Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Problem svchost.exe erzeugt hohe RAM-Auslastung

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 19.04.2015, 17:58   #1
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



Hallo liebes Forum.
Nach langem hin und her, mehreren Systemscans, etc. muss ich mich nun doch an euer Forum wenden. Die Ursachen für eine hohe Auslastung sind ja sind ja doch immer individuell und ein wirklicher Profi bin ich nun auch wieder nicht um dem Problem im Alleingang auf die Schliche zu kommen.

Ausgangssituation: Mein Vater hat mir ein Netbook von ASUS in die Hand gedrückt mit den Worten, schau mal ob du was machen kannst ist irgendwas kaputt.

Habe das Teil dann angeschmissen und auch gleich bemerkt, dass der echt extrem langsam ist. Soll heissen, selbst den Explorer zu öffnen oder die Systemsteuerung braucht einige Zeit und reagiert auch nur schleppend.
Bin daraufhin mal in den Ressourcen-Monitor und habe gleich 3 svchost-Prozesse drin gehabt die ca. 90% des Arbeitsspeichers in Anspruch nehmen.

Habe dann mal alle Programme deinstalliert die sinnlos sind, da das Netbook ohnehin nur noch für Internetsurfen genutzt werden soll bzw. genutzt wurde.
Die svchost-Prozesse sind allerdings immer noch drin und es hat sich von der Performance her nichts geändert.

Hier mal das FRST-Log oder wie man da sagt. :-)Hoffe ihr könnt mir weiterhelfen. Weil so ist das Teil leider nicht zu gebrauchen.
FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-04-2015 01
Ran by Netbook (administrator) on NETBOOK-PC on 19-04-2015 17:57:22
Running from C:\Users\Netbook\Desktop
Loaded Profiles: Netbook (Available profiles: Netbook)
Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE.EXE
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [GfxServiceInstall] => C:\windows\system32\GfxCUIServiceInstall.vbs [131 2012-06-27] ()
HKLM\...\Run: [HotkeyMon] => C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe [101800 2012-01-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12111576 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2262312 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [3331312 2012-08-14] (ASUSTek Computer Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-04-19] (Avast Software s.r.o.)
HKLM\...\Run: [SuperHybridEngine] => C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [426424 2012-02-10] (ASUSTeK Computer Inc.)
HKLM\...\Run: [LiveUpdate] => C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2012-01-05] (AsusTek Computer Inc.)
HKLM\...\Run: [HotkeyService] => C:\Program Files\ASUS\HotkeyService\HotkeyService.exe [1263024 2012-01-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [CapsHook] => C:\Program Files\ASUS\CapsHook\CapsHook.exe [445344 2010-11-15] (ASUS)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll [2012-06-27] (Intel Corporation)
HKU\S-1-5-21-309674158-46085917-1021320157-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5529880 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\scrnsave.scr [10240 2009-07-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-18] (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-309674158-46085917-1021320157-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-309674158-46085917-1021320157-1000 -> {E01C9CA2-DE19-4358-8456-44D35AABB4AC} URL = https://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-18] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-12-16] (Adblock Plus)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-18]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-18]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 ASUS InstantOn; C:\Program Files\ASUS\InstantOn for EPC\InsOnSrv.exe [92800 2011-12-01] (ASUS)
S2 AsusService; C:\windows\system32\AsusService.exe [224680 2012-01-11] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-18] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-04-18] (Avast Software)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [252632 2014-12-11] (Realtek Semiconductor)
S2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [91464 2011-03-26] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\windows\System32\drivers\AsIO.sys [11456 2010-06-28] ()
R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2010-08-03] ()
R2 aswHwid; C:\windows\system32\drivers\aswHwid.sys [24144 2015-04-18] ()
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [73440 2015-04-18] (Avast Software s.r.o.)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81728 2015-04-18] (Avast Software s.r.o.)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49904 2015-04-18] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [788272 2015-04-18] (Avast Software s.r.o.)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [427480 2015-04-18] (Avast Software s.r.o.)
S2 aswStm; C:\windows\system32\drivers\aswStm.sys [106912 2015-04-18] (Avast Software s.r.o.)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [206976 2015-04-18] ()
R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R3 L1C; C:\windows\System32\DRIVERS\L1C62x86.sys [109256 2000-01-01] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [13368 2015-04-17] (SlimWare Utilities, Inc.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-04-18] (Avast Software)
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Netbook\AppData\Local\Temp\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-19 17:57 - 2015-04-19 17:57 - 00009814 _____ () C:\Users\Netbook\Desktop\FRST.txt
2015-04-19 17:53 - 2015-04-19 17:53 - 01137664 _____ (Farbar) C:\Users\Netbook\Desktop\FRST.exe
2015-04-19 17:25 - 2015-04-19 17:57 - 00000000 ____D () C:\FRST
2015-04-19 17:14 - 2015-04-19 17:14 - 00000056 _____ () C:\windows\setupact.log
2015-04-19 17:14 - 2015-04-19 17:14 - 00000000 _____ () C:\windows\setuperr.log
2015-04-19 16:56 - 2015-04-19 16:56 - 02217984 _____ () C:\Users\Netbook\Desktop\adwcleaner_4.201.exe
2015-04-19 15:23 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-04-19 15:23 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-04-18 14:21 - 2015-04-18 14:21 - 00018533 _____ () C:\ComboFix.txt
2015-04-18 13:30 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2015-04-18 13:30 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2015-04-18 13:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2015-04-18 13:29 - 2015-04-18 14:21 - 00000000 ____D () C:\Qoobox
2015-04-18 13:28 - 2015-04-18 14:16 - 00000000 ____D () C:\windows\erdnt
2015-04-18 13:18 - 2015-04-18 13:18 - 00000207 _____ () C:\windows\tweaking.com-regbackup-NETBOOK-PC-Windows-7-Starter-(32-bit).dat
2015-04-18 13:18 - 2015-04-18 13:18 - 00000000 ____D () C:\RegBackup
2015-04-18 12:59 - 2015-01-31 05:33 - 02744320 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-04-18 12:59 - 2015-01-31 05:33 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2015-04-18 12:59 - 2015-01-31 02:48 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2015-04-18 12:56 - 2015-04-19 17:13 - 00000000 ____D () C:\AdwCleaner
2015-04-18 10:00 - 2015-04-18 10:00 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\AVAST Software
2015-04-18 09:59 - 2015-04-18 09:59 - 00002071 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-04-18 09:59 - 2015-04-18 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-04-18 09:58 - 2015-04-18 09:58 - 00788272 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswSnx.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00427480 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswSP.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00291312 _____ (Avast Software s.r.o.) C:\windows\system32\aswBoot.exe
2015-04-18 09:58 - 2015-04-18 09:58 - 00206976 _____ () C:\windows\system32\Drivers\aswVmm.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00106912 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswStm.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00081728 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswRdr2.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00073440 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswMonFlt.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00049904 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00043112 _____ (Avast Software s.r.o.) C:\windows\avastSS.scr
2015-04-18 09:58 - 2015-04-18 09:58 - 00024144 _____ () C:\windows\system32\Drivers\aswHwid.sys
2015-04-18 09:56 - 2015-04-18 09:56 - 00000000 ____D () C:\Program Files\AVAST Software
2015-04-17 21:44 - 2015-04-17 21:44 - 00000000 ____D () C:\Program Files\Common Files\Intel Corporation
2015-04-17 21:43 - 2015-04-17 21:43 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Intel Corporation
2015-04-17 21:27 - 2012-02-01 16:06 - 00470808 _____ (Intel Corporation) C:\windows\system32\Drivers\iaStor.sys
2015-04-17 20:50 - 2000-01-01 02:00 - 00109256 _____ (Qualcomm Atheros Co., Ltd.) C:\windows\system32\Drivers\L1C62x86.sys
2015-04-17 20:49 - 2015-04-17 20:49 - 00000000 ____D () C:\ProgramData\SlimWare Utilities, Inc
2015-04-17 20:44 - 2015-04-17 21:20 - 00013368 _____ (SlimWare Utilities, Inc.) C:\windows\system32\Drivers\SWDUMon.sys
2015-04-17 20:44 - 2015-04-17 20:44 - 00002455 _____ () C:\Users\Public\Desktop\SlimDrivers.lnk
2015-04-17 20:44 - 2015-04-17 20:44 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2015-04-17 20:44 - 2015-04-17 20:44 - 00000000 ____D () C:\Users\Netbook\AppData\Local\SlimWare Utilities Inc
2015-04-17 20:10 - 2015-04-17 20:10 - 00016896 _____ (ASUS) C:\windows\AsTaskSched.dll
2015-04-17 20:07 - 2015-04-17 20:07 - 00000000 __RSH () C:\MSDOS.SYS
2015-04-17 20:07 - 2015-04-17 20:07 - 00000000 __RSH () C:\IO.SYS
2015-04-17 19:21 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-04-17 19:21 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-04-17 19:21 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-04-17 19:21 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-04-17 19:21 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-04-17 19:21 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-04-17 19:21 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-04-17 19:21 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-04-17 19:21 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-04-17 19:21 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-04-17 19:21 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-04-17 19:21 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-04-17 19:21 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-04-17 19:21 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-04-17 19:21 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-04-17 19:21 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-04-17 19:21 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-04-17 19:21 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-04-17 19:21 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-04-17 19:21 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-04-17 19:21 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-04-17 19:21 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-04-17 19:21 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-04-17 19:21 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-04-17 19:21 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-04-17 19:21 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-04-17 19:21 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-04-17 19:21 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-04-17 19:21 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-04-17 19:21 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-04-17 19:21 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-04-17 19:19 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2015-04-17 19:19 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-04-17 19:19 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-04-17 19:19 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-04-17 19:19 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-04-17 19:19 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-04-17 19:19 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-04-17 19:19 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-04-17 19:19 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-04-17 19:19 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-04-17 19:19 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-04-17 19:19 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2015-04-17 19:19 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-04-17 19:18 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-04-17 19:18 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-04-17 19:17 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-04-17 19:17 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-04-17 19:17 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-04-17 19:17 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-04-17 19:17 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2015-04-17 18:40 - 2015-04-17 19:23 - 00000157 _____ () C:\AsusUpdate.log
2015-04-17 18:13 - 2015-04-17 20:09 - 00001769 _____ () C:\windows\Language_trs.ini
2015-04-17 18:07 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2015-04-17 18:01 - 2015-04-17 18:01 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Easeware
2015-04-11 22:47 - 2012-02-11 07:37 - 00317440 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2015-04-11 22:41 - 2014-12-11 19:47 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-04-11 22:20 - 2015-02-26 05:11 - 02381312 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-04-11 22:20 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-04-11 22:19 - 2014-09-05 03:52 - 05703168 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2015-04-11 22:16 - 2015-02-24 04:23 - 00246920 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-04-04 20:26 - 2015-04-04 20:26 - 00000000 ____D () C:\Program Files\Adblock Plus for IE
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieUserList
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieSiteList
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieBrowserModeList
2015-04-04 17:45 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-04-04 17:44 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-04-04 17:43 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2015-04-04 17:42 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00645120 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2015-04-04 16:34 - 2015-04-04 16:34 - 00610304 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00233472 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00208384 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00151552 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00127488 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00083456 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-04-04 16:34 - 2015-04-04 16:34 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2015-04-04 16:32 - 2015-04-04 16:32 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 01158144 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 01080832 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00906240 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00604160 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00364544 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00207872 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00187392 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00161792 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-04-04 16:07 - 2015-04-04 16:13 - 00000000 ___SD () C:\windows\system32\GWX
2015-04-04 14:56 - 2015-04-19 15:50 - 00000000 ____D () C:\windows\system32\MRT
2015-04-04 14:55 - 2015-04-19 15:34 - 125832184 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-04-04 14:26 - 2015-01-09 01:44 - 00419936 _____ () C:\windows\system32\locale.nls
2015-04-04 13:37 - 2012-07-26 05:21 - 00196608 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe
2015-04-04 13:37 - 2012-07-26 05:20 - 00613888 _____ (Microsoft Corporation) C:\windows\system32\WUDFx.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\WUDFCoinstaller.dll
2015-04-04 13:37 - 2012-07-26 04:33 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys
2015-04-04 13:37 - 2012-07-26 04:32 - 00155136 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys
2015-04-04 13:37 - 2012-06-02 16:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-04-04 13:33 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll
2015-04-04 13:33 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2015-04-04 13:33 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe
2015-04-04 13:33 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll
2015-04-04 12:25 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2015-04-04 12:25 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-04-04 12:25 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-04-04 12:25 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2015-04-04 12:25 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2015-04-04 12:25 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-04-04 12:25 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2015-04-04 12:25 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-04-04 12:25 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-04-04 12:25 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2015-04-04 11:43 - 2015-04-18 17:40 - 00007611 _____ () C:\Users\Netbook\AppData\Local\Resmon.ResmonCfg
2015-04-04 11:40 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2015-04-04 11:40 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2015-04-04 11:40 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2015-04-04 11:40 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2015-04-04 10:43 - 2015-04-19 15:54 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-04-04 10:43 - 2015-04-19 15:54 - 00000000 ____D () C:\windows\system32\appraiser
2015-04-04 05:40 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2015-04-04 05:37 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-04-04 05:37 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2015-04-04 05:37 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2015-04-04 05:37 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-04-04 05:37 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2015-04-04 05:37 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2015-04-04 05:37 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2015-04-04 05:36 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2015-04-04 05:36 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-04-04 05:36 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2015-04-04 05:36 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2015-04-04 05:36 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-04-04 05:36 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2015-04-04 05:34 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
2015-04-04 05:34 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\windows\system32\gameux.dll
2015-04-04 05:34 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\windows\system32\cero.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\windows\system32\esrb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\windows\system32\fpb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\windows\system32\oflc-nz.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\windows\system32\pegibbfc.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\windows\system32\csrr.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\windows\system32\cob-au.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\windows\system32\usk.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\windows\system32\oflc.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\windows\system32\grb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-pt.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-fi.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\windows\system32\djctq.rs
2015-04-04 05:33 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2015-04-04 05:33 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2015-04-04 05:33 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2015-04-04 05:33 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2015-04-04 05:33 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2015-04-04 05:28 - 2014-10-14 03:50 - 02363904 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-04-04 05:27 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\netcorehc.dll
2015-04-04 05:27 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\netevent.dll
2015-04-04 05:27 - 2012-10-03 18:40 - 00499712 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2015-04-04 05:27 - 2012-10-03 17:21 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2015-04-04 05:24 - 2013-10-04 03:58 - 00152576 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2015-04-04 05:24 - 2013-10-04 03:56 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2015-04-04 05:22 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-04-04 05:22 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2015-04-04 05:22 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2015-04-04 05:22 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2015-04-04 05:22 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-04-04 05:22 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-04-04 05:22 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2015-04-04 05:22 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-04-04 05:22 - 2012-11-23 04:48 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2015-04-04 05:22 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\windows\system32\dpnet.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2015-04-04 05:20 - 2014-12-06 05:50 - 00242688 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-04-04 05:20 - 2014-11-11 04:44 - 00186880 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2015-04-04 05:20 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2015-04-04 05:20 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2015-04-04 05:20 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2015-04-04 05:20 - 2012-10-03 18:42 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2015-04-04 05:19 - 2014-08-12 03:36 - 00701440 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2015-04-04 05:19 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2015-04-04 05:19 - 2013-07-03 05:36 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2015-04-04 05:19 - 2013-07-03 05:36 - 00025728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2015-04-04 05:19 - 2012-08-21 22:12 - 00245760 _____ (Microsoft Corporation) C:\windows\system32\OxpsConverter.exe
2015-04-04 05:19 - 2012-07-06 21:23 - 00393728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
2015-04-04 05:18 - 2014-11-08 04:45 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-04-04 05:18 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-04-04 05:18 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-04-04 05:17 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-04-04 05:17 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-04-04 05:17 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-04 05:17 - 2013-02-12 05:32 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-04-04 05:17 - 2013-01-24 06:47 - 00196328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2015-04-04 05:16 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2015-04-04 05:16 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2015-04-04 05:16 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2015-04-04 05:16 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2015-04-04 05:16 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2015-04-04 05:15 - 2014-12-19 04:43 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-04-04 05:12 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-04-04 05:12 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2015-04-04 05:12 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2015-04-04 05:11 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2015-04-04 05:11 - 2014-10-30 03:45 - 00155136 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2015-04-04 05:11 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2015-04-04 05:11 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2015-04-04 05:11 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2015-04-04 05:11 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-04-04 05:11 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-04-04 05:11 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-04-04 05:11 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2015-04-04 05:10 - 2014-10-25 03:32 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2015-04-04 05:10 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\netapi32.dll
2015-04-04 05:10 - 2012-07-04 23:14 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\browser.dll
2015-04-04 05:10 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\browcli.dll
2015-04-04 05:09 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-04-04 05:09 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2015-04-04 05:08 - 2013-06-26 00:56 - 00527064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2015-04-04 05:08 - 2012-11-29 00:57 - 00047720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2015-04-04 05:08 - 2012-11-29 00:57 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\Wdfres.dll
2015-04-04 05:08 - 2012-11-29 00:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-04-04 05:07 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-04-04 05:07 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2015-04-04 05:07 - 2014-12-19 03:34 - 00116224 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-04-04 05:07 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2015-04-04 05:06 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll
2015-04-04 05:06 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll
2015-04-04 05:06 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\windows\system32\synceng.dll
2015-04-04 05:05 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2015-04-04 05:05 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2015-04-04 05:05 - 2013-10-12 04:01 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2015-04-04 05:05 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2015-04-04 05:05 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2015-04-04 05:05 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-04-04 05:05 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-04-04 05:05 - 2013-08-28 02:57 - 00434688 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2015-04-04 05:05 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2015-04-04 05:04 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2015-04-04 05:04 - 2013-07-12 12:08 - 00146816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2015-04-04 05:04 - 2013-07-12 12:07 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2015-04-04 05:03 - 2015-01-09 04:48 - 00635904 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
2015-04-04 05:03 - 2015-01-09 04:48 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
2015-04-04 05:03 - 2015-01-09 04:48 - 00027136 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
2015-04-04 05:03 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-04-04 05:03 - 2014-11-11 03:32 - 00074752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-04-04 05:03 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2015-04-04 05:03 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2015-04-04 05:03 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-04-04 05:03 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-04-04 05:03 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2015-04-04 05:03 - 2013-11-27 03:14 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00006016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2015-04-04 05:03 - 2013-11-26 13:11 - 00240576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2015-04-04 05:03 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2015-04-04 05:03 - 2013-10-04 03:49 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2015-04-04 05:03 - 2013-10-04 03:17 - 00177152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2015-04-04 05:03 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2015-04-04 05:03 - 2012-08-22 19:16 - 00712048 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-04-04 05:03 - 2012-07-04 21:45 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\Drivers\RNDISMP.sys
2015-04-04 05:03 - 2012-05-14 06:33 - 00769024 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-04-04 05:02 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2015-04-04 05:02 - 2013-03-19 05:33 - 00040960 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
2015-04-04 05:02 - 2013-02-27 06:49 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-04-04 05:01 - 2014-10-14 03:50 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2015-04-04 05:01 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2015-04-04 05:00 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-04-04 03:56 - 2015-04-04 10:57 - 00004856 _____ () C:\windows\system32\TmInstall.log
2015-04-04 02:46 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2015-04-04 02:46 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2015-04-04 01:10 - 2015-04-04 12:31 - 00001380 _____ () C:\preference.xml
2015-04-02 21:59 - 2015-04-02 21:59 - 00000000 ____D () C:\windows\system32\vbox
2015-04-01 21:55 - 2014-06-28 02:21 - 00391640 __RSH () C:\bootmgr
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default\AppData\Local\ASUS
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default\AppData\Local\Adobe
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\ASUS
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\Adobe
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default\Documents\Asus WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default\AppData\Roaming\ASUS WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default User\Documents\Asus WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\ASUS WebStorage
2015-04-01 21:00 - 2012-08-14 09:54 - 00057560 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 21:00 - 2012-08-14 09:54 - 00057560 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 21:00 - 2012-08-14 09:54 - 00000000 ____D () C:\Users\Default\AppData\Local\Windows Live
2015-04-01 21:00 - 2012-08-14 09:54 - 00000000 ____D () C:\Users\Default User\AppData\Local\Windows Live
2015-04-01 21:00 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-04-01 21:00 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-04-01 21:00 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Default\AppData\Roaming\E-Cam
2015-04-01 21:00 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\E-Cam
2015-04-01 21:00 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Default\AppData\Roaming\InstallShield
2015-04-01 21:00 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\InstallShield
2015-04-01 20:59 - 2015-04-19 17:48 - 01429336 _____ () C:\windows\WindowsUpdate.log
2015-04-01 14:19 - 2015-04-01 14:19 - 00000961 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-04-01 14:19 - 2015-04-01 14:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-04-01 14:19 - 2015-04-01 14:19 - 00000000 ____D () C:\Program Files\CCleaner
2015-04-01 13:12 - 2015-04-18 16:22 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-01 13:12 - 2015-04-01 13:12 - 00001056 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-04-01 13:12 - 2015-04-01 13:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-01 13:11 - 2015-04-01 13:12 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-04-01 13:11 - 2015-04-01 13:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-01 13:11 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-04-01 13:11 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-04-01 13:11 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-04-01 12:40 - 2015-04-18 09:53 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-04-01 12:20 - 2015-04-01 12:20 - 00001405 _____ () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-01 12:20 - 2010-05-28 04:27 - 00005576 _____ () C:\windows\Language.ini
2015-04-01 12:19 - 2015-04-01 12:19 - 00001100 _____ () C:\Users\Public\Desktop\E-Manual.lnk
2015-04-01 12:19 - 2015-04-01 12:19 - 00000000 ____D () C:\windows\ConfigSetRoot
2015-04-01 12:18 - 2015-04-01 12:19 - 00000000 ____D () C:\Program Files\Qualcomm Atheros WiFi Driver Installation
2015-04-01 12:18 - 2012-01-15 08:37 - 00072522 _____ () C:\windows\system32\athrext.cat
2015-04-01 12:18 - 2012-01-10 21:39 - 02231808 _____ (Atheros Communications, Inc.) C:\windows\system32\Drivers\athr.sys
2015-04-01 12:18 - 2012-01-10 21:39 - 02231808 _____ (Atheros Communications, Inc.) C:\windows\system32\athr.sys
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____D () C:\Program Files\Synaptics
2015-04-01 12:16 - 2011-08-30 07:00 - 00001083 _____ () C:\setup.iss
2015-04-01 12:15 - 2015-04-04 19:37 - 00058016 _____ () C:\Users\Netbook\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 12:15 - 2015-04-01 12:20 - 00000000 ____D () C:\Users\Netbook\AppData\Local\VirtualStore
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Startmenü
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Netzwerkumgebung
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Druckumgebung
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Documents\Eigene Musik
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Documents\Eigene Bilder
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\AppData\Local\Verlauf
2015-04-01 12:14 - 2015-04-18 00:14 - 00000000 ____D () C:\Users\Netbook\AppData\Local\Adobe
2015-04-01 12:14 - 2015-04-17 21:28 - 00000000 ____D () C:\Users\Netbook\AppData\Local\Windows Live
2015-04-01 12:14 - 2015-04-01 12:20 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Adobe
2015-04-01 12:14 - 2015-04-01 12:15 - 00000000 ____D () C:\Users\Netbook
2015-04-01 12:14 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Netbook\AppData\Local\ASUS
2015-04-01 12:14 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Netbook\Documents\Asus WebStorage
2015-04-01 12:14 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\ASUS WebStorage
2015-04-01 12:14 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Macromedia
2015-04-01 12:14 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\E-Cam
2015-04-01 12:14 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\InstallShield
2015-04-01 12:14 - 2009-07-14 06:53 - 00000020 ___SH () C:\Users\Netbook\ntuser.ini
2015-04-01 12:14 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-01 12:14 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-01 12:12 - 2015-04-01 12:12 - 00000000 ____D () C:\Recovery

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-19 17:27 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-19 17:27 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-19 17:14 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-04-19 16:35 - 2011-02-16 17:44 - 00746534 _____ () C:\windows\system32\perfh013.dat
2015-04-19 16:35 - 2011-02-16 17:44 - 00156542 _____ () C:\windows\system32\perfc013.dat
2015-04-19 16:35 - 2011-02-16 17:39 - 00743082 _____ () C:\windows\system32\perfh010.dat
2015-04-19 16:35 - 2011-02-16 17:39 - 00150286 _____ () C:\windows\system32\perfc010.dat
2015-04-19 16:35 - 2009-07-27 12:11 - 04260840 _____ () C:\windows\system32\PerfStringBackup.INI
2015-04-19 16:35 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\de-DE
2015-04-19 16:34 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\fr-FR
2015-04-19 16:33 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\it-IT
2015-04-19 16:32 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\nl-NL
2015-04-18 15:10 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\DigitalLocker
2015-04-18 15:10 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-04-18 15:10 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-04-18 15:10 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Defender
2015-04-18 15:10 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\DVD Maker
2015-04-18 15:10 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\IME
2015-04-18 15:10 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-18 15:09 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\winrm
2015-04-18 15:09 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\WCN
2015-04-18 15:09 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\slmgr
2015-04-18 15:09 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\Printing_Admin_Scripts
2015-04-18 15:09 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\MUI
2015-04-18 15:09 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\com
2015-04-18 14:21 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2015-04-18 14:21 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-18 14:14 - 2009-07-14 04:04 - 00000215 _____ () C:\windows\system.ini
2015-04-18 13:55 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\Microsoft.NET
2015-04-18 00:15 - 2012-08-14 09:52 - 00000000 ____D () C:\ProgramData\Adobe
2015-04-17 21:35 - 2012-08-14 09:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-04-17 21:27 - 2012-08-14 09:35 - 00000000 ____D () C:\Program Files\Intel
2015-04-17 20:56 - 2012-08-14 09:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-04-17 20:51 - 2012-08-14 09:39 - 00000000 ____D () C:\windows\system32\Atheros_L1e
2015-04-17 20:26 - 2012-08-14 09:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-04-17 19:51 - 2012-08-14 09:35 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\windows\system32\CSVer.dll
2015-04-17 19:17 - 2012-08-14 09:49 - 00000000 ____D () C:\Program Files\Asus
2015-04-17 19:14 - 2012-08-14 09:36 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-04-17 18:24 - 2009-07-14 06:33 - 00267160 _____ () C:\windows\system32\FNTCACHE.DAT
2015-04-11 22:12 - 2009-07-27 12:56 - 00000000 ____D () C:\windows\panther
2015-04-04 17:46 - 2011-02-16 17:44 - 00000000 ____D () C:\windows\system32\Drivers\nl-NL
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-TW
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-HK
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-CN
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\tr-TR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\sv-SE
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ru-RU
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pt-PT
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pt-BR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pl-PL
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\nb-NO
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ko-KR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ja-JP
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\hu-HU
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\fi-FI
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\el-GR
2015-04-04 16:07 - 2011-02-16 17:39 - 00000000 ____D () C:\windows\system32\Drivers\it-IT
2015-04-04 16:07 - 2011-02-16 17:34 - 00000000 ____D () C:\windows\system32\Drivers\fr-FR
2015-04-04 16:07 - 2011-02-16 17:29 - 00000000 ____D () C:\windows\system32\Drivers\de-DE
2015-04-04 12:33 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-04 11:46 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing
2015-04-04 10:43 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat
2015-04-04 06:04 - 2012-08-14 09:38 - 00000000 ____D () C:\windows\system32\RTCOM
2015-04-04 03:52 - 2012-08-14 10:10 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-04-04 01:17 - 2012-08-14 09:49 - 00000000 ____D () C:\AsusVibeData
2015-04-04 01:16 - 2012-08-14 09:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2015-04-01 21:55 - 2009-07-14 06:57 - 00029696 ___SH () C:\windows\system32\config\BCD-Template.LOG
2015-04-01 21:55 - 2009-07-14 06:52 - 00032768 _____ () C:\windows\system32\config\BCD-Template
2015-04-01 21:11 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\rescache
2015-04-01 12:17 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\restore

