254E1F1693EBFE2883C85E02C08301512A5585A2 ] mcaudrv_simple  C:\Windows\system32\drivers\mcaudrv.sys
21:48:52.0608 0x1660  mcaudrv_simple - ok
21:48:52.0686 0x1660  [ 6D7E4FD4262DF716DD4A80FF3E902BA6, E7CB79A0992B92D04E1957453407C650013FFC328CFA656839230C44FF088E0C ] McShield        C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
21:48:52.0717 0x1660  McShield - ok
21:48:52.0795 0x1660  [ E273B126962C4EF7D5D1223ACF283F9A, BD7C53A7F1BB297ECB48073B868D6F4AB9FBBCCA0855CBC2CCF78D6A59CB0ABB ] McTaskManager   C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
21:48:52.0842 0x1660  McTaskManager - ok
21:48:52.0858 0x1660  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
21:48:52.0873 0x1660  Mcx2Svc - ok
21:48:52.0936 0x1660  [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
21:48:52.0967 0x1660  megasas - ok
21:48:52.0998 0x1660  [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
21:48:53.0014 0x1660  MegaSR - ok
21:48:53.0076 0x1660  [ 7BE502D61AB0F06A4E70CFBAAF7AD1E4, 3F2FABB0179612E9D914E8BF0EF3E9E1FF70FC61259E9038CA8BB5FCBC59DCB0 ] mfeapfk         C:\Windows\system32\drivers\mfeapfk.sys
21:48:53.0107 0x1660  mfeapfk - ok
21:48:53.0170 0x1660  [ 76EF59EBA904D73B86915517BC1EC761, 28E2A1D9B267A9B83582BF1CF2610AF8A366B2C2335EE659D4DFFFF739B89F70 ] mfeavfk         C:\Windows\system32\drivers\mfeavfk.sys
21:48:53.0201 0x1660  mfeavfk - ok
21:48:53.0217 0x1660  mfeavfk01 - ok
21:48:53.0232 0x1660  [ DBF9632C0C3310856F60FBC8E9E435EA, 17D9C412F4ED2F72F269FC86BA72B552390D51B3F68E7ECBC5E59B1968FCF5CA ] mfebopk         C:\Windows\system32\drivers\mfebopk.sys
21:48:53.0263 0x1660  mfebopk - ok
21:48:53.0341 0x1660  [ E2B7A654C25E4DF4F772EE3AF67E6411, EAEE48FAB14C6DAA654D09832324ECCDA9FF0AD010E8F28F62380198351A1D06 ] mfehidk         C:\Windows\system32\drivers\mfehidk.sys
21:48:53.0404 0x1660  mfehidk - ok
21:48:53.0435 0x1660  [ 69B0680101DAA00ADC1B6D5EF0D22510, F976DEBF8996E014EF98B35B71CFBDD8242FEA8A6D4A52FB6F878C66EF08BFE3 ] mferkdet        C:\Windows\system32\drivers\mferkdet.sys
21:48:53.0482 0x1660  mferkdet - ok
21:48:53.0529 0x1660  [ 3DB888B4B99CC81FEE84F6839FF255CC, B12A75D3B32C87BFF01CC0AAFFAB120384FC0AA2372B37DAB0442E7C94A2EDDF ] mfevtp          C:\Windows\system32\mfevtps.exe
21:48:53.0560 0x1660  mfevtp - ok
21:48:53.0607 0x1660  [ 8DF996AB6E7F7BD7960395C16AC5C1F1, 91109370902AB4ABCB062A26184A1CF81FF2B6CCBDF3350AF1B2DB5FF0D5C4F3 ] mfewfpk         C:\Windows\system32\drivers\mfewfpk.sys
21:48:53.0638 0x1660  mfewfpk - ok
21:48:53.0669 0x1660  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS           C:\Windows\system32\mmcss.dll
21:48:53.0731 0x1660  MMCSS - ok
21:48:53.0763 0x1660  [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem           C:\Windows\system32\drivers\modem.sys
21:48:53.0794 0x1660  Modem - ok
21:48:53.0856 0x1660  [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
21:48:53.0903 0x1660  monitor - ok
21:48:53.0934 0x1660  [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
21:48:53.0950 0x1660  mouclass - ok
21:48:53.0965 0x1660  [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
21:48:54.0012 0x1660  mouhid - ok
21:48:54.0075 0x1660  [ 644905A19D0F37F2233DFCE53BC4BC19, F52CB40AA0FD1EBF8CBF0F3BFB20C47142C637719840877FB93F10D085EB8C2B ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
21:48:54.0121 0x1660  mountmgr - ok
21:48:54.0199 0x1660  [ 269BDB3CB77EB77BABE2862BEAB1F208, EC693365C73D59244CB77E181042128A9901BA5C1109CD4F1B9A2008DF1F9582 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
21:48:54.0215 0x1660  MozillaMaintenance - ok
21:48:54.0262 0x1660  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio            C:\Windows\system32\drivers\mpio.sys
21:48:54.0277 0x1660  mpio - ok
21:48:54.0309 0x1660  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
21:48:54.0355 0x1660  mpsdrv - ok
21:48:54.0418 0x1660  [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc          C:\Windows\system32\mpssvc.dll
21:48:54.0511 0x1660  MpsSvc - ok
21:48:54.0558 0x1660  [ 03F899F521D2AAED1C55008F734DF252, 4E56A51476A13F5630719018037B1F63DF9ACEA1CFE782AF04E669BD696954C5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
21:48:54.0636 0x1660  MRxDAV - ok
21:48:54.0667 0x1660  [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
21:48:54.0777 0x1660  mrxsmb - ok
21:48:54.0792 0x1660  [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:48:54.0839 0x1660  mrxsmb10 - ok
21:48:54.0870 0x1660  [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:48:54.0917 0x1660  mrxsmb20 - ok
21:48:54.0964 0x1660  [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci          C:\Windows\system32\drivers\msahci.sys
21:48:54.0979 0x1660  msahci - ok
21:48:54.0995 0x1660  [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
21:48:55.0026 0x1660  msdsm - ok
21:48:55.0042 0x1660  [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC           C:\Windows\System32\msdtc.exe
21:48:55.0073 0x1660  MSDTC - ok
21:48:55.0120 0x1660  [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs            C:\Windows\system32\drivers\Msfs.sys
21:48:55.0198 0x1660  Msfs - ok
21:48:55.0213 0x1660  [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
21:48:55.0291 0x1660  mshidkmdf - ok
21:48:55.0323 0x1660  [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
21:48:55.0338 0x1660  msisadrv - ok
21:48:55.0416 0x1660  [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
21:48:55.0479 0x1660  MSiSCSI - ok
21:48:55.0479 0x1660  msiserver - ok
21:48:55.0525 0x1660  [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
21:48:55.0588 0x1660  MSKSSRV - ok
21:48:55.0650 0x1660  [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
21:48:55.0697 0x1660  MSPCLOCK - ok
21:48:55.0728 0x1660  [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
21:48:55.0775 0x1660  MSPQM - ok
21:48:55.0806 0x1660  [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
21:48:55.0822 0x1660  MsRPC - ok
21:48:55.0884 0x1660  [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
21:48:55.0915 0x1660  mssmbios - ok
21:48:55.0931 0x1660  [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
21:48:55.0978 0x1660  MSTEE - ok
21:48:55.0993 0x1660  [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
21:48:56.0025 0x1660  MTConfig - ok
21:48:56.0056 0x1660  [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup             C:\Windows\system32\Drivers\mup.sys
21:48:56.0071 0x1660  Mup - ok
21:48:56.0103 0x1660  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent        C:\Windows\system32\qagentRT.dll
21:48:56.0165 0x1660  napagent - ok
21:48:56.0196 0x1660  [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
21:48:56.0243 0x1660  NativeWifiP - ok
21:48:56.0290 0x1660  [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS            C:\Windows\system32\drivers\ndis.sys
21:48:56.0321 0x1660  NDIS - ok
21:48:56.0368 0x1660  [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
21:48:56.0430 0x1660  NdisCap - ok
21:48:56.0477 0x1660  [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
21:48:56.0524 0x1660  NdisTapi - ok
21:48:56.0571 0x1660  [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
21:48:56.0617 0x1660  Ndisuio - ok
21:48:56.0727 0x1660  [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
21:48:56.0805 0x1660  NdisWan - ok
21:48:56.0836 0x1660  [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
21:48:56.0867 0x1660  NDProxy - ok
21:48:56.0945 0x1660  [ 9213AA35BCA94EB79D366DA254E4BDF5, 5E1C71BEB6CFFF5A6F149E9FE6E169D087A6CBE63A504FEE8D42170284952F85 ] Netaapl         C:\Windows\system32\DRIVERS\netaapl.sys
21:48:57.0101 0x1660  Netaapl - ok
21:48:57.0288 0x1660  [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
21:48:57.0335 0x1660  NetBIOS - ok
21:48:57.0366 0x1660  [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
21:48:57.0397 0x1660  NetBT - ok
21:48:57.0413 0x1660  [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] Netlogon        C:\Windows\system32\lsass.exe
21:48:57.0429 0x1660  Netlogon - ok
21:48:57.0475 0x1660  [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman          C:\Windows\System32\netman.dll
21:48:57.0522 0x1660  Netman - ok
21:48:57.0585 0x1660  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:48:57.0616 0x1660  NetMsmqActivator - ok
21:48:57.0678 0x1660  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:48:57.0709 0x1660  NetPipeActivator - ok
21:48:57.0756 0x1660  [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm        C:\Windows\System32\netprofm.dll
21:48:57.0865 0x1660  netprofm - ok
21:48:57.0897 0x1660  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:48:57.0912 0x1660  NetTcpActivator - ok
21:48:57.0928 0x1660  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:48:57.0943 0x1660  NetTcpPortSharing - ok
21:48:57.0975 0x1660  [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
21:48:57.0990 0x1660  nfrd960 - ok
21:48:58.0068 0x1660  [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc          C:\Windows\System32\nlasvc.dll
21:48:58.0131 0x1660  NlaSvc - ok
21:48:58.0177 0x1660  [ B1EF4686961986DFFB7FE8F18E6FCB5B, 562F144DAA8C2D6E4D55C7ABEF1DB52FC67F1A09E03CD700E27DFC3A4920E271 ] nlsX86cc        C:\Windows\system32\nlssrv32.exe
21:48:58.0193 0x1660  nlsX86cc - detected UnsignedFile.Multi.Generic ( 1 )
21:49:00.0907 0x1660  Detect skipped due to KSN trusted
21:49:00.0907 0x1660  nlsX86cc - ok
21:49:00.0939 0x1660  [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
21:49:01.0001 0x1660  Npfs - ok
21:49:01.0032 0x1660  [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi             C:\Windows\system32\nsisvc.dll
21:49:01.0126 0x1660  nsi - ok
21:49:01.0173 0x1660  [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
21:49:01.0219 0x1660  nsiproxy - ok
21:49:01.0329 0x1660  [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
21:49:01.0407 0x1660  Ntfs - ok
21:49:01.0485 0x1660  [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null            C:\Windows\system32\drivers\Null.sys
21:49:01.0516 0x1660  Null - ok
21:49:01.0594 0x1660  [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
21:49:01.0609 0x1660  nvraid - ok
21:49:01.0656 0x1660  [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
21:49:01.0672 0x1660  nvstor - ok
21:49:01.0734 0x1660  [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
21:49:01.0750 0x1660  nv_agp - ok
21:49:01.0797 0x1660  [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
21:49:01.0828 0x1660  ohci1394 - ok
21:49:01.0921 0x1660  [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose             C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:49:01.0953 0x1660  ose - ok
21:49:02.0249 0x1660  [ EE5756BDA5BE5891270E0CC6CEC44096, EA18073EEE0F461B14C539D49A7DD91D33AB0C503236F67F70A000835FAAC890 ] osppsvc         C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:49:02.0514 0x1660  osppsvc - ok
21:49:02.0577 0x1660  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
21:49:02.0639 0x1660  p2pimsvc - ok
21:49:02.0670 0x1660  [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc          C:\Windows\system32\p2psvc.dll
21:49:02.0733 0x1660  p2psvc - ok
21:49:02.0779 0x1660  [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport         C:\Windows\system32\DRIVERS\parport.sys
21:49:02.0811 0x1660  Parport - ok
21:49:02.0842 0x1660  [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr         C:\Windows\system32\drivers\partmgr.sys
21:49:02.0857 0x1660  partmgr - ok
21:49:02.0873 0x1660  [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
21:49:02.0904 0x1660  Parvdm - ok
21:49:02.0967 0x1660  [ 52954BE460EC6C54C0ACB2B3B126FFC6, 9F9878EC5ABC74C5A8EE8E1D940F0934F081895B07D844F42F80A638FE713F7B ] PcaSvc          C:\Windows\System32\pcasvc.dll
21:49:03.0029 0x1660  PcaSvc - ok
21:49:03.0091 0x1660  [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci             C:\Windows\system32\drivers\pci.sys
21:49:03.0107 0x1660  pci - ok
21:49:03.0154 0x1660  [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide          C:\Windows\system32\drivers\pciide.sys
21:49:03.0169 0x1660  pciide - ok
21:49:03.0216 0x1660  [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
21:49:03.0247 0x1660  pcmcia - ok
21:49:03.0279 0x1660  [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw             C:\Windows\system32\drivers\pcw.sys
21:49:03.0294 0x1660  pcw - ok
21:49:03.0419 0x1660  [ AEBC369F7DC72AB3F5B9BDF34FA0D43F, 2A819154AC6C23E97C583D90B4D0C112188B7AE9D8D9B3F88811BFCED124E551 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
21:49:03.0513 0x1660  PEAUTH - ok
21:49:03.0591 0x1660  [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
21:49:03.0747 0x1660  PeerDistSvc - ok
21:49:03.0887 0x1660  [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla             C:\Windows\system32\pla.dll
21:49:04.0012 0x1660  pla - ok
21:49:04.0059 0x1660  [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
21:49:04.0152 0x1660  PlugPlay - ok
21:49:04.0230 0x1660  [ 379F7A0EC9FBE07629FD3F244D3E3E44, 6AA3EAF3A3240383A4FF8A6FD4002DA0082F8A1B91A247BCC5BA119D6E7C34A2 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
21:49:04.0277 0x1660  Pml Driver HPZ12 - ok
21:49:04.0308 0x1660  [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
21:49:04.0339 0x1660  PNRPAutoReg - ok
21:49:04.0371 0x1660  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
21:49:04.0386 0x1660  PNRPsvc - ok
21:49:04.0464 0x1660  [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
21:49:04.0527 0x1660  PolicyAgent - ok
21:49:04.0573 0x1660  [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power           C:\Windows\system32\umpo.dll
21:49:04.0605 0x1660  Power - ok
21:49:04.0651 0x1660  [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
21:49:04.0683 0x1660  PptpMiniport - ok
21:49:04.0698 0x1660  [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor       C:\Windows\system32\DRIVERS\processr.sys
21:49:04.0729 0x1660  Processor - ok
21:49:04.0807 0x1660  [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc         C:\Windows\system32\profsvc.dll
21:49:04.0901 0x1660  ProfSvc - ok
21:49:04.0932 0x1660  [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] ProtectedStorage C:\Windows\system32\lsass.exe
21:49:04.0948 0x1660  ProtectedStorage - ok
21:49:04.0995 0x1660  [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
21:49:05.0057 0x1660  Psched - ok
21:49:05.0119 0x1660  [ 68B57D7C11277EA89F78255480376B4D, 5530B58126BF33E6BCDED99C73C41B90BA148587BDA3866FD4DAD12035B302B5 ] PSI             C:\Windows\system32\DRIVERS\psi_mf_x86.sys
21:49:05.0151 0x1660  PSI - ok
21:49:05.0229 0x1660  [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
21:49:05.0322 0x1660  ql2300 - ok
21:49:05.0338 0x1660  [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
21:49:05.0353 0x1660  ql40xx - ok
21:49:05.0416 0x1660  [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE           C:\Windows\system32\qwave.dll
21:49:05.0447 0x1660  QWAVE - ok
21:49:05.0463 0x1660  [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
21:49:05.0509 0x1660  QWAVEdrv - ok
21:49:05.0525 0x1660  [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
21:49:05.0572 0x1660  RasAcd - ok
21:49:05.0603 0x1660  [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
21:49:05.0681 0x1660  RasAgileVpn - ok
21:49:05.0712 0x1660  [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto         C:\Windows\System32\rasauto.dll
