Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 08.05.2015, 14:31   #1
Labrat
 
DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



Hallo liebes Trojaner Board,

ich habe, wie viele andere auch diese vorgebliche DHL-Mail bekommen und da ich auf eine Lieferung gewartet habe, habe ich im Affekt auf den link geklickt. Als dann die ZIP Datei in den Downloadordner wanderte, hatte ich meinen Fehler gleich bemerkt und die Datei gelöscht.

Anschließend habe ich einen Scan mit Antivir und Spybot - Search and Destroy 2.2 gemacht und bin dann auf euer Forum gestoßen. Dummerweise habe ich mich nicht an die Regeln gehalten bzw. diese gelesen , sondern ich habe der Reihenfolge nach Kaspersky TDSSKiller, Malwarebyte (Korrekturen ausgeführt! - siehe log file), Adw Cleaner (Korrekturen ausgeführt! - siehe log file) und Junkware Removal Tool (siehe log file) benutzt. Danach habe ich auch den Eset online scanner laufen lassen (leider vergessen die log-file zu speichern und deinstallieren lassen).

Es wurde nirgendwo etwas gefunden!

Dennoch bin ich etwas paranoid geworden und habe den Kaspersky noch mal mit dem Häckchen bei "Verify digital signature" gemacht und dann findet er zumindest einen "suspicious file": Service:WUDFRd...!?

Kann den ein ZIP-file Schaden anrichten wenn man ihn nicht mal angeklickt bzw. entpackt hat? Sollte ich noch irgendwas tun?

Vielen Dank und Beste Grüße,
Stefan

Aktueller FRST File:


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2015 01
Ran by Labrat (administrator) on MAX_POWERS on 08-05-2015 15:17:46
Running from C:\Users\Labrat\Downloads
Loaded Profiles: Labrat (Available profiles: Labrat & Labrat_Adm)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
() C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Windows\runservice.exe
( ) C:\Windows\System32\lxbxcoms.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Micro-Star International) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
() C:\Program Files (x86)\Vidalia Bridge Bundle\Tor\tor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
() C:\Program Files (x86)\Opera\29.0.1795.47\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\29.0.1795.47\opera.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12480616 2012-04-24] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [728312 2015-05-05] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2014-10-16] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Run: [Vidalia] => C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe [6239727 2014-01-18] ()
HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Run: [OscarEditor] => "C:\Program Files (x86)\MOUSE Editor\\MouseEditor.exe" Minimum
HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\MountPoints2: {1e62b01c-2ad6-11df-95af-806e6f6e6963} - E:\Autorun.exe
HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\MountPoints2: {e5b8d7e1-ded8-11e4-acb4-806e6f6e6963} - E:\SETUP.EXE
HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\MountPoints2: {f25e9aa2-4740-11e0-b2ef-0024211056dd} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Autorun.exe
HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-11] (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-10] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-11-10] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-11-10] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Labrat\AppData\Roaming\Mozilla\Firefox\Profiles\d5h5b9mo.default-1412722597851
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.104.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.118.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.138.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-25] (ESN Social Software AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-10] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-11-10] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-01-14] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=1.1.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1690515653-3619170862-1892073707-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2014-12-16] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: NoScript - C:\Users\Labrat\AppData\Roaming\Mozilla\Firefox\Profiles\d5h5b9mo.default-1412722597851\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-01-23]
FF Extension: Adblock Plus - C:\Users\Labrat\AppData\Roaming\Mozilla\Firefox\Profiles\d5h5b9mo.default-1412722597851\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-23]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-04-24]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-04-24]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2015-04-24]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-04]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-11-14]
FF HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome: 
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.95\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_168.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.95\pdf.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll (Skype Technologies S.A.)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL No File
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll No File
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Wolfram Mathematica) - C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.4.2609412\npmathplugin.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U39) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.390.4) - C:\Windows\SysWOW64\npdeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Profile: C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-15]
CHR Extension: (Google Search) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-15]
CHR Extension: (Skype Click to Call) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-02-15]
CHR Extension: (Gmail) - C:\Users\Labrat\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-15]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]