==================== Files in the root of some directories =======

2015-04-04 11:43 - 2015-04-18 17:40 - 0007611 _____ () C:\Users\Netbook\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
C:\Users\Netbook\AppData\Local\Temp\Quarantine.exe
C:\Users\Netbook\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-18 14:39

==================== End Of Log ============================
         
--- --- ---

--- --- ---


Das hier sagt der Neuber-Analyzer


Alt 19.04.2015, 18:11   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



hi,

Addition.txt fehlt noch
__________________

__________________

Alt 19.04.2015, 18:25   #3
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



Ups, wird sofort nachgereicht :-)


FRST Additions Logfile:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-04-2015 01
Ran by Netbook at 2015-04-19 17:59:17
Running from C:\Users\Netbook\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adblock Plus für IE (32-Bit) (HKLM\...\{A2C33E25-4A8E-43F7-8998-BBEB690F1AB1}) (Version: 1.3 - Eyeo GmbH)
ASUSUpdate for Eee PC (HKLM\...\{587178E7-B1DF-494E-9838-FA4DD36E873C}) (Version: 1.06.03 - ASUSTeK Computer Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.19 - Atheros Communications Inc.)
Avast Free Antivirus (HKLM\...\Avast) (Version: 10.2.2214 - AVAST Software)
CapsHook (HKLM\...\{4B5092B6-F231-4D18-83BC-2618B729CA45}) (Version: 1.0.0.7 - AsusTek Computer)
CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
E-Cam (HKLM\...\{185AFA7A-F63E-450B-94AA-011CAC18090E}) (Version: 2.0.3.0 - AzureWave)
Eee Docking 3.10.5 (HKLM\...\Eee Docking_is1) (Version: 3.10.5 - ASUSTek Computer Inc.)
ExpressGateCloud (HKLM\...\InstallShield_{36B0DC39-3282-40EB-8587-B875CE46C3A7}) (Version: 2.7.61.310 - VideACE Co.)
ExpressGateCloud (Version: 2.7.61.310 - VideACE Co.) Hidden
FontResizer (HKLM\...\InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}) (Version: 1.01.0011 - ASUSTek)
FontResizer (Version: 1.01.0011 - ASUSTek) Hidden
Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Hotkey Service (HKLM\...\{71C0E38E-09F2-4386-9977-404D4F6640CD}) (Version: 1.46 - AsusTek Computer Inc.)
InstantOn for EPC (HKLM\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.1.6 - ASUS)
Intel(R) Control Center (HKLM\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.14.8.1083 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LiveUpdate (HKLM\...\{38E5A3B1-ADF1-47E0-8024-76310A30EB36}) (Version: 1.31 - AsusTek Computer Inc.)
Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Nederlands) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1043) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office (HKLM\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Qualcomm Atheros WiFi Driver Installation (HKLM\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
Raccolta foto di Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7404 - Realtek Semiconductor Corp.)
SlimDrivers (HKLM\...\{5AD12E7A-D739-4451-9BD1-3610EC56D8F5}) (Version: 2.2.45206 - SlimWare Utilities, Inc.)
Super Hybrid Engine (HKLM\...\{88F08F98-12BC-4613-81A2-8F9B88CFC73E}) (Version: 2.21 - AsusTek Computer)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.6.0 - Synaptics Incorporated)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

01-04-2015 12:17:07 Installiert Qualcomm Atheros WiFi Driver Installation
01-04-2015 12:27:13 Windows Update
01-04-2015 12:43:46 avast! antivirus system restore point
04-04-2015 00:57:05 Removed ASUS Media Sharing
04-04-2015 01:13:40 Removed AsusScreensaver
04-04-2015 02:25:22 Installed Microsoft Fix it 50123
04-04-2015 05:52:53 Windows Update
04-04-2015 11:41:01 Windows Update
04-04-2015 12:21:19 Windows Update
04-04-2015 12:46:36 Windows Update
04-04-2015 16:27:59 Windows Update
04-04-2015 17:39:29 Windows Update
04-04-2015 17:53:03 Windows Update
04-04-2015 20:25:17 Installed Adblock Plus for IE (32-bit)
10-04-2015 21:37:17 Windows Update
17-04-2015 17:50:29 Windows Update
17-04-2015 18:34:26 Installed ASUSUpdate for Eee PC
17-04-2015 18:40:29 Installed Plug9
17-04-2015 19:40:23 Configured ASUSUpdate for Eee PC
17-04-2015 20:47:59 SlimDrivers Installing Drivers
17-04-2015 20:53:02 Konfiguriert Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Et
17-04-2015 21:03:26 SlimDrivers Installing Drivers
17-04-2015 21:22:17 SlimDrivers Installing Drivers
17-04-2015 23:57:30 Removed Acrobat.com
18-04-2015 00:12:36 Removed Adobe Reader 9.1 MUI.
18-04-2015 00:15:58 avast! antivirus system restore point
18-04-2015 09:25:01 Windows Update
18-04-2015 09:55:32 avast! antivirus system restore point
18-04-2015 14:46:48 Sprachpaketdeinstallation
18-04-2015 21:53:24 Windows Update
19-04-2015 15:28:49 Windows Update
19-04-2015 16:20:28 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {197A0F48-168F-40C1-A168-BA252D39AA52} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {74D1C113-147B-4DF7-B0CB-5A5088805B9B} - System32\Tasks\{D412FCE7-3732-4D98-9FF6-35D52433017D} => pcalua.exe -a D:\Downloads\ASUSUpdt-V1_06_03\setup.exe -d D:\Downloads\ASUSUpdt-V1_06_03\
Task: {7746AE21-5642-4FDF-900A-86DE4BA4855F} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {8FC62142-5E94-4CD7-BD43-001C39283AC9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd)
Task: {916186CA-9909-4CF6-976D-AF52E0F7A89D} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {B0ACDC78-9C58-49D0-9D00-C200D9342908} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {B22D76D1-60BB-4B8C-AF7A-9D4D522CBBC4} - System32\Tasks\{D5534597-BC08-4FA3-B2A8-4EF6B46ECA68} => Iexplore.exe hxxp://ui.skype.com/ui/0/7.0.0.102/de/abandoninstall?page=tsMain
Task: {F980DD72-20DF-4857-821B-CD1E9CE4D98E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-04-18] (Avast Software s.r.o.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Loaded Modules (whitelisted) ==============

2015-04-18 09:58 - 2015-04-18 09:58 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-04-18 09:58 - 2015-04-18 09:58 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-04-19 15:05 - 2015-04-19 15:05 - 02926080 _____ () C:\Program Files\AVAST Software\Avast\defs\15041900\algo.dll
2015-04-18 09:58 - 2015-04-18 09:58 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-03-13 15:54 - 2015-03-13 15:54 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2015-04-18 09:58 - 2015-04-18 09:58 - 01359872 _____ () C:\Program Files\AVAST Software\Avast\libglesv2.dll
2015-04-18 09:58 - 2015-04-18 09:58 - 00212992 _____ () C:\Program Files\AVAST Software\Avast\libegl.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-309674158-46085917-1021320157-1000\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.178.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Eee Docking => C:\Program Files\ASUS\Eee Docking\Eee Docking.exe autorun
MSCONFIG\startupreg: VAWinAgent => C:\ExpressGateUtil\VAWinAgent.exe

==================== Accounts: =============================

Administrator (S-1-5-21-309674158-46085917-1021320157-500 - Administrator - Disabled)
Gast (S-1-5-21-309674158-46085917-1021320157-501 - Limited - Disabled)
Netbook (S-1-5-21-309674158-46085917-1021320157-1000 - Administrator - Enabled) => C:\Users\Netbook

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Der Index kann nicht initialisiert werden.


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Element nicht gefunden.  (HRESULT : 0x80070490) (0x80070490)

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Die Inhaltsindexdatenbank ist fehlerhaft.  (HRESULT : 0xc0041800) (0xc0041800)

Error: (04/19/2015 05:13:44 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet.


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:44 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben.


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:44 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: Der Jet-Eigenschaftenspeicher kann von Windows Search nicht geöffnet werden.


Details:
	0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft.  (HRESULT : 0xc0041800))

Error: (04/19/2015 05:13:44 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (5288) Windows: Fehler -1811 beim Öffnen von Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0000C.log.


System errors:
=============
Error: (04/19/2015 05:20:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/19/2015 05:20:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Rapid Storage Technology" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/19/2015 05:20:02 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/19/2015 05:19:59 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/19/2015 05:19:57 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "VideAceWindowsService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/19/2015 05:19:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Asus Launcher Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/19/2015 05:19:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "ASUS InstantOn Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/19/2015 05:19:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/19/2015 05:13:59 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Program Files\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll

Error: (04/19/2015 05:13:59 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul wurde unerwartet beendet.

Modulpfad: C:\Program Files\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


Microsoft Office Sessions:
=========================
Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: 
Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Kontext: Windows Anwendung


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Element nicht gefunden.  (HRESULT : 0x80070490) (0x80070490)
Search.TripoliIndexer

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)
Search.JetPropStore

Error: (04/19/2015 05:13:45 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Die Inhaltsindexdatenbank ist fehlerhaft.  (HRESULT : 0xc0041800) (0xc0041800)

Error: (04/19/2015 05:13:44 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: 
Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)
The catalog is corrupt

Error: (04/19/2015 05:13:44 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: 
Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)
4700

Error: (04/19/2015 05:13:44 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: 
Details:
	0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft.  (HRESULT : 0xc0041800))

Error: (04/19/2015 05:13:44 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows5288Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0000C.log-1811


==================== Memory info =========================== 

Processor: Intel(R) Atom(TM) CPU N2600 @ 1.60GHz
Percentage of memory in use: 89%
Total physical RAM: 1011.94 MB
Available physical RAM: 103.95 MB
Total Pagefile: 2035.94 MB
Available Pagefile: 959.19 MB
Total Virtual: 2047.88 MB
Available Virtual: 1923.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:100 GB) (Free:58.14 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:183.07 GB) (Free:182.66 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: A8D6F410)
Partition 1: (Active) - (Size=100 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=15 GB) - (Type=1B)
Partition 3: (Not Active) - (Size=183.1 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=16 MB) - (Type=EF)

==================== End Of Log ============================
         
--- --- ---
__________________

Alt 20.04.2015, 13:19   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



hi,

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 20.04.2015, 17:59   #5
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



Hy und schonmal Danke für die schnelle Antwort.

Also MBar hat nichts gefunden. Werde jetzt den TDSSKiller ausführen. Anbei schonmal die Log des Mbar.

Malwarebytes Anti-Rootkit BETA 1.09.1.1004
www.malwarebytes.org

Database version:
main: v2015.04.20.03
rootkit: v2015.03.31.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17728
Netbook :: NETBOOK-PC [administrator]

20.04.2015 18:09:06
mbar-log-2015-04-20 (18-09-06).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 306797
Time elapsed: 36 minute(s), 2 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)


Alt 20.04.2015, 18:09   #6
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



Auch kein Fund. Mysteriöses Kästchen dieses Netbook.

Ist das soweit ok, die Log-Files so reinzukopieren oder gibt es da bessere Möglichkeiten?