21:49:05.0743 0x1660  RasAuto - ok
21:49:05.0759 0x1660  [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
21:49:05.0821 0x1660  Rasl2tp - ok
21:49:05.0884 0x1660  [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan          C:\Windows\System32\rasmans.dll
21:49:05.0931 0x1660  RasMan - ok
21:49:05.0946 0x1660  [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
21:49:06.0009 0x1660  RasPppoe - ok
21:49:06.0071 0x1660  [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
21:49:06.0118 0x1660  RasSstp - ok
21:49:06.0149 0x1660  [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
21:49:06.0211 0x1660  rdbss - ok
21:49:06.0227 0x1660  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
21:49:06.0274 0x1660  rdpbus - ok
21:49:06.0289 0x1660  [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
21:49:06.0367 0x1660  RDPCDD - ok
21:49:06.0414 0x1660  [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
21:49:06.0492 0x1660  RDPDR - ok
21:49:06.0539 0x1660  [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
21:49:06.0570 0x1660  RDPENCDD - ok
21:49:06.0601 0x1660  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
21:49:06.0648 0x1660  RDPREFMP - ok
21:49:06.0757 0x1660  [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
21:49:06.0820 0x1660  RdpVideoMiniport - ok
21:49:06.0867 0x1660  [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
21:49:06.0945 0x1660  RDPWD - ok
21:49:06.0991 0x1660  [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
21:49:07.0007 0x1660  rdyboost - ok
21:49:07.0069 0x1660  [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess    C:\Windows\System32\mprdim.dll
21:49:07.0116 0x1660  RemoteAccess - ok
21:49:07.0147 0x1660  [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry  C:\Windows\system32\regsvc.dll
21:49:07.0225 0x1660  RemoteRegistry - ok
21:49:07.0257 0x1660  [ 6C1F93C0760C9F79A1869D07233DF39D, 70DD037E76F6E89CE9630175772707BB8588324058079B5F18C505B31306BACE ] rismxdp         C:\Windows\system32\DRIVERS\rixdptsk.sys
21:49:07.0335 0x1660  rismxdp - ok
21:49:07.0491 0x1660  [ E7062DBD907E0C5CEEB5ABDAF07E6B32, 6D6662E981510DBAD4D4E2FB38B560F2D50959EA47914FDD983FEA52DEF80E77 ] RosettaStoneDaemon C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
21:49:07.0537 0x1660  RosettaStoneDaemon - ok
21:49:07.0615 0x1660  [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
21:49:07.0678 0x1660  RpcEptMapper - ok
21:49:07.0709 0x1660  [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator      C:\Windows\system32\locator.exe
21:49:07.0771 0x1660  RpcLocator - ok
21:49:07.0818 0x1660  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs           C:\Windows\system32\rpcss.dll
21:49:07.0896 0x1660  RpcSs - ok
21:49:07.0927 0x1660  [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
21:49:07.0974 0x1660  rspndr - ok
21:49:08.0021 0x1660  [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
21:49:08.0083 0x1660  s3cap - ok
21:49:08.0099 0x1660  [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] SamSs           C:\Windows\system32\lsass.exe
21:49:08.0130 0x1660  SamSs - ok
21:49:08.0161 0x1660  SANDRA - ok
21:49:08.0193 0x1660  [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
21:49:08.0224 0x1660  sbp2port - ok
21:49:08.0286 0x1660  [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
21:49:08.0349 0x1660  SCardSvr - ok
21:49:08.0380 0x1660  [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
21:49:08.0442 0x1660  scfilter - ok
21:49:08.0536 0x1660  [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule        C:\Windows\system32\schedsvc.dll
21:49:08.0629 0x1660  Schedule - ok
21:49:08.0645 0x1660  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc     C:\Windows\System32\certprop.dll
21:49:08.0676 0x1660  SCPolicySvc - ok
21:49:08.0739 0x1660  [ 0328BE1C7F1CBA23848179F8762E391C, EA80853F04BAE6F46F658B3EFED34BFDDE20E6F2BDA349EBC17EC75DFF19855D ] sdbus           C:\Windows\system32\drivers\sdbus.sys
21:49:08.0770 0x1660  sdbus - ok
21:49:08.0832 0x1660  [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
21:49:08.0910 0x1660  SDRSVC - ok
21:49:08.0957 0x1660  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
21:49:09.0019 0x1660  secdrv - ok
21:49:09.0051 0x1660  [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon        C:\Windows\system32\seclogon.dll
21:49:09.0097 0x1660  seclogon - ok
21:49:09.0316 0x1660  [ 398A81D590424441B2F5C5C08073CADB, 1E064DFCC49EB0D8A4150276BF796B9DFA030C451570A170EC940F8CBAAD80F3 ] Secunia PSI Agent C:\Program Files\Secunia\PSI\PSIA.exe
21:49:09.0363 0x1660  Secunia PSI Agent - ok
21:49:09.0441 0x1660  [ 8C2D3A80FC90A860F0F24DEB67471481, CE4D17B63149C44B4CD5CB7776FD4705DC675F6D2D077D53BE15578294EBC9D4 ] Secunia Update Agent C:\Program Files\Secunia\PSI\sua.exe
21:49:09.0472 0x1660  Secunia Update Agent - ok
21:49:09.0550 0x1660  [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS            C:\Windows\System32\sens.dll
21:49:09.0581 0x1660  SENS - ok
21:49:09.0643 0x1660  [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
21:49:09.0706 0x1660  SensrSvc - ok
21:49:09.0784 0x1660  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
21:49:09.0831 0x1660  Serenum - ok
21:49:09.0862 0x1660  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
21:49:09.0878 0x1660  Serial - ok
21:49:09.0910 0x1660  [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
21:49:09.0956 0x1660  sermouse - ok
21:49:09.0988 0x1660  [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv      C:\Windows\system32\sessenv.dll
21:49:10.0019 0x1660  SessionEnv - ok
21:49:10.0050 0x1660  [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk         C:\Windows\system32\DRIVERS\sffdisk.sys
21:49:10.0066 0x1660  sffdisk - ok
21:49:10.0097 0x1660  [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
21:49:10.0112 0x1660  sffp_mmc - ok
21:49:10.0128 0x1660  [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd         C:\Windows\system32\DRIVERS\sffp_sd.sys
21:49:10.0144 0x1660  sffp_sd - ok
21:49:10.0159 0x1660  [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
21:49:10.0190 0x1660  sfloppy - ok
21:49:10.0253 0x1660  [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
21:49:10.0315 0x1660  SharedAccess - ok
21:49:10.0346 0x1660  [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:49:10.0393 0x1660  ShellHWDetection - ok
21:49:10.0424 0x1660  [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp          C:\Windows\system32\drivers\sisagp.sys
21:49:10.0440 0x1660  sisagp - ok
21:49:10.0487 0x1660  [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
21:49:10.0502 0x1660  SiSRaid2 - ok
21:49:10.0518 0x1660  [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
21:49:10.0549 0x1660  SiSRaid4 - ok
21:49:10.0674 0x1660  [ 704B4F81729F676BBF034529FC334D82, 1E50DAF97836807A500284385D99272780A8B69CA88761250451060B207824F8 ] SkypeUpdate     C:\Program Files\Skype\Updater\Updater.exe
21:49:10.0705 0x1660  SkypeUpdate - ok
21:49:10.0736 0x1660  [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
21:49:10.0799 0x1660  Smb - ok
21:49:10.0846 0x1660  [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
21:49:10.0861 0x1660  SNMPTRAP - ok
21:49:10.0893 0x1660  [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr           C:\Windows\system32\drivers\spldr.sys
21:49:10.0909 0x1660  spldr - ok
21:49:10.0971 0x1660  [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler         C:\Windows\System32\spoolsv.exe
21:49:11.0065 0x1660  Spooler - ok
21:49:11.0221 0x1660  [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc          C:\Windows\system32\sppsvc.exe
21:49:11.0471 0x1660  sppsvc - ok
21:49:11.0580 0x1660  [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify     C:\Windows\system32\sppuinotify.dll
21:49:11.0673 0x1660  sppuinotify - ok
21:49:11.0736 0x1660  [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv             C:\Windows\system32\DRIVERS\srv.sys
21:49:11.0783 0x1660  srv - ok
21:49:11.0814 0x1660  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
21:49:11.0861 0x1660  srv2 - ok
21:49:11.0892 0x1660  [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
21:49:11.0924 0x1660  srvnet - ok
21:49:11.0986 0x1660  [ 64E44ACD8C238FCBBB78F0BA4BDC4B05, 59D015DD86EA35AC8F667C063AE76FAFA9497F04225D256DF5A37EB1461F15D4 ] ssadbus         C:\Windows\system32\DRIVERS\ssadbus.sys
21:49:12.0033 0x1660  ssadbus - ok
21:49:12.0049 0x1660  [ BB2C84A15C765DA89FD832B0E73F26CE, BAE3E7726F075340B8CC7BCA18869DFEA304A03B0A0429B4C3D186B1149E9A9A ] ssadmdfl        C:\Windows\system32\DRIVERS\ssadmdfl.sys
21:49:12.0096 0x1660  ssadmdfl - ok
21:49:12.0111 0x1660  [ 6D0D132DDC6F43EDA00DCED6D8B1CA31, 0A37081D95A56861C3E48592048DFCFAE6FB38510D21AB41C9C73744743E7646 ] ssadmdm         C:\Windows\system32\DRIVERS\ssadmdm.sys
21:49:12.0158 0x1660  ssadmdm - ok
21:49:12.0189 0x1660  [ 1A5A397BC459F346AB56492B61EF79F6, 9CB7BE4E4A7B145D97BA0C72EE7ECB844DA6EB0282FBC3BE92A1CC5AD80FA6C4 ] ssadserd        C:\Windows\system32\DRIVERS\ssadserd.sys
21:49:12.0220 0x1660  ssadserd - ok
21:49:12.0252 0x1660  [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
21:49:12.0330 0x1660  SSDPSRV - ok
21:49:12.0361 0x1660  [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
21:49:12.0423 0x1660  SstpSvc - ok
21:49:12.0454 0x1660  [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
21:49:12.0470 0x1660  stexstor - ok
21:49:12.0517 0x1660  [ EDB05BD63148796F23EA78506404A538, 8EBF623D3DEB6CCAC75AAFCF8B23271029A28BE29D459088E40FBF109E80AA17 ] StillCam        C:\Windows\system32\DRIVERS\serscan.sys
21:49:12.0548 0x1660  StillCam - ok
21:49:12.0595 0x1660  [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc          C:\Windows\System32\wiaservc.dll
21:49:12.0642 0x1660  StiSvc - ok
21:49:12.0688 0x1660  [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
21:49:12.0704 0x1660  storflt - ok
21:49:12.0735 0x1660  [ 0BF669F0A910BEDA4A32258D363AF2A5, 83EEBACDE4F69A2866B69CAA633F5C8B3CB01D88CEDB01B6EA5988E0A25CEE47 ] StorSvc         C:\Windows\system32\storsvc.dll
21:49:12.0798 0x1660  StorSvc - ok
21:49:12.0829 0x1660  [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc         C:\Windows\system32\drivers\storvsc.sys
21:49:12.0844 0x1660  storvsc - ok
21:49:12.0860 0x1660  [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum          C:\Windows\system32\drivers\swenum.sys
21:49:12.0876 0x1660  swenum - ok
21:49:12.0907 0x1660  [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv           C:\Windows\System32\swprv.dll
21:49:12.0986 0x1660  swprv - ok
21:49:13.0064 0x1660  [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain         C:\Windows\system32\sysmain.dll
21:49:13.0204 0x1660  SysMain - ok
21:49:13.0282 0x1660  [ 5F5D2CA8D3E15B183E6BDF59C370B39A, CC8510CF4918433E445850EF7DAC5AEF62CAE06ADE2D5CBF328A866686243BC0 ] t3              C:\Windows\system32\drivers\t3.sys
21:49:13.0360 0x1660  t3 - ok
21:49:13.0391 0x1660  [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
21:49:13.0407 0x1660  TabletInputService - ok
21:49:13.0454 0x1660  [ 432D9D823C4C26B6070C41BAD4404CE4, 741B41F7467D312AF4CC733EA31F647FBCD06985CBB6A14117E8A87A6F7B06F5 ] tap0901         C:\Windows\system32\DRIVERS\tap0901.sys
21:49:13.0469 0x1660  tap0901 - ok
21:49:13.0532 0x1660  [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv         C:\Windows\System32\tapisrv.dll
21:49:13.0594 0x1660  TapiSrv - ok
21:49:13.0625 0x1660  [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS             C:\Windows\System32\tbssvc.dll
21:49:13.0672 0x1660  TBS - ok
21:49:13.0750 0x1660  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
21:49:13.0828 0x1660  Tcpip - ok
21:49:13.0937 0x1660  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
21:49:13.0984 0x1660  TCPIP6 - ok
21:49:14.0031 0x1660  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
21:49:14.0047 0x1660  tcpipreg - ok
21:49:14.0093 0x1660  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
21:49:14.0125 0x1660  TDPIPE - ok
21:49:14.0125 0x1660  [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
21:49:14.0156 0x1660  TDTCP - ok
21:49:14.0203 0x1660  [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
21:49:14.0249 0x1660  tdx - ok
21:49:14.0265 0x1660  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD          C:\Windows\system32\drivers\termdd.sys
21:49:14.0281 0x1660  TermDD - ok
21:49:14.0405 0x1660  [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService     C:\Windows\System32\termsrv.dll
21:49:14.0499 0x1660  TermService - ok
21:49:14.0530 0x1660  [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes          C:\Windows\system32\themeservice.dll
21:49:14.0577 0x1660  Themes - ok
21:49:14.0608 0x1660  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER     C:\Windows\system32\mmcss.dll
21:49:14.0639 0x1660  THREADORDER - ok
21:49:14.0686 0x1660  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks          C:\Windows\System32\trkwks.dll
21:49:14.0717 0x1660  TrkWks - ok
21:49:14.0780 0x1660  [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:49:14.0811 0x1660  TrustedInstaller - ok
21:49:14.0873 0x1660  [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
21:49:14.0889 0x1660  tssecsrv - ok
21:49:14.0936 0x1660  [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
21:49:14.0998 0x1660  TsUsbFlt - ok
21:49:15.0045 0x1660  [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
21:49:15.0092 0x1660  tunnel - ok
21:49:15.0170 0x1660  [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
21:49:15.0201 0x1660  uagp35 - ok
21:49:15.0248 0x1660  [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
21:49:15.0295 0x1660  udfs - ok
21:49:15.0357 0x1660  [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect       C:\Windows\system32\UI0Detect.exe
21:49:15.0435 0x1660  UI0Detect - ok
21:49:15.0497 0x1660  [ 16264D4A7F052A7CC516B23E00B14213, 0741A7629D8511F044ABB1DE0819FF07CAF4B6A6F5B0320C6E7B70D261861B5C ] UimBus          C:\Windows\system32\DRIVERS\UimBus.sys
21:49:15.0529 0x1660  UimBus - ok
21:49:15.0575 0x1660  [ 811E4296913821CE402B9E6629740350, 48762C3E4BA1D59C4518B334EFFA78ADFEC7408DD255970994FEC1BEF5BD2381 ] Uim_IM          C:\Windows\system32\Drivers\Uim_IM.sys
21:49:15.0638 0x1660  Uim_IM - ok
21:49:15.0669 0x1660  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
21:49:15.0700 0x1660  uliagpkx - ok
21:49:15.0732 0x1660  [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
21:49:15.0778 0x1660  umbus - ok
21:49:15.0825 0x1660  [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
21:49:15.0872 0x1660  UmPass - ok
21:49:15.0919 0x1660  [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService    C:\Windows\System32\umrdp.dll
21:49:15.0963 0x1660  UmRdpService - ok
21:49:16.0066 0x1660  [ 67A95B9D129ED5399E7965CD09CF30E7, F1F2F684146F1CCB293BB9871117B8CFC1D04588A830F67CE5D3F0D034D93B2A ] UMVPFSrv        C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
21:49:16.0112 0x1660  UMVPFSrv - ok
21:49:16.0159 0x1660  [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost        C:\Windows\System32\upnphost.dll
21:49:16.0222 0x1660  upnphost - ok
21:49:16.0268 0x1660  [ EC1C23779BB41A8B2AB2AA6FCE308BDE, D027A2B472CAE97AECB16F69BE52E06CB61E1C61AE196C22662050B711C1C72D ] USBAAPL         C:\Windows\system32\Drivers\usbaapl.sys
21:49:16.0346 0x1660  USBAAPL - ok