19:01:58.0962 0x1174 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
19:02:06.0840 0x1174 ============================================================
19:02:06.0840 0x1174 Current date / time: 2015/04/20 19:02:06.0840
19:02:06.0840 0x1174 SystemInfo:
19:02:06.0840 0x1174
19:02:06.0840 0x1174 OS Version: 6.1.7601 ServicePack: 1.0
19:02:06.0840 0x1174 Product type: Workstation
19:02:06.0840 0x1174 ComputerName: NETBOOK-PC
19:02:06.0840 0x1174 UserName: Netbook
19:02:06.0840 0x1174 Windows directory: C:\windows
19:02:06.0840 0x1174 System windows directory: C:\windows
19:02:06.0856 0x1174 Processor architecture: Intel x86
19:02:06.0856 0x1174 Number of processors: 4
19:02:06.0856 0x1174 Page size: 0x1000
19:02:06.0856 0x1174 Boot type: Normal boot
19:02:06.0856 0x1174 ============================================================
19:02:09.0757 0x1174 KLMD registered as C:\windows\system32\drivers\91150027.sys
19:02:11.0208 0x1174 System UUID: {6CE611C9-DEC3-D5EE-F9A0-8AB36925FA9B}
19:02:13.0876 0x1174 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:02:13.0891 0x1174 ============================================================
19:02:13.0891 0x1174 \Device\Harddisk0\DR0:
19:02:13.0891 0x1174 MBR partitions:
19:02:13.0891 0x1174 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xC800000
19:02:13.0891 0x1174 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xE600800, BlocksNum 0x16E26000
19:02:13.0891 0x1174 ============================================================
19:02:13.0938 0x1174 C: <-> \Device\Harddisk0\DR0\Partition1
19:02:14.0125 0x1174 D: <-> \Device\Harddisk0\DR0\Partition2
19:02:14.0157 0x1174 ============================================================
19:02:14.0157 0x1174 Initialize success
19:02:14.0157 0x1174 ============================================================
19:02:44.0748 0x17a4 ============================================================
19:02:44.0748 0x17a4 Scan started
19:02:44.0748 0x17a4 Mode: Manual;
19:02:44.0748 0x17a4 ============================================================
19:02:44.0748 0x17a4 KSN ping started
19:02:47.0478 0x17a4 KSN ping finished: true
19:02:48.0352 0x17a4 ================ Scan system memory ========================
19:02:48.0352 0x17a4 System memory - ok
19:02:48.0352 0x17a4 ================ Scan services =============================
19:02:49.0678 0x17a4 [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
19:02:49.0725 0x17a4 1394ohci - ok
19:02:49.0850 0x17a4 [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI C:\windows\system32\drivers\ACPI.sys
19:02:49.0881 0x17a4 ACPI - ok
19:02:49.0896 0x17a4 [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
19:02:49.0896 0x17a4 AcpiPmi - ok
19:02:49.0943 0x17a4 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\windows\system32\drivers\adp94xx.sys
19:02:49.0974 0x17a4 adp94xx - ok
19:02:50.0021 0x17a4 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\windows\system32\drivers\adpahci.sys
19:02:50.0052 0x17a4 adpahci - ok
19:02:50.0084 0x17a4 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\windows\system32\drivers\adpu320.sys
19:02:50.0099 0x17a4 adpu320 - ok
19:02:50.0146 0x17a4 [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\windows\System32\aelupsvc.dll
19:02:50.0177 0x17a4 AeLookupSvc - ok
19:02:50.0255 0x17a4 [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD C:\windows\system32\drivers\afd.sys
19:02:50.0286 0x17a4 AFD - ok
19:02:50.0333 0x17a4 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\windows\system32\drivers\agp440.sys
19:02:50.0333 0x17a4 agp440 - ok
19:02:50.0380 0x17a4 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\windows\system32\drivers\djsvs.sys
19:02:50.0396 0x17a4 aic78xx - ok
19:02:50.0442 0x17a4 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\windows\System32\alg.exe
19:02:50.0442 0x17a4 ALG - ok
19:02:50.0489 0x17a4 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\windows\system32\drivers\aliide.sys
19:02:50.0505 0x17a4 aliide - ok
19:02:50.0552 0x17a4 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\windows\system32\drivers\amdagp.sys
19:02:50.0567 0x17a4 amdagp - ok
19:02:50.0583 0x17a4 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\windows\system32\drivers\amdide.sys
19:02:50.0583 0x17a4 amdide - ok
19:02:50.0630 0x17a4 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\windows\system32\drivers\amdk8.sys
19:02:50.0630 0x17a4 AmdK8 - ok
19:02:50.0645 0x17a4 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\windows\system32\drivers\amdppm.sys
19:02:50.0661 0x17a4 AmdPPM - ok
19:02:50.0676 0x17a4 [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata C:\windows\system32\drivers\amdsata.sys
19:02:50.0676 0x17a4 amdsata - ok
19:02:50.0723 0x17a4 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\windows\system32\drivers\amdsbs.sys
19:02:50.0754 0x17a4 amdsbs - ok
19:02:50.0754 0x17a4 [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata C:\windows\system32\drivers\amdxata.sys
19:02:50.0770 0x17a4 amdxata - ok
19:02:50.0817 0x17a4 [ 81F97D8F8B3FB94A451CC6F7CF8B2965, 8DEBA4E47E1016D69740C0BB7CDD23852D86E0D42C1C1EA5A847ECB115C38CB1 ] AppID C:\windows\system32\drivers\appid.sys
19:02:50.0832 0x17a4 AppID - ok
19:02:50.0864 0x17a4 [ F5090F8FA6757C58E17BAEAA86093636, 5E14CF3032DF5801240F45C59AA93962EA41AA5648A0C6458D16D9B9D95A131F ] AppIDSvc C:\windows\System32\appidsvc.dll
19:02:50.0879 0x17a4 AppIDSvc - ok
19:02:50.0942 0x17a4 [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo C:\windows\System32\appinfo.dll
19:02:50.0973 0x17a4 Appinfo - ok
19:02:51.0051 0x17a4 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\windows\system32\drivers\arc.sys
19:02:51.0082 0x17a4 arc - ok
19:02:51.0113 0x17a4 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\windows\system32\drivers\arcsas.sys
19:02:51.0113 0x17a4 arcsas - ok
19:02:51.0144 0x17a4 [ 956C7177DBDA0F02436868AD644CCF31, BC18586452ED4C23772BF4BE7FE6EAB184BE142922F88229E20EA53FC185461D ] AsIO C:\windows\system32\drivers\AsIO.sys
19:02:51.0144 0x17a4 AsIO - ok
19:02:51.0597 0x17a4 [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
19:02:51.0597 0x17a4 aspnet_state - ok
19:02:51.0675 0x17a4 [ A9A565C669786C402752F609AFDD0DD5, 7D64828DE5503AF4B4A80F4C08BB2659B277CD664AB33724FB9387948BE8765A ] AsUpIO C:\windows\system32\drivers\AsUpIO.sys
19:02:51.0690 0x17a4 AsUpIO - ok
19:02:51.0768 0x17a4 [ 8165C8825C726A7D5EFDF863A2D1C28F, 20168F9B21AA3BB33F8B76802A03D805C245E0B3EA92C4F2255B73345621E5B7 ] ASUS InstantOn C:\Program Files\ASUS\InstantOn for EPC\InsOnSrv.exe
19:02:51.0784 0x17a4 ASUS InstantOn - ok
19:02:51.0846 0x17a4 [ 9E3579EB00FCD9264F83D75B7590BD0C, 9F625C1555F4651FC05DB4EC92925FA393FBF58B1BCE172050DE99297D6AB36A ] AsusService C:\windows\system32\AsusService.exe
19:02:51.0862 0x17a4 AsusService - ok
19:02:51.0909 0x17a4 [ AA69ED00EE72BFEE003C864DCFBC5038, 95B949C4AC7F1962FE84EE8FBA4C7CBE959B963ABEEAE0EF092EBB028D1435E2 ] aswHwid C:\windows\system32\drivers\aswHwid.sys
19:02:51.0909 0x17a4 aswHwid - ok
19:02:51.0956 0x17a4 [ 6FDAE6458E0FAC369005EEFE55E1190A, 518FEFEBE50CAC7F54AF839F8A2423307789989FC5D92535866C38A1FBDBDDE3 ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
19:02:51.0971 0x17a4 aswMonFlt - ok
19:02:52.0018 0x17a4 [ 0BD1C9E546CA7D801E25FED0E9CA58B8, 487C36B0A008EDD3E907B7537E69F085976B97BDD2D2E05D2BEC22DDD07923CA ] aswRdr C:\windows\system32\drivers\aswRdr2.sys
19:02:52.0034 0x17a4 aswRdr - ok
19:02:52.0065 0x17a4 [ 6FB92505DAA300DA62A1C374B949B574, CBF54038F1267A8B3420C5B58F4AAB77A71590B1C82B9144AD4FAB07E9B9B685 ] aswRvrt C:\windows\system32\drivers\aswRvrt.sys
19:02:52.0065 0x17a4 aswRvrt - ok
19:02:52.0174 0x17a4 [ C3A047ABB97AEB805E07A30EFDACD0B9, D62BD6FF27C42134FE3A22B87ED5D16EDEA1994E90C1EEC5E2680047B76DC4DC ] aswSnx C:\windows\system32\drivers\aswSnx.sys
19:02:52.0236 0x17a4 aswSnx - ok
19:02:52.0314 0x17a4 [ E5F230B70F1A9764EB7AC4A76445F79F, 22D938B96D6E1BCAF2E5DD109A880BDB640AC048970876EB75DA5BB7DD858DDA ] aswSP C:\windows\system32\drivers\aswSP.sys
19:02:52.0377 0x17a4 aswSP - ok
19:02:52.0408 0x17a4 [ F761D13D43D0F4FB2986308CFFD7F589, 035EEABBAB6D3DC71C659DE91C860B7D2F6BC581E6B5D5F506169FC7FD7A4F88 ] aswStm C:\windows\system32\drivers\aswStm.sys
19:02:52.0408 0x17a4 aswStm - ok
19:02:52.0455 0x17a4 [ 2EBD0ACCAFC67088D4B9EBDF7428F6AD, F2872CB350CE46BED8FCD3790921612B808292D32A58BC6F646BBD2EEEA4ADE0 ] aswVmm C:\windows\system32\drivers\aswVmm.sys
19:02:52.0517 0x17a4 aswVmm - ok
19:02:52.0564 0x17a4 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
19:02:52.0564 0x17a4 AsyncMac - ok
19:02:52.0626 0x17a4 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\windows\system32\drivers\atapi.sys
19:02:52.0642 0x17a4 atapi - ok
19:02:52.0970 0x17a4 [ 8309BF4D39DAA99E5035B58C7B1533D9, 78A986B99FF6329F4BE64EEF99C411EF55171D1F867DB1801E2EEFF19B7FE2BD ] athr C:\windows\system32\DRIVERS\athr.sys
19:02:53.0172 0x17a4 athr - ok
19:02:53.0282 0x17a4 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
19:02:53.0313 0x17a4 AudioEndpointBuilder - ok
19:02:53.0344 0x17a4 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv C:\windows\System32\Audiosrv.dll
19:02:53.0375 0x17a4 Audiosrv - ok
19:02:53.0609 0x17a4 [ 35714DC1ADD995681D890D4382C75721, C1D10F2D47D348DCEA363B676E35A363FE8FA0E24295C4AD90F7EA37826A822D ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
19:02:53.0640 0x17a4 avast! Antivirus - ok
19:02:54.0327 0x17a4 [ 5019A83BE87FD8B60F7333901BFD35E5, 674DF51CAA1B6C0BC9CA9755B3BC5A9A71C583BD7C7A2826BD280E107B855092 ] AvastVBoxSvc C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
19:02:54.0639 0x17a4 AvastVBoxSvc - ok
19:02:55.0200 0x17a4 [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV C:\windows\System32\AxInstSV.dll
19:02:55.0232 0x17a4 AxInstSV - ok
19:02:55.0419 0x17a4 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\windows\system32\drivers\bxvbdx.sys
19:02:55.0528 0x17a4 b06bdrv - ok
19:02:55.0575 0x17a4 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
19:02:55.0590 0x17a4 b57nd60x - ok
19:02:55.0684 0x17a4 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\windows\System32\bdesvc.dll
19:02:55.0700 0x17a4 BDESVC - ok
19:02:55.0700 0x17a4 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\windows\system32\drivers\Beep.sys
19:02:55.0715 0x17a4 Beep - ok
19:02:55.0778 0x17a4 [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE C:\windows\System32\bfe.dll
19:02:55.0809 0x17a4 BFE - ok
19:02:56.0027 0x17a4 [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\windows\system32\qmgr.dll
19:02:56.0121 0x17a4 BITS - ok
19:02:56.0168 0x17a4 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
19:02:56.0183 0x17a4 blbdrive - ok
19:02:56.0214 0x17a4 [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\windows\system32\DRIVERS\bowser.sys
19:02:56.0230 0x17a4 bowser - ok
19:02:56.0246 0x17a4 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
19:02:56.0246 0x17a4 BrFiltLo - ok
19:02:56.0261 0x17a4 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
19:02:56.0261 0x17a4 BrFiltUp - ok
19:02:56.0308 0x17a4 [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C8862FAA68F6179A3BA9D6B69AE64 ] BridgeMP C:\windows\system32\DRIVERS\bridge.sys
19:02:56.0308 0x17a4 BridgeMP - ok
19:02:56.0386 0x17a4 [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser C:\windows\System32\browser.dll
19:02:56.0402 0x17a4 Browser - ok
19:02:56.0464 0x17a4 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\windows\System32\Drivers\Brserid.sys
19:02:56.0495 0x17a4 Brserid - ok
19:02:56.0511 0x17a4 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
19:02:56.0526 0x17a4 BrSerWdm - ok
19:02:56.0526 0x17a4 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
19:02:56.0542 0x17a4 BrUsbMdm - ok
19:02:56.0558 0x17a4 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
19:02:56.0558 0x17a4 BrUsbSer - ok
19:02:56.0620 0x17a4 [ 2865A5C8E98C70C605F417908CEBB3A4, B1C5AC228BD7072AF8668C009C6CDC13EE9FCB9481F57524300F37C40BF1E935 ] BthEnum C:\windows\system32\drivers\BthEnum.sys
19:02:56.0620 0x17a4 BthEnum - ok
19:02:56.0667 0x17a4 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
19:02:56.0682 0x17a4 BTHMODEM - ok
19:02:56.0698 0x17a4 [ AD1872E5829E8A2C3B5B4B641C3EAB0E, 8C2DBCAC08DDB41E2B44E257C55FA2D0272959B308EFF9EAF5FF9AE1E4A0AA39 ] BthPan C:\windows\system32\DRIVERS\bthpan.sys
19:02:56.0714 0x17a4 BthPan - ok
19:02:56.0823 0x17a4 [ 1153DE2E4F5941E10C399CB5592F78A1, 2B88AF246D62F72FA9F5B921B0375AE59A0F263672472D5EC9FDB5CA5EF51C31 ] BTHPORT C:\windows\System32\Drivers\BTHport.sys
19:02:56.0885 0x17a4 BTHPORT - ok
19:02:56.0932 0x17a4 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\windows\system32\bthserv.dll
19:02:56.0979 0x17a4 bthserv - ok
19:02:57.0026 0x17a4 [ C81E9413A25A439F436B1D4B6A0CF9E9, A4C290163207AED22C70C7F90B28F6FC24892889643D60D915059405AC5A4A72 ] BTHUSB C:\windows\System32\Drivers\BTHUSB.sys
19:02:57.0026 0x17a4 BTHUSB - ok
19:02:57.0244 0x17a4 catchme - ok
19:02:57.0291 0x17a4 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
19:02:57.0306 0x17a4 cdfs - ok
19:02:57.0353 0x17a4 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\windows\system32\drivers\cdrom.sys
19:02:57.0369 0x17a4 cdrom - ok
19:02:57.0462 0x17a4 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\windows\System32\certprop.dll
19:02:57.0478 0x17a4 CertPropSvc - ok
19:02:57.0494 0x17a4 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\windows\system32\drivers\circlass.sys
19:02:57.0509 0x17a4 circlass - ok
19:02:57.0556 0x17a4 [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS C:\windows\system32\CLFS.sys
19:02:57.0587 0x17a4 CLFS - ok
19:02:57.0743 0x17a4 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:02:57.0759 0x17a4 clr_optimization_v2.0.50727_32 - ok
19:02:57.0837 0x17a4 [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:02:57.0852 0x17a4 clr_optimization_v4.0.30319_32 - ok
19:02:57.0884 0x17a4 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
19:02:57.0884 0x17a4 CmBatt - ok
19:02:57.0946 0x17a4 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\windows\system32\drivers\cmdide.sys
19:02:57.0946 0x17a4 cmdide - ok
19:02:58.0008 0x17a4 [ 3051724F223EA48968B19567DE2A81F4, DCC27DE1B2B35866FC6DBDE95A368E7D0D346B6C3F31D0BACA63DD39B0A8874E ] CNG C:\windows\system32\Drivers\cng.sys
19:02:58.0055 0x17a4 CNG - ok
19:02:58.0102 0x17a4 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\windows\system32\drivers\compbatt.sys
19:02:58.0118 0x17a4 Compbatt - ok
19:02:58.0133 0x17a4 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\windows\system32\DRIVERS\CompositeBus.sys
19:02:58.0133 0x17a4 CompositeBus - ok
19:02:58.0196 0x17a4 COMSysApp - ok
19:02:58.0242 0x17a4 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
19:02:58.0242 0x17a4 crcdisk - ok
19:02:58.0352 0x17a4 [ 49474B3E37969AF4B5C076F42B623AFF, BDA6B57E9B60EF1B67C74099263D33A367AAA035667239F76AB8B268FD3E8F23 ] CryptSvc C:\windows\system32\cryptsvc.dll
19:02:58.0367 0x17a4 CryptSvc - ok
19:02:58.0508 0x17a4 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\windows\system32\rpcss.dll
19:02:58.0554 0x17a4 DcomLaunch - ok
19:02:58.0617 0x17a4 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\windows\System32\defragsvc.dll
19:02:58.0632 0x17a4 defragsvc - ok
19:02:58.0679 0x17a4 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\windows\system32\Drivers\dfsc.sys
19:02:58.0679 0x17a4 DfsC - ok
19:02:58.0757 0x17a4 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\windows\system32\dhcpcore.dll
19:02:58.0788 0x17a4 Dhcp - ok
19:02:58.0804 0x17a4 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\windows\system32\drivers\discache.sys
19:02:58.0820 0x17a4 discache - ok
19:02:58.0851 0x17a4 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\windows\system32\drivers\disk.sys
19:02:58.0866 0x17a4 Disk - ok
19:02:58.0898 0x17a4 [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache C:\windows\System32\dnsrslvr.dll
19:02:58.0913 0x17a4 Dnscache - ok
19:02:58.0944 0x17a4 [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc C:\windows\System32\dot3svc.dll
19:02:58.0991 0x17a4 dot3svc - ok
19:02:59.0038 0x17a4 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\windows\system32\dps.dll
19:02:59.0054 0x17a4 DPS - ok
19:02:59.0116 0x17a4 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\windows\system32\drivers\drmkaud.sys
19:02:59.0116 0x17a4 drmkaud - ok
19:02:59.0288 0x17a4 [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
19:02:59.0350 0x17a4 DXGKrnl - ok
19:02:59.0412 0x17a4 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\windows\System32\eapsvc.dll
19:02:59.0428 0x17a4 EapHost - ok
19:02:59.0490 0x17a4 Scan was interrupted by user!
19:02:59.0490 0x17a4 Waiting for KSN requests completion. In queue: 66
19:03:00.0504 0x17a4 Waiting for KSN requests completion. In queue: 66
19:03:01.0518 0x17a4 Waiting for KSN requests completion. In queue: 66
19:03:02.0657 0x17a4 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 10.2.2214.845 ), 0x41000 ( enabled : updated )
19:03:02.0829 0x17a4 Win FW state via NFP2: enabled
19:03:05.0309 0x17a4 ============================================================
19:03:05.0309 0x17a4 Scan finished
19:03:05.0309 0x17a4 ============================================================
19:03:05.0325 0x1624 Detected object count: 0
19:03:05.0325 0x1624 Actual detected object count: 0
19:03:28.0288 0x0ec8 ============================================================
19:03:28.0288 0x0ec8 Scan started
19:03:28.0288 0x0ec8 Mode: Manual; SigCheck; TDLFS;
19:03:28.0288 0x0ec8 ============================================================
19:03:28.0288 0x0ec8 KSN ping started
19:03:30.0737 0x0ec8 KSN ping finished: true
19:03:31.0096 0x0ec8 ================ Scan system memory ========================
19:03:31.0096 0x0ec8 System memory - ok
19:03:31.0096 0x0ec8 ================ Scan services =============================
19:03:31.0876 0x0ec8 [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
19:03:32.0375 0x0ec8 1394ohci - ok
19:03:32.0422 0x0ec8 [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI C:\windows\system32\drivers\ACPI.sys
19:03:32.0469 0x0ec8 ACPI - ok
19:03:32.0484 0x0ec8 [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
19:03:32.0687 0x0ec8 AcpiPmi - ok
19:03:32.0765 0x0ec8 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\windows\system32\drivers\adp94xx.sys
19:03:32.0828 0x0ec8 adp94xx - ok
19:03:32.0859 0x0ec8 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\windows\system32\drivers\adpahci.sys
19:03:32.0921 0x0ec8 adpahci - ok
19:03:32.0952 0x0ec8 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\windows\system32\drivers\adpu320.sys
19:03:32.0999 0x0ec8 adpu320 - ok
19:03:33.0062 0x0ec8 [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\windows\System32\aelupsvc.dll
19:03:33.0389 0x0ec8 AeLookupSvc - ok
19:03:33.0514 0x0ec8 [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD C:\windows\system32\drivers\afd.sys
19:03:33.0717 0x0ec8 AFD - ok
19:03:33.0779 0x0ec8 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\windows\system32\drivers\agp440.sys
19:03:33.0810 0x0ec8 agp440 - ok
19:03:33.0857 0x0ec8 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\windows\system32\drivers\djsvs.sys
19:03:33.0904 0x0ec8 aic78xx - ok
19:03:33.0951 0x0ec8 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\windows\System32\alg.exe
19:03:34.0076 0x0ec8 ALG - ok
19:03:34.0122 0x0ec8 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\windows\system32\drivers\aliide.sys
19:03:34.0154 0x0ec8 aliide - ok
19:03:34.0185 0x0ec8 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\windows\system32\drivers\amdagp.sys
19:03:34.0232 0x0ec8 amdagp - ok
19:03:34.0263 0x0ec8 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\windows\system32\drivers\amdide.sys
19:03:34.0294 0x0ec8 amdide - ok
19:03:34.0325 0x0ec8 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\windows\system32\drivers\amdk8.sys
19:03:34.0450 0x0ec8 AmdK8 - ok
19:03:34.0466 0x0ec8 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\windows\system32\drivers\amdppm.sys
19:03:34.0575 0x0ec8 AmdPPM - ok
19:03:34.0606 0x0ec8 [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata C:\windows\system32\drivers\amdsata.sys
19:03:34.0668 0x0ec8 amdsata - ok
19:03:34.0700 0x0ec8 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\windows\system32\drivers\amdsbs.sys
19:03:34.0746 0x0ec8 amdsbs - ok
19:03:34.0809 0x0ec8 [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata C:\windows\system32\drivers\amdxata.sys
19:03:34.0840 0x0ec8 amdxata - ok
19:03:34.0934 0x0ec8 [ 81F97D8F8B3FB94A451CC6F7CF8B2965, 8DEBA4E47E1016D69740C0BB7CDD23852D86E0D42C1C1EA5A847ECB115C38CB1 ] AppID C:\windows\system32\drivers\appid.sys
19:03:35.0074 0x0ec8 AppID - ok
19:03:35.0121 0x0ec8 [ F5090F8FA6757C58E17BAEAA86093636, 5E14CF3032DF5801240F45C59AA93962EA41AA5648A0C6458D16D9B9D95A131F ] AppIDSvc C:\windows\System32\appidsvc.dll
19:03:35.0199 0x0ec8 AppIDSvc - ok
19:03:35.0308 0x0ec8 [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo C:\windows\System32\appinfo.dll
19:03:35.0480 0x0ec8 Appinfo - ok
19:03:35.0526 0x0ec8 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\windows\system32\drivers\arc.sys
19:03:35.0558 0x0ec8 arc - ok
19:03:35.0589 0x0ec8 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\windows\system32\drivers\arcsas.sys
19:03:35.0620 0x0ec8 arcsas - ok
19:03:35.0636 0x0ec8 [ 956C7177DBDA0F02436868AD644CCF31, BC18586452ED4C23772BF4BE7FE6EAB184BE142922F88229E20EA53FC185461D ] AsIO C:\windows\system32\drivers\AsIO.sys
19:03:35.0682 0x0ec8 AsIO - ok
19:03:36.0010 0x0ec8 [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
19:03:36.0057 0x0ec8 aspnet_state - ok
19:03:36.0104 0x0ec8 [ A9A565C669786C402752F609AFDD0DD5, 7D64828DE5503AF4B4A80F4C08BB2659B277CD664AB33724FB9387948BE8765A ] AsUpIO C:\windows\system32\drivers\AsUpIO.sys
19:03:36.0135 0x0ec8 AsUpIO - ok
19:03:36.0228 0x0ec8 [ 8165C8825C726A7D5EFDF863A2D1C28F, 20168F9B21AA3BB33F8B76802A03D805C245E0B3EA92C4F2255B73345621E5B7 ] ASUS InstantOn C:\Program Files\ASUS\InstantOn for EPC\InsOnSrv.exe
19:03:36.0275 0x0ec8 ASUS InstantOn - ok
19:03:36.0322 0x0ec8 [ 9E3579EB00FCD9264F83D75B7590BD0C, 9F625C1555F4651FC05DB4EC92925FA393FBF58B1BCE172050DE99297D6AB36A ] AsusService C:\windows\system32\AsusService.exe
19:03:36.0384 0x0ec8 AsusService - ok
19:03:36.0416 0x0ec8 [ AA69ED00EE72BFEE003C864DCFBC5038, 95B949C4AC7F1962FE84EE8FBA4C7CBE959B963ABEEAE0EF092EBB028D1435E2 ] aswHwid C:\windows\system32\drivers\aswHwid.sys
19:03:36.0462 0x0ec8 aswHwid - ok
19:03:36.0509 0x0ec8 [ 6FDAE6458E0FAC369005EEFE55E1190A, 518FEFEBE50CAC7F54AF839F8A2423307789989FC5D92535866C38A1FBDBDDE3 ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
19:03:36.0556 0x0ec8 aswMonFlt - ok
19:03:36.0587 0x0ec8 [ 0BD1C9E546CA7D801E25FED0E9CA58B8, 487C36B0A008EDD3E907B7537E69F085976B97BDD2D2E05D2BEC22DDD07923CA ] aswRdr C:\windows\system32\drivers\aswRdr2.sys
19:03:36.0634 0x0ec8 aswRdr - ok
19:03:36.0665 0x0ec8 [ 6FB92505DAA300DA62A1C374B949B574, CBF54038F1267A8B3420C5B58F4AAB77A71590B1C82B9144AD4FAB07E9B9B685 ] aswRvrt C:\windows\system32\drivers\aswRvrt.sys
19:03:36.0712 0x0ec8 aswRvrt - ok
19:03:36.0790 0x0ec8 [ C3A047ABB97AEB805E07A30EFDACD0B9, D62BD6FF27C42134FE3A22B87ED5D16EDEA1994E90C1EEC5E2680047B76DC4DC ] aswSnx C:\windows\system32\drivers\aswSnx.sys
19:03:36.0884 0x0ec8 aswSnx - ok
19:03:36.0930 0x0ec8 [ E5F230B70F1A9764EB7AC4A76445F79F, 22D938B96D6E1BCAF2E5DD109A880BDB640AC048970876EB75DA5BB7DD858DDA ] aswSP C:\windows\system32\drivers\aswSP.sys
19:03:36.0993 0x0ec8 aswSP - ok
19:03:37.0055 0x0ec8 [ F761D13D43D0F4FB2986308CFFD7F589, 035EEABBAB6D3DC71C659DE91C860B7D2F6BC581E6B5D5F506169FC7FD7A4F88 ] aswStm C:\windows\system32\drivers\aswStm.sys
19:03:37.0102 0x0ec8 aswStm - ok
19:03:37.0227 0x0ec8 [ 2EBD0ACCAFC67088D4B9EBDF7428F6AD, F2872CB350CE46BED8FCD3790921612B808292D32A58BC6F646BBD2EEEA4ADE0 ] aswVmm C:\windows\system32\drivers\aswVmm.sys
19:03:37.0289 0x0ec8 aswVmm - ok
19:03:37.0305 0x0ec8 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
19:03:37.0476 0x0ec8 AsyncMac - ok
19:03:37.0523 0x0ec8 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\windows\system32\drivers\atapi.sys
19:03:37.0554 0x0ec8 atapi - ok
19:03:37.0913 0x0ec8 [ 8309BF4D39DAA99E5035B58C7B1533D9, 78A986B99FF6329F4BE64EEF99C411EF55171D1F867DB1801E2EEFF19B7FE2BD ] athr C:\windows\system32\DRIVERS\athr.sys
19:03:38.0178 0x0ec8 athr - ok
19:03:38.0288 0x0ec8 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
19:03:38.0412 0x0ec8 AudioEndpointBuilder - ok
19:03:38.0490 0x0ec8 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv C:\windows\System32\Audiosrv.dll
19:03:38.0568 0x0ec8 Audiosrv - ok
19:03:38.0958 0x0ec8 [ 35714DC1ADD995681D890D4382C75721, C1D10F2D47D348DCEA363B676E35A363FE8FA0E24295C4AD90F7EA37826A822D ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
19:03:39.0114 0x0ec8 avast! Antivirus - ok
19:03:39.0707 0x0ec8 [ 5019A83BE87FD8B60F7333901BFD35E5, 674DF51CAA1B6C0BC9CA9755B3BC5A9A71C583BD7C7A2826BD280E107B855092 ] AvastVBoxSvc C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
19:03:39.0972 0x0ec8 AvastVBoxSvc - ok
19:03:40.0066 0x0ec8 [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV C:\windows\System32\AxInstSV.dll
19:03:40.0253 0x0ec8 AxInstSV - ok
19:03:40.0331 0x0ec8 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\windows\system32\drivers\bxvbdx.sys
19:03:40.0518 0x0ec8 b06bdrv - ok
19:03:40.0565 0x0ec8 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
19:03:40.0628 0x0ec8 b57nd60x - ok
19:03:40.0674 0x0ec8 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\windows\System32\bdesvc.dll
19:03:40.0799 0x0ec8 BDESVC - ok
19:03:40.0830 0x0ec8 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\windows\system32\drivers\Beep.sys
19:03:40.0940 0x0ec8 Beep - ok
19:03:40.0986 0x0ec8 [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE C:\windows\System32\bfe.dll
19:03:41.0127 0x0ec8 BFE - ok
19:03:41.0252 0x0ec8 [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\windows\system32\qmgr.dll
19:03:41.0408 0x0ec8 BITS - ok
19:03:41.0439 0x0ec8 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
19:03:41.0501 0x0ec8 blbdrive - ok
19:03:41.0532 0x0ec8 [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\windows\system32\DRIVERS\bowser.sys
19:03:41.0673 0x0ec8 bowser - ok
19:03:41.0688 0x0ec8 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
19:03:41.0798 0x0ec8 BrFiltLo - ok
19:03:41.0813 0x0ec8 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
19:03:41.0876 0x0ec8 BrFiltUp - ok
19:03:41.0907 0x0ec8 [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C8862FAA68F6179A3BA9D6B69AE64 ] BridgeMP C:\windows\system32\DRIVERS\bridge.sys
19:03:42.0047 0x0ec8 BridgeMP - ok
19:03:42.0094 0x0ec8 [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser C:\windows\System32\browser.dll
19:03:42.0234 0x0ec8 Browser - ok
19:03:42.0297 0x0ec8 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\windows\System32\Drivers\Brserid.sys
19:03:42.0437 0x0ec8 Brserid - ok
19:03:42.0453 0x0ec8 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
19:03:42.0515 0x0ec8 BrSerWdm - ok
19:03:42.0593 0x0ec8 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
19:03:42.0671 0x0ec8 BrUsbMdm - ok
19:03:42.0687 0x0ec8 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
19:03:42.0765 0x0ec8 BrUsbSer - ok
19:03:42.0812 0x0ec8 [ 2865A5C8E98C70C605F417908CEBB3A4, B1C5AC228BD7072AF8668C009C6CDC13EE9FCB9481F57524300F37C40BF1E935 ] BthEnum C:\windows\system32\drivers\BthEnum.sys
19:03:42.0968 0x0ec8 BthEnum - ok
19:03:42.0999 0x0ec8 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
19:03:43.0124 0x0ec8 BTHMODEM - ok
19:03:43.0155 0x0ec8 [ AD1872E5829E8A2C3B5B4B641C3EAB0E, 8C2DBCAC08DDB41E2B44E257C55FA2D0272959B308EFF9EAF5FF9AE1E4A0AA39 ] BthPan C:\windows\system32\DRIVERS\bthpan.sys
19:03:43.0217 0x0ec8 BthPan - ok
19:03:43.0295 0x0ec8 [ 1153DE2E4F5941E10C399CB5592F78A1, 2B88AF246D62F72FA9F5B921B0375AE59A0F263672472D5EC9FDB5CA5EF51C31 ] BTHPORT C:\windows\System32\Drivers\BTHport.sys
19:03:43.0436 0x0ec8 BTHPORT - ok
19:03:43.0482 0x0ec8 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\windows\system32\bthserv.dll
19:03:43.0592 0x0ec8 bthserv - ok
19:03:43.0638 0x0ec8 [ C81E9413A25A439F436B1D4B6A0CF9E9, A4C290163207AED22C70C7F90B28F6FC24892889643D60D915059405AC5A4A72 ] BTHUSB C:\windows\System32\Drivers\BTHUSB.sys
19:03:43.0701 0x0ec8 BTHUSB - ok
19:03:43.0841 0x0ec8 catchme - ok
19:03:43.0904 0x0ec8 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
19:03:44.0028 0x0ec8 cdfs - ok
19:03:44.0044 0x0ec8 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\windows\system32\drivers\cdrom.sys
19:03:44.0231 0x0ec8 cdrom - ok
19:03:44.0278 0x0ec8 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\windows\System32\certprop.dll
19:03:44.0372 0x0ec8 CertPropSvc - ok
19:03:44.0403 0x0ec8 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\windows\system32\drivers\circlass.sys
19:03:44.0465 0x0ec8 circlass - ok
19:03:44.0512 0x0ec8 [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS C:\windows\system32\CLFS.sys
19:03:44.0574 0x0ec8 CLFS - ok
19:03:44.0746 0x0ec8 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:03:44.0808 0x0ec8 clr_optimization_v2.0.50727_32 - ok
19:03:44.0855 0x0ec8 [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:03:44.0902 0x0ec8 clr_optimization_v4.0.30319_32 - ok
19:03:44.0964 0x0ec8 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
19:03:45.0027 0x0ec8 CmBatt - ok
19:03:45.0074 0x0ec8 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\windows\system32\drivers\cmdide.sys
19:03:45.0105 0x0ec8 cmdide - ok
19:03:45.0198 0x0ec8 [ 3051724F223EA48968B19567DE2A81F4, DCC27DE1B2B35866FC6DBDE95A368E7D0D346B6C3F31D0BACA63DD39B0A8874E ] CNG C:\windows\system32\Drivers\cng.sys
19:03:45.0292 0x0ec8 CNG - ok
19:03:45.0339 0x0ec8 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\windows\system32\drivers\compbatt.sys
19:03:45.0370 0x0ec8 Compbatt - ok
19:03:45.0386 0x0ec8 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\windows\system32\DRIVERS\CompositeBus.sys
19:03:45.0464 0x0ec8 CompositeBus - ok
19:03:45.0479 0x0ec8 COMSysApp - ok
19:03:45.0495 0x0ec8 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
19:03:45.0526 0x0ec8 crcdisk - ok
19:03:45.0604 0x0ec8 [ 49474B3E37969AF4B5C076F42B623AFF, BDA6B57E9B60EF1B67C74099263D33A367AAA035667239F76AB8B268FD3E8F23 ] CryptSvc C:\windows\system32\cryptsvc.dll
19:03:45.0682 0x0ec8 CryptSvc - ok
19:03:45.0791 0x0ec8 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\windows\system32\rpcss.dll
19:03:45.0978 0x0ec8 DcomLaunch - ok
19:03:46.0025 0x0ec8 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\windows\System32\defragsvc.dll
19:03:46.0150 0x0ec8 defragsvc - ok
19:03:46.0166 0x0ec8 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\windows\system32\Drivers\dfsc.sys
19:03:46.0275 0x0ec8 DfsC - ok
19:03:46.0322 0x0ec8 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\windows\system32\dhcpcore.dll
19:03:46.0431 0x0ec8 Dhcp - ok
19:03:46.0478 0x0ec8 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\windows\system32\drivers\discache.sys
19:03:46.0556 0x0ec8 discache - ok
19:03:46.0587 0x0ec8 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\windows\system32\drivers\disk.sys
19:03:46.0634 0x0ec8 Disk - ok
19:03:46.0727 0x0ec8 [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache C:\windows\System32\dnsrslvr.dll
19:03:46.0852 0x0ec8 Dnscache - ok
19:03:46.0914 0x0ec8 [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc C:\windows\System32\dot3svc.dll
19:03:47.0024 0x0ec8 dot3svc - ok
19:03:47.0070 0x0ec8 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\windows\system32\dps.dll
19:03:47.0195 0x0ec8 DPS - ok
19:03:47.0273 0x0ec8 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\windows\system32\drivers\drmkaud.sys
19:03:47.0382 0x0ec8 drmkaud - ok
19:03:47.0507 0x0ec8 [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
19:03:47.0601 0x0ec8 DXGKrnl - ok
19:03:47.0648 0x0ec8 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\windows\System32\eapsvc.dll
19:03:47.0757 0x0ec8 EapHost - ok
19:03:48.0069 0x0ec8 [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\windows\system32\drivers\evbdx.sys
19:03:48.0428 0x0ec8 ebdrv - ok
19:03:48.0474 0x0ec8 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] EFS C:\windows\System32\lsass.exe
19:03:48.0646 0x0ec8 EFS - ok
19:03:48.0708 0x0ec8 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\windows\system32\drivers\elxstor.sys
19:03:48.0802 0x0ec8 elxstor - ok
19:03:48.0818 0x0ec8 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\windows\system32\drivers\errdev.sys
19:03:48.0880 0x0ec8 ErrDev - ok
19:03:48.0958 0x0ec8 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\windows\system32\es.dll
19:03:49.0083 0x0ec8 EventSystem - ok
19:03:49.0114 0x0ec8 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\windows\system32\drivers\exfat.sys
19:03:49.0239 0x0ec8 exfat - ok
19:03:49.0270 0x0ec8 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\windows\system32\drivers\fastfat.sys
19:03:49.0395 0x0ec8 fastfat - ok
19:03:49.0535 0x0ec8 [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax C:\windows\system32\fxssvc.exe
19:03:49.0738 0x0ec8 Fax - ok
19:03:49.0785 0x0ec8 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\windows\system32\drivers\fdc.sys
19:03:49.0832 0x0ec8 fdc - ok
19:03:49.0878 0x0ec8 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\windows\system32\fdPHost.dll
19:03:49.0988 0x0ec8 fdPHost - ok
19:03:49.0988 0x0ec8 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\windows\system32\fdrespub.dll
19:03:50.0112 0x0ec8 FDResPub - ok
19:03:50.0159 0x0ec8 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
19:03:50.0222 0x0ec8 FileInfo - ok
19:03:50.0237 0x0ec8 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\windows\system32\drivers\filetrace.sys
19:03:50.0331 0x0ec8 Filetrace - ok
19:03:50.0331 0x0ec8 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\windows\system32\drivers\flpydisk.sys
19:03:50.0393 0x0ec8 flpydisk - ok
19:03:50.0424 0x0ec8 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
19:03:50.0471 0x0ec8 FltMgr - ok
19:03:50.0612 0x0ec8 [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache C:\windows\system32\FntCache.dll
19:03:50.0861 0x0ec8 FontCache - ok
19:03:50.0955 0x0ec8 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
19:03:51.0048 0x0ec8 FontCache3.0.0.0 - ok
19:03:51.0080 0x0ec8 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\windows\system32\drivers\FsDepends.sys
19:03:51.0111 0x0ec8 FsDepends - ok
19:03:51.0158 0x0ec8 [ BFAAA92861526BB0ADCD01E964AB6609, 5C0B7BAEF04F20C45897CE88559D4B5664121475EFD2489F3D89191DCFC7C8ED ] fssfltr C:\windows\system32\DRIVERS\fssfltr.sys
19:03:51.0189 0x0ec8 fssfltr - ok
19:03:51.0407 0x0ec8 [ 40CDFAD174B3D5E80F95DDA003C0B97F, 2DA149CE42B87681ECDCC8905D0957443F430A9C7002FF78F22A95F9112A7C4C ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe
19:03:51.0594 0x0ec8 fsssvc - ok
19:03:51.0657 0x0ec8 [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
19:03:51.0704 0x0ec8 Fs_Rec - ok
19:03:51.0782 0x0ec8 [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
19:03:51.0860 0x0ec8 fvevol - ok
19:03:51.0906 0x0ec8 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
19:03:51.0938 0x0ec8 gagp30kx - ok
19:03:52.0016 0x0ec8 [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc C:\windows\System32\gpsvc.dll
19:03:52.0172 0x0ec8 gpsvc - ok
19:03:52.0218 0x0ec8 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
19:03:52.0328 0x0ec8 hcw85cir - ok
19:03:52.0421 0x0ec8 [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
19:03:52.0499 0x0ec8 HdAudAddService - ok
19:03:52.0562 0x0ec8 [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus C:\windows\system32\DRIVERS\HDAudBus.sys
19:03:52.0655 0x0ec8 HDAudBus - ok
19:03:52.0686 0x0ec8 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\windows\system32\drivers\HidBatt.sys
19:03:52.0764 0x0ec8 HidBatt - ok
19:03:52.0811 0x0ec8 [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\windows\system32\drivers\hidbth.sys
19:03:52.0889 0x0ec8 HidBth - ok
19:03:52.0920 0x0ec8 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\windows\system32\drivers\hidir.sys
19:03:52.0998 0x0ec8 HidIr - ok
19:03:53.0061 0x0ec8 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\windows\System32\hidserv.dll
19:03:53.0170 0x0ec8 hidserv - ok
19:03:53.0264 0x0ec8 [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
19:03:53.0451 0x0ec8 HidUsb - ok
19:03:53.0482 0x0ec8 [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc C:\windows\system32\kmsvc.dll
19:03:53.0591 0x0ec8 hkmsvc - ok
19:03:53.0732 0x0ec8 [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\windows\system32\ListSvc.dll
19:03:53.0997 0x0ec8 HomeGroupListener - ok
19:03:54.0059 0x0ec8 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\windows\system32\provsvc.dll
19:03:54.0184 0x0ec8 HomeGroupProvider - ok
19:03:54.0340 0x0ec8 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
19:03:54.0387 0x0ec8 HpSAMD - ok
19:03:54.0527 0x0ec8 [ 487569E5DA56A5A432FF8AF6D3599CF9, 7C974D8379C60B4F69A20B01876C49181B0A63AC318C4BD0A21DABFF27A15C9D ] HTTP C:\windows\system32\drivers\HTTP.sys
19:03:54.0668 0x0ec8 HTTP - ok
19:03:54.0730 0x0ec8 [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
19:03:54.0761 0x0ec8 hwpolicy - ok
19:03:54.0808 0x0ec8 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
19:03:54.0902 0x0ec8 i8042prt - ok
19:03:55.0058 0x0ec8 [ 76C3966183BD5382E14CEB6DF97D9709, 52A2676FED3A73182D7BA3AC4EA954BC2DC8879CE71DB973E37720B2F0A7392A ] iaStor C:\windows\system32\drivers\iaStor.sys
19:03:55.0136 0x0ec8 iaStor - ok
19:03:55.0292 0x0ec8 [ 545462D0DBE24AF379BA869B7C185CCD, 056F9D0D5FD4FEF37665A35A4029722FF60D02A69854E952DC361CC0E5CD26F9 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
19:03:55.0338 0x0ec8 IAStorDataMgrSvc - ok
19:03:55.0494 0x0ec8 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
19:03:55.0572 0x0ec8 iaStorV - ok
19:03:55.0791 0x0ec8 [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
19:03:55.0931 0x0ec8 idsvc - ok
19:03:55.0978 0x0ec8 IEEtwCollectorService - ok
19:03:56.0196 0x0ec8 [ 96FE1D82D1B4420D350AB6493C6FCE41, E4BE6087ADCA0DA6D54CAE4D9FA8D01F04DFA5A248DF0D4242EDFE22289A40E9 ] igddim32 C:\windows\system32\DRIVERS\igddim32.sys
19:03:56.0477 0x0ec8 igddim32 - ok
19:03:56.0586 0x0ec8 [ 30D8327539E11CFE5006BCF762F07EB9, 465CCF714DFA33B491EEC389C9F9A0F3913A6BBC83A1198C4B6A03E7DA3C0A04 ] igdkmd32 C:\windows\system32\DRIVERS\igdkmd32.sys
19:03:56.0774 0x0ec8 igdkmd32 - ok
19:03:56.0836 0x0ec8 [ 30D8327539E11CFE5006BCF762F07EB9, 465CCF714DFA33B491EEC389C9F9A0F3913A6BBC83A1198C4B6A03E7DA3C0A04 ] igfx C:\windows\system32\DRIVERS\igdkmd32.sys
19:03:56.0914 0x0ec8 igfx - ok
19:03:56.0976 0x0ec8 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\windows\system32\drivers\iirsp.sys
19:03:57.0008 0x0ec8 iirsp - ok
19:03:57.0164 0x0ec8 [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT C:\windows\System32\ikeext.dll
19:03:57.0335 0x0ec8 IKEEXT - ok
19:03:57.0959 0x0ec8 [ DAA00AE67B4F8B083442BEAB684A387B, 8770DE3B80F8F192E333311A90BB0AD8E2CA0959B2CF363589C54E15F3D37569 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHDA.sys
19:03:58.0396 0x0ec8 IntcAzAudAddService - ok
19:03:58.0474 0x0ec8 [ 8F4D251F1EA15FA97E8399128A72CC83, 210F724C2586DA4EA847439EDAAA7ABA170435A88698C077ED31D057C0997164 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
19:03:58.0630 0x0ec8 IntcDAud - ok
19:03:58.0677 0x0ec8 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\windows\system32\drivers\intelide.sys
19:03:58.0739 0x0ec8 intelide - ok
19:03:58.0802 0x0ec8 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\windows\system32\DRIVERS\intelppm.sys
19:03:58.0864 0x0ec8 intelppm - ok
19:03:58.0942 0x0ec8 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\windows\system32\ipbusenum.dll
19:03:59.0051 0x0ec8 IPBusEnum - ok
19:03:59.0114 0x0ec8 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
19:03:59.0207 0x0ec8 IpFilterDriver - ok
19:03:59.0332 0x0ec8 [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
19:03:59.0550 0x0ec8 iphlpsvc - ok
19:03:59.0582 0x0ec8 [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
19:03:59.0660 0x0ec8 IPMIDRV - ok
19:03:59.0675 0x0ec8 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\windows\system32\drivers\ipnat.sys
19:03:59.0784 0x0ec8 IPNAT - ok
19:03:59.0862 0x0ec8 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\windows\system32\drivers\irenum.sys
19:03:59.0987 0x0ec8 IRENUM - ok
19:04:00.0003 0x0ec8 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\windows\system32\drivers\isapnp.sys
19:04:00.0065 0x0ec8 isapnp - ok
19:04:00.0128 0x0ec8 [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
19:04:00.0206 0x0ec8 iScsiPrt - ok
19:04:00.0237 0x0ec8 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
19:04:00.0284 0x0ec8 kbdclass - ok
19:04:00.0315 0x0ec8 [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid C:\windows\system32\drivers\kbdhid.sys
19:04:00.0377 0x0ec8 kbdhid - ok
19:04:00.0424 0x0ec8 [ 3EB803312987FF44265C87CB960DF6AB, D6F44702F92089A0C847044A3933F7311D6A72C4647C3FECB35CDBF96A913A40 ] kbfiltr C:\windows\system32\DRIVERS\kbfiltr.sys
19:04:00.0455 0x0ec8 kbfiltr - ok
19:04:00.0502 0x0ec8 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] KeyIso C:\windows\system32\lsass.exe
19:04:00.0564 0x0ec8 KeyIso - ok
19:04:00.0642 0x0ec8 [ 746F89CE0C6569C589E6AC4D3DA82D41, 6D41311CBA8BB7C9C09C1757D7947539B67FE3EFF6299502176C673809BAEAD8 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
19:04:00.0705 0x0ec8 KSecDD - ok
19:04:00.0736 0x0ec8 [ D800E1EAF33630A1636BB21E8256AA92, D07542A242E0D52B494BE63A6A141207D0A59CF66ABEBA9CE33877594BF7BA5D ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
19:04:00.0783 0x0ec8 KSecPkg - ok
19:04:00.0845 0x0ec8 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\windows\system32\msdtckrm.dll
19:04:01.0001 0x0ec8 KtmRm - ok
19:04:01.0095 0x0ec8 [ 01D2FC703B5DE56BAF7A94ADFD81427A, 5BF89ABB0CA665252D62228D261C286CCBCC24906A45C306A1A8B993778B9564 ] L1C C:\windows\system32\DRIVERS\L1C62x86.sys
19:04:01.0142 0x0ec8 L1C - ok
19:04:01.0220 0x0ec8 [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer C:\windows\System32\srvsvc.dll
19:04:01.0376 0x0ec8 LanmanServer - ok
19:04:01.0454 0x0ec8 [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
19:04:01.0578 0x0ec8 LanmanWorkstation - ok
19:04:01.0656 0x0ec8 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
19:04:01.0750 0x0ec8 lltdio - ok
19:04:01.0859 0x0ec8 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\windows\System32\lltdsvc.dll
19:04:01.0984 0x0ec8 lltdsvc - ok
19:04:02.0000 0x0ec8 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\windows\System32\lmhsvc.dll
19:04:02.0093 0x0ec8 lmhosts - ok
19:04:02.0156 0x0ec8 [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
19:04:02.0202 0x0ec8 LSI_FC - ok
19:04:02.0234 0x0ec8 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
19:04:02.0280 0x0ec8 LSI_SAS - ok
19:04:02.0343 0x0ec8 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
19:04:02.0405 0x0ec8 LSI_SAS2 - ok
19:04:02.0452 0x0ec8 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
19:04:02.0499 0x0ec8 LSI_SCSI - ok
19:04:02.0514 0x0ec8 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\windows\system32\drivers\luafv.sys
19:04:02.0624 0x0ec8 luafv - ok
19:04:02.0717 0x0ec8 [ AB73A39A5E45F465B02C11C500BB0278, 6863B27DA7A0808F232B93CB74ACA09751B6F63FD9FB26EB3FA0282636CE9807 ] MBAMProtector C:\windows\system32\drivers\mbam.sys
19:04:02.0764 0x0ec8 MBAMProtector - ok
19:04:02.0920 0x0ec8 [ E27891A49DF92004041FEC5C3A2D4230, A4679A1F10F84935875E35A83FC7075499B8F4CBB543209A38C0D946347CD264 ] MBAMService C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe
19:04:03.0060 0x0ec8 MBAMService - ok
19:04:03.0138 0x0ec8 [ 2A1B51A1FE8DC4DC0D52EC700CB02CEF, BF689A361F941F91B63D5F8E54925550333C068F65E59E4DBF0A7B66B8C7EDD6 ] MBAMWebAccessControl C:\windows\system32\drivers\mwac.sys
19:04:03.0201 0x0ec8 MBAMWebAccessControl - ok
19:04:03.0248 0x0ec8 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\windows\system32\drivers\megasas.sys
19:04:03.0310 0x0ec8 megasas - ok
19:04:03.0357 0x0ec8 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\windows\system32\drivers\MegaSR.sys
19:04:03.0419 0x0ec8 MegaSR - ok
19:04:03.0466 0x0ec8 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\windows\system32\mmcss.dll
19:04:03.0560 0x0ec8 MMCSS - ok
19:04:03.0575 0x0ec8 [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\windows\system32\drivers\modem.sys
19:04:03.0669 0x0ec8 Modem - ok
19:04:03.0731 0x0ec8 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\windows\system32\DRIVERS\monitor.sys
19:04:03.0794 0x0ec8 monitor - ok
19:04:03.0825 0x0ec8 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
19:04:03.0887 0x0ec8 mouclass - ok
19:04:03.0918 0x0ec8 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
19:04:04.0012 0x0ec8 mouhid - ok
19:04:04.0074 0x0ec8 [ 644905A19D0F37F2233DFCE53BC4BC19, F52CB40AA0FD1EBF8CBF0F3BFB20C47142C637719840877FB93F10D085EB8C2B ] mountmgr C:\windows\system32\drivers\mountmgr.sys
19:04:04.0106 0x0ec8 mountmgr - ok
19:04:04.0199 0x0ec8 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio C:\windows\system32\drivers\mpio.sys
19:04:04.0262 0x0ec8 mpio - ok
19:04:04.0308 0x0ec8 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
19:04:04.0418 0x0ec8 mpsdrv - ok
19:04:04.0574 0x0ec8 [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc C:\windows\system32\mpssvc.dll
19:04:04.0745 0x0ec8 MpsSvc - ok
19:04:04.0854 0x0ec8 [ 03F899F521D2AAED1C55008F734DF252, 4E56A51476A13F5630719018037B1F63DF9ACEA1CFE782AF04E669BD696954C5 ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
19:04:04.0995 0x0ec8 MRxDAV - ok
19:04:05.0057 0x0ec8 [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
19:04:05.0260 0x0ec8 mrxsmb - ok
19:04:05.0338 0x0ec8 [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
19:04:05.0510 0x0ec8 mrxsmb10 - ok
19:04:05.0541 0x0ec8 [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
19:04:05.0603 0x0ec8 mrxsmb20 - ok
19:04:05.0634 0x0ec8 [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci C:\windows\system32\drivers\msahci.sys
19:04:05.0681 0x0ec8 msahci - ok
19:04:05.0790 0x0ec8 [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm C:\windows\system32\drivers\msdsm.sys
19:04:05.0853 0x0ec8 msdsm - ok
19:04:06.0383 0x0ec8 [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\windows\System32\msdtc.exe
19:04:06.0555 0x0ec8 MSDTC - ok
19:04:06.0758 0x0ec8 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\windows\system32\drivers\Msfs.sys
19:04:06.0898 0x0ec8 Msfs - ok
19:04:06.0945 0x0ec8 [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
19:04:07.0070 0x0ec8 mshidkmdf - ok
19:04:07.0085 0x0ec8 [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
19:04:07.0132 0x0ec8 msisadrv - ok
19:04:07.0272 0x0ec8 [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\windows\system32\iscsiexe.dll
19:04:07.0382 0x0ec8 MSiSCSI - ok
19:04:07.0382 0x0ec8 msiserver - ok
19:04:07.0522 0x0ec8 [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
19:04:07.0616 0x0ec8 MSKSSRV - ok
19:04:07.0772 0x0ec8 [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
19:04:07.0928 0x0ec8 MSPCLOCK - ok
19:04:07.0974 0x0ec8 [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
19:04:08.0084 0x0ec8 MSPQM - ok
19:04:08.0208 0x0ec8 [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
19:04:08.0271 0x0ec8 MsRPC - ok
19:04:08.0333 0x0ec8 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\windows\system32\DRIVERS\mssmbios.sys
19:04:08.0380 0x0ec8 mssmbios - ok
19:04:08.0442 0x0ec8 [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\windows\system32\drivers\MSTEE.sys
19:04:08.0552 0x0ec8 MSTEE - ok
19:04:08.0567 0x0ec8 [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\windows\system32\drivers\MTConfig.sys
19:04:08.0645 0x0ec8 MTConfig - ok
19:04:08.0676 0x0ec8 [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\windows\system32\Drivers\mup.sys
19:04:08.0723 0x0ec8 Mup - ok
19:04:08.0832 0x0ec8 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent C:\windows\system32\qagentRT.dll
19:04:09.0004 0x0ec8 napagent - ok
19:04:09.0191 0x0ec8 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
19:04:09.0363 0x0ec8 NativeWifiP - ok
19:04:09.0644 0x0ec8 [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS C:\windows\system32\drivers\ndis.sys
19:04:09.0768 0x0ec8 NDIS - ok
19:04:09.0862 0x0ec8 [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
19:04:09.0987 0x0ec8 NdisCap - ok
19:04:10.0002 0x0ec8 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
19:04:10.0096 0x0ec8 NdisTapi - ok
19:04:10.0143 0x0ec8 [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
19:04:10.0283 0x0ec8 Ndisuio - ok
19:04:10.0314 0x0ec8 [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
19:04:10.0424 0x0ec8 NdisWan - ok
19:04:10.0424 0x0ec8 [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy C:\windows\system32\drivers\NDProxy.sys
19:04:10.0533 0x0ec8 NDProxy - ok
19:04:10.0580 0x0ec8 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
19:04:10.0689 0x0ec8 NetBIOS - ok
19:04:10.0720 0x0ec8 [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
19:04:10.0829 0x0ec8 NetBT - ok
19:04:10.0860 0x0ec8 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] Netlogon C:\windows\system32\lsass.exe
19:04:10.0938 0x0ec8 Netlogon - ok
19:04:11.0048 0x0ec8 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\windows\System32\netman.dll
19:04:11.0219 0x0ec8 Netman - ok
19:04:11.0266 0x0ec8 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:04:11.0328 0x0ec8 NetMsmqActivator - ok
19:04:11.0344 0x0ec8 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:04:11.0406 0x0ec8 NetPipeActivator - ok
19:04:11.0531 0x0ec8 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\windows\System32\netprofm.dll
19:04:11.0687 0x0ec8 netprofm - ok
19:04:11.0734 0x0ec8 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:04:11.0781 0x0ec8 NetTcpActivator - ok
19:04:11.0828 0x0ec8 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
19:04:11.0906 0x0ec8 NetTcpPortSharing - ok
19:04:11.0984 0x0ec8 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
19:04:12.0030 0x0ec8 nfrd960 - ok
19:04:12.0140 0x0ec8 [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc C:\windows\System32\nlasvc.dll
19:04:12.0280 0x0ec8 NlaSvc - ok
19:04:12.0358 0x0ec8 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\windows\system32\drivers\Npfs.sys
19:04:12.0467 0x0ec8 Npfs - ok
19:04:12.0514 0x0ec8 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\windows\system32\nsisvc.dll
19:04:12.0623 0x0ec8 nsi - ok
19:04:12.0654 0x0ec8 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
19:04:12.0748 0x0ec8 nsiproxy - ok
19:04:12.0920 0x0ec8 [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs C:\windows\system32\drivers\Ntfs.sys
19:04:13.0107 0x0ec8 Ntfs - ok
19:04:13.0169 0x0ec8 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\windows\system32\drivers\Null.sys
19:04:13.0263 0x0ec8 Null - ok
19:04:13.0310 0x0ec8 [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid C:\windows\system32\drivers\nvraid.sys
19:04:13.0356 0x0ec8 nvraid - ok
19:04:13.0372 0x0ec8 [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor C:\windows\system32\drivers\nvstor.sys
19:04:13.0419 0x0ec8 nvstor - ok
19:04:13.0450 0x0ec8 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\windows\system32\drivers\nv_agp.sys
19:04:13.0497 0x0ec8 nv_agp - ok
19:04:13.0512 0x0ec8 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
19:04:13.0575 0x0ec8 ohci1394 - ok
19:04:13.0622 0x0ec8 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\windows\system32\pnrpsvc.dll
19:04:13.0793 0x0ec8 p2pimsvc - ok
19:04:13.0902 0x0ec8 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\windows\system32\p2psvc.dll
19:04:14.0027 0x0ec8 p2psvc - ok
19:04:14.0058 0x0ec8 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\windows\system32\drivers\parport.sys
19:04:14.0136 0x0ec8 Parport - ok
19:04:14.0152 0x0ec8 [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr C:\windows\system32\drivers\partmgr.sys
19:04:14.0199 0x0ec8 partmgr - ok
19:04:14.0214 0x0ec8 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\windows\system32\drivers\parvdm.sys
19:04:14.0292 0x0ec8 Parvdm - ok
19:04:14.0355 0x0ec8 [ 52954BE460EC6C54C0ACB2B3B126FFC6, 9F9878EC5ABC74C5A8EE8E1D940F0934F081895B07D844F42F80A638FE713F7B ] PcaSvc C:\windows\System32\pcasvc.dll
19:04:14.0511 0x0ec8 PcaSvc - ok
19:04:14.0558 0x0ec8 [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\windows\system32\drivers\pci.sys
19:04:14.0604 0x0ec8 pci - ok
19:04:14.0651 0x0ec8 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\windows\system32\drivers\pciide.sys
19:04:14.0698 0x0ec8 pciide - ok
19:04:14.0823 0x0ec8 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\windows\system32\drivers\pcmcia.sys
19:04:14.0870 0x0ec8 pcmcia - ok
19:04:14.0885 0x0ec8 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\windows\system32\drivers\pcw.sys
19:04:14.0932 0x0ec8 pcw - ok
19:04:15.0275 0x0ec8 [ AEBC369F7DC72AB3F5B9BDF34FA0D43F, 2A819154AC6C23E97C583D90B4D0C112188B7AE9D8D9B3F88811BFCED124E551 ] PEAUTH C:\windows\system32\drivers\peauth.sys
19:04:15.0431 0x0ec8 PEAUTH - ok
19:04:15.0696 0x0ec8 [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\windows\system32\pla.dll
19:04:15.0977 0x0ec8 pla - ok
19:04:16.0102 0x0ec8 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\windows\system32\umpnpmgr.dll
19:04:16.0258 0x0ec8 PlugPlay - ok
19:04:16.0320 0x0ec8 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
19:04:16.0461 0x0ec8 PNRPAutoReg - ok
19:04:16.0508 0x0ec8 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\windows\system32\pnrpsvc.dll
19:04:16.0586 0x0ec8 PNRPsvc - ok
19:04:16.0648 0x0ec8 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
19:04:16.0804 0x0ec8 PolicyAgent - ok