21:49:16.0409 0x1660  [ A1977C315BF5691DA99235AA4A6907AF, 34B52FBA83F0E1C6B001D0AD1808B00152F731D18AAECC3C53B9918AA89BACEC ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
21:49:16.0487 0x1660  usbaudio - ok
21:49:16.0518 0x1660  [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
21:49:16.0549 0x1660  usbccgp - ok
21:49:16.0612 0x1660  [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir          C:\Windows\system32\drivers\usbcir.sys
21:49:16.0658 0x1660  usbcir - ok
21:49:16.0705 0x1660  [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
21:49:16.0721 0x1660  usbehci - ok
21:49:16.0768 0x1660  [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
21:49:16.0799 0x1660  usbhub - ok
21:49:16.0814 0x1660  [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
21:49:16.0877 0x1660  usbohci - ok
21:49:16.0908 0x1660  [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
21:49:16.0986 0x1660  usbprint - ok
21:49:17.0017 0x1660  [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:49:17.0064 0x1660  USBSTOR - ok
21:49:17.0111 0x1660  [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci         C:\Windows\system32\DRIVERS\usbuhci.sys
21:49:17.0142 0x1660  usbuhci - ok
21:49:17.0220 0x1660  [ DE014425522610BEDCA3821BB8C0F1D5, D6FEA0DF07F89834AEEE8C02CC7FD41068D758B6CCECE2EEE5CF4B9DB646FA1E ] usbvideo        C:\Windows\System32\Drivers\usbvideo.sys
21:49:17.0251 0x1660  usbvideo - ok
21:49:17.0282 0x1660  [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms           C:\Windows\System32\uxsms.dll
21:49:17.0345 0x1660  UxSms - ok
21:49:17.0376 0x1660  [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] VaultSvc        C:\Windows\system32\lsass.exe
21:49:17.0392 0x1660  VaultSvc - ok
21:49:17.0501 0x1660  [ DAEF3AC067094497402C77476BBC3540, BE2CD4AB987BCB9258E97C48450399D6A3D610A199AE2A6BF91CDC7F54DF490A ] VClone          C:\Windows\system32\DRIVERS\VClone.sys
21:49:17.0548 0x1660  VClone - ok
21:49:17.0594 0x1660  [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
21:49:17.0610 0x1660  vdrvroot - ok
21:49:17.0657 0x1660  [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds             C:\Windows\System32\vds.exe
21:49:17.0766 0x1660  vds - ok
21:49:17.0813 0x1660  [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
21:49:17.0906 0x1660  vga - ok
21:49:17.0922 0x1660  [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave         C:\Windows\System32\drivers\vga.sys
21:49:17.0984 0x1660  VgaSave - ok
21:49:18.0016 0x1660  [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
21:49:18.0047 0x1660  vhdmp - ok
21:49:18.0078 0x1660  [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
21:49:18.0094 0x1660  viaagp - ok
21:49:18.0109 0x1660  [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7           C:\Windows\system32\DRIVERS\viac7.sys
21:49:18.0140 0x1660  ViaC7 - ok
21:49:18.0172 0x1660  [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide          C:\Windows\system32\drivers\viaide.sys
21:49:18.0203 0x1660  viaide - ok
21:49:18.0250 0x1660  [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus           C:\Windows\system32\drivers\vmbus.sys
21:49:18.0281 0x1660  vmbus - ok
21:49:18.0312 0x1660  [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
21:49:18.0328 0x1660  VMBusHID - ok
21:49:18.0343 0x1660  [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
21:49:18.0374 0x1660  volmgr - ok
21:49:18.0390 0x1660  [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
21:49:18.0437 0x1660  volmgrx - ok
21:49:18.0468 0x1660  [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
21:49:18.0499 0x1660  volsnap - ok
21:49:18.0640 0x1660  [ D9ED5BF4CEDDD0D029A71E615A65D4EF, 3710A1C644AF8503B4194D556ED788E767EC08032E71F6B82BE8AB28C007A377 ] vpnagent        C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
21:49:18.0686 0x1660  vpnagent - ok
21:49:18.0749 0x1660  [ FDAAED2C4DBFCBCF6F8283A915C32B66, BA600630E79FB71DAA569698E2897A28E8992BCF33C5D2BC49908C71845284CB ] vpnva           C:\Windows\system32\DRIVERS\vpnva-6.sys
21:49:18.0764 0x1660  vpnva - ok
21:49:18.0858 0x1660  [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
21:49:18.0889 0x1660  vsmraid - ok
21:49:18.0967 0x1660  [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS             C:\Windows\system32\vssvc.exe
21:49:19.0092 0x1660  VSS - ok
21:49:19.0123 0x1660  [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
21:49:19.0139 0x1660  vwifibus - ok
21:49:19.0201 0x1660  [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
21:49:19.0232 0x1660  vwififlt - ok
21:49:19.0295 0x1660  [ A3F04CBEA6C2A10E6CB01F8B47611882, 32AFE18B07FECA30BC95831A5DC94C784E543784DF16165334A777DC84E91EF3 ] vwifimp         C:\Windows\system32\DRIVERS\vwifimp.sys
21:49:19.0326 0x1660  vwifimp - ok
21:49:19.0388 0x1660  [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time         C:\Windows\system32\w32time.dll
21:49:19.0466 0x1660  W32Time - ok
21:49:19.0513 0x1660  [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
21:49:19.0529 0x1660  WacomPen - ok
21:49:19.0560 0x1660  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
21:49:19.0591 0x1660  WANARP - ok
21:49:19.0591 0x1660  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
21:49:19.0622 0x1660  Wanarpv6 - ok
21:49:19.0810 0x1660  [ 353A04C273EC58475D8633E75CCD5604, FFAE53B6B53AEFC9E8A10BF27480E072D74430276BEB532FE1D473E9616D8CE0 ] WatAdminSvc     C:\Windows\system32\Wat\WatAdminSvc.exe
21:49:19.0888 0x1660  WatAdminSvc - ok
21:49:19.0966 0x1660  [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine        C:\Windows\system32\wbengine.exe
21:49:20.0090 0x1660  wbengine - ok
21:49:20.0137 0x1660  [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
21:49:20.0215 0x1660  WbioSrvc - ok
21:49:20.0356 0x1660  [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc         C:\Windows\System32\wcncsvc.dll
21:49:20.0418 0x1660  wcncsvc - ok
21:49:20.0465 0x1660  [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:49:20.0527 0x1660  WcsPlugInService - ok
21:49:20.0574 0x1660  [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd              C:\Windows\system32\DRIVERS\wd.sys
21:49:20.0590 0x1660  Wd - ok
21:49:20.0652 0x1660  [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
21:49:20.0746 0x1660  Wdf01000 - ok
21:49:20.0808 0x1660  [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiServiceHost  C:\Windows\system32\wdi.dll
21:49:20.0870 0x1660  WdiServiceHost - ok
21:49:20.0886 0x1660  [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiSystemHost   C:\Windows\system32\wdi.dll
21:49:20.0902 0x1660  WdiSystemHost - ok
21:49:20.0964 0x1660  [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient       C:\Windows\System32\webclnt.dll
21:49:21.0011 0x1660  WebClient - ok
21:49:21.0042 0x1660  [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc          C:\Windows\system32\wecsvc.dll
21:49:21.0089 0x1660  Wecsvc - ok
21:49:21.0120 0x1660  [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
21:49:21.0167 0x1660  wercplsupport - ok
21:49:21.0198 0x1660  [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc          C:\Windows\System32\WerSvc.dll
21:49:21.0229 0x1660  WerSvc - ok
21:49:21.0260 0x1660  [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
21:49:21.0338 0x1660  WfpLwf - ok
21:49:21.0448 0x1660  [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
21:49:21.0479 0x1660  WIMMount - ok
21:49:21.0588 0x1660  [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
21:49:21.0666 0x1660  WinDefend - ok
21:49:21.0697 0x1660  WinHttpAutoProxySvc - ok
21:49:21.0744 0x1660  [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
21:49:21.0806 0x1660  Winmgmt - ok
21:49:21.0916 0x1660  [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM           C:\Windows\system32\WsmSvc.dll
21:49:22.0025 0x1660  WinRM - ok
21:49:22.0072 0x1660  [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
21:49:22.0103 0x1660  WinUsb - ok
21:49:22.0181 0x1660  [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc         C:\Windows\System32\wlansvc.dll
21:49:22.0274 0x1660  Wlansvc - ok
21:49:22.0321 0x1660  [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
21:49:22.0352 0x1660  WmiAcpi - ok
21:49:22.0399 0x1660  [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
21:49:22.0477 0x1660  wmiApSrv - ok
21:49:22.0602 0x1660  [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
21:49:22.0758 0x1660  WMPNetworkSvc - ok
21:49:22.0836 0x1660  [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
21:49:22.0867 0x1660  WPCSvc - ok
21:49:22.0883 0x1660  [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
21:49:22.0976 0x1660  WPDBusEnum - ok
21:49:23.0023 0x1660  [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
21:49:23.0086 0x1660  ws2ifsl - ok
21:49:23.0117 0x1660  [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc          C:\Windows\System32\wscsvc.dll
21:49:23.0148 0x1660  wscsvc - ok
21:49:23.0210 0x1660  [ 553F6CCD7C58EB98D4A8FBDAF283D7A9, 71FBE50C470D1F54FDAADCECEC2CB021AE240CD59DE4E8EB5BCAA6E7F2F86560 ] WSDPrintDevice  C:\Windows\system32\DRIVERS\WSDPrint.sys
21:49:23.0242 0x1660  WSDPrintDevice - ok
21:49:23.0242 0x1660  WSearch - ok
21:49:23.0429 0x1660  [ 7E5C454A3F986FEBAD075DB8D915917E, 9E9147DDACD075958689523130DB92FC4ED0E38433461D8AB8792BCFBD9376DA ] wuauserv        C:\Windows\system32\wuaueng.dll
21:49:23.0678 0x1660  wuauserv - ok
21:49:23.0710 0x1660  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
21:49:23.0772 0x1660  WudfPf - ok
21:49:23.0803 0x1660  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
21:49:23.0834 0x1660  WUDFRd - ok
21:49:23.0866 0x1660  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
21:49:23.0897 0x1660  wudfsvc - ok
21:49:23.0944 0x1660  [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc         C:\Windows\System32\wwansvc.dll
21:49:24.0006 0x1660  WwanSvc - ok
21:49:24.0100 0x1660  ================ Scan global ===============================
21:49:24.0131 0x1660  [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
21:49:24.0193 0x1660  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
21:49:24.0224 0x1660  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
21:49:24.0256 0x1660  [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
21:49:24.0287 0x1660  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
21:49:24.0302 0x1660  [ Global ] - ok
21:49:24.0302 0x1660  ================ Scan MBR ==================================
21:49:24.0318 0x1660  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:49:25.0254 0x1660  \Device\Harddisk0\DR0 - ok
21:49:25.0254 0x1660  ================ Scan VBR ==================================
21:49:25.0301 0x1660  [ 9DCEB0FBC5194179F029EF2FA730C037 ] \Device\Harddisk0\DR0\Partition1
21:49:25.0410 0x1660  \Device\Harddisk0\DR0\Partition1 - ok
21:49:25.0426 0x1660  [ 3EE48B38F7388CAE339123F5E7BB5928 ] \Device\Harddisk0\DR0\Partition2
21:49:25.0426 0x1660  \Device\Harddisk0\DR0\Partition2 - ok
21:49:25.0426 0x1660  ================ Scan generic autorun ======================
21:49:25.0488 0x1660  [ A6AADFE1B60E2232038BED6AA6666637, D3AC327BB9793C082B4E2FC94DD1EF885155291C9DC800E9178E26D4CB768156 ] C:\Program Files\McAfee\Common Framework\udaterui.exe
21:49:25.0504 0x1660  McAfeeUpdaterUI - ok
21:49:25.0566 0x1660  [ E5ED0DC1902D63733445D07D295CDA7C, 93310EE0ABE6F0AE9F71D8281096CDB1970AA92B6650B732319927CC71BEAE9A ] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
21:49:25.0582 0x1660  ShStatEXE - ok
21:49:25.0644 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
21:49:25.0831 0x1660  Sidebar - ok
21:49:25.0862 0x1660  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
21:49:25.0894 0x1660  mctadmin - ok
21:49:25.0925 0x1660  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
21:49:25.0972 0x1660  Sidebar - ok
21:49:25.0987 0x1660  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
21:49:26.0003 0x1660  mctadmin - ok
21:49:26.0315 0x1660  [ 2E0CF98623181D40BF79558387875F35, BC0E204D36CAF4864FD93A8FE260468320B7F5936ED338DF77DDE9A774C8C964 ] C:\Program Files\FileHippo.com\FileHippo.AppManager.exe
21:49:26.0486 0x1660  FileHippo.com - ok
21:49:27.0844 0x1660  [ A75228DE9117A017BC7A3B44953B2648, 9AA3D2F883F187620612CD7CA3871187B8181ACE9EF918C31A74DBAAF2F81A60 ] C:\Program Files\CCleaner\CCleaner.exe
21:49:28.0405 0x1660  CCleaner Monitoring - ok
21:49:28.0436 0x1660  SandboxieControl - ok
21:49:28.0686 0x1660  [ E74BF46DE94E62FA01C61EF084F7A7DD, 51CD74F0790C7FBDF0DEA16F1A582F07F4BCF7C9A87EA72B7D0FBC0B8EFD42EF ] C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe
21:49:28.0748 0x1660  Spotify Web Helper - ok
21:49:28.0873 0x1660  [ EC58C1A9A3281CE0C8FCC05BDBFECB37, 3738BBC112346B32F686F1CB4B4AAD89B06AA1F8FB2D333BC2D2F554212A0A59 ] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
21:49:28.0889 0x1660  iCloudServices - ok
21:49:28.0920 0x1660  [ 105C276BB7B43501225C419B062096D0, F5D35230FC5E116FB04147F216313D2E2542D96E975B19F5FD9F7641CF11271F ] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
21:49:28.0936 0x1660  ApplePhotoStreams - ok
21:49:29.0029 0x1660  [ 7E0B4C8EFEDDEBE87D2A1F5A33B965B5, D7102B38A0F1BDA2DC3D5C7A8DAE13758F5CFC29C5AE3D3791EFAFB5A9F7275D ] C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe
21:49:29.0060 0x1660  AppleIEDAV - ok
21:49:29.0076 0x1660  SUPERAntiSpyware - ok
21:49:29.0123 0x1660  SWITCHdrive - ok
21:49:29.0341 0x1660  [ 32E8A4FCE03B255E7C7448F3B4910BC0, 56EA3F53A5636549271C18FE6126D7F572F97415852D27B966E32304B4A70004 ] C:\Users\Marci\AppData\Roaming\Spotify\SpotifyWebHelper.exe
21:49:29.0466 0x1660  Spotify Web Helper - ok
21:49:30.0121 0x1660  [ A75228DE9117A017BC7A3B44953B2648, 9AA3D2F883F187620612CD7CA3871187B8181ACE9EF918C31A74DBAAF2F81A60 ] C:\Program Files\CCleaner\CCleaner.exe
21:49:30.0277 0x1660  CCleaner Monitoring - ok
21:49:30.0620 0x1660  [ 60428B7F66FE3A08DE7FCB12A5EA58F6, 3C0F9FD7646B324F3EB5775D75BAA72E1B90AA0ADD8F812603565769943954DF ] C:\Users\Marci\AppData\Roaming\Spotify\Spotify.exe
21:49:30.0964 0x1660  Spotify - ok
21:49:30.0979 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:31.0993 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:33.0007 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:34.0021 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:35.0035 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:36.0049 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:37.0063 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:38.0077 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:39.0091 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:40.0105 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:41.0119 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:42.0133 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:43.0147 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:44.0161 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:45.0175 0x1660  Waiting for KSN requests completion. In queue: 82
21:49:46.0252 0x1660  AV detected via SS2: McAfee VirusScan Enterprise, "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /!REMEDIATE (  ), 0x61000 ( enabled : updated )
21:49:46.0283 0x1660  Win FW state via NFP2: enabled
21:49:49.0044 0x1660  ============================================================
21:49:49.0044 0x1660  Scan finished
21:49:49.0044 0x1660  ============================================================
21:49:49.0044 0x15d4  Detected object count: 0
21:49:49.0044 0x15d4  Actual detected object count: 0
         