19:04:16.0851 0x0ec8 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\windows\system32\umpo.dll
19:04:16.0991 0x0ec8 Power - ok
19:04:17.0054 0x0ec8 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
19:04:17.0147 0x0ec8 PptpMiniport - ok
19:04:17.0210 0x0ec8 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\windows\system32\drivers\processr.sys
19:04:17.0272 0x0ec8 Processor - ok
19:04:17.0334 0x0ec8 [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc C:\windows\system32\profsvc.dll
19:04:17.0475 0x0ec8 ProfSvc - ok
19:04:17.0506 0x0ec8 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] ProtectedStorage C:\windows\system32\lsass.exe
19:04:17.0600 0x0ec8 ProtectedStorage - ok
19:04:17.0631 0x0ec8 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\windows\system32\DRIVERS\pacer.sys
19:04:17.0756 0x0ec8 Psched - ok
19:04:17.0990 0x0ec8 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\windows\system32\drivers\ql2300.sys
19:04:18.0208 0x0ec8 ql2300 - ok
19:04:18.0224 0x0ec8 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\windows\system32\drivers\ql40xx.sys
19:04:18.0270 0x0ec8 ql40xx - ok
19:04:18.0317 0x0ec8 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\windows\system32\qwave.dll
19:04:18.0411 0x0ec8 QWAVE - ok
19:04:18.0504 0x0ec8 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
19:04:18.0598 0x0ec8 QWAVEdrv - ok
19:04:18.0614 0x0ec8 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
19:04:18.0707 0x0ec8 RasAcd - ok
19:04:18.0754 0x0ec8 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
19:04:18.0848 0x0ec8 RasAgileVpn - ok
19:04:19.0238 0x0ec8 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\windows\System32\rasauto.dll
19:04:19.0378 0x0ec8 RasAuto - ok
19:04:19.0425 0x0ec8 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
19:04:19.0534 0x0ec8 Rasl2tp - ok
19:04:19.0612 0x0ec8 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\windows\System32\rasmans.dll
19:04:19.0737 0x0ec8 RasMan - ok
19:04:19.0784 0x0ec8 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
19:04:19.0924 0x0ec8 RasPppoe - ok
19:04:19.0955 0x0ec8 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
19:04:20.0064 0x0ec8 RasSstp - ok
19:04:20.0080 0x0ec8 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
19:04:20.0189 0x0ec8 rdbss - ok
19:04:20.0236 0x0ec8 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\windows\system32\drivers\rdpbus.sys
19:04:20.0314 0x0ec8 rdpbus - ok
19:04:20.0330 0x0ec8 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
19:04:20.0439 0x0ec8 RDPCDD - ok
19:04:20.0470 0x0ec8 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
19:04:20.0579 0x0ec8 RDPENCDD - ok
19:04:20.0642 0x0ec8 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
19:04:20.0766 0x0ec8 RDPREFMP - ok
19:04:20.0938 0x0ec8 [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\windows\system32\drivers\rdpvideominiport.sys
19:04:21.0078 0x0ec8 RdpVideoMiniport - ok
19:04:21.0172 0x0ec8 [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
19:04:21.0328 0x0ec8 RDPWD - ok
19:04:21.0406 0x0ec8 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
19:04:21.0484 0x0ec8 rdyboost - ok
19:04:21.0593 0x0ec8 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\windows\System32\mprdim.dll
19:04:21.0718 0x0ec8 RemoteAccess - ok
19:04:21.0765 0x0ec8 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\windows\system32\regsvc.dll
19:04:21.0874 0x0ec8 RemoteRegistry - ok
19:04:21.0936 0x0ec8 [ CB928D9E6DAF51879DD6BA8D02F01321, DFD263B67DDF98AE09AF6D6986CBC7BE3206BCE8403AAC51BCF9459E78233D12 ] RFCOMM C:\windows\system32\DRIVERS\rfcomm.sys
19:04:22.0014 0x0ec8 RFCOMM - ok
19:04:22.0092 0x0ec8 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
19:04:22.0217 0x0ec8 RpcEptMapper - ok
19:04:22.0311 0x0ec8 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\windows\system32\locator.exe
19:04:22.0404 0x0ec8 RpcLocator - ok
19:04:22.0482 0x0ec8 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\windows\system32\rpcss.dll
19:04:22.0607 0x0ec8 RpcSs - ok
19:04:22.0670 0x0ec8 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
19:04:22.0779 0x0ec8 rspndr - ok
19:04:22.0857 0x0ec8 [ D313E25114C6AE5D3E9764190725C04A, 1AEF37ACC35F2F50396F0D49BE7E82B60A8DB6835007CCD991DDC948C4A4B3FD ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
19:04:22.0935 0x0ec8 RtkAudioService - ok
19:04:22.0950 0x0ec8 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] SamSs C:\windows\system32\lsass.exe
19:04:23.0028 0x0ec8 SamSs - ok
19:04:23.0075 0x0ec8 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\windows\system32\drivers\sbp2port.sys
19:04:23.0122 0x0ec8 sbp2port - ok
19:04:23.0216 0x0ec8 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\windows\System32\SCardSvr.dll
19:04:23.0356 0x0ec8 SCardSvr - ok
19:04:23.0387 0x0ec8 [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
19:04:23.0496 0x0ec8 scfilter - ok
19:04:23.0590 0x0ec8 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\windows\system32\schedsvc.dll
19:04:23.0762 0x0ec8 Schedule - ok
19:04:23.0808 0x0ec8 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\windows\System32\certprop.dll
19:04:23.0902 0x0ec8 SCPolicySvc - ok
19:04:23.0949 0x0ec8 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\windows\System32\SDRSVC.dll
19:04:24.0074 0x0ec8 SDRSVC - ok
19:04:24.0136 0x0ec8 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\windows\system32\drivers\secdrv.sys
19:04:24.0230 0x0ec8 secdrv - ok
19:04:24.0276 0x0ec8 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\windows\system32\seclogon.dll
19:04:24.0386 0x0ec8 seclogon - ok
19:04:24.0448 0x0ec8 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\windows\system32\sens.dll
19:04:24.0573 0x0ec8 SENS - ok
19:04:24.0620 0x0ec8 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\windows\system32\drivers\serenum.sys
19:04:24.0729 0x0ec8 Serenum - ok
19:04:24.0776 0x0ec8 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\windows\system32\drivers\serial.sys
19:04:24.0869 0x0ec8 Serial - ok
19:04:24.0885 0x0ec8 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\windows\system32\drivers\sermouse.sys
19:04:24.0947 0x0ec8 sermouse - ok
19:04:25.0010 0x0ec8 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\windows\system32\sessenv.dll
19:04:25.0166 0x0ec8 SessionEnv - ok
19:04:25.0181 0x0ec8 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\windows\system32\drivers\sffdisk.sys
19:04:25.0259 0x0ec8 sffdisk - ok
19:04:25.0306 0x0ec8 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
19:04:25.0368 0x0ec8 sffp_mmc - ok
19:04:25.0384 0x0ec8 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
19:04:25.0493 0x0ec8 sffp_sd - ok
19:04:25.0524 0x0ec8 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
19:04:25.0587 0x0ec8 sfloppy - ok
19:04:25.0712 0x0ec8 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\windows\System32\ipnathlp.dll
19:04:25.0852 0x0ec8 SharedAccess - ok
19:04:25.0961 0x0ec8 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\windows\System32\shsvcs.dll
19:04:26.0148 0x0ec8 ShellHWDetection - ok
19:04:26.0226 0x0ec8 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\windows\system32\drivers\sisagp.sys
19:04:26.0289 0x0ec8 sisagp - ok
19:04:26.0320 0x0ec8 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
19:04:26.0367 0x0ec8 SiSRaid2 - ok
19:04:26.0398 0x0ec8 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
19:04:26.0445 0x0ec8 SiSRaid4 - ok
19:04:26.0507 0x0ec8 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\windows\system32\DRIVERS\smb.sys
19:04:26.0648 0x0ec8 Smb - ok
19:04:26.0710 0x0ec8 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\windows\System32\snmptrap.exe
19:04:26.0804 0x0ec8 SNMPTRAP - ok
19:04:26.0835 0x0ec8 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\windows\system32\drivers\spldr.sys
19:04:26.0882 0x0ec8 spldr - ok
19:04:27.0022 0x0ec8 [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler C:\windows\System32\spoolsv.exe
19:04:27.0256 0x0ec8 Spooler - ok
19:04:27.0724 0x0ec8 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\windows\system32\sppsvc.exe
19:04:28.0145 0x0ec8 sppsvc - ok
19:04:28.0192 0x0ec8 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\windows\system32\sppuinotify.dll
19:04:28.0301 0x0ec8 sppuinotify - ok
19:04:28.0410 0x0ec8 [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv C:\windows\system32\DRIVERS\srv.sys
19:04:28.0566 0x0ec8 srv - ok
19:04:28.0598 0x0ec8 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
19:04:28.0691 0x0ec8 srv2 - ok
19:04:28.0722 0x0ec8 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
19:04:28.0785 0x0ec8 srvnet - ok
19:04:28.0847 0x0ec8 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\windows\System32\ssdpsrv.dll
19:04:28.0972 0x0ec8 SSDPSRV - ok
19:04:28.0988 0x0ec8 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\windows\system32\sstpsvc.dll
19:04:29.0097 0x0ec8 SstpSvc - ok
19:04:29.0112 0x0ec8 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\windows\system32\drivers\stexstor.sys
19:04:29.0159 0x0ec8 stexstor - ok
19:04:29.0253 0x0ec8 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\windows\System32\wiaservc.dll
19:04:29.0393 0x0ec8 StiSvc - ok
19:04:29.0471 0x0ec8 [ 966EC3458E8B2A78CFE5D7127206D9A2, 801F507AC61FF3050F2158C41C10163210D3F901F2BC4FFD8ED90D3F12FE3058 ] SWDUMon C:\windows\system32\DRIVERS\SWDUMon.sys
19:04:29.0518 0x0ec8 SWDUMon - ok
19:04:29.0549 0x0ec8 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\windows\system32\DRIVERS\swenum.sys
19:04:29.0612 0x0ec8 swenum - ok
19:04:29.0721 0x0ec8 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\windows\System32\swprv.dll
19:04:29.0924 0x0ec8 swprv - ok
19:04:30.0158 0x0ec8 [ 4DB524DCD5CECE0349D9F8C3738DA0B2, A07447A2C2C8692CD7C07E761D742EBC9C7C164952ECA12D5038046615F1A8E9 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys
19:04:30.0345 0x0ec8 SynTP - ok
19:04:30.0548 0x0ec8 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\windows\system32\sysmain.dll
19:04:30.0750 0x0ec8 SysMain - ok
19:04:30.0782 0x0ec8 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\windows\System32\TabSvc.dll
19:04:30.0860 0x0ec8 TabletInputService - ok
19:04:30.0922 0x0ec8 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\windows\System32\tapisrv.dll
19:04:31.0062 0x0ec8 TapiSrv - ok
19:04:31.0094 0x0ec8 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\windows\System32\tbssvc.dll
19:04:31.0203 0x0ec8 TBS - ok
19:04:31.0343 0x0ec8 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip C:\windows\system32\drivers\tcpip.sys
19:04:31.0499 0x0ec8 Tcpip - ok
19:04:31.0796 0x0ec8 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
19:04:31.0920 0x0ec8 TCPIP6 - ok
19:04:31.0998 0x0ec8 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
19:04:32.0139 0x0ec8 tcpipreg - ok
19:04:32.0201 0x0ec8 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
19:04:32.0279 0x0ec8 TDPIPE - ok
19:04:32.0310 0x0ec8 [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
19:04:32.0388 0x0ec8 TDTCP - ok
19:04:32.0435 0x0ec8 [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx C:\windows\system32\DRIVERS\tdx.sys
19:04:32.0560 0x0ec8 tdx - ok
19:04:32.0607 0x0ec8 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\windows\system32\DRIVERS\termdd.sys
19:04:32.0654 0x0ec8 TermDD - ok
19:04:32.0794 0x0ec8 [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService C:\windows\System32\termsrv.dll
19:04:32.0966 0x0ec8 TermService - ok
19:04:33.0012 0x0ec8 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\windows\system32\themeservice.dll
19:04:33.0106 0x0ec8 Themes - ok
19:04:33.0153 0x0ec8 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\windows\system32\mmcss.dll
19:04:33.0246 0x0ec8 THREADORDER - ok
19:04:33.0324 0x0ec8 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\windows\System32\trkwks.dll
19:04:33.0449 0x0ec8 TrkWks - ok
19:04:33.0590 0x0ec8 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
19:04:33.0714 0x0ec8 TrustedInstaller - ok
19:04:33.0777 0x0ec8 [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
19:04:33.0855 0x0ec8 tssecsrv - ok
19:04:33.0886 0x0ec8 [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys
19:04:34.0011 0x0ec8 TsUsbFlt - ok
19:04:34.0073 0x0ec8 [ 01246F0BAAD7B68EC0F472AA41E33282, 51F975AF029AD015576FFFA3E88F5DBB8B40C7CD30ECDEDE8AFABCB08C954199 ] TsUsbGD C:\windows\system32\drivers\TsUsbGD.sys
19:04:34.0167 0x0ec8 TsUsbGD - ok
19:04:34.0214 0x0ec8 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
19:04:34.0323 0x0ec8 tunnel - ok
19:04:34.0338 0x0ec8 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\windows\system32\drivers\uagp35.sys
19:04:34.0385 0x0ec8 uagp35 - ok
19:04:34.0432 0x0ec8 [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\windows\system32\DRIVERS\udfs.sys
19:04:34.0557 0x0ec8 udfs - ok
19:04:34.0619 0x0ec8 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\windows\system32\UI0Detect.exe
19:04:34.0728 0x0ec8 UI0Detect - ok
19:04:34.0791 0x0ec8 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
19:04:34.0838 0x0ec8 uliagpkx - ok
19:04:34.0916 0x0ec8 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\windows\system32\DRIVERS\umbus.sys
19:04:34.0978 0x0ec8 umbus - ok
19:04:35.0056 0x0ec8 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\windows\system32\drivers\umpass.sys
19:04:35.0134 0x0ec8 UmPass - ok
19:04:35.0212 0x0ec8 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\windows\System32\upnphost.dll
19:04:35.0352 0x0ec8 upnphost - ok
19:04:35.0446 0x0ec8 [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
19:04:35.0555 0x0ec8 usbccgp - ok
19:04:35.0602 0x0ec8 [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\windows\system32\drivers\usbcir.sys
19:04:35.0680 0x0ec8 usbcir - ok
19:04:35.0711 0x0ec8 [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci C:\windows\system32\drivers\usbehci.sys
19:04:35.0774 0x0ec8 usbehci - ok
19:04:35.0867 0x0ec8 [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
19:04:35.0976 0x0ec8 usbhub - ok
19:04:36.0023 0x0ec8 [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci C:\windows\system32\drivers\usbohci.sys
19:04:36.0086 0x0ec8 usbohci - ok
19:04:36.0132 0x0ec8 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\windows\system32\drivers\usbprint.sys
19:04:36.0195 0x0ec8 usbprint - ok
19:04:36.0226 0x0ec8 [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
19:04:36.0351 0x0ec8 USBSTOR - ok
19:04:36.0398 0x0ec8 [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci C:\windows\system32\drivers\usbuhci.sys
19:04:36.0460 0x0ec8 usbuhci - ok
19:04:36.0522 0x0ec8 [ DE014425522610BEDCA3821BB8C0F1D5, D6FEA0DF07F89834AEEE8C02CC7FD41068D758B6CCECE2EEE5CF4B9DB646FA1E ] usbvideo C:\windows\System32\Drivers\usbvideo.sys
19:04:36.0585 0x0ec8 usbvideo - ok
19:04:36.0632 0x0ec8 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\windows\System32\uxsms.dll
19:04:36.0741 0x0ec8 UxSms - ok
19:04:36.0772 0x0ec8 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] VaultSvc C:\windows\system32\lsass.exe
19:04:36.0834 0x0ec8 VaultSvc - ok
19:04:37.0131 0x0ec8 [ EA9ADB96A31020D4D3E5167FE31427DE, 5635513F58CF89AF87B7A5CE570B348A932C5C74D3FBAF575D708198B174D641 ] VBoxAswDrv C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys
19:04:37.0193 0x0ec8 VBoxAswDrv - ok
19:04:37.0240 0x0ec8 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
19:04:37.0271 0x0ec8 vdrvroot - ok
19:04:37.0365 0x0ec8 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\windows\System32\vds.exe
19:04:37.0505 0x0ec8 vds - ok
19:04:37.0552 0x0ec8 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
19:04:37.0630 0x0ec8 vga - ok
19:04:37.0646 0x0ec8 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\windows\System32\drivers\vga.sys
19:04:37.0755 0x0ec8 VgaSave - ok
19:04:37.0786 0x0ec8 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\windows\system32\drivers\vhdmp.sys
19:04:37.0848 0x0ec8 vhdmp - ok
19:04:37.0895 0x0ec8 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\windows\system32\drivers\viaagp.sys
19:04:37.0958 0x0ec8 viaagp - ok
19:04:37.0973 0x0ec8 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\windows\system32\drivers\viac7.sys
19:04:38.0051 0x0ec8 ViaC7 - ok
19:04:38.0098 0x0ec8 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\windows\system32\drivers\viaide.sys
19:04:38.0145 0x0ec8 viaide - ok
19:04:38.0207 0x0ec8 [ C37CE43FB54066FFB540729C6E6E194E, EF96BFF5696C1BE3078B748CD08352773430C7042BE89E439EE67046E46D293B ] VideAceWindowsService C:\ExpressGateUtil\VAWinService.exe
19:04:38.0254 0x0ec8 VideAceWindowsService - ok
19:04:38.0301 0x0ec8 [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\windows\system32\drivers\volmgr.sys
19:04:38.0332 0x0ec8 volmgr - ok
19:04:38.0394 0x0ec8 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\windows\system32\drivers\volmgrx.sys
19:04:38.0457 0x0ec8 volmgrx - ok
19:04:38.0504 0x0ec8 [ C37AEE5966EB5929E2051AC7409B5730, 95701CDFCD57D3832E007BC7E6F00AA3A8080601317278EA6F0C4ADF0EF27A2C ] volsnap C:\windows\system32\drivers\volsnap.sys
19:04:38.0566 0x0ec8 volsnap - ok
19:04:38.0613 0x0ec8 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
19:04:38.0660 0x0ec8 vsmraid - ok
19:04:38.0894 0x0ec8 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\windows\system32\vssvc.exe
19:04:39.0081 0x0ec8 VSS - ok
19:04:39.0128 0x0ec8 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
19:04:39.0190 0x0ec8 vwifibus - ok
19:04:39.0237 0x0ec8 [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
19:04:39.0299 0x0ec8 vwififlt - ok
19:04:39.0424 0x0ec8 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\windows\system32\w32time.dll
19:04:39.0596 0x0ec8 W32Time - ok
19:04:39.0658 0x0ec8 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\windows\system32\drivers\wacompen.sys
19:04:39.0736 0x0ec8 WacomPen - ok
19:04:39.0814 0x0ec8 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
19:04:39.0892 0x0ec8 WANARP - ok
19:04:39.0908 0x0ec8 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
19:04:40.0001 0x0ec8 Wanarpv6 - ok
19:04:40.0220 0x0ec8 [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\windows\system32\wbengine.exe
19:04:40.0516 0x0ec8 wbengine - ok
19:04:40.0563 0x0ec8 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
19:04:40.0672 0x0ec8 WbioSrvc - ok
19:04:40.0719 0x0ec8 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\windows\System32\wcncsvc.dll
19:04:40.0844 0x0ec8 wcncsvc - ok
19:04:40.0891 0x0ec8 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
19:04:41.0047 0x0ec8 WcsPlugInService - ok
19:04:41.0093 0x0ec8 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\windows\system32\drivers\wd.sys
19:04:41.0140 0x0ec8 Wd - ok
19:04:41.0265 0x0ec8 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
19:04:41.0359 0x0ec8 Wdf01000 - ok
19:04:41.0452 0x0ec8 [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiServiceHost C:\windows\system32\wdi.dll
19:04:41.0561 0x0ec8 WdiServiceHost - ok
19:04:41.0577 0x0ec8 [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiSystemHost C:\windows\system32\wdi.dll
19:04:41.0639 0x0ec8 WdiSystemHost - ok
19:04:41.0686 0x0ec8 [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient C:\windows\System32\webclnt.dll
19:04:41.0795 0x0ec8 WebClient - ok
19:04:41.0873 0x0ec8 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\windows\system32\wecsvc.dll
19:04:41.0983 0x0ec8 Wecsvc - ok
19:04:42.0014 0x0ec8 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\windows\System32\wercplsupport.dll
19:04:42.0123 0x0ec8 wercplsupport - ok
19:04:42.0170 0x0ec8 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\windows\System32\WerSvc.dll
19:04:42.0279 0x0ec8 WerSvc - ok
19:04:42.0388 0x0ec8 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
19:04:42.0513 0x0ec8 WfpLwf - ok
19:04:42.0529 0x0ec8 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\windows\system32\drivers\wimmount.sys
19:04:42.0560 0x0ec8 WIMMount - ok
19:04:42.0809 0x0ec8 [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
19:04:43.0012 0x0ec8 WinDefend - ok
19:04:43.0106 0x0ec8 WinHttpAutoProxySvc - ok
19:04:43.0340 0x0ec8 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
19:04:43.0480 0x0ec8 Winmgmt - ok
19:04:43.0683 0x0ec8 [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM C:\windows\system32\WsmSvc.dll
19:04:43.0948 0x0ec8 WinRM - ok
19:04:44.0151 0x0ec8 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\windows\System32\wlansvc.dll
19:04:44.0307 0x0ec8 Wlansvc - ok
19:04:44.0510 0x0ec8 [ 6067ACEF367E79914AF628FA1E9B5330, 491A705267B48C103E00B26BBD21FA8829DB03A88343CBC27264CEE5DE8C8DEF ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
19:04:44.0635 0x0ec8 wlcrasvc - ok
19:04:44.0947 0x0ec8 [ FB01D4AE207B9EFDBABFC55DC95C7E31, E0EFDBBE0BAC275230C8C1A053948C21BCF20B99B92E50939E95FFB9DC87F6BA ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
19:04:45.0134 0x0ec8 wlidsvc - ok
19:04:45.0181 0x0ec8 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\windows\system32\DRIVERS\wmiacpi.sys
19:04:45.0243 0x0ec8 WmiAcpi - ok
19:04:45.0290 0x0ec8 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
19:04:45.0415 0x0ec8 wmiApSrv - ok
19:04:45.0695 0x0ec8 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
19:04:45.0929 0x0ec8 WMPNetworkSvc - ok
19:04:45.0976 0x0ec8 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\windows\System32\wpcsvc.dll
19:04:46.0117 0x0ec8 WPCSvc - ok
19:04:46.0132 0x0ec8 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
19:04:46.0288 0x0ec8 WPDBusEnum - ok
19:04:46.0335 0x0ec8 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
19:04:46.0429 0x0ec8 ws2ifsl - ok
19:04:46.0491 0x0ec8 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\windows\system32\wscsvc.dll
19:04:46.0585 0x0ec8 wscsvc - ok
19:04:46.0600 0x0ec8 WSearch - ok
19:04:46.0881 0x0ec8 [ 7E5C454A3F986FEBAD075DB8D915917E, 9E9147DDACD075958689523130DB92FC4ED0E38433461D8AB8792BCFBD9376DA ] wuauserv C:\windows\system32\wuaueng.dll
19:04:47.0177 0x0ec8 wuauserv - ok
19:04:47.0240 0x0ec8 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\windows\system32\drivers\WudfPf.sys
19:04:47.0318 0x0ec8 WudfPf - ok
19:04:47.0349 0x0ec8 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
19:04:47.0443 0x0ec8 WUDFRd - ok
19:04:47.0489 0x0ec8 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\windows\System32\WUDFSvc.dll
19:04:47.0567 0x0ec8 wudfsvc - ok
19:04:47.0661 0x0ec8 [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc C:\windows\System32\wwansvc.dll
19:04:48.0269 0x0ec8 WwanSvc - ok
19:04:48.0472 0x0ec8 ================ Scan global ===============================
19:04:48.0519 0x0ec8 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\windows\system32\basesrv.dll
19:04:48.0581 0x0ec8 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\windows\system32\winsrv.dll
19:04:48.0628 0x0ec8 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\windows\system32\winsrv.dll
19:04:48.0691 0x0ec8 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\windows\system32\sxssrv.dll
19:04:48.0753 0x0ec8 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\windows\system32\services.exe
19:04:48.0784 0x0ec8 [ Global ] - ok
19:04:48.0784 0x0ec8 ================ Scan MBR ==================================
19:04:48.0815 0x0ec8 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
19:04:50.0157 0x0ec8 \Device\Harddisk0\DR0 - ok
19:04:50.0157 0x0ec8 ================ Scan VBR ==================================
19:04:50.0188 0x0ec8 [ D0FEF344BEE318B0DC342DF14DFB5A07 ] \Device\Harddisk0\DR0\Partition1
19:04:50.0188 0x0ec8 \Device\Harddisk0\DR0\Partition1 - ok
19:04:50.0251 0x0ec8 [ 5227DB24F17502F97DBE952E1B66BC39 ] \Device\Harddisk0\DR0\Partition2
19:04:50.0266 0x0ec8 \Device\Harddisk0\DR0\Partition2 - ok
19:04:50.0266 0x0ec8 ================ Scan generic autorun ======================
19:04:50.0297 0x0ec8 [ 1B0BD45BE994B6170CA21BB5FEBBC04E, 39001CEE705E685FB2428A8B77169772A47970B9CC81109775AA6904FF85617A ] C:\windows\system32\GfxCUIServiceInstall.vbs
19:04:50.0469 0x0ec8 GfxServiceInstall - ok
19:04:50.0485 0x0ec8 HotkeyMon - ok
19:04:50.0516 0x0ec8 [ 92B464057C9EA14BF375B19368B9BEA7, 11E698FD08B20D43802076E3683A62985F535BFCF2828E710F2BF15CFB39644C ] C:\windows\system32\igfxtray.exe
19:04:50.0563 0x0ec8 IgfxTray - ok
19:04:51.0842 0x0ec8 [ D72ABA21ABB9314DA878FB9760E7A4C2, 90E3892B4070A6265CE8AB33115EEBED7D61F6FDB836B5EB1972BE7DD30E21F0 ] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
19:04:52.0840 0x0ec8 RtHDVCpl - ok
19:04:53.0137 0x0ec8 [ 4532A5E1A86501E75C1519278CDBD6B6, 6D59928DE77DE4A1BCE0DED07C173EA84B803A5DD5FFEEDA65126D410723026E ] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
19:04:53.0417 0x0ec8 SynTPEnh - ok
19:04:53.0885 0x0ec8 [ 86D3BEA2B995DCEA877D25725D77DC5E, 5C91AD24E7473D5E665A68A7CF52BDD8A795E63E864246577C6F7D4C82F1E5C1 ] C:\Program Files\ASUS\APRP\APRP.EXE
19:04:54.0307 0x0ec8 ASUSPRP - detected UnsignedFile.Multi.Generic ( 1 )
19:04:56.0881 0x0ec8 Detect skipped due to KSN trusted
19:04:56.0881 0x0ec8 ASUSPRP - ok
19:04:57.0005 0x0ec8 [ 5514B64F7F2D25E09E2FDAF5D62B688C, 43263715ADC49250762A01E41DB2832C6A8B63CE4F66CDD8FC0B51DCA031DF27 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
19:04:57.0037 0x0ec8 IAStorIcon - ok
19:04:57.0629 0x0ec8 [ 938FA6F63B210FB8EF5A7B2FC1229431, 545DDA9C32DF14B50688F8192A345FE66D2DB3F8763ECBF85B38AC829E49E1D9 ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
19:04:58.0160 0x0ec8 AvastUI.exe - ok
19:04:58.0253 0x0ec8 [ 5EC4244D6D9715FDEA45C6954CDCC30F, 19767EC303BB80996D67D771E7C4A0206F0C2D7B77FC22CB10CBE3BCAFC16178 ] C:\windows\system32\igfxpers.exe
19:04:58.0316 0x0ec8 Persistence - ok
19:04:58.0363 0x0ec8 [ 429F77AF7B473B8C7714B64AF7E9D56B, E9960C1F6326D90CDB4125F23E333E5A85FEDA462D77DC3E5E2DA9ABB6DCAB67 ] C:\windows\system32\hkcmd.exe
19:04:58.0425 0x0ec8 HotKeysCmds - ok
19:04:58.0441 0x0ec8 SuperHybridEngine - ok
19:04:58.0456 0x0ec8 LiveUpdate - ok
19:04:58.0456 0x0ec8 HotkeyService - ok
19:04:58.0456 0x0ec8 CapsHook - ok
19:04:58.0597 0x0ec8 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\sidebar.exe
19:04:58.0815 0x0ec8 Sidebar - ok
19:04:59.0704 0x0ec8 [ A75228DE9117A017BC7A3B44953B2648, 9AA3D2F883F187620612CD7CA3871187B8181ACE9EF918C31A74DBAAF2F81A60 ] C:\Program Files\CCleaner\CCleaner.exe
19:05:00.0359 0x0ec8 CCleaner Monitoring - ok
19:05:00.0391 0x0ec8 Waiting for KSN requests completion. In queue: 6
19:05:01.0405 0x0ec8 Waiting for KSN requests completion. In queue: 6
19:05:02.0419 0x0ec8 Waiting for KSN requests completion. In queue: 6
19:05:03.0526 0x0ec8 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 10.2.2214.845 ), 0x41000 ( enabled : updated )
19:05:03.0573 0x0ec8 Win FW state via NFP2: enabled
19:05:06.0069 0x0ec8 ============================================================
19:05:06.0069 0x0ec8 Scan finished
19:05:06.0069 0x0ec8 ============================================================
19:05:06.0085 0x114c Detected object count: 0
19:05:06.0085 0x114c Actual detected object count: 0

Geändert von FuG67 (20.04.2015 um 18:16 Uhr)

Alt 21.04.2015, 10:33   #7
schrauber
/// the machine
/// TB-Ausbilder
 

Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.




Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 21.04.2015, 16:34   #8
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



Hallo, soeben ist ComboFix fertig geworden. zwischendurch kam folgender Screen.



Habe Combofix aber dennoch weiter laufen lassen, da du mir ja empfohlen hattest nichts zu tun. Der Screen hat sich nach einiger Zeit wieder geschlossen. Ist das in dem Log-File ersichtlich?

Code:
ATTFilter
ComboFix 15-04-19.01 - Netbook 21.04.2015  16:49:25.3.4 - x86
Microsoft Windows 7 Starter   6.1.7601.1.1252.49.1031.18.1012.288 [GMT 2:00]
ausgeführt von:: c:\users\Netbook\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((   Dateien erstellt von 2015-03-21 bis 2015-04-21  ))))))))))))))))))))))))))))))
.
.
2015-04-21 15:11 . 2015-04-21 15:11	--------	d-----w-	c:\users\Default\AppData\Local\temp
2015-04-20 16:07 . 2015-04-20 16:45	--------	d-----w-	c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-04-19 15:25 . 2015-04-19 16:00	--------	d-----w-	C:\FRST
2015-04-19 13:23 . 2015-03-23 03:06	576000	----a-w-	c:\windows\system32\generaltel.dll
2015-04-19 13:23 . 2015-03-23 03:06	630784	----a-w-	c:\windows\system32\invagent.dll
2015-04-19 13:23 . 2015-03-23 03:06	331264	----a-w-	c:\windows\system32\devinv.dll
2015-04-19 13:23 . 2015-03-23 03:06	26112	----a-w-	c:\windows\system32\acmigration.dll
2015-04-19 13:23 . 2015-03-23 03:06	159744	----a-w-	c:\windows\system32\aepic.dll
2015-04-19 13:23 . 2015-03-23 02:59	896000	----a-w-	c:\windows\system32\aeinv.dll
2015-04-19 13:23 . 2015-03-23 03:06	202752	----a-w-	c:\windows\system32\aepdu.dll
2015-04-18 11:18 . 2015-04-18 11:18	--------	d-----w-	C:\RegBackup
2015-04-18 10:59 . 2015-01-31 03:33	2744320	----a-w-	c:\windows\system32\rdpcorets.dll
2015-04-18 10:59 . 2015-01-31 03:33	13824	----a-w-	c:\windows\system32\RdpGroupPolicyExtension.dll
2015-04-18 10:59 . 2015-01-31 00:48	221184	----a-w-	c:\windows\system32\rdpudd.dll
2015-04-18 10:56 . 2015-04-19 15:13	--------	d-----w-	C:\AdwCleaner
2015-04-18 07:58 . 2015-04-18 07:58	73440	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys
2015-04-18 07:58 . 2015-04-18 07:58	49904	----a-w-	c:\windows\system32\drivers\aswRvrt.sys
2015-04-18 07:58 . 2015-04-18 07:58	427480	----a-w-	c:\windows\system32\drivers\aswSP.sys
2015-04-18 07:58 . 2015-04-18 07:58	206976	----a-w-	c:\windows\system32\drivers\aswVmm.sys
2015-04-18 07:58 . 2015-04-18 07:58	106912	----a-w-	c:\windows\system32\drivers\aswStm.sys
2015-04-18 07:58 . 2015-04-18 07:58	81728	----a-w-	c:\windows\system32\drivers\aswRdr2.sys
2015-04-18 07:58 . 2015-04-18 07:58	24144	----a-w-	c:\windows\system32\drivers\aswHwid.sys
2015-04-18 07:58 . 2015-04-18 07:58	788272	----a-w-	c:\windows\system32\drivers\aswSnx.sys
2015-04-18 07:58 . 2015-04-18 07:58	291312	----a-w-	c:\windows\system32\aswBoot.exe
2015-04-18 07:58 . 2015-04-18 07:58	43112	----a-w-	c:\windows\avastSS.scr
2015-04-18 07:56 . 2015-04-18 07:56	--------	d-----w-	c:\program files\AVAST Software
2015-04-17 19:44 . 2015-04-17 19:44	--------	d-----w-	c:\program files\Common Files\Intel Corporation
2015-04-17 19:27 . 2012-02-01 14:06	470808	----a-w-	c:\windows\system32\drivers\iaStor.sys
2015-04-17 18:50 . 2000-01-01 00:00	109256	----a-w-	c:\windows\system32\drivers\L1C62x86.sys
2015-04-17 18:49 . 2015-04-17 18:49	--------	d-----w-	c:\programdata\SlimWare Utilities, Inc
2015-04-17 18:44 . 2015-04-17 19:20	13368	----a-w-	c:\windows\system32\drivers\SWDUMon.sys
2015-04-17 18:44 . 2015-04-17 18:44	--------	d-----w-	c:\program files\SlimDrivers
2015-04-17 18:10 . 2015-04-17 18:10	16896	----a-w-	c:\windows\AsTaskSched.dll
2015-04-17 17:45 . 2015-04-19 13:45	62576	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{08600286-887A-47F7-9116-60DE16C8D51A}\offreg.dll
2015-04-17 17:19 . 2015-03-04 04:16	249784	----a-w-	c:\windows\system32\clfs.sys
2015-04-17 17:18 . 2015-03-17 04:53	146432	----a-w-	c:\windows\system32\msaudite.dll
2015-04-17 17:18 . 2015-03-17 04:53	60416	----a-w-	c:\windows\system32\msobjs.dll
2015-04-17 16:39 . 2003-09-03 00:27	69715	----a-w-	c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2015-04-17 16:39 . 2003-09-03 00:26	266240	----a-w-	c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2015-04-17 16:39 . 2003-09-03 00:26	192512	----a-w-	c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2015-04-17 16:39 . 2003-09-03 00:25	5632	----a-w-	c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2015-04-17 16:39 . 2003-09-03 00:28	724992	----a-w-	c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2015-04-17 16:39 . 2015-04-17 16:39	184452	----a-w-	c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2015-04-17 16:39 . 2015-04-17 16:39	311428	----a-w-	c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2015-04-17 16:07 . 2014-06-27 01:45	2285056	----a-w-	c:\windows\system32\msmpeg2vdec.dll
2015-04-11 20:47 . 2012-02-11 05:37	317440	----a-w-	c:\windows\system32\spoolsv.exe
2015-04-11 20:41 . 2014-12-11 17:47	74240	----a-w-	c:\windows\system32\TSWbPrxy.exe
2015-04-11 20:20 . 2014-06-24 02:59	1987584	----a-w-	c:\windows\system32\d3d10warp.dll
2015-04-11 20:20 . 2015-02-26 03:11	2381312	----a-w-	c:\windows\system32\win32k.sys
2015-04-11 20:19 . 2014-07-09 01:29	6144	----a-w-	c:\windows\system32\KBDYAK.DLL
2015-04-11 20:19 . 2014-07-09 01:29	6144	----a-w-	c:\windows\system32\KBDBASH.DLL
2015-04-11 20:19 . 2014-09-05 01:52	5703168	----a-w-	c:\windows\system32\mstscax.dll
2015-04-11 20:16 . 2015-02-24 02:23	246920	------w-	c:\windows\system32\MpSigStub.exe
2015-04-04 18:26 . 2015-04-04 18:26	--------	d-----w-	c:\program files\Adblock Plus for IE
2015-04-04 15:45 . 2015-02-03 03:12	1230848	----a-w-	c:\windows\system32\WindowsCodecs.dll
2015-04-04 15:44 . 2015-02-04 02:54	417792	----a-w-	c:\windows\system32\WMPhoto.dll
2015-04-04 15:43 . 2012-08-23 14:44	14848	----a-w-	c:\windows\system32\drivers\rdpvideominiport.sys
2015-04-04 15:42 . 2012-08-23 11:12	192000	----a-w-	c:\windows\system32\rdpendp_winip.dll
2015-04-04 14:32 . 2015-04-04 14:32	4096	---ha-w-	c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-04-04 14:07 . 2015-04-04 14:13	--------	d-s---w-	c:\windows\system32\GWX
2015-04-04 12:56 . 2015-04-19 13:50	--------	d-----w-	c:\windows\system32\MRT
2015-04-04 11:37 . 2012-07-26 02:33	66560	----a-w-	c:\windows\system32\drivers\WUDFPf.sys
2015-04-04 11:37 . 2012-07-26 02:32	155136	----a-w-	c:\windows\system32\drivers\WUDFRd.sys
2015-04-04 11:37 . 2012-07-26 03:20	73216	----a-w-	c:\windows\system32\WUDFSvc.dll
2015-04-04 11:37 . 2012-07-26 03:20	172032	----a-w-	c:\windows\system32\WUDFPlatform.dll
2015-04-04 11:37 . 2012-07-26 03:21	196608	----a-w-	c:\windows\system32\WUDFHost.exe
2015-04-04 11:37 . 2012-07-26 03:20	613888	----a-w-	c:\windows\system32\WUDFx.dll
2015-04-04 11:37 . 2012-07-26 03:20	38912	----a-w-	c:\windows\system32\WUDFCoinstaller.dll
2015-04-04 11:33 . 2014-03-09 21:47	99480	----a-w-	c:\windows\system32\infocardapi.dll
2015-04-04 11:33 . 2014-06-30 22:14	8856	----a-w-	c:\windows\system32\icardres.dll
2015-04-04 11:33 . 2014-03-09 21:47	619672	----a-w-	c:\windows\system32\icardagt.exe
2015-04-04 11:33 . 2014-06-06 06:16	35480	----a-w-	c:\windows\system32\TsWpfWrp.exe
2015-04-04 11:09 . 2015-04-04 11:09	--------	d-----w-	c:\windows\Migration
2015-04-04 10:25 . 2013-10-01 23:45	32256	----a-w-	c:\windows\system32\TsUsbGDCoInstaller.dll
2015-04-04 10:25 . 2013-10-02 00:32	12800	----a-w-	c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-04-04 10:25 . 2013-10-02 00:42	49152	----a-w-	c:\windows\system32\drivers\TsUsbFlt.sys
2015-04-04 10:25 . 2013-10-02 00:30	14336	----a-w-	c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-04-04 10:25 . 2013-10-02 00:14	50176	----a-w-	c:\windows\system32\MsRdpWebAccess.dll
2015-04-04 10:25 . 2013-10-02 00:14	17920	----a-w-	c:\windows\system32\wksprtPS.dll
2015-04-04 10:25 . 2013-10-01 23:58	53248	----a-w-	c:\windows\system32\tsgqec.dll
2015-04-04 10:25 . 2013-10-01 23:08	855552	----a-w-	c:\windows\system32\rdvidcrl.dll
2015-04-04 10:25 . 2013-10-01 22:53	350208	----a-w-	c:\windows\system32\wksprt.exe
2015-04-04 10:25 . 2013-10-01 22:34	1068544	----a-w-	c:\windows\system32\mstsc.exe
2015-04-04 09:40 . 2014-02-04 02:07	149440	----a-w-	c:\windows\system32\drivers\storport.sys
2015-04-04 09:40 . 2014-02-04 02:07	234432	----a-w-	c:\windows\system32\drivers\msiscsi.sys
2015-04-04 09:40 . 2014-02-04 02:07	27072	----a-w-	c:\windows\system32\drivers\Diskdump.sys
2015-04-04 09:40 . 2014-02-04 02:00	2048	----a-w-	c:\windows\system32\iologmsg.dll
2015-04-04 08:43 . 2015-04-19 13:54	--------	d-s---w-	c:\windows\system32\CompatTel
2015-04-04 08:43 . 2015-04-19 13:54	--------	d-----w-	c:\windows\system32\appraiser
2015-04-04 03:40 . 2014-03-04 09:17	293376	----a-w-	c:\windows\system32\KernelBase.dll
2015-04-04 03:40 . 2014-03-04 09:17	538112	----a-w-	c:\windows\system32\objsel.dll
2015-04-04 03:40 . 2014-03-04 09:17	47616	----a-w-	c:\windows\system32\dpapiprovider.dll
2015-04-04 03:40 . 2014-03-04 09:17	36864	----a-w-	c:\windows\system32\dimsroam.dll
2015-04-04 03:40 . 2014-03-04 09:17	51200	----a-w-	c:\windows\system32\cngprovider.dll
2015-04-04 03:40 . 2014-03-04 09:17	48128	----a-w-	c:\windows\system32\capiprovider.dll
2015-04-04 03:40 . 2014-03-04 09:17	49664	----a-w-	c:\windows\system32\adprovider.dll
2015-04-04 03:40 . 2014-03-04 09:17	35328	----a-w-	c:\windows\system32\wincredprovider.dll
2015-04-04 03:36 . 2015-02-03 03:12	50688	----a-w-	c:\windows\system32\appidapi.dll
2015-04-04 03:34 . 2012-12-07 10:46	43520	----a-w-	c:\windows\system32\csrr.rs
2015-04-04 03:33 . 2014-07-17 01:39	304128	----a-w-	c:\windows\system32\winlogon.exe
2015-04-04 03:33 . 2014-07-17 01:40	157696	----a-w-	c:\windows\system32\winsta.dll
2015-04-04 03:33 . 2014-07-17 01:39	130048	----a-w-	c:\windows\system32\rdpcorekmts.dll
2015-04-04 03:33 . 2014-07-17 01:03	184320	----a-w-	c:\windows\system32\drivers\rdpwd.sys
2015-04-04 03:33 . 2014-07-17 01:02	31232	----a-w-	c:\windows\system32\drivers\tssecsrv.sys
2015-04-04 03:28 . 2014-10-14 01:50	2363904	----a-w-	c:\windows\system32\msi.dll
2015-04-04 03:27 . 2012-10-03 16:42	175104	----a-w-	c:\windows\system32\netcorehc.dll
2015-04-04 03:27 . 2012-10-03 16:40	499712	----a-w-	c:\windows\system32\iphlpsvc.dll
2015-04-04 03:27 . 2012-10-03 15:21	35328	----a-w-	c:\windows\system32\drivers\tcpipreg.sys
2015-04-04 03:27 . 2012-10-03 16:42	18944	----a-w-	c:\windows\system32\netevent.dll
2015-04-04 03:24 . 2013-10-04 01:58	152576	----a-w-	c:\windows\system32\SmartcardCredentialProvider.dll
2015-04-04 03:24 . 2013-10-04 01:56	168960	----a-w-	c:\windows\system32\credui.dll
2015-04-04 03:22 . 2014-07-14 01:42	654336	----a-w-	c:\windows\system32\rpcrt4.dll
2015-04-04 03:22 . 2012-11-23 02:48	49152	----a-w-	c:\windows\system32\taskhost.exe
2015-04-04 03:22 . 2014-05-30 06:36	338944	----a-w-	c:\windows\system32\drivers\afd.sys
2015-04-04 03:22 . 2012-11-02 05:11	376832	----a-w-	c:\windows\system32\dpnet.dll
2015-04-04 03:22 . 2014-06-16 01:44	730048	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys
2015-04-04 03:22 . 2014-06-16 01:44	219072	----a-w-	c:\windows\system32\drivers\dxgmms1.sys
2015-04-04 03:22 . 2014-06-16 01:40	107520	----a-w-	c:\windows\system32\cdd.dll
2015-04-04 03:22 . 2014-06-03 09:30	101824	----a-w-	c:\windows\system32\consent.exe
2015-04-04 03:22 . 2014-06-03 09:29	1805824	----a-w-	c:\windows\system32\authui.dll
2015-04-04 03:22 . 2014-06-03 09:29	337408	----a-w-	c:\windows\system32\msihnd.dll
2015-04-04 03:21 . 2013-05-27 04:57	680960	----a-w-	c:\program files\Windows Defender\MpSvc.dll
2015-04-04 03:21 . 2013-05-27 04:57	392704	----a-w-	c:\program files\Windows Defender\MpClient.dll
2015-04-04 03:21 . 2013-05-27 04:57	224768	----a-w-	c:\program files\Windows Defender\MpCommu.dll
2015-04-04 03:21 . 2014-06-18 22:23	156824	----a-w-	c:\windows\system32\mscorier.dll
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-04-17 17:51 . 2012-08-14 07:35	53248	----a-w-	c:\windows\system32\CSVer.dll
2015-04-01 10:37 . 2011-03-29 01:36	23256	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2015-02-04 10:23 . 2015-02-04 10:23	875688	----a-w-	c:\windows\system32\msvcr120_clr0400.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-04-18 07:58	644608	----a-w-	c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2015-03-13 5529880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GfxServiceInstall"="c:\windows\system32\GfxCUIServiceInstall.vbs" [2012-06-27 131]
"HotkeyMon"="AsusSender.exe" [2012-01-05 34728]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-07-04 142144]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2014-12-11 12111576]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-05-05 2262312]
"ASUSPRP"="c:\program files\ASUS\APRP\APRP.EXE" [2012-08-14 3331312]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-04-19 5511352]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-07-04 168256]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-07-04 175936]
"SuperHybridEngine"="AsusSender.exe" [2012-01-05 34728]
"LiveUpdate"="AsusSender.exe" [2012-01-05 34728]
"HotkeyService"="AsusSender.exe" [2012-01-05 34728]
"CapsHook"="AsusSender.exe" [2012-01-05 34728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eee Docking]
2011-07-14 02:53	417456	----a-w-	c:\program files\Asus\Eee Docking\Eee Docking.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAWinAgent]
2012-01-12 23:26	45448	----a-w-	c:\expressgateutil\VAWinAgent.exe
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2015-04-18 106912]
R2 MBAMService;MBAMService;c:\program files\ Malwarebytes Anti-Malware \mbamservice.exe [2015-03-17 1080120]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-03-13 102912]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-03-17 51928]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [2015-04-17 13368]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-08-03 11832]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2015-04-18 788272]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2015-04-18 427480]
S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files\ASUS\InstantOn for EPC\InsOnSrv.exe [2011-12-01 92800]
S2 AsusService;Asus Launcher Service;c:\windows\system32\AsusService.exe [2012-01-11 224680]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2015-04-18 24144]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2015-04-18 73440]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-02-01 13592]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService.exe [2014-12-11 252632]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-04-18 220240]
S2 VideAceWindowsService;VideAceWindowsService;c:\expressgateutil\VAWinService.exe [2011-03-26 91464]
S3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-04-18 3205216]
S3 igddim32;igddim32;c:\windows\system32\DRIVERS\igddim32.sys [2012-06-27 1349120]
S3 igdkmd32;igdkmd32;c:\windows\system32\DRIVERS\igdkmd32.sys [2012-06-27 435200]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-06-09 278528]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2000-01-01 109256]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-03-17 23256]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation	REG_MULTI_SZ   	SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
TCP: DhcpNameServer = 192.168.178.1
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2015-04-21  17:18:53
ComboFix-quarantined-files.txt  2015-04-21 15:18
ComboFix2.txt  2015-04-18 12:21
.
Vor Suchlauf: 14 Verzeichnis(se), 60.756.357.120 Bytes frei
Nach Suchlauf: 15 Verzeichnis(se), 60.850.249.728 Bytes frei
.
- - End Of File - - A530995A90FEE933AF2F89E529BCD84D
A36C5E4F47E84449FF07ED3517B43A31
         

Alt 22.04.2015, 08:40   #9
schrauber
/// the machine
/// TB-Ausbilder
 

Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



passt schon


Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 22.04.2015, 12:47   #10
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



MBAM

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 22.04.2015
Suchlauf-Zeit: 12:25:13
Logdatei: mbam.txt
Administrator: Ja

Version: 2.01.4.1018
Malware Datenbank: v2015.04.22.02
Rootkit Datenbank: v2015.04.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Netbook

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 305257
Verstrichene Zeit: 41 Min, 23 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente gefunden)

Module: 0
(Keine schädliche Elemente gefunden)

Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)

Registrierungswerte: 0
(Keine schädliche Elemente gefunden)

Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)

Ordner: 0
(Keine schädliche Elemente gefunden)

Dateien: 0
(Keine schädliche Elemente gefunden)

Physische Sektoren: 0
(Keine schädliche Elemente gefunden)


(end)
         
AdwCleaner

Code:
ATTFilter
# AdwCleaner v4.201 - Bericht erstellt 22/04/2015 um 13:14:52
# Aktualisiert 08/04/2015 von Xplode
# Datenbank : 2015-04-21.3 [Server]
# Betriebssystem : Windows 7 Starter Service Pack 1 (x86)
# Benutzername : Netbook - NETBOOK-PC
# Gestarted von : C:\Users\Netbook\Desktop\AdwCleaner_4.201.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17728


*************************

AdwCleaner[R0].txt - [780 Bytes] - [18/04/2015 12:56:31]
AdwCleaner[R1].txt - [867 Bytes] - [19/04/2015 17:10:31]
AdwCleaner[R2].txt - [983 Bytes] - [22/04/2015 13:11:57]
AdwCleaner[S0].txt - [838 Bytes] - [18/04/2015 13:01:09]
AdwCleaner[S1].txt - [925 Bytes] - [19/04/2015 17:13:13]
AdwCleaner[S2].txt - [904 Bytes] - [22/04/2015 13:14:52]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [962  Bytes] ##########
         
JRT

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.0 (04.20.2015:1)
OS: Windows 7 Starter x86
Ran by Netbook on 22.04.2015 at 13:20:08,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Netbook\appdata\local\{560B0DC8-A9BA-4344-A9CA-6D93BA526199}





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.04.2015 at 13:26:42,20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
FRST