__________________

Alt 18.04.2015, 19:52   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 19.04.2015, 15:12   #5
kittyhawk
 
Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Danke, hier der Code:

Wie sieht es aus soweit?

Code:
ATTFilter
ComboFix 15-04-16.01 - Admin 19.04.2015  14:33:41.2.2 - x86
Microsoft Windows 7 Professional   6.1.7601.1.1252.49.1033.18.3582.2471 [GMT 2:00]
ausgeführt von:: c:\users\Standard User\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
SP: McAfee VirusScan Enterprise Antispyware Module *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
 ADS - Windows: deleted 0 bytes in 1 streams. 
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Vorheriger Suchlauf -------
.
c:\programdata\ntuser.pol
c:\users\Public\sdelevURL.tmp
c:\windows\system32\AdobePDF.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2015-03-19 bis 2015-04-19  ))))))))))))))))))))))))))))))
.
.
2015-04-19 12:56 . 2015-04-19 12:56	--------	d-----w-	c:\users\Marci\AppData\Local\temp
2015-04-19 12:56 . 2015-04-19 12:56	--------	d-----w-	c:\users\Default\AppData\Local\temp
2015-04-19 09:08 . 2015-04-19 12:56	--------	d-----w-	c:\users\Admin\AppData\Local\temp
2015-04-18 13:44 . 2015-04-18 13:44	163504	----a-w-	c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2015-04-17 19:01 . 2015-04-17 19:44	--------	d-----w-	c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-04-17 17:51 . 2015-04-17 17:56	--------	d-----w-	C:\FRST
2015-04-17 09:31 . 2015-04-19 08:14	--------	d-----w-	C:\QUARANTINE
2015-04-17 07:47 . 2015-04-17 07:47	--------	d-----w-	c:\program files\Common Files\Java
2015-04-15 17:49 . 2015-03-04 04:16	249784	----a-w-	c:\windows\system32\clfs.sys
2015-04-15 17:49 . 2015-03-04 04:10	58880	----a-w-	c:\windows\system32\clfsw32.dll
2015-04-15 17:49 . 2015-03-17 04:59	1306112	----a-w-	c:\windows\system32\ntdll.dll
2015-04-15 17:49 . 2015-03-17 05:01	3920824	----a-w-	c:\windows\system32\ntoskrnl.exe
2015-04-15 17:49 . 2015-03-17 05:01	3976632	----a-w-	c:\windows\system32\ntkrnlpa.exe
2015-04-15 17:49 . 2015-03-17 04:57	1061376	----a-w-	c:\windows\system32\lsasrv.dll
2015-04-15 17:49 . 2015-03-17 05:01	137656	----a-w-	c:\windows\system32\drivers\ksecpkg.sys
2015-04-15 17:49 . 2015-03-17 04:57	248832	----a-w-	c:\windows\system32\schannel.dll
2015-04-15 17:41 . 2015-03-05 04:06	305152	----a-w-	c:\windows\system32\gdi32.dll
2015-04-15 17:38 . 2015-02-25 03:03	514560	----a-w-	c:\windows\system32\drivers\http.sys
2015-04-15 17:14 . 2015-03-10 03:08	1237504	----a-w-	c:\windows\system32\msxml3.dll
2015-04-15 17:14 . 2015-03-10 03:05	2048	----a-w-	c:\windows\system32\msxml3r.dll
2015-04-11 09:55 . 2015-04-11 09:55	--------	d-----w-	c:\program files\iPod
2015-04-11 09:55 . 2015-04-11 09:58	--------	d-----w-	c:\programdata\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-11 09:55 . 2015-04-11 09:58	--------	d-----w-	c:\program files\iTunes
2015-04-11 09:40 . 2015-04-11 09:40	--------	d-----w-	c:\users\Standard User\Tracing
2015-04-11 09:22 . 2015-04-11 09:25	--------	d-s---w-	c:\windows\system32\GWX
2015-04-11 07:10 . 2015-03-23 03:06	860160	----a-w-	c:\windows\system32\appraiser.dll
2015-04-11 07:10 . 2015-03-23 03:06	576000	----a-w-	c:\windows\system32\generaltel.dll
2015-04-11 07:10 . 2015-03-23 03:06	26112	----a-w-	c:\windows\system32\acmigration.dll
2015-04-11 07:10 . 2015-03-23 02:59	896000	----a-w-	c:\windows\system32\aeinv.dll
2015-04-02 13:26 . 2015-04-02 13:26	2984632	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\1031\MSOINTL.DLL
2015-03-31 08:22 . 2015-03-31 08:22	550064	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\MSOSQM.EXE
2015-03-31 08:22 . 2015-03-31 08:22	26825912	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2015-03-31 08:22 . 2015-03-31 08:22	112452792	----a-w-	c:\program files\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-04-18 10:03 . 2014-07-12 12:12	119512	----a-w-	c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-04-17 19:00 . 2014-07-12 12:12	92888	----a-w-	c:\windows\system32\drivers\mbamchameleon.sys
2015-04-17 07:44 . 2015-03-06 16:56	96680	----a-w-	c:\windows\system32\WindowsAccessBridge.dll
2015-04-17 06:56 . 2012-06-04 16:13	778416	----a-w-	c:\windows\system32\FlashPlayerApp.exe
2015-04-17 06:56 . 2012-06-04 15:40	142512	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl
2015-03-17 05:15 . 2014-07-12 12:12	51928	----a-w-	c:\windows\system32\drivers\mwac.sys
2015-03-17 05:15 . 2012-06-04 10:10	23256	----a-w-	c:\windows\system32\drivers\mbam.sys
2015-02-26 03:11 . 2015-03-13 08:44	2381312	----a-w-	c:\windows\system32\win32k.sys
2015-02-20 04:13 . 2015-03-13 08:37	26624	----a-w-	c:\windows\system32\lpk.dll
2015-02-20 04:13 . 2015-03-13 08:37	70656	----a-w-	c:\windows\system32\fontsub.dll
2015-02-20 04:13 . 2015-03-13 08:37	10240	----a-w-	c:\windows\system32\dciman32.dll
2015-02-20 04:13 . 2015-03-13 08:37	34304	----a-w-	c:\windows\system32\atmlib.dll
2015-02-20 03:09 . 2015-03-13 08:37	299008	----a-w-	c:\windows\system32\atmfd.dll
2015-02-17 14:29 . 2015-02-17 14:29	1247912	----a-w-	c:\windows\system32\FM20.DLL
2015-02-04 10:23 . 2015-02-04 10:23	875688	----a-w-	c:\windows\system32\msvcr120_clr0400.dll
2015-02-04 02:54 . 2015-03-13 08:37	417792	----a-w-	c:\windows\system32\WMPhoto.dll
2015-02-03 03:16 . 2015-03-13 08:35	78784	----a-w-	c:\windows\system32\drivers\mountmgr.sys
2015-02-03 03:12 . 2015-03-13 08:35	179200	----a-w-	c:\windows\system32\wintrust.dll
2015-02-03 03:12 . 2015-03-13 08:35	617984	----a-w-	c:\windows\system32\wmdrmsdk.dll
2015-02-03 03:12 . 2015-03-13 08:44	1230848	----a-w-	c:\windows\system32\WindowsCodecs.dll
2015-02-03 03:12 . 2015-03-13 08:37	171520	----a-w-	c:\windows\system32\ubpm.dll
2015-02-03 03:12 . 2015-03-13 08:34	4096	----a-w-	c:\windows\system32\msdxm.ocx
2015-02-03 03:12 . 2015-03-13 08:34	4096	----a-w-	c:\windows\system32\dxmasf.dll
2015-02-03 03:12 . 2015-03-13 08:34	50176	----a-w-	c:\windows\system32\setbcdlocale.dll
2015-02-03 03:12 . 2015-03-13 08:35	1329664	----a-w-	c:\windows\system32\quartz.dll
2015-02-03 03:12 . 2015-03-13 08:35	519680	----a-w-	c:\windows\system32\qdvd.dll
2015-02-03 03:12 . 2015-03-13 08:35	442880	----a-w-	c:\windows\system32\AUDIOKSE.dll
2015-02-03 03:12 . 2015-03-13 08:35	157184	----a-w-	c:\windows\system32\pcasvc.dll
2015-02-03 03:12 . 2015-03-13 08:35	28160	----a-w-	c:\windows\system32\pcadm.dll
2015-02-03 03:12 . 2015-03-13 08:34	8192	----a-w-	c:\windows\system32\spwmp.dll
2015-02-03 03:12 . 2015-03-13 08:35	504320	----a-w-	c:\windows\system32\msscp.dll
2015-02-03 03:12 . 2015-03-13 08:35	265216	----a-w-	c:\windows\system32\msnetobj.dll
2015-02-03 03:12 . 2015-03-13 08:34	10752	----a-w-	c:\windows\system32\msmmsp.dll
2015-02-03 03:12 . 2015-03-13 08:36	3209728	----a-w-	c:\windows\system32\mf.dll
2015-02-03 03:12 . 2015-03-13 08:35	354816	----a-w-	c:\windows\system32\mfplat.dll
2015-02-03 03:12 . 2015-03-13 08:35	103424	----a-w-	c:\windows\system32\mfps.dll
2015-02-03 03:12 . 2015-03-13 08:35	489984	----a-w-	c:\windows\system32\evr.dll
2015-02-03 03:12 . 2015-03-13 08:34	275968	----a-w-	c:\windows\system32\EncDump.dll
2015-02-03 03:12 . 2015-03-13 08:35	988160	----a-w-	c:\windows\system32\drmv2clt.dll
2015-02-03 03:12 . 2015-03-13 08:35	406016	----a-w-	c:\windows\system32\drmmgrtn.dll
2015-02-03 03:12 . 2015-03-13 08:36	1174528	----a-w-	c:\windows\system32\crypt32.dll
2015-02-03 03:12 . 2015-03-13 08:35	1005056	----a-w-	c:\windows\system32\cryptui.dll
2015-02-03 03:12 . 2015-03-13 08:35	103936	----a-w-	c:\windows\system32\cryptnet.dll
2015-02-03 03:12 . 2015-03-13 08:35	143872	----a-w-	c:\windows\system32\cryptsvc.dll
2015-02-03 03:12 . 2015-03-13 08:34	81408	----a-w-	c:\windows\system32\cryptsp.dll
2015-02-03 03:12 . 2015-03-13 08:35	744960	----a-w-	c:\windows\system32\blackbox.dll
2015-02-03 03:12 . 2015-03-13 08:35	475136	----a-w-	c:\windows\system32\audiosrv.dll
2015-02-03 03:12 . 2015-03-13 08:35	374784	----a-w-	c:\windows\system32\AudioEng.dll
2015-02-03 03:12 . 2015-03-13 08:35	50688	----a-w-	c:\windows\system32\appidapi.dll
2015-02-03 03:12 . 2015-03-13 08:34	195584	----a-w-	c:\windows\system32\AudioSes.dll
2015-02-03 03:12 . 2015-03-13 08:34	27648	----a-w-	c:\windows\system32\appidsvc.dll
2015-02-03 03:11 . 2015-03-13 08:35	50176	----a-w-	c:\windows\system32\rrinstaller.exe
2015-02-03 03:11 . 2015-03-13 08:34	9728	----a-w-	c:\windows\system32\pcawrk.exe
2015-02-03 03:11 . 2015-03-13 08:34	8192	----a-w-	c:\windows\system32\pcalua.exe
2015-02-03 03:11 . 2015-03-13 08:34	23040	----a-w-	c:\windows\system32\mfpmp.exe
2015-02-03 03:11 . 2015-03-13 08:35	100864	----a-w-	c:\windows\system32\audiodg.exe
2015-02-03 03:11 . 2015-03-13 08:34	96768	----a-w-	c:\windows\system32\appidpolicyconverter.exe
2015-02-03 03:11 . 2015-03-13 08:34	16896	----a-w-	c:\windows\system32\appidcertstorecheck.exe
2015-02-03 03:11 . 2015-03-13 08:34	12625408	----a-w-	c:\windows\system32\wmploc.DLL
2015-02-03 03:10 . 2015-03-13 08:34	8704	----a-w-	c:\windows\system32\pcaevts.dll
2015-02-03 03:09 . 2015-03-13 08:34	2048	----a-w-	c:\windows\system32\mferror.dll
2015-02-03 03:00 . 2015-03-13 08:35	593920	----a-w-	c:\windows\system32\drivers\PEAuth.sys
2015-02-03 02:26 . 2015-03-13 08:34	50176	----a-w-	c:\windows\system32\drivers\appid.sys
2015-01-31 03:33 . 2015-03-13 08:44	2744320	----a-w-	c:\windows\system32\rdpcorets.dll
2015-01-31 03:33 . 2015-03-13 08:44	13824	----a-w-	c:\windows\system32\RdpGroupPolicyExtension.dll
2015-01-31 00:48 . 2015-03-13 08:44	221184	----a-w-	c:\windows\system32\rdpudd.dll
2015-01-30 23:56 . 2015-03-13 08:35	370488	----a-w-	c:\windows\system32\drivers\cng.sys
2015-01-27 23:36 . 2015-02-11 19:21	1167520	----a-w-	c:\windows\system32\aitstatic.exe
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  OCError]
@="{0960F090-F328-48A3-B746-276B1E3C3722}"
[HKEY_CLASSES_ROOT\CLSID\{0960F090-F328-48A3-B746-276B1E3C3722}]
2014-11-06 14:46	268800	----a-w-	c:\program files\SWITCHdrive\shellext\OCOverlays_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  OCErrorShared]
@="{0960F091-F328-48A3-B746-276B1E3C3722}"
[HKEY_CLASSES_ROOT\CLSID\{0960F091-F328-48A3-B746-276B1E3C3722}]
2014-11-06 14:46	268800	----a-w-	c:\program files\SWITCHdrive\shellext\OCOverlays_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  OCOK]
@="{0960F092-F328-48A3-B746-276B1E3C3722}"
[HKEY_CLASSES_ROOT\CLSID\{0960F092-F328-48A3-B746-276B1E3C3722}]
2014-11-06 14:46	268800	----a-w-	c:\program files\SWITCHdrive\shellext\OCOverlays_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  OCOKShared]
@="{0960F093-F328-48A3-B746-276B1E3C3722}"
[HKEY_CLASSES_ROOT\CLSID\{0960F093-F328-48A3-B746-276B1E3C3722}]
2014-11-06 14:46	268800	----a-w-	c:\program files\SWITCHdrive\shellext\OCOverlays_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  OCSync]
@="{0960F094-F328-48A3-B746-276B1E3C3722}"
[HKEY_CLASSES_ROOT\CLSID\{0960F094-F328-48A3-B746-276B1E3C3722}]
2014-11-06 14:46	268800	----a-w-	c:\program files\SWITCHdrive\shellext\OCOverlays_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  OCSyncShared]
@="{0960F095-F328-48A3-B746-276B1E3C3722}"
[HKEY_CLASSES_ROOT\CLSID\{0960F095-F328-48A3-B746-276B1E3C3722}]
2014-11-06 14:46	268800	----a-w-	c:\program files\SWITCHdrive\shellext\OCOverlays_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  OCWarning]
@="{0960F096-F328-48A3-B746-276B1E3C3722}"
[HKEY_CLASSES_ROOT\CLSID\{0960F096-F328-48A3-B746-276B1E3C3722}]
2014-11-06 14:46	268800	----a-w-	c:\program files\SWITCHdrive\shellext\OCOverlays_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\  OCWarningShared]
@="{0960F097-F328-48A3-B746-276B1E3C3722}"
[HKEY_CLASSES_ROOT\CLSID\{0960F097-F328-48A3-B746-276B1E3C3722}]
2014-11-06 14:46	268800	----a-w-	c:\program files\SWITCHdrive\shellext\OCOverlays_x86.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"="c:\program files\FileHippo.com\FileHippo.AppManager.exe" [2015-01-27 2926800]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2015-03-13 5529880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2013-06-25 337440]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2014-01-15 243560]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-04-10 335232]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2013-12-6 565464]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Moveslink for Movestick Mini.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Moveslink for Movestick Mini.lnk
backup=c:\windows\pss\Moveslink for Movestick Mini.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Produktregistrierung.lnk]
path=c:\users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
backup=c:\windows\pss\Logitech . Produktregistrierung.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2014-12-03 06:31	3498728	----a-w-	c:\program files\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2014-12-19 16:50	1022152	----a-w-	c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2014-02-27 19:38	558496	----a-w-	c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2015-03-20 16:12	60712	----a-w-	c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
2015-03-13 11:10	5529880	----a-w-	c:\program files\CCleaner\CCleaner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cisco AnyConnect Secure Mobility Agent for Windows]
2014-08-15 18:25	707496	----a-w-	c:\program files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2015-04-06 22:29	157480	----a-w-	c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Download Assistant]
2012-09-20 15:02	1425208	----a-w-	c:\windows\System32\LogiLDA.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-11-11 13:08	205336	----a-w-	c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Plugin Install]
2014-11-04 07:50	86016	----a-w-	c:\program files\QuickTime\Plugins\DeleteMe1.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2014-10-02 13:23	421888	----a-w-	c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPIRunE]
2009-03-05 03:55	18432	----a-w-	c:\windows\System32\SpiRunE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2015-04-10 09:57	335232	----a-w-	c:\program files\Common Files\Java\Java Update\jusched.exe
.
R2 FreemakeVideoCapture;FreemakeVideoCapture;c:\program files\Freemake\CaptureLib\CaptureLibService.exe [x]
R2 MBAMService;MBAMService;c:\program files\ Malwarebytes Anti-Malware \mbamservice.exe [2015-03-17 1080120]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-02-18 315488]
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock.sys [2014-08-15 92528]
R3 ALSysIO;ALSysIO;c:\users\Admin\AppData\Local\Temp\ALSysIO.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 30312]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2014-09-23 79360]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-03-13 102912]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys [2012-07-20 34432]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-03-17 51928]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv.sys [2012-07-20 25088]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2014-10-13 93144]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [2013-07-25 18944]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_x86.sys [2013-12-06 16024]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 121064]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 12776]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 136808]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 114280]
R3 t3;SB Xtreme Audio Notebook;c:\windows\system32\drivers\t3.sys [2009-05-06 413208]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-11 1343400]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-03-28 57112]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2014-10-13 213872]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2014-10-13 174968]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\nlssrv32.exe [2011-02-15 66560]
S2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2011-03-31 1646056]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2013-12-06 1229528]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2013-12-06 662232]
S2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2014-08-15 563112]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-03-17 23256]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12	REG_MULTI_SZ   	Pml Driver HPZ12 Net Driver HPZ12
.
Inhalt des "geplante Tasks" Ordners
.
2015-04-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-04 06:56]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = about:blank
mStart Page = about:blank
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\79jwsajk.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\SUPERAntiSpyware\SASSEH.DLL
MSConfigStartUp-BCSSync - c:\program files\Microsoft Office\Office14\BCSSync.exe
MSConfigStartUp-BrMfcWnd - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
MSConfigStartUp-ControlCenter3 - c:\program files\Brother\ControlCenter3\brctrcen.exe
MSConfigStartUp-GarminExpressTrayApp - c:\program files\Garmin\Express Tray\ExpressTray.exe
MSConfigStartUp-HP Software Update - c:\program files\Hp\HP Software Update\HPWuSchd2.exe
MSConfigStartUp-Logitech Vid - c:\program files\Logitech\Vid\Vid.exe
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSConfigStartUp-VirtualCloneDrive - c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
AddRemove-FileHippo Update Checker Packages - c:\users\Admin\AppData\Roaming\0F1L1I1P0H1L1E1E1F\FileHippo Update Checker Packages\uninstaller.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{0BDAEB60-C3D2-11D1-B61B-006008185990}]
@DACL=(02 0000)
@="IPClient"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{3F0E1952-4D09-11D4-A8EA-0050DA73E80C}]
@DACL=(02 0000)
@="GraphPad Prism 4 Project"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{3F0E1953-4D09-11D4-A8EA-0050DA73E80C}]
@DACL=(02 0000)
@="IPNoLink"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{3F0E1955-4D09-11D4-A8EA-0050DA73E80C}]
@DACL=(02 0000)
@="Prism.Command"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{3F0E1956-4D09-11D4-A8EA-0050DA73E80C}]
@DACL=(02 0000)
@="GraphPad Prism Template"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{55EDB536-FD77-48AE-AF61-B43DC6348AEA}]
@DACL=(02 0000)
@="GraphPad Prism 5 Project"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{55EDB537-FD77-48AE-AF61-B43DC6348AEA}]
@DACL=(02 0000)
@="IPNoLink"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{55EDB538-FD77-48AE-AF61-B43DC6348AEA}]
@DACL=(02 0000)
@="IPClient"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{55EDB539-FD77-48AE-AF61-B43DC6348AEA}]
@DACL=(02 0000)
@="Prism.Command"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{55EDB53A-FD77-48AE-AF61-B43DC6348AEA}]
@DACL=(02 0000)
@="GraphPad Prism Template"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{7F452540-55A0-11CF-AE24-444553540000}]
@DACL=(02 0000)
@="GraphPad Prism Template"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{7F452541-55A0-11CF-AE24-444553540000}]
@DACL=(02 0000)
@="IPNoLink"
.
[HKEY_USERS\S-1-5-21-3271901242-2791666843-1555295335-1003_Classes\CLSID\{F6E3D4E0-962F-11D0-AE3E-444553540000}]
@DACL=(02 0000)
@="Prism.Command"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2015-04-19  14:59:20
ComboFix-quarantined-files.txt  2015-04-19 12:59
.
Vor Suchlauf: 31.955.234.816 bytes free
Nach Suchlauf: 31.839.748.096 bytes free
.
- - End Of File - - B045BF61583AD741E6585257C4810CDF
A36C5E4F47E84449FF07ED3517B43A31
         