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by Netbook (administrator) on NETBOOK-PC on 22-04-2015 13:32:11
Running from C:\Users\Netbook\Desktop
Loaded Profiles: Netbook (Available profiles: Netbook)
Platform: Microsoft Windows 7 Starter  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE.EXE
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [GfxServiceInstall] => C:\windows\system32\GfxCUIServiceInstall.vbs [131 2012-06-27] ()
HKLM\...\Run: [HotkeyMon] => C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe [101800 2012-01-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12111576 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2262312 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [3331312 2012-08-14] (ASUSTek Computer Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-04-19] (Avast Software s.r.o.)
HKLM\...\Run: [SuperHybridEngine] => C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [426424 2012-02-10] (ASUSTeK Computer Inc.)
HKLM\...\Run: [LiveUpdate] => C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2012-01-05] (AsusTek Computer Inc.)
HKLM\...\Run: [HotkeyService] => C:\Program Files\ASUS\HotkeyService\HotkeyService.exe [1263024 2012-01-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [CapsHook] => C:\Program Files\ASUS\CapsHook\CapsHook.exe [445344 2010-11-15] (ASUS)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll [2012-06-27] (Intel Corporation)
HKU\S-1-5-21-309674158-46085917-1021320157-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5529880 2015-03-13] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-18] (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-309674158-46085917-1021320157-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-309674158-46085917-1021320157-1000 -> {E01C9CA2-DE19-4358-8456-44D35AABB4AC} URL = https://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-18] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-12-16] (Adblock Plus)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-18]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-18]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 ASUS InstantOn; C:\Program Files\ASUS\InstantOn for EPC\InsOnSrv.exe [92800 2011-12-01] (ASUS)
S2 AsusService; C:\windows\system32\AsusService.exe [224680 2012-01-11] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-18] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-04-18] (Avast Software)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [252632 2014-12-11] (Realtek Semiconductor)
S2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [91464 2011-03-26] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\windows\System32\drivers\AsIO.sys [11456 2010-06-28] ()
R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2010-08-03] ()
R2 aswHwid; C:\windows\system32\drivers\aswHwid.sys [24144 2015-04-18] ()
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [73440 2015-04-18] (Avast Software s.r.o.)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81728 2015-04-18] (Avast Software s.r.o.)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49904 2015-04-18] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [788272 2015-04-18] (Avast Software s.r.o.)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [427480 2015-04-18] (Avast Software s.r.o.)
S2 aswStm; C:\windows\system32\drivers\aswStm.sys [106912 2015-04-18] (Avast Software s.r.o.)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [206976 2015-04-18] ()
R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R3 L1C; C:\windows\System32\DRIVERS\L1C62x86.sys [109256 2000-01-01] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [13368 2015-04-17] (SlimWare Utilities, Inc.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-04-18] (Avast Software)
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Netbook\AppData\Local\Temp\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-22 13:32 - 2015-04-22 13:34 - 00009701 _____ () C:\Users\Netbook\Desktop\FRST.txt
2015-04-22 13:31 - 2015-04-22 13:31 - 01139200 _____ (Farbar) C:\Users\Netbook\Desktop\FRST.exe
2015-04-22 13:26 - 2015-04-22 13:26 - 00000707 _____ () C:\Users\Netbook\Desktop\JRT.txt
2015-04-22 13:10 - 2015-04-22 13:10 - 00001213 _____ () C:\Users\Netbook\Desktop\mbam.txt
2015-04-22 12:24 - 2015-04-22 13:19 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-22 12:24 - 2015-04-22 12:24 - 00001056 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-04-22 12:24 - 2015-04-22 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-22 12:24 - 2015-04-22 12:24 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-04-22 12:24 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-04-22 12:24 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-04-22 12:24 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-04-22 12:21 - 2015-04-22 12:21 - 02685507 _____ (Thisisu) C:\Users\Netbook\Desktop\JRT.exe
2015-04-22 12:20 - 2015-04-22 12:20 - 02217984 _____ () C:\Users\Netbook\Desktop\AdwCleaner_4.201.exe
2015-04-21 17:54 - 2015-04-21 17:54 - 00000000 ___SD () C:\ComboFix
2015-04-21 17:37 - 2015-04-22 13:16 - 00000912 _____ () C:\windows\PFRO.log
2015-04-21 17:18 - 2015-04-21 17:18 - 00018369 _____ () C:\ComboFix.txt
2015-04-21 16:35 - 2015-04-21 16:35 - 05619466 ____R (Swearware) C:\Users\Netbook\Desktop\ComboFix.exe
2015-04-20 19:01 - 2015-04-20 19:01 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Netbook\Desktop\tdsskiller.exe
2015-04-20 18:07 - 2015-04-20 18:45 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-20 18:04 - 2015-04-20 18:45 - 00000000 ____D () C:\Users\Netbook\Desktop\mbar
2015-04-20 02:41 - 2015-04-22 13:16 - 00000504 _____ () C:\windows\setupact.log
2015-04-20 02:41 - 2015-04-20 02:41 - 00000000 _____ () C:\windows\setuperr.log
2015-04-19 17:59 - 2015-04-19 18:00 - 00021567 _____ () C:\Users\Netbook\Desktop\Addition.txt
2015-04-19 17:25 - 2015-04-22 13:32 - 00000000 ____D () C:\FRST
2015-04-19 15:23 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-04-19 15:23 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-04-18 13:30 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2015-04-18 13:30 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2015-04-18 13:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2015-04-18 13:29 - 2015-04-21 17:54 - 00000000 ____D () C:\Qoobox
2015-04-18 13:28 - 2015-04-18 14:16 - 00000000 ____D () C:\windows\erdnt
2015-04-18 13:18 - 2015-04-18 13:18 - 00000207 _____ () C:\windows\tweaking.com-regbackup-NETBOOK-PC-Windows-7-Starter-(32-bit).dat
2015-04-18 13:18 - 2015-04-18 13:18 - 00000000 ____D () C:\RegBackup
2015-04-18 12:59 - 2015-01-31 05:33 - 02744320 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-04-18 12:59 - 2015-01-31 05:33 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2015-04-18 12:59 - 2015-01-31 02:48 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2015-04-18 12:56 - 2015-04-22 13:14 - 00000000 ____D () C:\AdwCleaner
2015-04-18 10:00 - 2015-04-18 10:00 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\AVAST Software
2015-04-18 09:59 - 2015-04-18 09:59 - 00002071 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-04-18 09:59 - 2015-04-18 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-04-18 09:58 - 2015-04-18 09:58 - 00788272 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswSnx.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00427480 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswSP.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00291312 _____ (Avast Software s.r.o.) C:\windows\system32\aswBoot.exe
2015-04-18 09:58 - 2015-04-18 09:58 - 00206976 _____ () C:\windows\system32\Drivers\aswVmm.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00106912 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswStm.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00081728 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswRdr2.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00073440 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswMonFlt.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00049904 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00043112 _____ (Avast Software s.r.o.) C:\windows\avastSS.scr
2015-04-18 09:58 - 2015-04-18 09:58 - 00024144 _____ () C:\windows\system32\Drivers\aswHwid.sys
2015-04-18 09:56 - 2015-04-18 09:56 - 00000000 ____D () C:\Program Files\AVAST Software
2015-04-17 21:44 - 2015-04-17 21:44 - 00000000 ____D () C:\Program Files\Common Files\Intel Corporation
2015-04-17 21:43 - 2015-04-17 21:43 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Intel Corporation
2015-04-17 21:27 - 2012-02-01 16:06 - 00470808 _____ (Intel Corporation) C:\windows\system32\Drivers\iaStor.sys
2015-04-17 20:50 - 2000-01-01 02:00 - 00109256 _____ (Qualcomm Atheros Co., Ltd.) C:\windows\system32\Drivers\L1C62x86.sys
2015-04-17 20:49 - 2015-04-17 20:49 - 00000000 ____D () C:\ProgramData\SlimWare Utilities, Inc
2015-04-17 20:44 - 2015-04-17 21:20 - 00013368 _____ (SlimWare Utilities, Inc.) C:\windows\system32\Drivers\SWDUMon.sys
2015-04-17 20:44 - 2015-04-17 20:44 - 00002455 _____ () C:\Users\Public\Desktop\SlimDrivers.lnk
2015-04-17 20:44 - 2015-04-17 20:44 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2015-04-17 20:44 - 2015-04-17 20:44 - 00000000 ____D () C:\Users\Netbook\AppData\Local\SlimWare Utilities Inc
2015-04-17 20:10 - 2015-04-17 20:10 - 00016896 _____ (ASUS) C:\windows\AsTaskSched.dll
2015-04-17 20:07 - 2015-04-17 20:07 - 00000000 __RSH () C:\MSDOS.SYS
2015-04-17 20:07 - 2015-04-17 20:07 - 00000000 __RSH () C:\IO.SYS
2015-04-17 19:21 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-04-17 19:21 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-04-17 19:21 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-04-17 19:21 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-04-17 19:21 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-04-17 19:21 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-04-17 19:21 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-04-17 19:21 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-04-17 19:21 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-04-17 19:21 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-04-17 19:21 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-04-17 19:21 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-04-17 19:21 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-04-17 19:21 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-04-17 19:21 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-04-17 19:21 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-04-17 19:21 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-04-17 19:21 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-04-17 19:21 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-04-17 19:21 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-04-17 19:21 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-04-17 19:21 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-04-17 19:21 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-04-17 19:21 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-04-17 19:21 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-04-17 19:21 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-04-17 19:21 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-04-17 19:21 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-04-17 19:21 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-04-17 19:21 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-04-17 19:21 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-04-17 19:19 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2015-04-17 19:19 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-04-17 19:19 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-04-17 19:19 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-04-17 19:19 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-04-17 19:19 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-04-17 19:19 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-04-17 19:19 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-04-17 19:19 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-04-17 19:19 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-04-17 19:19 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-04-17 19:19 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2015-04-17 19:19 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-04-17 19:18 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-04-17 19:18 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-04-17 19:17 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-04-17 19:17 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-04-17 19:17 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-04-17 19:17 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-04-17 19:17 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2015-04-17 18:40 - 2015-04-17 19:23 - 00000157 _____ () C:\AsusUpdate.log
2015-04-17 18:13 - 2015-04-17 20:09 - 00001769 _____ () C:\windows\Language_trs.ini
2015-04-17 18:07 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2015-04-17 18:01 - 2015-04-17 18:01 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Easeware
2015-04-11 22:47 - 2012-02-11 07:37 - 00317440 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2015-04-11 22:41 - 2014-12-11 19:47 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-04-11 22:20 - 2015-02-26 05:11 - 02381312 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-04-11 22:20 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-04-11 22:19 - 2014-09-05 03:52 - 05703168 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2015-04-11 22:16 - 2015-02-24 04:23 - 00246920 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-04-04 20:26 - 2015-04-04 20:26 - 00000000 ____D () C:\Program Files\Adblock Plus for IE
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieUserList
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieSiteList
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieBrowserModeList
2015-04-04 17:45 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-04-04 17:44 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-04-04 17:43 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2015-04-04 17:42 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00645120 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2015-04-04 16:34 - 2015-04-04 16:34 - 00610304 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00233472 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00208384 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00151552 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00127488 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00083456 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-04-04 16:34 - 2015-04-04 16:34 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2015-04-04 16:32 - 2015-04-04 16:32 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 01158144 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 01080832 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00906240 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00604160 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00364544 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00207872 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00187392 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00161792 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-04-04 16:07 - 2015-04-04 16:13 - 00000000 ___SD () C:\windows\system32\GWX
2015-04-04 14:56 - 2015-04-19 15:50 - 00000000 ____D () C:\windows\system32\MRT
2015-04-04 14:55 - 2015-04-19 15:34 - 125832184 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-04-04 14:26 - 2015-01-09 01:44 - 00419936 _____ () C:\windows\system32\locale.nls
2015-04-04 13:37 - 2012-07-26 05:21 - 00196608 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe
2015-04-04 13:37 - 2012-07-26 05:20 - 00613888 _____ (Microsoft Corporation) C:\windows\system32\WUDFx.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\WUDFCoinstaller.dll
2015-04-04 13:37 - 2012-07-26 04:33 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys
2015-04-04 13:37 - 2012-07-26 04:32 - 00155136 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys
2015-04-04 13:37 - 2012-06-02 16:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-04-04 13:33 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll
2015-04-04 13:33 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2015-04-04 13:33 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe
2015-04-04 13:33 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll
2015-04-04 12:25 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2015-04-04 12:25 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-04-04 12:25 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-04-04 12:25 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2015-04-04 12:25 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2015-04-04 12:25 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-04-04 12:25 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2015-04-04 12:25 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-04-04 12:25 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-04-04 12:25 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2015-04-04 11:43 - 2015-04-19 23:04 - 00007608 _____ () C:\Users\Netbook\AppData\Local\Resmon.ResmonCfg
2015-04-04 11:40 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2015-04-04 11:40 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2015-04-04 11:40 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2015-04-04 11:40 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2015-04-04 10:43 - 2015-04-19 15:54 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-04-04 10:43 - 2015-04-19 15:54 - 00000000 ____D () C:\windows\system32\appraiser
2015-04-04 05:40 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2015-04-04 05:37 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-04-04 05:37 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2015-04-04 05:37 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2015-04-04 05:37 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-04-04 05:37 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2015-04-04 05:37 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2015-04-04 05:37 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2015-04-04 05:36 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2015-04-04 05:36 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-04-04 05:36 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2015-04-04 05:36 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2015-04-04 05:36 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-04-04 05:36 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2015-04-04 05:34 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
2015-04-04 05:34 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\windows\system32\gameux.dll
2015-04-04 05:34 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\windows\system32\cero.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\windows\system32\esrb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\windows\system32\fpb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\windows\system32\oflc-nz.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\windows\system32\pegibbfc.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\windows\system32\csrr.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\windows\system32\cob-au.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\windows\system32\usk.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\windows\system32\oflc.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\windows\system32\grb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-pt.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-fi.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\windows\system32\djctq.rs
2015-04-04 05:33 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2015-04-04 05:33 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2015-04-04 05:33 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2015-04-04 05:33 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2015-04-04 05:33 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2015-04-04 05:28 - 2014-10-14 03:50 - 02363904 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-04-04 05:27 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\netcorehc.dll
2015-04-04 05:27 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\netevent.dll
2015-04-04 05:27 - 2012-10-03 18:40 - 00499712 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2015-04-04 05:27 - 2012-10-03 17:21 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2015-04-04 05:24 - 2013-10-04 03:58 - 00152576 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2015-04-04 05:24 - 2013-10-04 03:56 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2015-04-04 05:22 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-04-04 05:22 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2015-04-04 05:22 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2015-04-04 05:22 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2015-04-04 05:22 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-04-04 05:22 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-04-04 05:22 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2015-04-04 05:22 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-04-04 05:22 - 2012-11-23 04:48 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2015-04-04 05:22 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\windows\system32\dpnet.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2015-04-04 05:20 - 2014-12-06 05:50 - 00242688 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-04-04 05:20 - 2014-11-11 04:44 - 00186880 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2015-04-04 05:20 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2015-04-04 05:20 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2015-04-04 05:20 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2015-04-04 05:20 - 2012-10-03 18:42 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2015-04-04 05:19 - 2014-08-12 03:36 - 00701440 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2015-04-04 05:19 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2015-04-04 05:19 - 2013-07-03 05:36 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2015-04-04 05:19 - 2013-07-03 05:36 - 00025728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2015-04-04 05:19 - 2012-08-21 22:12 - 00245760 _____ (Microsoft Corporation) C:\windows\system32\OxpsConverter.exe
2015-04-04 05:19 - 2012-07-06 21:23 - 00393728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
2015-04-04 05:18 - 2014-11-08 04:45 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-04-04 05:18 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-04-04 05:18 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-04-04 05:17 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-04-04 05:17 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-04-04 05:17 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-04 05:17 - 2013-02-12 05:32 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-04-04 05:17 - 2013-01-24 06:47 - 00196328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2015-04-04 05:16 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2015-04-04 05:16 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2015-04-04 05:16 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2015-04-04 05:16 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2015-04-04 05:16 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2015-04-04 05:15 - 2014-12-19 04:43 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-04-04 05:12 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-04-04 05:12 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2015-04-04 05:12 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2015-04-04 05:11 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2015-04-04 05:11 - 2014-10-30 03:45 - 00155136 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2015-04-04 05:11 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2015-04-04 05:11 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2015-04-04 05:11 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2015-04-04 05:11 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-04-04 05:11 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-04-04 05:11 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-04-04 05:11 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2015-04-04 05:10 - 2014-10-25 03:32 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2015-04-04 05:10 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\netapi32.dll
2015-04-04 05:10 - 2012-07-04 23:14 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\browser.dll
2015-04-04 05:10 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\browcli.dll
2015-04-04 05:09 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-04-04 05:09 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2015-04-04 05:08 - 2013-06-26 00:56 - 00527064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2015-04-04 05:08 - 2012-11-29 00:57 - 00047720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2015-04-04 05:08 - 2012-11-29 00:57 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\Wdfres.dll
2015-04-04 05:08 - 2012-11-29 00:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-04-04 05:07 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-04-04 05:07 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2015-04-04 05:07 - 2014-12-19 03:34 - 00116224 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-04-04 05:07 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2015-04-04 05:06 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll
2015-04-04 05:06 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll
2015-04-04 05:06 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\windows\system32\synceng.dll
2015-04-04 05:05 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2015-04-04 05:05 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2015-04-04 05:05 - 2013-10-12 04:01 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2015-04-04 05:05 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2015-04-04 05:05 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2015-04-04 05:05 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-04-04 05:05 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-04-04 05:05 - 2013-08-28 02:57 - 00434688 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2015-04-04 05:05 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2015-04-04 05:04 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2015-04-04 05:04 - 2013-07-12 12:08 - 00146816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2015-04-04 05:04 - 2013-07-12 12:07 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2015-04-04 05:03 - 2015-01-09 04:48 - 00635904 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
2015-04-04 05:03 - 2015-01-09 04:48 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
2015-04-04 05:03 - 2015-01-09 04:48 - 00027136 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
2015-04-04 05:03 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-04-04 05:03 - 2014-11-11 03:32 - 00074752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-04-04 05:03 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2015-04-04 05:03 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2015-04-04 05:03 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-04-04 05:03 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-04-04 05:03 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2015-04-04 05:03 - 2013-11-27 03:14 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00006016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2015-04-04 05:03 - 2013-11-26 13:11 - 00240576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2015-04-04 05:03 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2015-04-04 05:03 - 2013-10-04 03:49 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2015-04-04 05:03 - 2013-10-04 03:17 - 00177152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2015-04-04 05:03 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2015-04-04 05:03 - 2012-08-22 19:16 - 00712048 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-04-04 05:03 - 2012-07-04 21:45 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\Drivers\RNDISMP.sys
2015-04-04 05:03 - 2012-05-14 06:33 - 00769024 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-04-04 05:02 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2015-04-04 05:02 - 2013-03-19 05:33 - 00040960 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
2015-04-04 05:02 - 2013-02-27 06:49 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-04-04 05:01 - 2014-10-14 03:50 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2015-04-04 05:01 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2015-04-04 05:00 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-04-04 03:56 - 2015-04-04 10:57 - 00004856 _____ () C:\windows\system32\TmInstall.log
2015-04-04 02:46 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2015-04-04 02:46 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2015-04-04 01:10 - 2015-04-04 12:31 - 00001380 _____ () C:\preference.xml
2015-04-02 21:59 - 2015-04-02 21:59 - 00000000 ____D () C:\windows\system32\vbox
2015-04-01 21:55 - 2014-06-28 02:21 - 00391640 __RSH () C:\bootmgr
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default\AppData\Local\ASUS
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default\AppData\Local\Adobe
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\ASUS
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\Adobe
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default\Documents\Asus WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default\AppData\Roaming\ASUS WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default User\Documents\Asus WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\ASUS WebStorage
2015-04-01 21:00 - 2012-08-14 09:54 - 00057560 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 21:00 - 2012-08-14 09:54 - 00057560 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 21:00 - 2012-08-14 09:54 - 00000000 ____D () C:\Users\Default\AppData\Local\Windows Live
2015-04-01 21:00 - 2012-08-14 09:54 - 00000000 ____D () C:\Users\Default User\AppData\Local\Windows Live
2015-04-01 21:00 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-04-01 21:00 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-04-01 21:00 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Default\AppData\Roaming\E-Cam
2015-04-01 21:00 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\E-Cam
2015-04-01 21:00 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Default\AppData\Roaming\InstallShield
2015-04-01 21:00 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\InstallShield
2015-04-01 20:59 - 2015-04-22 13:24 - 01542453 _____ () C:\windows\WindowsUpdate.log
2015-04-01 14:19 - 2015-04-01 14:19 - 00000961 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-04-01 14:19 - 2015-04-01 14:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-04-01 14:19 - 2015-04-01 14:19 - 00000000 ____D () C:\Program Files\CCleaner
2015-04-01 13:11 - 2015-04-01 13:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-01 12:40 - 2015-04-18 09:53 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-04-01 12:20 - 2015-04-01 12:20 - 00001405 _____ () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-01 12:20 - 2010-05-28 04:27 - 00005576 _____ () C:\windows\Language.ini
2015-04-01 12:19 - 2015-04-01 12:19 - 00001100 _____ () C:\Users\Public\Desktop\E-Manual.lnk
2015-04-01 12:19 - 2015-04-01 12:19 - 00000000 ____D () C:\windows\ConfigSetRoot
2015-04-01 12:18 - 2015-04-01 12:19 - 00000000 ____D () C:\Program Files\Qualcomm Atheros WiFi Driver Installation
2015-04-01 12:18 - 2012-01-15 08:37 - 00072522 _____ () C:\windows\system32\athrext.cat
2015-04-01 12:18 - 2012-01-10 21:39 - 02231808 _____ (Atheros Communications, Inc.) C:\windows\system32\Drivers\athr.sys
2015-04-01 12:18 - 2012-01-10 21:39 - 02231808 _____ (Atheros Communications, Inc.) C:\windows\system32\athr.sys
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____D () C:\Program Files\Synaptics
2015-04-01 12:16 - 2011-08-30 07:00 - 00001083 _____ () C:\setup.iss
2015-04-01 12:15 - 2015-04-04 19:37 - 00058016 _____ () C:\Users\Netbook\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 12:15 - 2015-04-01 12:20 - 00000000 ____D () C:\Users\Netbook\AppData\Local\VirtualStore
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Startmenü
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Netzwerkumgebung
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Druckumgebung
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Documents\Eigene Musik
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Documents\Eigene Bilder
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\AppData\Local\Verlauf
2015-04-01 12:14 - 2015-04-19 18:54 - 00000000 ____D () C:\Users\Netbook\AppData\Local\Windows Live
2015-04-01 12:14 - 2015-04-18 00:14 - 00000000 ____D () C:\Users\Netbook\AppData\Local\Adobe
2015-04-01 12:14 - 2015-04-01 12:20 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Adobe
2015-04-01 12:14 - 2015-04-01 12:15 - 00000000 ____D () C:\Users\Netbook
2015-04-01 12:14 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Netbook\AppData\Local\ASUS
2015-04-01 12:14 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Netbook\Documents\Asus WebStorage
2015-04-01 12:14 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\ASUS WebStorage
2015-04-01 12:14 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Macromedia
2015-04-01 12:14 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\E-Cam
2015-04-01 12:14 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\InstallShield
2015-04-01 12:14 - 2009-07-14 06:53 - 00000020 ___SH () C:\Users\Netbook\ntuser.ini
2015-04-01 12:14 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-01 12:14 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-01 12:12 - 2015-04-01 12:12 - 00000000 ____D () C:\Recovery

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-22 13:30 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-22 13:30 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-22 13:16 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-04-21 18:41 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat
2015-04-21 17:11 - 2009-07-14 04:04 - 00000215 _____ () C:\windows\system.ini
2015-04-20 22:45 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\rescache
2015-04-20 22:38 - 2011-02-16 17:29 - 00000000 ____D () C:\windows\system32\XPSViewer
2015-04-20 22:38 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\winrm
2015-04-20 22:38 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\WCN
2015-04-20 22:38 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\slmgr
2015-04-20 22:38 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-04-20 22:38 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Defender
2015-04-20 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\nl-NL
2015-04-20 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\MUI
2015-04-20 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\IME
2015-04-20 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-20 22:21 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\DigitalLocker
2015-04-20 22:21 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-04-20 22:21 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\DVD Maker
2015-04-20 22:21 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\it-IT
2015-04-20 22:20 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\Printing_Admin_Scripts
2015-04-20 22:20 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\com
2015-04-20 22:01 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\fr-FR
2015-04-20 02:50 - 2009-07-27 12:11 - 04348482 _____ () C:\windows\system32\PerfStringBackup.INI
2015-04-19 16:35 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\de-DE
2015-04-18 14:21 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2015-04-18 14:21 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-18 13:55 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\Microsoft.NET
2015-04-18 00:15 - 2012-08-14 09:52 - 00000000 ____D () C:\ProgramData\Adobe
2015-04-17 21:35 - 2012-08-14 09:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-04-17 21:27 - 2012-08-14 09:35 - 00000000 ____D () C:\Program Files\Intel
2015-04-17 20:56 - 2012-08-14 09:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-04-17 20:51 - 2012-08-14 09:39 - 00000000 ____D () C:\windows\system32\Atheros_L1e
2015-04-17 20:26 - 2012-08-14 09:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-04-17 19:51 - 2012-08-14 09:35 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\windows\system32\CSVer.dll
2015-04-17 19:17 - 2012-08-14 09:49 - 00000000 ____D () C:\Program Files\Asus
2015-04-17 19:14 - 2012-08-14 09:36 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-04-17 18:24 - 2009-07-14 06:33 - 00267160 _____ () C:\windows\system32\FNTCACHE.DAT
2015-04-11 22:12 - 2009-07-27 12:56 - 00000000 ____D () C:\windows\panther
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-TW
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-HK
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-CN
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\tr-TR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\sv-SE
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ru-RU
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pt-PT
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pt-BR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pl-PL
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\nb-NO
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ko-KR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ja-JP
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\hu-HU
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\fi-FI
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\el-GR
2015-04-04 16:07 - 2011-02-16 17:29 - 00000000 ____D () C:\windows\system32\Drivers\de-DE
2015-04-04 12:33 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-04 11:46 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing
2015-04-04 06:04 - 2012-08-14 09:38 - 00000000 ____D () C:\windows\system32\RTCOM
2015-04-04 03:52 - 2012-08-14 10:10 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-04-04 01:17 - 2012-08-14 09:49 - 00000000 ____D () C:\AsusVibeData
2015-04-04 01:16 - 2012-08-14 09:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2015-04-01 21:55 - 2009-07-14 06:57 - 00029696 ___SH () C:\windows\system32\config\BCD-Template.LOG
2015-04-01 21:55 - 2009-07-14 06:52 - 00032768 _____ () C:\windows\system32\config\BCD-Template
2015-04-01 12:17 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\restore

==================== Files in the root of some directories =======

2015-04-04 11:43 - 2015-04-19 23:04 - 0007608 _____ () C:\Users\Netbook\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
C:\Users\Netbook\AppData\Local\Temp\Quarantine.exe
C:\Users\Netbook\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-18 14:39

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---


Benötigst du das Addition auch?

Alt 23.04.2015, 07:04   #11
schrauber
/// the machine
/// TB-Ausbilder
 

Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung







ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 23.04.2015, 12:24   #12
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



Eset

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=8d6876ed46767f4c9024151c4f26620d
# engine=23522
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-04-23 10:42:58
# local_time=2015-04-23 12:42:58 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 71 91 329312 442106 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 148534 181416969 0 0
# scanned=93962
# found=0
# cleaned=0
# scan_time=5066
         