Alt 20.04.2015, 13:06   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> Windows 7: McAfee findet Artemis

Alt 21.04.2015, 18:36   #7
kittyhawk
 
Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



So hier die Logs.

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 21.04.2015
Suchlauf-Zeit: 17:25:23
Logdatei: 
Administrator: Ja

Version: 2.01.4.1018
Malware Datenbank: v2015.04.21.04
Rootkit Datenbank: v2015.04.20.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Admin

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 428415
Verstrichene Zeit: 1 Std, 16 Min, 34 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente gefunden)

Module: 0
(Keine schädliche Elemente gefunden)

Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)

Registrierungswerte: 0
(Keine schädliche Elemente gefunden)

Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)

Ordner: 0
(Keine schädliche Elemente gefunden)

Dateien: 0
(Keine schädliche Elemente gefunden)

Physische Sektoren: 0
(Keine schädliche Elemente gefunden)


(end)
         

Code:
ATTFilter
# AdwCleaner v4.201 - Logfile created 21/04/2015 at 19:13:33
# Updated 08/04/2015 by Xplode
# Database : 2015-04-20.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x86)
# Username : Admin - -
# Running from : C:\Users\Standard User\Desktop\AdwCleaner_4.201.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\PIP

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17728


-\\ Mozilla Firefox v37.0.1 (x86 en-US)


-\\ Opera v0.0.0.0


*************************

AdwCleaner[R0].txt - [1064 bytes] - [21/04/2015 19:11:43]
AdwCleaner[S0].txt - [1005 bytes] - [21/04/2015 19:13:33]

########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [1064  bytes] ##########
         

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.0 (04.20.2015:1)
OS: Windows 7 Professional x86
Ran by Admin on 21.04.2015 at 19:19:43,61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Garmin Core Update Service



~~~ Files



~~~ Folders





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.04.2015 at 19:21:31,37
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by Admin (administrator) on - on 21-04-2015 19:28:54
Running from C:\Users\Standard User\Desktop
Loaded Profiles: Admin & Standard User (Available profiles: Admin & Standard User & Marci)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
(Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [McAfeeUpdaterUI] => C:\Program Files\McAfee\Common Framework\udaterui.exe [337440 2013-06-25] (McAfee, Inc.)
HKLM\...\Run: [ShStatEXE] => C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [243560 2014-01-15] (McAfee, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\...\Run: [FileHippo.com] => C:\Program Files\FileHippo.com\FileHippo.AppManager.exe [2926800 2015-01-27] ()
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5529880 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[S0].txt [1142 2015-04-21] ()
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SandboxieControl] => "C:\Program Files\Sandboxie\SbieCtrl.exe"
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [Spotify Web Helper] => C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-04-02] (Spotify Ltd)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [AppleIEDAV] => C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [1080104 2014-09-19] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SWITCHdrive] => C:\Program Files\SWITCHdrive\SWITCHdrive.exe
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoControlPanel] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-11-05]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
ShellIconOverlayIdentifiers: [  OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-3271901242-2791666843-1555295335-1003] => 127.0.0.1:4001
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20141013204033.dll [2014-10-13] (McAfee, Inc.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3271901242-2791666843-1555295335-1003 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60

FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\79jwsajk.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-29] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-11-04] (Apple Inc.)
FF Extension: OneClickDownloader - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles\extensions\OneClickDownload@OneClickDownload.com [2012-09-14]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-06-28]
FF HKLM\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files\Common Files\McAfee\SystemCore
FF Extension: McAfee ScriptScan for Firefox - C:\Program Files\Common Files\McAfee\SystemCore [2014-10-13]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - No Path Or update_url value
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-12-03]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [Not Found]
CHR HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bckipplcmnfhblnpibpbehenelnkpecd] - C:\Program Files\OkayFreedom\okayfreedom.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-09-23] (Creative Labs) [File not signed]
S2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-23] (Creative Technology Ltd) [File not signed]
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S2 McAfeeFramework; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [130080 2013-06-25] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [204320 2014-10-13] (McAfee, Inc.)
R2 McTaskManager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [208416 2014-01-15] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [174968 2014-10-13] (McAfee, Inc.)
S2 nlsX86cc; C:\Windows\system32\nlssrv32.exe [66560 2011-02-15] (Nalpeiron Ltd.) [File not signed]
S2 RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [1646056 2011-03-31] (Rosetta Stone Ltd.)
S2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
S2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [563112 2014-08-15] (Cisco Systems, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 acsock; C:\Windows\System32\DRIVERS\acsock.sys [92528 2014-08-15] (Cisco Systems, Inc.)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [63464 2013-05-29] (FTDI Ltd.)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [57112 2011-03-28] (Paragon Software Group)
R1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [82168 2013-11-21] (EZB Systems, Inc.)
R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [65640 2010-07-13] (ITE Tech. Inc. )
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-07-20] (ManyCam LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [25088 2012-07-20] (ManyCam LLC)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [134472 2014-10-13] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [236480 2014-10-13] (McAfee, Inc.)
R3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [66408 2014-10-13] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [573136 2014-10-13] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93144 2014-10-13] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [213872 2014-10-13] (McAfee, Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia)
S3 t3; C:\Windows\System32\drivers\t3.sys [413208 2009-05-06] (Creative Technology Ltd.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [40824 2011-03-28] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [381032 2011-03-28] (Paragon)
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva-6.sys [43888 2014-08-15] (Cisco Systems, Inc.)
S3 ALSysIO; \??\C:\Users\Admin\AppData\Local\Temp\ALSysIO.sys [X]
S3 catchme; \??\C:\Users\Admin\AppData\Local\Temp\catchme.sys [X]
U3 mfeavfk01; No ImagePath
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP5c\WNt500x86\Sandra.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 19:26 - 2015-04-21 19:26 - 00001484 _____ () C:\Users\Admin\Downloads\JRT12.txt
2015-04-21 19:25 - 2015-04-21 19:25 - 00000741 _____ () C:\Users\Admin\Downloads\JRT.txt
2015-04-21 19:21 - 2015-04-21 19:25 - 00000741 _____ () C:\Users\Admin\Desktop\JRT.txt
2015-04-21 19:19 - 2015-04-21 19:19 - 00000207 _____ () C:\Windows\tweaking.com-regbackup---Windows-7-Professional-(32-bit).dat
2015-04-21 19:19 - 2015-04-21 19:19 - 00000000 ____D () C:\RegBackup
2015-04-21 19:16 - 2015-04-21 19:16 - 00001142 _____ () C:\Users\Standard User\Desktop\AdwCleaner[S0].txt
2015-04-21 19:11 - 2015-04-21 19:13 - 00000000 ____D () C:\AdwCleaner
2015-04-21 17:30 - 2015-04-21 17:30 - 01139200 _____ (Farbar) C:\Users\Standard User\Desktop\FRST.exe
2015-04-21 17:28 - 2015-04-21 17:28 - 02685507 _____ (Thisisu) C:\Users\Standard User\Desktop\JRT.exe
2015-04-21 17:27 - 2015-04-21 17:27 - 02217984 _____ () C:\Users\Standard User\Desktop\AdwCleaner_4.201.exe
2015-04-19 14:59 - 2015-04-19 14:59 - 00024926 _____ () C:\ComboFix.txt
2015-04-19 10:22 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-19 10:22 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-19 10:22 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-19 10:21 - 2015-04-19 14:59 - 00000000 ____D () C:\Qoobox
2015-04-19 10:20 - 2015-04-19 14:58 - 00000000 ____D () C:\Windows\erdnt
2015-04-17 21:21 - 2015-04-17 21:21 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Standard User\Desktop\tdsskiller.exe
2015-04-17 21:01 - 2015-04-17 21:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-17 20:59 - 2015-04-17 20:59 - 00000000 ____D () C:\Users\Standard User\Desktop\mbar-1.09.1.1004
2015-04-17 20:58 - 2015-04-17 20:59 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Standard User\Desktop\mbar-1.09.1.1004.exe
2015-04-17 20:49 - 2015-04-17 20:49 - 00001164 _____ () C:\Users\Admin\Desktop\Gmer.txt
2015-04-17 20:07 - 2015-04-17 20:07 - 00380416 _____ () C:\Users\Standard User\Desktop\Gmer-19357.exe
2015-04-17 19:56 - 2015-04-21 19:28 - 00018503 _____ () C:\Users\Standard User\Desktop\FRST.txt
2015-04-17 19:56 - 2015-04-17 19:56 - 00031810 _____ () C:\Users\Standard User\Desktop\Addition.txt
2015-04-17 19:51 - 2015-04-21 19:28 - 00000000 ____D () C:\FRST
2015-04-17 11:31 - 2015-04-21 17:34 - 00000000 ____D () C:\QUARANTINE
2015-04-17 09:47 - 2015-04-17 09:47 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-04-15 19:49 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 19:49 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 19:49 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 19:49 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 19:49 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 19:49 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 19:49 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 19:49 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 19:48 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 19:48 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 19:48 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 19:48 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 19:48 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 19:48 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 19:48 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 19:48 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 19:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 19:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 19:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 19:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 19:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 19:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 19:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 19:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 19:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 19:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 19:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 19:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 19:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 19:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 19:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 19:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 19:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 19:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 19:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 19:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 19:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 19:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 19:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 19:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 19:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 19:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 19:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 19:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 19:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 19:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 19:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 19:41 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 19:38 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 19:14 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 19:14 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-11 11:58 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\Program Files\iTunes
2015-04-11 11:55 - 2015-04-11 11:55 - 00000000 ____D () C:\Program Files\iPod
2015-04-11 11:40 - 2015-04-11 11:40 - 00000000 ____D () C:\Users\Standard User\Tracing
2015-04-11 11:22 - 2015-04-11 11:25 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-11 09:10 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-11 09:10 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-11 09:10 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-11 09:10 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-11 09:09 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-11 09:09 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-02 12:02 - 2015-04-02 12:02 - 00000000 ____D () C:\Users\Standard User\Downloads\Manu Chao - La Radiolina
2015-04-02 11:54 - 2015-04-02 12:25 - 00000000 ____D () C:\Users\Standard User\Downloads\Siberie m etait conteee
2015-04-02 11:47 - 2015-04-02 12:27 - 00000000 ____D () C:\Users\Standard User\Downloads\Manu Chao and Friends - Manu Chao and Friends (2011)
2015-04-02 09:56 - 2015-04-02 09:56 - 00002135 _____ () C:\Users\Admin\Desktop\JDownloader 2.lnk
2015-04-02 09:56 - 2015-04-02 09:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2015-04-02 09:03 - 2015-04-19 16:34 - 00001770 _____ () C:\Windows\PFRO.log
2015-03-29 13:00 - 2015-03-29 13:00 - 00000000 __RSH () C:\MSDOS.SYS
2015-03-29 13:00 - 2015-03-29 13:00 - 00000000 __RSH () C:\IO.SYS
2015-03-23 08:57 - 2015-04-11 10:21 - 00000000 ____D () C:\Program Files\Mozilla Firefox

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 19:27 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 19:27 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-21 19:14 - 2015-03-01 21:12 - 00006520 _____ () C:\Windows\setupact.log
2015-04-21 19:14 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-21 19:13 - 2012-06-04 11:35 - 01764505 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 19:07 - 2012-06-04 18:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-21 19:00 - 2012-06-05 09:18 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\foobar2000
2015-04-21 17:34 - 2015-01-31 16:28 - 00000000 ____D () C:\Program Files\SWITCHdrive
2015-04-21 17:24 - 2014-07-12 14:12 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-21 17:20 - 2014-05-14 11:59 - 00000000 ____D () C:\Users\Standard User\AppData\Local\C6B895D1-C4F4-4AA5-B457-2F5A43379524.aplzod
2015-04-20 18:11 - 2014-11-05 22:40 - 00000000 ____D () C:\Users\Marci\AppData\Local\Spotify
2015-04-20 16:35 - 2014-11-05 22:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\Spotify
2015-04-19 22:11 - 2013-11-05 22:16 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Spotify
2015-04-19 22:10 - 2013-11-05 22:15 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Spotify
2015-04-19 14:59 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2015-04-19 14:59 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-19 14:57 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2015-04-19 13:54 - 2014-11-05 22:40 - 00001798 _____ () C:\Users\Marci\Desktop\Spotify.lnk
2015-04-19 13:54 - 2014-11-05 22:40 - 00001784 _____ () C:\Users\Marci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-04-19 10:58 - 2012-10-03 21:15 - 00000000 ____D () C:\ProgramData\Temp
2015-04-18 20:25 - 2012-09-03 14:36 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\vlc
2015-04-18 13:35 - 2015-02-15 16:25 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Popcorn-Time
2015-04-18 09:22 - 2014-12-17 21:11 - 00000000 ____D () C:\Users\Standard User\SWITCHdrive
2015-04-17 21:00 - 2014-07-12 14:12 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-17 19:21 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-17 10:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-17 09:59 - 2012-06-04 12:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-17 09:49 - 2013-11-19 16:42 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-04-17 09:47 - 2014-08-28 15:08 - 00000000 ____D () C:\Program Files\Java
2015-04-17 09:44 - 2015-03-06 18:56 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-04-17 09:39 - 2015-03-13 23:29 - 00003890 _____ () C:\Windows\SecuniaPackage.log
2015-04-17 09:20 - 2012-06-04 11:46 - 00785866 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-17 08:57 - 2012-07-06 19:26 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Adobe
2015-04-17 08:56 - 2012-06-04 18:13 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-17 08:56 - 2012-06-04 17:40 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-17 08:52 - 2014-08-31 14:31 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe
2015-04-17 07:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-15 20:53 - 2014-10-10 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-15 20:52 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-04-15 20:47 - 2013-07-14 13:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 20:42 - 2012-06-04 11:42 - 00000000 ____D () C:\Users\Admin
2015-04-15 20:31 - 2012-06-04 12:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 19:10 - 2014-11-06 10:27 - 00000000 ____D () C:\Users\Marci\AppData\Local\Popcorn-Time
2015-04-11 11:55 - 2012-06-04 18:50 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-04-11 11:41 - 2012-09-15 15:28 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Skype
2015-04-11 11:39 - 2012-09-15 15:27 - 00000000 ____D () C:\ProgramData\Skype
2015-04-11 11:32 - 2012-06-04 17:33 - 00001035 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2015-04-11 11:32 - 2012-06-04 17:33 - 00000000 ____D () C:\Program Files\foobar2000
2015-04-11 11:24 - 2014-05-15 18:56 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-11 11:22 - 2014-12-12 14:03 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-11 11:22 - 2014-05-06 10:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-02 16:02 - 2015-01-24 17:19 - 00001838 _____ () C:\Users\Standard User\Desktop\Spotify.lnk
2015-04-02 16:02 - 2013-11-05 22:16 - 00001824 _____ () C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-04-02 09:51 - 2012-06-26 10:44 - 00000000 ____D () C:\Program Files\JDownloader
2015-04-01 10:17 - 2012-06-04 19:28 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-30 08:32 - 2014-06-29 20:22 - 00000000 ____D () C:\Users\Standard User\Downloads\navigon
2015-03-29 14:26 - 2012-08-26 20:54 - 00000000 ____D () C:\ProgramData\boost_interprocess
2015-03-23 21:36 - 2014-07-12 14:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-03-23 21:36 - 2014-07-12 14:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-03-23 17:03 - 2014-10-06 15:28 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\Skype

==================== Files in the root of some directories =======

2012-10-23 03:30 - 2012-10-23 03:30 - 0000218 _____ () C:\Users\Admin\AppData\Local\recently-used.xbel
2012-09-16 05:21 - 2013-11-25 20:23 - 0017408 _____ () C:\Users\Admin\AppData\Local\WebpageIcons.db
2014-08-13 12:21 - 2014-08-13 12:21 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\temp\Quarantine.exe
C:\Users\Admin\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-17 17:55

==================== End Of Log ============================
         
--- --- ---

Alt 22.04.2015, 08:44   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 26.04.2015, 20:01   #9
kittyhawk
 
Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Hier die Logs.
Der PC läuft gut soweit.
Ich nehme an, die ganzen Ordner der Scanner unter C kann man wieder löschen?

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=2f8888305212ff41a2466d27056a91e5
# engine=23549
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-04-24 09:45:37
# local_time=2015-04-24 11:45:37 (+0100, W. Europe Daylight Time)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='McAfee VirusScan Enterprise'
# compatibility_mode=5128 16777213 100 100 16686432 40106257 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 56391369 181543128 0 0
# scanned=171765
# found=0
# cleaned=0
# scan_time=13850
         

Code:
ATTFilter
 Results of screen317's Security Check version 1.00  
 Windows 7 Service Pack 1 x86 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
McAfee VirusScan Enterprise   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:````````` 
 Secunia PSI (3.0.0.9016)   
 CCleaner     
 Java 8 Update 45  
 Java version 32-bit out of Date! 
 Adobe Flash Player 	17.0.0.169  
 Adobe Reader XI  
 Mozilla Firefox (37.0.2) 
````````Process Check: objlist.exe by Laurent````````  
 McAfee VirusScan Enterprise VsTskMgr.exe  
 McAfee VirusScan Enterprise mfeann.exe  
 McAfee VirusScan Enterprise SHSTAT.EXE  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 6% 
````````````````````End of Log``````````````````````
         

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-04-2015
Ran by Standard User (ATTENTION: The logged in user is not administrator) on - on 26-04-2015 20:56:07
Running from C:\Users\Standard User\Desktop
Loaded Profiles: Admin & Standard User (Available profiles: Admin & Standard User & Marci)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> svchost.exe
Failed to access process -> winlogon.exe
Failed to access process -> svchost.exe
Failed to access process -> atiesrxx.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> UMVPFSrv.exe
Failed to access process -> CTAudSvc.exe
Failed to access process -> svchost.exe
Failed to access process -> atieclxx.exe
Failed to access process -> vpnagent.exe
Failed to access process -> svchost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> armsvc.exe
Failed to access process -> AppleMobileDeviceService.exe
Failed to access process -> mDNSResponder.exe
Failed to access process -> svchost.exe
Failed to access process -> FrameworkService.exe
Failed to access process -> VsTskMgr.exe
Failed to access process -> mfevtps.exe
Failed to access process -> nlssrv32.exe
Failed to access process -> mfeann.exe
Failed to access process -> conhost.exe
Failed to access process -> naPrdMgr.exe
Failed to access process -> svchost.exe
Failed to access process -> RosettaStoneDaemon.exe
Failed to access process -> psia.exe
Failed to access process -> svchost.exe
Failed to access process -> mcshield.exe
Failed to access process -> svchost.exe
Failed to access process -> WUDFHost.exe
Failed to access process -> sua.exe
Failed to access process -> USBVaccine.exe
(McAfee, Inc.) C:\Program Files\McAfee\Common Framework\UdaterUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Spotify Ltd) C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(McAfee, Inc.) C:\Program Files\McAfee\Common Framework\McTray.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
() C:\Users\Standard User\AppData\Local\Popcorn Time\node-webkit\Popcorn Time.exe
() C:\Users\Standard User\AppData\Local\Popcorn Time\node-webkit\Popcorn Time.exe
() C:\Users\Standard User\AppData\Local\Popcorn Time\node-webkit\Popcorn Time.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe
Failed to access process -> svchost.exe
Failed to access process -> WmiPrvSE.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [McAfeeUpdaterUI] => C:\Program Files\McAfee\Common Framework\udaterui.exe [337440 2013-06-25] (McAfee, Inc.)
HKLM\...\Run: [ShStatEXE] => C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [243560 2014-01-15] (McAfee, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SandboxieControl] => "C:\Program Files\Sandboxie\SbieCtrl.exe"
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [Spotify Web Helper] => C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-04-02] (Spotify Ltd)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [AppleIEDAV] => C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [1080104 2014-09-19] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SWITCHdrive] => C:\Program Files\SWITCHdrive\SWITCHdrive.exe
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-11-05]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
ShellIconOverlayIdentifiers: [  OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-3271901242-2791666843-1555295335-1003] => 127.0.0.1:4001
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
URLSearchHook: [S-1-5-21-3271901242-2791666843-1555295335-1000] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20141013204033.dll [2014-10-13] (McAfee, Inc.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3271901242-2791666843-1555295335-1003 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60

FireFox:
========
FF ProfilePath: C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default
FF Homepage: https://news.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-29] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-11-04] (Apple Inc.)
FF Extension: OpenDownload² - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{210249CE-F888-11DD-B868-4CB456D89593} [2015-01-12]
FF Extension: WOT - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-06-23]
FF Extension: Ghostery - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\firefox@ghostery.com.xpi [2014-06-23]
FF Extension: Boerse.bz Bypass - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\jid1-vasLCl9ZsexfAQ@jetpack.xpi [2014-08-11]
FF Extension: Zoom Page - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\zoompage@DW-dev.xpi [2015-03-30]
FF Extension: Session Manager - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2014-08-28]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2014-06-23]
FF Extension: NoScript - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-08-28]
FF Extension: Simple RSS Reader (SRR) - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{A5475360-A7EA-437b-9A79-29208F476940}.xpi [2014-08-04]
FF Extension: Right Links - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{B5F5E8D3-AE31-49A1-AC42-78B7B1CC5CDC}.xpi [2014-06-23]
FF Extension: Image Preview - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{D0A81AC1-3B12-4cec-AA8D-40EBDC4241EA}.xpi [2014-06-23]
FF Extension: Adblock Plus - C:\Users\Standard User\AppData\Roaming\Mozilla\Firefox\Profiles\u7c5wv5h.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-23]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-06-28]
FF HKLM\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files\Common Files\McAfee\SystemCore
FF Extension: McAfee ScriptScan for Firefox - C:\Program Files\Common Files\McAfee\SystemCore [2014-10-13]

Chrome: 
=======
CHR Profile: C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-29]
CHR Extension: (Google Drive) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-29]
CHR Extension: (YouTube) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-29]
CHR Extension: (Google Search) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-29]
CHR Extension: (Google Wallet) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-29]
CHR Extension: (Gmail) - C:\Users\Standard User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-29]
CHR HKLM\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - No Path Or update_url value
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-12-03]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [Not Found]
CHR HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bckipplcmnfhblnpibpbehenelnkpecd] - C:\Program Files\OkayFreedom\okayfreedom.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-09-23] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-23] (Creative Technology Ltd) [File not signed]
R2 lmhosts; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 McAfeeFramework; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [130080 2013-06-25] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [204320 2014-10-13] (McAfee, Inc.)
R2 McTaskManager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [208416 2014-01-15] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [174968 2014-10-13] (McAfee, Inc.)
R2 NlaSvc; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nlsX86cc; C:\Windows\system32\nlssrv32.exe [66560 2011-02-15] (Nalpeiron Ltd.) [File not signed]
R2 nsi; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [1646056 2011-03-31] (Rosetta Stone Ltd.)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [563112 2014-08-15] (Cisco Systems, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 FreemakeVideoCapture; "C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 acsock; C:\Windows\System32\DRIVERS\acsock.sys [92528 2014-08-15] (Cisco Systems, Inc.)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [63464 2013-05-29] (FTDI Ltd.)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [57112 2011-03-28] (Paragon Software Group)
R1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [82168 2013-11-21] (EZB Systems, Inc.)
R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [65640 2010-07-13] (ITE Tech. Inc. )
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-07-20] (ManyCam LLC)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [25088 2012-07-20] (ManyCam LLC)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [134472 2014-10-13] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [236480 2014-10-13] (McAfee, Inc.)
R3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [66408 2014-10-13] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [573136 2014-10-13] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93144 2014-10-13] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [213872 2014-10-13] (McAfee, Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia)
S3 t3; C:\Windows\System32\drivers\t3.sys [413208 2009-05-06] (Creative Technology Ltd.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [40824 2011-03-28] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [381032 2011-03-28] (Paragon)
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva-6.sys [43888 2014-08-15] (Cisco Systems, Inc.)
S3 ALSysIO; \??\C:\Users\Admin\AppData\Local\Temp\ALSysIO.sys [X]
S3 catchme; \??\C:\Users\Admin\AppData\Local\Temp\catchme.sys [X]
U3 mfeavfk01; No ImagePath
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP5c\WNt500x86\Sandra.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-26 20:55 - 2015-04-26 20:55 - 00000000 ____D () C:\Users\Standard User\Desktop\FRST-OlderVersion
2015-04-25 20:09 - 2015-04-25 20:09 - 00000504 _____ () C:\Windows\PFRO.log
2015-04-24 09:02 - 2015-04-24 09:02 - 00852616 _____ () C:\Users\Standard User\Desktop\SecurityCheck.exe
2015-04-22 18:54 - 2015-04-22 18:54 - 00000000 ____D () C:\Program Files\ESET
2015-04-22 18:53 - 2015-04-22 18:53 - 02347384 _____ (ESET) C:\Users\Standard User\Desktop\esetsmartinstaller_deu.exe
2015-04-21 20:31 - 2015-04-26 19:40 - 00001120 _____ () C:\Windows\setupact.log
2015-04-21 20:31 - 2015-04-24 09:40 - 00000000 ____D () C:\Users\Standard User\AppData\Local\VirtualStore
2015-04-21 20:31 - 2015-04-21 20:31 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-21 20:23 - 2015-04-26 20:40 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Popcorn-Time
2015-04-21 20:22 - 2015-04-21 20:22 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2015-04-21 20:20 - 2015-04-21 20:22 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Popcorn Time
2015-04-21 19:40 - 2015-04-21 19:40 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-21 19:19 - 2015-04-21 19:19 - 00000207 _____ () C:\Windows\tweaking.com-regbackup---Windows-7-Professional-(32-bit).dat
2015-04-21 19:19 - 2015-04-21 19:19 - 00000000 ____D () C:\RegBackup
2015-04-21 19:16 - 2015-04-21 19:16 - 00001142 _____ () C:\Users\Standard User\Desktop\AdwCleaner[S0].txt
2015-04-21 17:30 - 2015-04-26 20:55 - 01140736 _____ (Farbar) C:\Users\Standard User\Desktop\FRST.exe
2015-04-21 17:28 - 2015-04-21 17:28 - 02685507 _____ (Thisisu) C:\Users\Standard User\Desktop\JRT.exe
2015-04-21 17:27 - 2015-04-21 17:27 - 02217984 _____ () C:\Users\Standard User\Desktop\AdwCleaner_4.201.exe
2015-04-19 10:22 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-19 10:22 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-19 10:22 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-19 10:21 - 2015-04-19 14:59 - 00000000 ____D () C:\Qoobox
2015-04-19 10:20 - 2015-04-19 14:58 - 00000000 ____D () C:\Windows\erdnt
2015-04-17 21:21 - 2015-04-17 21:21 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Standard User\Desktop\tdsskiller.exe
2015-04-17 21:01 - 2015-04-17 21:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-17 20:59 - 2015-04-17 20:59 - 00000000 ____D () C:\Users\Standard User\Desktop\mbar-1.09.1.1004
2015-04-17 20:58 - 2015-04-17 20:59 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Standard User\Desktop\mbar-1.09.1.1004.exe
2015-04-17 20:07 - 2015-04-17 20:07 - 00380416 _____ () C:\Users\Standard User\Desktop\Gmer-19357.exe
2015-04-17 19:56 - 2015-04-26 20:56 - 00023067 _____ () C:\Users\Standard User\Desktop\FRST.txt
2015-04-17 19:56 - 2015-04-17 19:56 - 00031810 _____ () C:\Users\Standard User\Desktop\Addition.txt
2015-04-17 19:51 - 2015-04-26 20:56 - 00000000 ____D () C:\FRST
2015-04-17 11:31 - 2015-04-21 17:34 - 00000000 ____D () C:\QUARANTINE
2015-04-17 09:47 - 2015-04-17 09:47 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-04-15 19:49 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 19:49 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 19:49 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 19:49 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 19:49 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 19:49 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 19:49 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 19:49 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 19:48 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 19:48 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 19:48 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 19:48 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 19:48 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 19:48 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 19:48 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 19:48 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 19:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 19:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 19:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 19:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 19:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 19:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 19:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 19:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 19:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 19:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 19:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 19:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 19:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 19:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 19:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 19:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 19:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 19:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 19:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 19:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 19:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 19:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 19:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 19:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 19:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 19:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 19:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 19:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 19:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 19:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 19:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 19:41 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 19:38 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 19:14 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 19:14 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-11 11:58 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\Program Files\iTunes
2015-04-11 11:55 - 2015-04-11 11:55 - 00000000 ____D () C:\Program Files\iPod
2015-04-11 11:22 - 2015-04-11 11:25 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-11 09:10 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-11 09:10 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-11 09:10 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-11 09:10 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-11 09:09 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-11 09:09 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-02 11:54 - 2015-04-02 12:25 - 00000000 ____D () C:\Users\Standard User\Downloads\Siberie m etait conteee
2015-03-29 13:00 - 2015-03-29 13:00 - 00000000 __RSH () C:\MSDOS.SYS
2015-03-29 13:00 - 2015-03-29 13:00 - 00000000 __RSH () C:\IO.SYS