Security Check

Code:
ATTFilter
 Results of screen317's Security Check version 1.00  
 Windows 7 Service Pack 1 x86 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
avast! Antivirus   
 Antivirus out of date!  
`````````Anti-malware/Other Utilities Check:````````` 
 CCleaner     
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast avastui.exe  
 AVAST Software Avast ng vbox\AvastVBoxSVC.exe 
 AVAST Software Avast avastui.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
FRST


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-04-2015 01
Ran by Netbook (administrator) on NETBOOK-PC on 23-04-2015 13:07:44
Running from C:\Users\Netbook\Desktop
Loaded Profiles: Netbook (Available profiles: Netbook)
Platform: Microsoft Windows 7 Starter  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files\Asus\InstantOn for EPC\InsOnSrv.exe
() C:\Windows\System32\AsusService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(ASUSTeK Computer Inc.) C:\Program Files\Asus\HotkeyService\HotKeyMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUSTeK Computer Inc.) C:\Program Files\Asus\HotkeyService\HotkeyService.exe
() C:\ExpressGateUtil\VAWinService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ASUSTeK Computer Inc.) C:\Program Files\Asus\SHE\SuperHybridEngine.exe
(AsusTek Computer Inc.) C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(ASUS) C:\Program Files\Asus\CapsHook\CapsHook.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(ASUS) C:\Program Files\Asus\InstantOn for EPC\InsOnWMI.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [GfxServiceInstall] => C:\windows\system32\GfxCUIServiceInstall.vbs [131 2012-06-27] ()
HKLM\...\Run: [HotkeyMon] => C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe [101800 2012-01-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12111576 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2262312 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [3331312 2012-08-14] (ASUSTek Computer Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-04-19] (Avast Software s.r.o.)
HKLM\...\Run: [SuperHybridEngine] => C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [426424 2012-02-10] (ASUSTeK Computer Inc.)
HKLM\...\Run: [LiveUpdate] => C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2012-01-05] (AsusTek Computer Inc.)
HKLM\...\Run: [HotkeyService] => C:\Program Files\ASUS\HotkeyService\HotkeyService.exe [1263024 2012-01-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [CapsHook] => C:\Program Files\ASUS\CapsHook\CapsHook.exe [445344 2010-11-15] (ASUS)
HKU\S-1-5-21-309674158-46085917-1021320157-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5529880 2015-03-13] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-18] (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-309674158-46085917-1021320157-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKU\S-1-5-21-309674158-46085917-1021320157-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-309674158-46085917-1021320157-1000 -> {E01C9CA2-DE19-4358-8456-44D35AABB4AC} URL = https://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-18] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-12-16] (Adblock Plus)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-18]

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-18]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files\ASUS\InstantOn for EPC\InsOnSrv.exe [92800 2011-12-01] (ASUS)
R2 AsusService; C:\windows\system32\AsusService.exe [224680 2012-01-11] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-18] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-04-18] (Avast Software)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [252632 2014-12-11] (Realtek Semiconductor)
R2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [91464 2011-03-26] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\windows\System32\drivers\AsIO.sys [11456 2010-06-28] ()
R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2010-08-03] ()
R2 aswHwid; C:\windows\system32\drivers\aswHwid.sys [24144 2015-04-18] ()
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [73440 2015-04-18] (Avast Software s.r.o.)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81728 2015-04-18] (Avast Software s.r.o.)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49904 2015-04-18] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [788272 2015-04-18] (Avast Software s.r.o.)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [427480 2015-04-18] (Avast Software s.r.o.)
S2 aswStm; C:\windows\system32\drivers\aswStm.sys [106912 2015-04-18] (Avast Software s.r.o.)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [206976 2015-04-18] ()
R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R3 L1C; C:\windows\System32\DRIVERS\L1C62x86.sys [109256 2000-01-01] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [13368 2015-04-17] (SlimWare Utilities, Inc.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-04-18] (Avast Software)
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Netbook\AppData\Local\Temp\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-23 13:07 - 2015-04-23 13:07 - 00010697 _____ () C:\Users\Netbook\Desktop\FRST.txt
2015-04-23 13:07 - 2015-04-23 13:07 - 00000767 _____ () C:\Users\Netbook\Desktop\checkup systemcheck.txt
2015-04-23 12:52 - 2015-04-23 12:52 - 01139200 _____ (Farbar) C:\Users\Netbook\Desktop\FRST.exe
2015-04-23 12:50 - 2015-04-23 12:50 - 00852616 _____ () C:\Users\Netbook\Desktop\SecurityCheck.exe
2015-04-22 13:26 - 2015-04-22 13:26 - 00000707 _____ () C:\Users\Netbook\Desktop\JRT.txt
2015-04-22 13:10 - 2015-04-22 13:38 - 00001213 _____ () C:\Users\Netbook\Desktop\mbam.txt
2015-04-22 12:24 - 2015-04-22 13:19 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-22 12:24 - 2015-04-22 12:24 - 00001056 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-04-22 12:24 - 2015-04-22 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-22 12:24 - 2015-04-22 12:24 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 
2015-04-22 12:24 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-04-22 12:24 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-04-22 12:24 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-04-22 12:21 - 2015-04-22 12:21 - 02685507 _____ (Thisisu) C:\Users\Netbook\Desktop\JRT.exe
2015-04-22 12:20 - 2015-04-22 12:20 - 02217984 _____ () C:\Users\Netbook\Desktop\AdwCleaner_4.201.exe
2015-04-21 17:54 - 2015-04-21 17:54 - 00000000 ___SD () C:\ComboFix
2015-04-21 17:37 - 2015-04-22 13:16 - 00000912 _____ () C:\windows\PFRO.log
2015-04-21 17:18 - 2015-04-21 17:18 - 00018369 _____ () C:\ComboFix.txt
2015-04-21 16:35 - 2015-04-21 16:35 - 05619466 ____R (Swearware) C:\Users\Netbook\Desktop\ComboFix.exe
2015-04-20 19:01 - 2015-04-20 19:01 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Netbook\Desktop\tdsskiller.exe
2015-04-20 18:07 - 2015-04-20 18:45 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-20 18:04 - 2015-04-20 18:45 - 00000000 ____D () C:\Users\Netbook\Desktop\mbar
2015-04-20 02:41 - 2015-04-23 11:01 - 00000616 _____ () C:\windows\setupact.log
2015-04-20 02:41 - 2015-04-20 02:41 - 00000000 _____ () C:\windows\setuperr.log
2015-04-19 17:25 - 2015-04-23 13:07 - 00000000 ____D () C:\FRST
2015-04-19 15:23 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-04-19 15:23 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-04-19 15:23 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-04-18 13:30 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2015-04-18 13:30 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2015-04-18 13:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2015-04-18 13:30 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2015-04-18 13:29 - 2015-04-21 17:54 - 00000000 ____D () C:\Qoobox
2015-04-18 13:28 - 2015-04-18 14:16 - 00000000 ____D () C:\windows\erdnt
2015-04-18 13:18 - 2015-04-18 13:18 - 00000207 _____ () C:\windows\tweaking.com-regbackup-NETBOOK-PC-Windows-7-Starter-(32-bit).dat
2015-04-18 13:18 - 2015-04-18 13:18 - 00000000 ____D () C:\RegBackup
2015-04-18 12:59 - 2015-01-31 05:33 - 02744320 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2015-04-18 12:59 - 2015-01-31 05:33 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2015-04-18 12:59 - 2015-01-31 02:48 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2015-04-18 12:56 - 2015-04-22 13:14 - 00000000 ____D () C:\AdwCleaner
2015-04-18 10:00 - 2015-04-18 10:00 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\AVAST Software
2015-04-18 09:59 - 2015-04-18 09:59 - 00002071 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-04-18 09:59 - 2015-04-18 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-04-18 09:58 - 2015-04-18 09:58 - 00788272 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswSnx.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00427480 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswSP.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00291312 _____ (Avast Software s.r.o.) C:\windows\system32\aswBoot.exe
2015-04-18 09:58 - 2015-04-18 09:58 - 00206976 _____ () C:\windows\system32\Drivers\aswVmm.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00106912 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswStm.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00081728 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswRdr2.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00073440 _____ (Avast Software s.r.o.) C:\windows\system32\Drivers\aswMonFlt.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00049904 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2015-04-18 09:58 - 2015-04-18 09:58 - 00043112 _____ (Avast Software s.r.o.) C:\windows\avastSS.scr
2015-04-18 09:58 - 2015-04-18 09:58 - 00024144 _____ () C:\windows\system32\Drivers\aswHwid.sys
2015-04-18 09:56 - 2015-04-18 09:56 - 00000000 ____D () C:\Program Files\AVAST Software
2015-04-17 21:44 - 2015-04-17 21:44 - 00000000 ____D () C:\Program Files\Common Files\Intel Corporation
2015-04-17 21:43 - 2015-04-17 21:43 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Intel Corporation
2015-04-17 21:27 - 2012-02-01 16:06 - 00470808 _____ (Intel Corporation) C:\windows\system32\Drivers\iaStor.sys
2015-04-17 20:50 - 2000-01-01 02:00 - 00109256 _____ (Qualcomm Atheros Co., Ltd.) C:\windows\system32\Drivers\L1C62x86.sys
2015-04-17 20:49 - 2015-04-17 20:49 - 00000000 ____D () C:\ProgramData\SlimWare Utilities, Inc
2015-04-17 20:44 - 2015-04-17 21:20 - 00013368 _____ (SlimWare Utilities, Inc.) C:\windows\system32\Drivers\SWDUMon.sys
2015-04-17 20:44 - 2015-04-17 20:44 - 00002455 _____ () C:\Users\Public\Desktop\SlimDrivers.lnk
2015-04-17 20:44 - 2015-04-17 20:44 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2015-04-17 20:44 - 2015-04-17 20:44 - 00000000 ____D () C:\Users\Netbook\AppData\Local\SlimWare Utilities Inc
2015-04-17 20:10 - 2015-04-17 20:10 - 00016896 _____ (ASUS) C:\windows\AsTaskSched.dll
2015-04-17 20:07 - 2015-04-17 20:07 - 00000000 __RSH () C:\MSDOS.SYS
2015-04-17 20:07 - 2015-04-17 20:07 - 00000000 __RSH () C:\IO.SYS
2015-04-17 19:21 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-04-17 19:21 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-04-17 19:21 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-04-17 19:21 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-04-17 19:21 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-04-17 19:21 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-04-17 19:21 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-04-17 19:21 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-04-17 19:21 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-04-17 19:21 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-04-17 19:21 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-04-17 19:21 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-04-17 19:21 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-04-17 19:21 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-04-17 19:21 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-04-17 19:21 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-04-17 19:21 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-04-17 19:21 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-04-17 19:21 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-04-17 19:21 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-04-17 19:21 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-04-17 19:21 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-04-17 19:21 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-04-17 19:21 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-04-17 19:21 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-04-17 19:21 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-04-17 19:21 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-04-17 19:21 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-04-17 19:21 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-04-17 19:21 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-04-17 19:21 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-04-17 19:19 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2015-04-17 19:19 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-04-17 19:19 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-04-17 19:19 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-04-17 19:19 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-04-17 19:19 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-04-17 19:19 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-04-17 19:19 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-04-17 19:19 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-04-17 19:19 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-04-17 19:19 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-04-17 19:19 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-04-17 19:19 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-04-17 19:19 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2015-04-17 19:19 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-04-17 19:18 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-04-17 19:18 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-04-17 19:17 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-04-17 19:17 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-04-17 19:17 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-04-17 19:17 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-04-17 19:17 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-04-17 19:17 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2015-04-17 18:40 - 2015-04-17 19:23 - 00000157 _____ () C:\AsusUpdate.log
2015-04-17 18:13 - 2015-04-17 20:09 - 00001769 _____ () C:\windows\Language_trs.ini
2015-04-17 18:07 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2015-04-17 18:01 - 2015-04-17 18:01 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Easeware
2015-04-11 22:47 - 2012-02-11 07:37 - 00317440 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2015-04-11 22:41 - 2014-12-11 19:47 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-04-11 22:20 - 2015-02-26 05:11 - 02381312 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-04-11 22:20 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
2015-04-11 22:19 - 2014-09-05 03:52 - 05703168 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
2015-04-11 22:19 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
2015-04-11 22:16 - 2015-02-24 04:23 - 00246920 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-04-04 20:26 - 2015-04-04 20:26 - 00000000 ____D () C:\Program Files\Adblock Plus for IE
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieUserList
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieSiteList
2015-04-04 19:17 - 2015-04-04 19:17 - 00000000 __SHD () C:\Users\Netbook\AppData\Local\EmieBrowserModeList
2015-04-04 17:45 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-04-04 17:44 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-04-04 17:43 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2015-04-04 17:42 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00645120 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2015-04-04 16:34 - 2015-04-04 16:34 - 00610304 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00233472 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00208384 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00151552 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00127488 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00083456 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-04-04 16:34 - 2015-04-04 16:34 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2015-04-04 16:34 - 2015-04-04 16:34 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2015-04-04 16:34 - 2015-04-04 16:34 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2015-04-04 16:32 - 2015-04-04 16:32 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 01158144 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 01080832 _____ (Microsoft Corporation) C:\windows\system32\d3d10.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00906240 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00604160 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00364544 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00249856 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1core.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\d3d10core.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00207872 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecsExt.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00187392 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00161792 _____ (Microsoft Corporation) C:\windows\system32\d3d10_1.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00010752 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00009728 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00005632 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-04-04 16:32 - 2015-04-04 16:32 - 00002560 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-04-04 16:07 - 2015-04-04 16:13 - 00000000 ___SD () C:\windows\system32\GWX
2015-04-04 14:56 - 2015-04-19 15:50 - 00000000 ____D () C:\windows\system32\MRT
2015-04-04 14:55 - 2015-04-19 15:34 - 125832184 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-04-04 14:26 - 2015-01-09 01:44 - 00419936 _____ () C:\windows\system32\locale.nls
2015-04-04 13:37 - 2012-07-26 05:21 - 00196608 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe
2015-04-04 13:37 - 2012-07-26 05:20 - 00613888 _____ (Microsoft Corporation) C:\windows\system32\WUDFx.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll
2015-04-04 13:37 - 2012-07-26 05:20 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\WUDFCoinstaller.dll
2015-04-04 13:37 - 2012-07-26 04:33 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys
2015-04-04 13:37 - 2012-07-26 04:32 - 00155136 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys
2015-04-04 13:37 - 2012-06-02 16:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-04-04 13:33 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll
2015-04-04 13:33 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
2015-04-04 13:33 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe
2015-04-04 13:33 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll
2015-04-04 12:25 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2015-04-04 12:25 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-04-04 12:25 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-04-04 12:25 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2015-04-04 12:25 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2015-04-04 12:25 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2015-04-04 12:25 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2015-04-04 12:25 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-04-04 12:25 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2015-04-04 12:25 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2015-04-04 11:43 - 2015-04-19 23:04 - 00007608 _____ () C:\Users\Netbook\AppData\Local\Resmon.ResmonCfg
2015-04-04 11:40 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2015-04-04 11:40 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2015-04-04 11:40 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2015-04-04 11:40 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2015-04-04 10:43 - 2015-04-19 15:54 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-04-04 10:43 - 2015-04-19 15:54 - 00000000 ____D () C:\windows\system32\appraiser
2015-04-04 05:40 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2015-04-04 05:40 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2015-04-04 05:37 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-04-04 05:37 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-04-04 05:37 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2015-04-04 05:37 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2015-04-04 05:37 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-04-04 05:37 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2015-04-04 05:37 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2015-04-04 05:37 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2015-04-04 05:36 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2015-04-04 05:36 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2015-04-04 05:36 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-04-04 05:36 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2015-04-04 05:36 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2015-04-04 05:36 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2015-04-04 05:36 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-04-04 05:36 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2015-04-04 05:34 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
2015-04-04 05:34 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\windows\system32\gameux.dll
2015-04-04 05:34 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\windows\system32\cero.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\windows\system32\esrb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\windows\system32\fpb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\windows\system32\oflc-nz.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\windows\system32\pegibbfc.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\windows\system32\csrr.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\windows\system32\cob-au.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\windows\system32\usk.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\windows\system32\oflc.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\windows\system32\grb.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-pt.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi-fi.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\windows\system32\pegi.rs
2015-04-04 05:34 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\windows\system32\djctq.rs
2015-04-04 05:33 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2015-04-04 05:33 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2015-04-04 05:33 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2015-04-04 05:33 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2015-04-04 05:33 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2015-04-04 05:28 - 2014-10-14 03:50 - 02363904 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-04-04 05:27 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\netcorehc.dll
2015-04-04 05:27 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\netevent.dll
2015-04-04 05:27 - 2012-10-03 18:40 - 00499712 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
2015-04-04 05:27 - 2012-10-03 17:21 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2015-04-04 05:24 - 2013-10-04 03:58 - 00152576 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2015-04-04 05:24 - 2013-10-04 03:56 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2015-04-04 05:22 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-04-04 05:22 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2015-04-04 05:22 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2015-04-04 05:22 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2015-04-04 05:22 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2015-04-04 05:22 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-04-04 05:22 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2015-04-04 05:22 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2015-04-04 05:22 - 2012-11-23 04:48 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe
2015-04-04 05:22 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\windows\system32\dpnet.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2015-04-04 05:21 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2015-04-04 05:20 - 2014-12-06 05:50 - 00242688 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-04-04 05:20 - 2014-11-11 04:44 - 00186880 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2015-04-04 05:20 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2015-04-04 05:20 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2015-04-04 05:20 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2015-04-04 05:20 - 2012-10-03 18:42 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2015-04-04 05:19 - 2014-08-12 03:36 - 00701440 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2015-04-04 05:19 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2015-04-04 05:19 - 2013-07-03 05:36 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2015-04-04 05:19 - 2013-07-03 05:36 - 00025728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2015-04-04 05:19 - 2012-08-21 22:12 - 00245760 _____ (Microsoft Corporation) C:\windows\system32\OxpsConverter.exe
2015-04-04 05:19 - 2012-07-06 21:23 - 00393728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
2015-04-04 05:18 - 2014-11-08 04:45 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2015-04-04 05:18 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-04-04 05:18 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2015-04-04 05:17 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-04-04 05:17 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-04-04 05:17 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-04 05:17 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-04 05:17 - 2013-02-12 05:32 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-04-04 05:17 - 2013-01-24 06:47 - 00196328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2015-04-04 05:16 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2015-04-04 05:16 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2015-04-04 05:16 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2015-04-04 05:16 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2015-04-04 05:16 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2015-04-04 05:15 - 2014-12-19 04:43 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-04-04 05:12 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-04-04 05:12 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-04-04 05:12 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll
2015-04-04 05:12 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2015-04-04 05:11 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2015-04-04 05:11 - 2014-10-30 03:45 - 00155136 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2015-04-04 05:11 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll
2015-04-04 05:11 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll
2015-04-04 05:11 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll
2015-04-04 05:11 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe
2015-04-04 05:11 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe
2015-04-04 05:11 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-04-04 05:11 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-04-04 05:11 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-04-04 05:11 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2015-04-04 05:10 - 2014-10-25 03:32 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2015-04-04 05:10 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\netapi32.dll
2015-04-04 05:10 - 2012-07-04 23:14 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\browser.dll
2015-04-04 05:10 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\browcli.dll
2015-04-04 05:09 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-04-04 05:09 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2015-04-04 05:08 - 2013-06-26 00:56 - 00527064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys
2015-04-04 05:08 - 2012-11-29 00:57 - 00047720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys
2015-04-04 05:08 - 2012-11-29 00:57 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\Wdfres.dll
2015-04-04 05:08 - 2012-11-29 00:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-04-04 05:07 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-04-04 05:07 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2015-04-04 05:07 - 2014-12-19 03:34 - 00116224 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-04-04 05:07 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2015-04-04 05:06 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll
2015-04-04 05:06 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll
2015-04-04 05:06 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\windows\system32\synceng.dll
2015-04-04 05:05 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2015-04-04 05:05 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2015-04-04 05:05 - 2013-10-12 04:01 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2015-04-04 05:05 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2015-04-04 05:05 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2015-04-04 05:05 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-04-04 05:05 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-04-04 05:05 - 2013-08-28 02:57 - 00434688 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2015-04-04 05:05 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2015-04-04 05:04 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2015-04-04 05:04 - 2013-07-12 12:08 - 00146816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys
2015-04-04 05:04 - 2013-07-12 12:07 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys
2015-04-04 05:03 - 2015-01-09 04:48 - 00635904 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
2015-04-04 05:03 - 2015-01-09 04:48 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
2015-04-04 05:03 - 2015-01-09 04:48 - 00027136 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
2015-04-04 05:03 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-04-04 05:03 - 2014-11-11 03:32 - 00074752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2015-04-04 05:03 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2015-04-04 05:03 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2015-04-04 05:03 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-04-04 05:03 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-04-04 05:03 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2015-04-04 05:03 - 2013-11-27 03:14 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2015-04-04 05:03 - 2013-11-27 03:13 - 00006016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2015-04-04 05:03 - 2013-11-26 13:11 - 00240576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2015-04-04 05:03 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2015-04-04 05:03 - 2013-10-04 03:49 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2015-04-04 05:03 - 2013-10-04 03:17 - 00177152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2015-04-04 05:03 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2015-04-04 05:03 - 2012-08-22 19:16 - 00712048 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-04-04 05:03 - 2012-07-04 21:45 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\Drivers\RNDISMP.sys
2015-04-04 05:03 - 2012-05-14 06:33 - 00769024 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2015-04-04 05:02 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2015-04-04 05:02 - 2013-03-19 05:33 - 00040960 _____ (Microsoft Corporation) C:\windows\system32\wwanprotdim.dll
2015-04-04 05:02 - 2013-02-27 06:49 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2015-04-04 05:01 - 2014-10-14 03:50 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2015-04-04 05:01 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2015-04-04 05:00 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-04-04 03:56 - 2015-04-04 10:57 - 00004856 _____ () C:\windows\system32\TmInstall.log
2015-04-04 02:46 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2015-04-04 02:46 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2015-04-04 02:46 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2015-04-04 01:10 - 2015-04-04 12:31 - 00001380 _____ () C:\preference.xml
2015-04-02 21:59 - 2015-04-02 21:59 - 00000000 ____D () C:\windows\system32\vbox
2015-04-01 21:55 - 2014-06-28 02:21 - 00391640 __RSH () C:\bootmgr
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default\AppData\Local\ASUS
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default\AppData\Local\Adobe
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\ASUS
2015-04-01 21:00 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\Adobe
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default\Documents\Asus WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default\AppData\Roaming\ASUS WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default User\Documents\Asus WebStorage
2015-04-01 21:00 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\ASUS WebStorage
2015-04-01 21:00 - 2012-08-14 09:54 - 00057560 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 21:00 - 2012-08-14 09:54 - 00057560 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 21:00 - 2012-08-14 09:54 - 00000000 ____D () C:\Users\Default\AppData\Local\Windows Live
2015-04-01 21:00 - 2012-08-14 09:54 - 00000000 ____D () C:\Users\Default User\AppData\Local\Windows Live
2015-04-01 21:00 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-04-01 21:00 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-04-01 21:00 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Default\AppData\Roaming\E-Cam
2015-04-01 21:00 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\E-Cam
2015-04-01 21:00 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Default\AppData\Roaming\InstallShield
2015-04-01 21:00 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\InstallShield
2015-04-01 20:59 - 2015-04-23 12:37 - 01565076 _____ () C:\windows\WindowsUpdate.log
2015-04-01 14:19 - 2015-04-01 14:19 - 00000961 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-04-01 14:19 - 2015-04-01 14:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-04-01 14:19 - 2015-04-01 14:19 - 00000000 ____D () C:\Program Files\CCleaner
2015-04-01 13:11 - 2015-04-01 13:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-01 12:40 - 2015-04-18 09:53 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-04-01 12:20 - 2015-04-01 12:20 - 00001405 _____ () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-01 12:20 - 2010-05-28 04:27 - 00005576 _____ () C:\windows\Language.ini
2015-04-01 12:19 - 2015-04-01 12:19 - 00001100 _____ () C:\Users\Public\Desktop\E-Manual.lnk
2015-04-01 12:19 - 2015-04-01 12:19 - 00000000 ____D () C:\windows\ConfigSetRoot
2015-04-01 12:18 - 2015-04-01 12:19 - 00000000 ____D () C:\Program Files\Qualcomm Atheros WiFi Driver Installation
2015-04-01 12:18 - 2012-01-15 08:37 - 00072522 _____ () C:\windows\system32\athrext.cat
2015-04-01 12:18 - 2012-01-10 21:39 - 02231808 _____ (Atheros Communications, Inc.) C:\windows\system32\Drivers\athr.sys
2015-04-01 12:18 - 2012-01-10 21:39 - 02231808 _____ (Atheros Communications, Inc.) C:\windows\system32\athr.sys
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2015-04-01 12:16 - 2015-04-01 12:16 - 00000000 ____D () C:\Program Files\Synaptics
2015-04-01 12:16 - 2011-08-30 07:00 - 00001083 _____ () C:\setup.iss
2015-04-01 12:15 - 2015-04-04 19:37 - 00058016 _____ () C:\Users\Netbook\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 12:15 - 2015-04-01 12:20 - 00000000 ____D () C:\Users\Netbook\AppData\Local\VirtualStore
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Startmenü
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Netzwerkumgebung
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Druckumgebung
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Documents\Eigene Musik
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\Documents\Eigene Bilder
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-04-01 12:15 - 2015-04-01 12:15 - 00000000 _SHDL () C:\Users\Netbook\AppData\Local\Verlauf
2015-04-01 12:14 - 2015-04-19 18:54 - 00000000 ____D () C:\Users\Netbook\AppData\Local\Windows Live
2015-04-01 12:14 - 2015-04-18 00:14 - 00000000 ____D () C:\Users\Netbook\AppData\Local\Adobe
2015-04-01 12:14 - 2015-04-01 12:20 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Adobe
2015-04-01 12:14 - 2015-04-01 12:15 - 00000000 ____D () C:\Users\Netbook
2015-04-01 12:14 - 2012-08-14 10:13 - 00000000 ____D () C:\Users\Netbook\AppData\Local\ASUS
2015-04-01 12:14 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Netbook\Documents\Asus WebStorage
2015-04-01 12:14 - 2012-08-14 10:08 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\ASUS WebStorage
2015-04-01 12:14 - 2012-08-14 09:52 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\Macromedia
2015-04-01 12:14 - 2012-08-14 09:51 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\E-Cam
2015-04-01 12:14 - 2012-08-14 09:36 - 00000000 ____D () C:\Users\Netbook\AppData\Roaming\InstallShield
2015-04-01 12:14 - 2009-07-14 06:53 - 00000020 ___SH () C:\Users\Netbook\ntuser.ini
2015-04-01 12:14 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-01 12:14 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Netbook\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-01 12:12 - 2015-04-01 12:12 - 00000000 ____D () C:\Recovery

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-23 11:11 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-23 11:11 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-23 11:01 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-04-21 18:41 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat
2015-04-21 17:11 - 2009-07-14 04:04 - 00000215 _____ () C:\windows\system.ini
2015-04-20 22:45 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\rescache
2015-04-20 22:38 - 2011-02-16 17:29 - 00000000 ____D () C:\windows\system32\XPSViewer
2015-04-20 22:38 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\winrm
2015-04-20 22:38 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\WCN
2015-04-20 22:38 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\slmgr
2015-04-20 22:38 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-04-20 22:38 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Defender
2015-04-20 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\nl-NL
2015-04-20 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\MUI
2015-04-20 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\IME
2015-04-20 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-20 22:21 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\DigitalLocker
2015-04-20 22:21 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-04-20 22:21 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\DVD Maker
2015-04-20 22:21 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\it-IT
2015-04-20 22:20 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\Printing_Admin_Scripts
2015-04-20 22:20 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\com
2015-04-20 22:01 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\fr-FR
2015-04-20 02:50 - 2009-07-27 12:11 - 04348482 _____ () C:\windows\system32\PerfStringBackup.INI
2015-04-19 16:35 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\de-DE
2015-04-18 14:21 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2015-04-18 14:21 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-18 13:55 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\Microsoft.NET
2015-04-18 00:15 - 2012-08-14 09:52 - 00000000 ____D () C:\ProgramData\Adobe
2015-04-17 21:35 - 2012-08-14 09:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-04-17 21:27 - 2012-08-14 09:35 - 00000000 ____D () C:\Program Files\Intel
2015-04-17 20:56 - 2012-08-14 09:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-04-17 20:51 - 2012-08-14 09:39 - 00000000 ____D () C:\windows\system32\Atheros_L1e
2015-04-17 20:26 - 2012-08-14 09:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-04-17 19:51 - 2012-08-14 09:35 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\windows\system32\CSVer.dll
2015-04-17 19:17 - 2012-08-14 09:49 - 00000000 ____D () C:\Program Files\Asus
2015-04-17 19:14 - 2012-08-14 09:36 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-04-17 18:24 - 2009-07-14 06:33 - 00267160 _____ () C:\windows\system32\FNTCACHE.DAT
2015-04-11 22:12 - 2009-07-27 12:56 - 00000000 ____D () C:\windows\panther
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-TW
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-HK
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\zh-CN
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\tr-TR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\sv-SE
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ru-RU
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pt-PT
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pt-BR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\pl-PL
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\nb-NO
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ko-KR
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\ja-JP
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\hu-HU
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\fi-FI
2015-04-04 17:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\el-GR
2015-04-04 16:07 - 2011-02-16 17:29 - 00000000 ____D () C:\windows\system32\Drivers\de-DE
2015-04-04 12:33 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-04 11:46 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing
2015-04-04 06:04 - 2012-08-14 09:38 - 00000000 ____D () C:\windows\system32\RTCOM
2015-04-04 03:52 - 2012-08-14 10:10 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-04-04 01:17 - 2012-08-14 09:49 - 00000000 ____D () C:\AsusVibeData
2015-04-04 01:16 - 2012-08-14 09:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2015-04-01 21:55 - 2009-07-14 06:57 - 00029696 ___SH () C:\windows\system32\config\BCD-Template.LOG
2015-04-01 21:55 - 2009-07-14 06:52 - 00032768 _____ () C:\windows\system32\config\BCD-Template
2015-04-01 12:17 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\restore

==================== Files in the root of some directories =======

2015-04-04 11:43 - 2015-04-19 23:04 - 0007608 _____ () C:\Users\Netbook\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
C:\Users\Netbook\AppData\Local\Temp\Quarantine.exe
C:\Users\Netbook\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-18 14:39

==================== End Of Log ============================
         
--- --- ---

--- --- ---


Werde nun mal einen Neustart durchführen

Hat sich leider bisher nichts geändert. Die Auslastung bleibt selbst im Leerlauf bei ca. 75%
Könnte es ein Hardwaredefekt sein?

Geändert von FuG67 (23.04.2015 um 12:14 Uhr)

Alt 24.04.2015, 07:42   #13
schrauber
/// the machine
/// TB-Ausbilder
 

Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



ProcessExplorer als Ersatz für den Windows Taskmanager installieren

Lade Dir den Process Explorer als Ersatz für den Taskmanager herunter und installiere ihn, hier findest Du eine Anleitung. Das ist ein wesentlich leistungsfähigerer Ersatz für den Windows-Taskmanager. Im Menü unter "Options" kannst Du den ProcessExplorer dauerhaft als Ersatz für den Taskmanager einrichten (Replace Taskmanager). Das ist sehr empfehlenswert, weil der ProcessExplorer erheblich mehr Funktionen als der Taskmanager hat. Wenn Du diese Einstellung gemacht hast, öffnet sich mit der Tastenkombination STRG + ALT + Entf. nicht mehr der Taskmanager, sondern der ProcessExplorer. Das kann jederzeit durch Abhaken dieser Einstellung wieder rückgängig gemacht werden.

Was wir jetzt konkret brauchen: In jeder Zeile steht ein Prozess, ein paar der Zeilen sind keine richtigen Prozesse, sondern nur Pseudoprozesse für die Tätigkeit des Windos-Kernels. Im Menü View => Select Columns wird ein Dialog geöffnet, in dem Du auswählen kannst, welche Spalten mit Informationen zu den Prozessen angezeigt werden sollen. In dem gehe in das Register "Process Performance" und stelle sicher, dass dort "CPU Usage" angehakt ist, "CPU History" wäre ebenfalls sinnvoll. Unter "CPU Usage" wird der aktuelle Wert der Prozessorauslastung für jeden Prozess angezeigt (im Tabellentitel steht nur kurz "CPU"), "CPU History" blendet für jeden Prozess ein Diagramm ein, das eine Kurve mit der Prozessorauslastung für die letzte Zeit anzeigt.

Damit sollte es Dir möglich sein, zu identifizieren, welcher Prozess Deine CPU in Trab hält. Mache einen Doppelklick auf den Prozess. Du kannst von dem ganzen auch einen Screenshot machen und ihn als Anhang mit Deiner Antwort hochladen (auf "Erweitert" unter dem Textfeld klicken und über "Anhänge verwalten" auf Deinem Rechner suchen lassen und über "Hochladen" anhängen).
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 24.04.2015, 19:34   #14
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



Vielen, vielen Dank für die Mühe und die Unterstützung. Eine Spende sei dir/euch sicher.
Werde ich morgen gleich machen und melde mich dann.

Alt 25.04.2015, 12:50   #15
FuG67
 
Problem svchost.exe erzeugt hohe RAM-Auslastung - Standard

Problem svchost.exe erzeugt hohe RAM-Auslastung



So, habe nun nach deiner Anleitung den Process Explorer als Standard festgelegt. Es sind immer noch die üblichen Verdächtigen, welche die hohe Auslastung erzeugen.
Meinst du das Problem besteht immer noch, wenn ich das System neu aufsetze?
Habe mal 2 Screenshots gemacht.

Die höchste Auslastung erzeugt der "System Idle Process". Habe auf diesen dann geklickt und es kam die Meldung, dass ich das Microsoft Debbuging Tool laden soll. Danach konnte ich dann in die normale Maske des Prozesses. Siehe Foto.

Der Svchost-Analyzer haut mir auch immer noch die gleiche Meldung raus wie auf dem Foto zu Beginn des Themas. Allmählich überkommt mich schon die Wut, wenn ich das Teil nur anschmeisse und ich schon diese "Gerechne" der Platte höre.
Miniaturansicht angehängter Grafiken
Problem svchost.exe erzeugt hohe RAM-Auslastung-unbenannt.jpg  
Angehängte Grafiken
Dateityp: jpg Unbenannt2.jpg (148,9 KB, 294x aufgerufen)
Dateityp: jpg Unbenannt3.jpg (116,2 KB, 289x aufgerufen)

Antwort

Themen zu Problem svchost.exe erzeugt hohe RAM-Auslastung
administrator, adobe, antivirus, auslastung, avast, browser, computer, defender, explorer, helper, langsam, object, performance, problem, programme, realtek, registry, security, services.exe, software, surfen, svchost.exe, temp, windows, windows xp



Ähnliche Themen: Problem svchost.exe erzeugt hohe RAM-Auslastung


  1. Windows 7: svchost netsvcs verursacht hohe CPU auslastung
    Log-Analyse und Auswertung - 10.09.2015 (21)
  2. svchost.exe (netsvcs) verursacht hohe CPU-Auslastung (windows 7)
    Plagegeister aller Art und deren Bekämpfung - 02.09.2015 (21)
  3. hohe CPU-Auslastung durch svchost.exe
    Log-Analyse und Auswertung - 30.08.2015 (1)
  4. Hohe CPU-Auslastung, svchost.exe Schuld?
    Netzwerk und Hardware - 12.08.2015 (2)
  5. Win7 System sehr träge, svchost.exe hohe Auslastung
    Log-Analyse und Auswertung - 12.01.2015 (13)
  6. Hohe CPU Auslastung durch svchost.exe
    Plagegeister aller Art und deren Bekämpfung - 12.11.2014 (1)
  7. Hohe CPU-Auslastung durch svchost.exe und weitere Plagegeister
    Plagegeister aller Art und deren Bekämpfung - 16.10.2014 (9)
  8. Sehr hohe CPU Auslastung aufgrund von svchost.exe
    Plagegeister aller Art und deren Bekämpfung - 03.10.2014 (30)
  9. Habe ein Problem mit svchost. (Hohe auslastung des Arbeitsspeichers)
    Log-Analyse und Auswertung - 03.05.2014 (17)
  10. Windows7: Hohe CPU-Auslastung- svchost.exe
    Log-Analyse und Auswertung - 27.12.2013 (7)
  11. Hohe Auslastung durch svchost.exe
    Log-Analyse und Auswertung - 08.12.2013 (25)
  12. svchost.exe verursacht hohe Auslastung + Internet lahmt
    Log-Analyse und Auswertung - 11.04.2013 (8)
  13. svchost.exe und unerklärlich hohe RAM-Auslastung (99%)
    Log-Analyse und Auswertung - 05.04.2012 (7)
  14. Hohe CPU Auslastung durch svchost.exe
    Log-Analyse und Auswertung - 17.02.2012 (24)
  15. svchost.exe und explorer.exe haben hohe cpu auslastung
    Log-Analyse und Auswertung - 19.10.2007 (6)
  16. svchost: Hohe CPU-Auslastung + Speicherfraß
    Plagegeister aller Art und deren Bekämpfung - 22.01.2006 (12)
  17. svchost.exe erzeugt 100% CPU-Auslastung
    Log-Analyse und Auswertung - 06.12.2005 (3)

Zum Thema Problem svchost.exe erzeugt hohe RAM-Auslastung - Hallo liebes Forum. Nach langem hin und her, mehreren Systemscans, etc. muss ich mich nun doch an euer Forum wenden. Die Ursachen für eine hohe Auslastung sind ja sind ja - Problem svchost.exe erzeugt hohe RAM-Auslastung...
Archiv
Du betrachtest: Problem svchost.exe erzeugt hohe RAM-Auslastung auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.