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-26 20:10 - 2012-06-04 11:35 - 01923303 _____ () C:\Windows\WindowsUpdate.log
2015-04-26 20:07 - 2012-06-04 18:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-26 20:03 - 2012-09-15 15:28 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Skype
2015-04-26 20:02 - 2012-09-15 15:27 - 00000000 ____D () C:\ProgramData\Skype
2015-04-26 19:49 - 2014-07-12 14:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-26 19:49 - 2014-07-12 14:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-04-26 19:49 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-26 19:49 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-26 19:48 - 2012-06-04 19:28 - 00000000 ____D () C:\Program Files\CCleaner
2015-04-26 19:46 - 2014-05-14 11:59 - 00000000 ____D () C:\Users\Standard User\AppData\Local\C6B895D1-C4F4-4AA5-B457-2F5A43379524.aplzod
2015-04-26 19:40 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-26 10:24 - 2014-11-05 22:40 - 00000000 ____D () C:\Users\Marci\AppData\Local\Spotify
2015-04-26 10:03 - 2014-11-05 22:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\Spotify
2015-04-26 09:58 - 2012-06-04 11:46 - 00785866 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-26 09:51 - 2012-09-03 14:36 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\vlc
2015-04-25 23:21 - 2014-11-06 10:27 - 00000000 ____D () C:\Users\Marci\AppData\Local\Popcorn-Time
2015-04-25 23:21 - 2014-09-08 21:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\vlc
2015-04-24 23:45 - 2013-11-05 22:16 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Spotify
2015-04-24 21:10 - 2013-11-05 22:15 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Spotify
2015-04-24 19:28 - 2014-08-13 23:01 - 00000000 ____D () C:\Users\Standard User\Downloads\BRUJERIA - Raza Odiada
2015-04-21 20:36 - 2012-06-04 11:42 - 00000000 ____D () C:\Users\Admin
2015-04-21 20:31 - 2014-05-15 18:56 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-21 20:22 - 2015-02-15 16:24 - 00002245 _____ () C:\Users\Standard User\Desktop\Popcorn Time.lnk
2015-04-21 20:14 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-04-21 19:00 - 2012-06-05 09:18 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\foobar2000
2015-04-21 17:34 - 2015-01-31 16:28 - 00000000 ____D () C:\Program Files\SWITCHdrive
2015-04-21 17:24 - 2014-07-12 14:12 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-19 14:59 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2015-04-19 14:59 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-19 14:57 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2015-04-19 10:58 - 2012-10-03 21:15 - 00000000 ____D () C:\ProgramData\Temp
2015-04-18 09:22 - 2014-12-17 21:11 - 00000000 ____D () C:\Users\Standard User\SWITCHdrive
2015-04-17 19:21 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-17 10:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-17 09:59 - 2012-06-04 12:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-17 09:49 - 2013-11-19 16:42 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-04-17 09:47 - 2014-08-28 15:08 - 00000000 ____D () C:\Program Files\Java
2015-04-17 09:44 - 2015-03-06 18:56 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-04-17 08:57 - 2012-07-06 19:26 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Adobe
2015-04-17 08:56 - 2012-06-04 18:13 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-17 08:56 - 2012-06-04 17:40 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-17 08:52 - 2014-08-31 14:31 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe
2015-04-17 07:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-15 20:53 - 2014-10-10 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-15 20:52 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-04-15 20:47 - 2013-07-14 13:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 20:31 - 2012-06-04 12:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-14 09:37 - 2014-07-12 14:12 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-14 09:37 - 2014-07-12 14:12 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-14 09:37 - 2012-06-04 12:10 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-11 11:55 - 2012-06-04 18:50 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-04-11 11:32 - 2012-06-04 17:33 - 00001035 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2015-04-11 11:32 - 2012-06-04 17:33 - 00000000 ____D () C:\Program Files\foobar2000
2015-04-11 11:22 - 2014-12-12 14:03 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-11 11:22 - 2014-05-06 10:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-02 16:02 - 2015-01-24 17:19 - 00001838 _____ () C:\Users\Standard User\Desktop\Spotify.lnk
2015-04-02 16:02 - 2013-11-05 22:16 - 00001824 _____ () C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-04-02 09:51 - 2012-06-26 10:44 - 00000000 ____D () C:\Program Files\JDownloader
2015-03-30 08:32 - 2014-06-29 20:22 - 00000000 ____D () C:\Users\Standard User\Downloads\navigon
2015-03-29 14:26 - 2012-08-26 20:54 - 00000000 ____D () C:\ProgramData\boost_interprocess

==================== Files in the root of some directories =======

2012-06-05 10:35 - 2014-08-14 13:16 - 0000363 _____ () C:\Users\Standard User\AppData\Roaming\burnaware.ini
2012-10-23 03:23 - 2012-09-04 08:44 - 11624448 _____ () C:\Users\Standard User\AppData\Roaming\Sandra.mdb
2013-12-27 13:41 - 2014-02-18 23:18 - 0017408 _____ () C:\Users\Standard User\AppData\Local\WebpageIcons.db
2014-08-13 12:21 - 2014-08-13 12:21 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\Quarantine.exe
C:\Users\Admin\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


ATTENTION: ==> Could not access BCD. Check to make sure user is administrator or see Addition.txt for additional information.

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 27.04.2015, 14:55   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Die werden beim Aufräumen automatisch entfernt. FRST bitte nochmal, das Tool braucht immer Adminrechte
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 29.04.2015, 07:59   #11
kittyhawk
 
Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Also ich habe immernoch einige Ordner dort.
z.B. MSOChache, Qoobox, Quarantine, RegBackup, Recovery....


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-04-2015 01
Ran by Admin (administrator) on - on 29-04-2015 08:47:37
Running from C:\Users\Standard User\Desktop
Loaded Profiles: Admin & Standard User (Available profiles: Admin & Standard User & Marci)
Platform: Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(McAfee, Inc.) C:\Program Files\McAfee\Common Framework\FrameworkService.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
(Nalpeiron Ltd.) C:\Windows\System32\nlssrv32.exe
(Rosetta Stone Ltd.) C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
(McAfee, Inc.) C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
(Secunia) C:\Program Files\Secunia\PSI\sua.exe
(Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe
(McAfee, Inc.) C:\Program Files\McAfee\Common Framework\UdaterUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Spotify Ltd) C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(McAfee, Inc.) C:\Program Files\McAfee\Common Framework\McTray.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan Enterprise\scan32.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [McAfeeUpdaterUI] => C:\Program Files\McAfee\Common Framework\udaterui.exe [337440 2013-06-25] (McAfee, Inc.)
HKLM\...\Run: [ShStatEXE] => C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [243560 2014-01-15] (McAfee, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\...\Run: [FileHippo.com] => C:\Program Files\FileHippo.com\FileHippo.AppManager.exe [2926800 2015-01-27] ()
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6278424 2015-04-23] (Piriform Ltd)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[S0].txt
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SandboxieControl] => "C:\Program Files\Sandboxie\SbieCtrl.exe"
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [Spotify Web Helper] => C:\Users\Standard User\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-27] (Spotify Ltd)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [AppleIEDAV] => C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [1080104 2014-09-19] (Apple Inc.)
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\...\Run: [SWITCHdrive] => C:\Program Files\SWITCHdrive\SWITCHdrive.exe
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-11-05]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
ShellIconOverlayIdentifiers: [  OCError] -> {0960F090-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCErrorShared] -> {0960F091-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOK] -> {0960F092-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCOKShared] -> {0960F093-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSync] -> {0960F094-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCSyncShared] -> {0960F095-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarning] -> {0960F096-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)
ShellIconOverlayIdentifiers: [  OCWarningShared] -> {0960F097-F328-48A3-B746-276B1E3C3722} => C:\Program Files\SWITCHdrive\shellext\OCOverlays_x86.dll [2014-11-06] (ownCloud Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-3271901242-2791666843-1555295335-1003] => 127.0.0.1:4001
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20141013204033.dll [2014-10-13] (McAfee, Inc.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3271901242-2791666843-1555295335-1003 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-05-08] (Adobe Systems Incorporated)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_10-windows-i586.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 62.2.24.162 62.2.17.61 62.2.24.158 62.2.17.60

FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\79jwsajk.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-29] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-11-04] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-11-04] (Apple Inc.)
FF Extension: OneClickDownloader - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\profiles\extensions\OneClickDownload@OneClickDownload.com [2012-09-14]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-06-28]
FF HKLM\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files\Common Files\McAfee\SystemCore
FF Extension: McAfee ScriptScan for Firefox - C:\Program Files\Common Files\McAfee\SystemCore [2014-10-13]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - No Path Or update_url value
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-12-03]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [Not Found]
CHR HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bckipplcmnfhblnpibpbehenelnkpecd] - C:\Program Files\OkayFreedom\okayfreedom.crx [Not Found]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-09-23] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-23] (Creative Technology Ltd) [File not signed]
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 McAfeeFramework; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [130080 2013-06-25] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [204320 2014-10-13] (McAfee, Inc.)
R2 McTaskManager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [208416 2014-01-15] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [174968 2014-10-13] (McAfee, Inc.)
R2 nlsX86cc; C:\Windows\system32\nlssrv32.exe [66560 2011-02-15] (Nalpeiron Ltd.) [File not signed]
R2 RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [1646056 2011-03-31] (Rosetta Stone Ltd.)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [563112 2014-08-15] (Cisco Systems, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 FreemakeVideoCapture; "C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 acsock; C:\Windows\System32\DRIVERS\acsock.sys [92528 2014-08-15] (Cisco Systems, Inc.)
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [63464 2013-05-29] (FTDI Ltd.)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [57112 2011-03-28] (Paragon Software Group)
R1 ISODrive; C:\Program Files\UltraISO\drivers\ISODrive.sys [82168 2013-11-21] (EZB Systems, Inc.)
R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [65640 2010-07-13] (ITE Tech. Inc. )
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [34432 2012-07-20] (ManyCam LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [25088 2012-07-20] (ManyCam LLC)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [134472 2014-10-13] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [236480 2014-10-13] (McAfee, Inc.)
R3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [66408 2014-10-13] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [573136 2014-10-13] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93144 2014-10-13] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [213872 2014-10-13] (McAfee, Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia)
S3 t3; C:\Windows\System32\drivers\t3.sys [413208 2009-05-06] (Creative Technology Ltd.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [40824 2011-03-28] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [381032 2011-03-28] (Paragon)
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva-6.sys [43888 2014-08-15] (Cisco Systems, Inc.)
S3 ALSysIO; \??\C:\Users\Admin\AppData\Local\Temp\ALSysIO.sys [X]
S3 catchme; \??\C:\Users\Admin\AppData\Local\Temp\catchme.sys [X]
U3 mfeavfk01; No ImagePath
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP5c\WNt500x86\Sandra.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-29 08:47 - 2015-04-29 08:52 - 00019741 _____ () C:\Users\Standard User\Desktop\FRST.txt
2015-04-29 08:46 - 2015-04-29 08:46 - 01140736 _____ (Farbar) C:\Users\Standard User\Desktop\FRST.exe
2015-04-27 21:48 - 2015-04-27 21:48 - 00000000 ____D () C:\Users\Standard User\Tracing
2015-04-27 20:06 - 2015-04-27 20:06 - 40518200 _____ () C:\Users\libcef.dll
2015-04-27 20:06 - 2015-04-27 20:06 - 10490576 _____ () C:\Users\icudtl.dat
2015-04-27 20:06 - 2015-04-27 20:06 - 07168568 _____ (Spotify Ltd) C:\Users\Spotify.exe
2015-04-27 20:06 - 2015-04-27 20:06 - 05066068 _____ () C:\Users\devtools_resources.pak
2015-04-27 20:06 - 2015-04-27 20:06 - 03457592 _____ (Microsoft Corporation) C:\Users\d3dcompiler_47.dll
2015-04-27 20:06 - 2015-04-27 20:06 - 02314260 _____ () C:\Users\Apps\musixmatch-lyrics.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 02157551 _____ () C:\Users\Apps\glue-resources.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 02106424 _____ (Microsoft Corporation) C:\Users\d3dcompiler_43.dll
2015-04-27 20:06 - 2015-04-27 20:06 - 02020920 _____ (Spotify Ltd) C:\Users\SpotifyWebHelper.exe
2015-04-27 20:06 - 2015-04-27 20:06 - 01894102 _____ () C:\Users\cef.pak
2015-04-27 20:06 - 2015-04-27 20:06 - 01365560 _____ () C:\Users\libGLESv2.dll
2015-04-27 20:06 - 2015-04-27 20:06 - 00990776 _____ () C:\Users\ffmpegsumo.dll
2015-04-27 20:06 - 2015-04-27 20:06 - 00786242 _____ () C:\Users\Apps\zlink.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00778808 _____ (Spotify Ltd) C:\Users\SpotifyCrashService.exe
2015-04-27 20:06 - 2015-04-27 20:06 - 00641130 _____ () C:\Users\Apps\browse.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00544454 _____ () C:\Users\cef_200_percent.pak
2015-04-27 20:06 - 2015-04-27 20:06 - 00532827 _____ () C:\Users\Apps\notification-center.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00523472 _____ () C:\Users\Apps\collection.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00499645 _____ () C:\Users\Apps\collection-artist.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00490705 _____ () C:\Users\Apps\genre.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00460102 _____ () C:\Users\Apps\collection-album.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00421742 _____ () C:\Users\Apps\article.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00406724 _____ () C:\Users\Apps\album.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00392015 _____ () C:\Users\cef_100_percent.pak
2015-04-27 20:06 - 2015-04-27 20:06 - 00370740 _____ () C:\Users\Apps\discover.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00359237 _____ () C:\Users\Apps\artist.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00359155 _____ () C:\Users\Apps\messages.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00356912 _____ () C:\Users\Apps\collection-songs.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00343647 _____ () C:\Users\Apps\buddy-list.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00341194 _____ () C:\Users\Apps\social-chart.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00339237 _____ () C:\Users\Apps\charts.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00334226 _____ () C:\Users\Apps\social-feed.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00316343 _____ () C:\Users\Apps\playlist-desktop.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00295101 _____ () C:\Users\Apps\radio.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00279292 _____ () C:\Users\Apps\profile.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00275408 _____ () C:\Users\Apps\folder.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00230599 _____ () C:\Users\Apps\chart.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00227514 _____ () C:\Users\Apps\share.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00219192 _____ () C:\Users\libEGL.dll
2015-04-27 20:06 - 2015-04-27 20:06 - 00191376 _____ () C:\Users\Apps\search.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00176991 _____ () C:\Users\Apps\suggest.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00175821 _____ () C:\Users\Apps\settings.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00162003 _____ () C:\Users\Apps\zlink-queue.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00158229 _____ () C:\Users\Apps\follow.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00147345 _____ () C:\Users\Apps\findfriends.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00124472 _____ (Spotify Ltd) C:\Users\SpotifyLauncher.exe
2015-04-27 20:06 - 2015-04-27 20:06 - 00112286 _____ () C:\Users\Apps\zlogin.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00086213 _____ () C:\Users\Apps\about.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00073272 _____ () C:\Users\wow_helper.exe
2015-04-27 20:06 - 2015-04-27 20:06 - 00053532 _____ () C:\Users\Apps\ad.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00040253 _____ () C:\Users\Apps\licenses.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00038320 _____ () C:\Users\Apps\error.spa
2015-04-27 20:06 - 2015-04-27 20:06 - 00012316 _____ () C:\Users\locales\en-US.pak
2015-04-27 20:06 - 2015-04-27 20:06 - 00007047 _____ () C:\Users\locales\el.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00006945 _____ () C:\Users\locales\ru.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00006203 _____ () C:\Users\locales\ja.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00006086 _____ () C:\Users\locales\fr-CA.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00006079 _____ () C:\Users\locales\hu.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00006022 _____ () C:\Users\locales\fr.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00006007 _____ () C:\Users\locales\fi.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00006006 _____ () C:\Users\locales\pl.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005947 _____ () C:\Users\locales\es-419.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005914 _____ () C:\Users\locales\nl.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005872 _____ () C:\Users\locales\es.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005868 _____ () C:\Users\locales\zsm.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005868 _____ () C:\Users\locales\de.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005859 _____ () C:\Users\locales\tr.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005859 _____ () C:\Users\locales\it.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005858 _____ () C:\Users\locales\zh-Hant.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005852 _____ () C:\Users\locales\pt-BR.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005808 _____ () C:\Users\locales\sv.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005694 _____ () C:\Users\locales\arb.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00005623 _____ () C:\Users\locales\en.mo
2015-04-27 20:06 - 2015-04-27 20:06 - 00000020 _____ () C:\Users\inst_ver.dat
2015-04-27 20:06 - 2015-04-27 20:06 - 00000000 ____D () C:\Users\locales
2015-04-27 20:06 - 2015-04-27 20:06 - 00000000 _____ () C:\Users\Standard.redir
2015-04-26 20:33 - 2015-04-26 20:33 - 00000949 _____ () C:\Users\Admin\Desktop\SEC_checkup.txt
2015-04-25 20:09 - 2015-04-25 20:09 - 00000504 _____ () C:\Windows\PFRO.log
2015-04-24 18:07 - 2015-04-24 18:07 - 00000992 _____ () C:\Users\Admin\Desktop\checkup.txt
2015-04-22 18:54 - 2015-04-22 18:54 - 00000000 ____D () C:\Program Files\ESET
2015-04-21 20:31 - 2015-04-29 08:28 - 00001344 _____ () C:\Windows\setupact.log
2015-04-21 20:31 - 2015-04-24 09:40 - 00000000 ____D () C:\Users\Standard User\AppData\Local\VirtualStore
2015-04-21 20:31 - 2015-04-21 20:31 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-21 20:23 - 2015-04-27 23:09 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Popcorn-Time
2015-04-21 20:22 - 2015-04-21 20:22 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2015-04-21 20:20 - 2015-04-21 20:22 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Popcorn Time
2015-04-21 19:40 - 2015-04-21 19:40 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-21 19:26 - 2015-04-21 19:26 - 00001484 _____ () C:\Users\Admin\Downloads\JRT12.txt
2015-04-21 19:25 - 2015-04-21 19:25 - 00000741 _____ () C:\Users\Admin\Downloads\JRT.txt
2015-04-21 19:21 - 2015-04-21 19:25 - 00000741 _____ () C:\Users\Admin\Desktop\JRT.txt
2015-04-21 19:19 - 2015-04-21 19:19 - 00000207 _____ () C:\Windows\tweaking.com-regbackup---Windows-7-Professional-(32-bit).dat
2015-04-21 19:19 - 2015-04-21 19:19 - 00000000 ____D () C:\RegBackup
2015-04-19 10:22 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-19 10:22 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-19 10:22 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-19 10:22 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-19 10:21 - 2015-04-19 14:59 - 00000000 ____D () C:\Qoobox
2015-04-19 10:20 - 2015-04-19 14:58 - 00000000 ____D () C:\Windows\erdnt
2015-04-17 21:01 - 2015-04-17 21:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-17 20:49 - 2015-04-17 20:49 - 00001164 _____ () C:\Users\Admin\Desktop\Gmer.txt
2015-04-17 19:51 - 2015-04-29 08:48 - 00000000 ____D () C:\FRST
2015-04-17 11:31 - 2015-04-21 17:34 - 00000000 ____D () C:\QUARANTINE
2015-04-17 09:47 - 2015-04-17 09:47 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-04-15 19:49 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 19:49 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 19:49 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 19:49 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 19:49 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 19:49 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 19:49 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 19:49 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 19:48 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 19:48 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 19:48 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 19:48 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 19:48 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 19:48 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 19:48 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 19:48 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 19:48 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 19:48 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 19:41 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 19:41 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 19:41 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 19:41 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 19:41 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 19:41 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 19:41 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 19:41 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 19:41 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 19:41 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 19:41 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 19:41 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 19:41 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 19:41 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 19:41 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 19:41 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 19:41 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 19:41 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 19:41 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 19:41 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 19:41 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 19:41 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 19:41 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 19:41 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 19:41 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 19:41 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 19:41 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 19:41 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 19:41 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 19:41 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 19:41 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 19:41 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 19:38 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 19:14 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 19:14 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-11 11:58 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-11 11:55 - 2015-04-11 11:58 - 00000000 ____D () C:\Program Files\iTunes
2015-04-11 11:55 - 2015-04-11 11:55 - 00000000 ____D () C:\Program Files\iPod
2015-04-11 11:22 - 2015-04-11 11:25 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-11 09:10 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-11 09:10 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-11 09:10 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-11 09:10 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-11 09:09 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-11 09:09 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-11 09:09 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-11 09:09 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-02 11:54 - 2015-04-02 12:25 - 00000000 ____D () C:\Users\Standard User\Downloads\Siberie m etait conteee
2015-04-02 09:56 - 2015-04-02 09:56 - 00002135 _____ () C:\Users\Admin\Desktop\JDownloader 2.lnk
2015-04-02 09:56 - 2015-04-02 09:56 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-29 08:36 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-29 08:36 - 2009-07-14 06:34 - 00025760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-29 08:34 - 2014-05-14 11:59 - 00000000 ____D () C:\Users\Standard User\AppData\Local\C6B895D1-C4F4-4AA5-B457-2F5A43379524.aplzod
2015-04-29 08:33 - 2012-06-04 11:35 - 01974710 _____ () C:\Windows\WindowsUpdate.log
2015-04-29 08:28 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-27 23:09 - 2012-09-03 14:36 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\vlc
2015-04-27 23:07 - 2012-06-04 18:13 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-27 21:50 - 2012-09-15 15:28 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Skype
2015-04-27 21:14 - 2013-11-05 22:16 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Spotify
2015-04-27 21:01 - 2013-11-05 22:15 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\Spotify
2015-04-27 16:23 - 2014-11-05 22:40 - 00000000 ____D () C:\Users\Marci\AppData\Local\Spotify
2015-04-27 16:01 - 2014-11-05 22:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\Spotify
2015-04-27 09:12 - 2014-07-12 14:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-04-26 20:02 - 2012-09-15 15:27 - 00000000 ____D () C:\ProgramData\Skype
2015-04-26 19:49 - 2014-07-12 14:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-26 19:48 - 2012-06-04 19:28 - 00000000 ____D () C:\Program Files\CCleaner
2015-04-26 09:58 - 2012-06-04 11:46 - 00785866 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-25 23:21 - 2014-11-06 10:27 - 00000000 ____D () C:\Users\Marci\AppData\Local\Popcorn-Time
2015-04-25 23:21 - 2014-09-08 21:27 - 00000000 ____D () C:\Users\Marci\AppData\Roaming\vlc
2015-04-24 19:28 - 2014-08-13 23:01 - 00000000 ____D () C:\Users\Standard User\Downloads\BRUJERIA - Raza Odiada
2015-04-21 20:36 - 2012-06-04 11:42 - 00000000 ____D () C:\Users\Admin
2015-04-21 20:31 - 2014-05-15 18:56 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-21 20:22 - 2015-02-15 16:24 - 00002245 _____ () C:\Users\Standard User\Desktop\Popcorn Time.lnk
2015-04-21 20:14 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-04-21 19:00 - 2012-06-05 09:18 - 00000000 ____D () C:\Users\Standard User\AppData\Roaming\foobar2000
2015-04-21 17:34 - 2015-01-31 16:28 - 00000000 ____D () C:\Program Files\SWITCHdrive
2015-04-21 17:24 - 2014-07-12 14:12 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-19 14:59 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2015-04-19 14:59 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-19 14:57 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2015-04-19 13:54 - 2014-11-05 22:40 - 00001798 _____ () C:\Users\Marci\Desktop\Spotify.lnk
2015-04-19 13:54 - 2014-11-05 22:40 - 00001784 _____ () C:\Users\Marci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-04-19 10:58 - 2012-10-03 21:15 - 00000000 ____D () C:\ProgramData\Temp
2015-04-18 09:22 - 2014-12-17 21:11 - 00000000 ____D () C:\Users\Standard User\SWITCHdrive
2015-04-17 19:21 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-17 10:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-17 09:59 - 2012-06-04 12:08 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-17 09:49 - 2013-11-19 16:42 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-04-17 09:47 - 2014-08-28 15:08 - 00000000 ____D () C:\Program Files\Java
2015-04-17 09:44 - 2015-03-06 18:56 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-04-17 08:57 - 2012-07-06 19:26 - 00000000 ____D () C:\Users\Standard User\AppData\Local\Adobe
2015-04-17 08:56 - 2012-06-04 18:13 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-17 08:56 - 2012-06-04 17:40 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-17 08:52 - 2014-08-31 14:31 - 00000000 ____D () C:\Users\Admin\AppData\Local\Adobe
2015-04-17 07:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-15 20:53 - 2014-10-10 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-15 20:52 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-04-15 20:47 - 2013-07-14 13:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 20:31 - 2012-06-04 12:46 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-14 09:37 - 2014-07-12 14:12 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-14 09:37 - 2014-07-12 14:12 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-14 09:37 - 2012-06-04 12:10 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-11 11:55 - 2012-06-04 18:50 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-04-11 11:32 - 2012-06-04 17:33 - 00001035 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2015-04-11 11:32 - 2012-06-04 17:33 - 00000000 ____D () C:\Program Files\foobar2000
2015-04-11 11:22 - 2014-12-12 14:03 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-11 11:22 - 2014-05-06 10:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-02 16:02 - 2015-01-24 17:19 - 00001838 _____ () C:\Users\Standard User\Desktop\Spotify.lnk
2015-04-02 16:02 - 2013-11-05 22:16 - 00001824 _____ () C:\Users\Standard User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-04-02 09:51 - 2012-06-26 10:44 - 00000000 ____D () C:\Program Files\JDownloader
2015-03-30 08:32 - 2014-06-29 20:22 - 00000000 ____D () C:\Users\Standard User\Downloads\navigon

==================== Files in the root of some directories =======

2012-10-23 03:30 - 2012-10-23 03:30 - 0000218 _____ () C:\Users\Admin\AppData\Local\recently-used.xbel
2012-09-16 05:21 - 2013-11-25 20:23 - 0017408 _____ () C:\Users\Admin\AppData\Local\WebpageIcons.db
2014-08-13 12:21 - 2014-08-13 12:21 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\temp\Quarantine.exe
C:\Users\Admin\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-17 17:55

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 30.04.2015, 06:51   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Ich hab doch gesagt die werden beim Aufräumen automatisch entfernt. Wir haben noch nicht aufgeräumt


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
RemoveProxy:
Emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.





Jetzt räumen wir auf



Cleanup:
(Die Reihenfolge ist hier entscheidend)

Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken.

Falls Combofix verwendet wurde:
Combofix deinstallieren .
  • Wichtig: Bitte Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke bitte die + R Taste und schreibe Combofix /Uninstall in das Ausführen-Fenster.
  • Klicke auf OK.
    Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert.
  • Nun die eben deaktivierten Programme wieder aktivieren.

Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.

Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen.

Absicherung:
Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen:

Browser
Java
Flash-Player
PDF-Reader

Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.
Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.

Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.

Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank.
Meine Empfehlung:

Emsisoft

Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen.

Optional:
NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen.
Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.


Lade Software von einem sauberen Portal wie .
Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwarecleaner .


Abschließend noch ein paar grundsätzliche Bemerkungen:
Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.05.2015, 08:31   #13
kittyhawk
 
Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Super, vielen Dank!!!

Hier das log

Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 29-04-2015 01
Ran by Admin at 2015-04-30 20:44:34 Run:1
Running from C:\Users\Standard User\Desktop
Loaded Profiles: Admin & Standard User (Available profiles: Admin & Standard User & Marci)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
RemoveProxy:
Emptytemp:
         
*****************


========= RemoveProxy: =========

"HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\S-1-5-21-3271901242-2791666843-1555295335-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\S-1-5-21-3271901242-2791666843-1555295335-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.


========= End of RemoveProxy: =========

EmptyTemp: => Removed 853.3 MB temporary data.


The system needed a reboot. 

==== End of Fixlog 20:49:19 ====
         

Alt 10.05.2015, 06:01   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7: McAfee findet Artemis - Standard

Windows 7: McAfee findet Artemis



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Windows 7: McAfee findet Artemis
adobe, adware, avast, bonjour, browser, cpu, defender, desktop, explorer, firefox, flash player, homepage, installation, lws.exe, mozilla, officejet, photoshop, prozesse, registry, rundll, scan, security, starten, superantispyware, temp, trojanisches pferd, windows



Ähnliche Themen: Windows 7: McAfee findet Artemis


  1. McAfee isoliert Artemis! 7563DE18185A
    Plagegeister aller Art und deren Bekämpfung - 20.07.2015 (23)
  2. Windows 7: Trojaner artemis!E* wird bei fast jedem Scan auf meinem PC gefunden
    Log-Analyse und Auswertung - 20.04.2015 (20)
  3. Mcafee: Artemis auf dem Laptop der Tochter mit WIN 8
    Log-Analyse und Auswertung - 29.12.2014 (18)
  4. Trojaner Artemis in C:\Windows\System32\microsoft.com
    Log-Analyse und Auswertung - 08.08.2014 (41)
  5. Ntoskrnl verursachen sehr hohe HDD-Auslastung | Windows 8.1, McAfee hat ARTEMIS entdeckt
    Log-Analyse und Auswertung - 29.06.2014 (13)
  6. Windows 7: McAfee durch Gruppenrichtlinie gesperrt.
    Log-Analyse und Auswertung - 20.05.2014 (13)
  7. McAfee meldet Trojaner Artemis!88866BFA9466, entfernt ihn aber nicht
    Log-Analyse und Auswertung - 13.04.2014 (43)
  8. McAfee findet Aartemis! Trojaner
    Log-Analyse und Auswertung - 23.01.2014 (14)
  9. Mcafee findt mehrere Artemis Trojaner was tun???
    Plagegeister aller Art und deren Bekämpfung - 07.06.2013 (15)
  10. Mcafee findet Artemis!4B3812C4890C ( Trojaner ) in einer E-mail Anlage
    Plagegeister aller Art und deren Bekämpfung - 29.10.2011 (6)
  11. Mcafee findet Artemis!4B3812C4890C in einer E-mail Anlage
    Mülltonne - 26.10.2011 (1)
  12. McAfee meldet Trojaner-Befall Artemis!317AB1B0B53C
    Log-Analyse und Auswertung - 26.10.2010 (8)
  13. Signatur-Update von McAfee macht Windows-PCs unbenutzbar
    Nachrichten - 22.04.2010 (0)
  14. PatchedSFC in Windows\system32\sfc_os.dll von McAfee erkannt
    Plagegeister aller Art und deren Bekämpfung - 23.03.2010 (3)
  15. McAfee findet Adware?
    Mülltonne - 27.12.2008 (0)
  16. McAfee Rootkit Detective 1.1 findet verstekte Einträge
    Plagegeister aller Art und deren Bekämpfung - 06.02.2008 (5)
  17. McAfee Internet Security 5.0/Probleme mit Windows
    Antiviren-, Firewall- und andere Schutzprogramme - 23.06.2003 (0)

Zum Thema Windows 7: McAfee findet Artemis - Hallo liebes Trojaner-Board-Team, McAfee hat heute bei einem Scan einen Artemis Trojaner gefunden. Der PC hatte heute Morgen Probleme beim Installieren von verschiedenen Updates. Gmer stürzt ab, sobald es zu - Windows 7: McAfee findet Artemis...
Archiv
Du betrachtest: Windows 7: McAfee findet Artemis auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.