Opera: 
=======
OPR Extension: (Adblock Plus) - C:\Users\Labrat\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2013-11-19]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeActiveFileMonitor5.0; C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe [102400 2006-09-14] () [File not signed]
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) [File not signed]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [827640 2015-05-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-05-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-05-05] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1185584 2015-05-05] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2719928 2015-04-22] (Microsoft Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LicCtrlService; C:\Windows\runservice.exe [16384 2010-09-28] () [File not signed]
R2 lxbx_device; C:\Windows\system32\lxbxcoms.exe [566704 2007-03-22] ( )
R2 lxbx_device; C:\Windows\SysWOW64\lxbxcoms.exe [537520 2007-03-22] ( )
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [84432 2014-07-01] (Micro-Star International)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [162800 2014-03-17] (MSI)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
S2 SuperRAIDSvc; C:\MSI\Smart Utilities\SuperRAIDSvc.exe [27632 2014-04-30] (Micro-Star International)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdide64; C:\Windows\System32\DRIVERS\amdide64.sys [11944 2012-12-03] (Advanced Micro Devices Inc.)
S0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices)
S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] () [File not signed]
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2010-03-16] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [152744 2015-05-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-05-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-10] (Avira Operations GmbH & Co. KG)
S3 dsNcAdpt; C:\Windows\System32\DRIVERS\dsNcAdpt.sys [32768 2013-02-18] (Juniper Networks) [File not signed]
S3 johci; C:\Windows\System32\DRIVERS\johci.sys [26200 2011-11-30] (JMicron Technology Corp.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2010-03-16] ()
R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [31024 2012-08-02] (Windows (R) Win 7 DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-08] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R0 MxEFUF; C:\Windows\System32\DRIVERS\MxEFUF64.sys [157696 2011-10-20] (Matrox Graphics Inc.)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
S3 NTIOLib_MSI_RAID; C:\MSI\Smart Utilities\NTIOLib_X64.sys [13808 2014-03-17] (MSI)
R3 pikbd; C:\Windows\System32\DRIVERS\pikbd.sys [22880 2013-11-30] (Christian Gulden)
S3 RTLE8023x64; C:\Windows\System32\DRIVERS\Rtenic64.sys [402024 2012-02-23] (Realtek Semiconductor Corporation                           )
S3 SliceDisk5; C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys [31824 2011-02-25] (Atola) [File not signed]
R0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows (R) Server 2003 DDK provider)
S3 StarOpen; No ImagePath
R3 ubohci; C:\Windows\System32\DRIVERS\ubohci.sys [132608 2012-10-05] (Unibrain)
R2 ubsbm; C:\Windows\System32\DRIVERS\ubsbm.sys [24064 2012-10-05] (Unibrain)
R2 ubumapi; C:\Windows\System32\DRIVERS\ubumapi.sys [92160 2012-10-05] (Unibrain)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [51712 2011-02-18] (Apple, Inc.) [File not signed]
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-10-16] (Cisco Systems, Inc.)
S3 WUDFRd; C:\Windows\system32\drivers\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) [File not signed]
R3 ZCLDRV; C:\Windows\System32\DRIVERS\ZclDrv64.sys [71680 2013-06-27] (TechnoScope Co., Ltd.)
S3 FLASHSYS; \??\C:\Program Files (x86)\MSI\Live Update 4\LU4\FLASHSYS64.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP1\WNt500x64\Sandra.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-08 15:14 - 2015-05-08 15:14 - 00000000 ____D () C:\Users\Labrat\Downloads\FRST-OlderVersion
2015-05-08 08:49 - 2015-05-08 08:49 - 00000000 ____D () C:\TDSSKiller_Quarantine
2015-05-06 20:23 - 2015-05-06 20:38 - 00000000 ____D () C:\Users\Labrat\Desktop\FIgures_PDF
2015-05-06 13:14 - 2015-05-06 13:14 - 02347384 _____ (ESET) C:\Users\Labrat\Downloads\esetsmartinstaller_deu.exe
2015-05-06 13:09 - 2015-05-06 13:09 - 00090375 _____ () C:\Users\Labrat\Downloads\Addition.txt
2015-05-06 13:08 - 2015-05-08 15:17 - 00029428 _____ () C:\Users\Labrat\Downloads\FRST.txt
2015-05-06 13:08 - 2015-05-08 15:17 - 00000000 ____D () C:\FRST
2015-05-06 13:07 - 2015-05-08 15:14 - 02102272 _____ (Farbar) C:\Users\Labrat\Downloads\FRST64.exe
2015-05-06 13:06 - 2015-05-06 13:06 - 00001082 _____ () C:\Users\Labrat\Desktop\JRT.txt
2015-05-06 12:26 - 2015-05-06 12:26 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-MAX_POWERS-Windows-7-Professional-(64-bit).dat
2015-05-06 12:26 - 2015-05-06 12:26 - 00000000 ____D () C:\RegBackup
2015-05-06 12:18 - 2015-05-06 12:52 - 00000000 ____D () C:\AdwCleaner
2015-05-06 12:16 - 2015-05-06 13:10 - 00000000 ____D () C:\Users\Labrat\Desktop\Virensuchlauf
2015-05-06 11:53 - 2015-05-08 15:15 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-06 11:53 - 2015-05-06 11:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-05-06 11:53 - 2015-05-06 11:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-06 11:53 - 2015-05-06 11:53 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-05-06 11:53 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-06 11:53 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-06 11:53 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-06 11:51 - 2015-05-06 11:52 - 02716306 _____ (Thisisu) C:\Users\Labrat\Downloads\JRT.exe
2015-05-06 11:51 - 2015-05-06 11:51 - 02204160 _____ () C:\Users\Labrat\Downloads\AdwCleaner_4.203.exe
2015-05-06 11:50 - 2015-05-06 11:52 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Labrat\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-06 11:39 - 2015-05-06 12:54 - 00003980 _____ () C:\Windows\PFRO.log
2015-05-06 01:05 - 2015-03-14 05:21 - 01632768 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-06 01:05 - 2015-03-14 05:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-05-06 01:05 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-05-06 01:05 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-05-06 01:05 - 2015-03-04 06:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-06 01:05 - 2015-03-04 06:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-06 01:05 - 2015-03-04 06:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-06 01:05 - 2015-03-04 06:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-06 01:05 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-05-06 01:05 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-05-06 01:05 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-06 01:05 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-05-06 01:05 - 2015-02-18 09:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-06 01:05 - 2015-01-29 05:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-06 01:05 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-03 12:23 - 2015-05-03 12:25 - 00000000 ____D () C:\Users\Labrat\Desktop\Tickets_u_Buchungsbestätigungen
2015-04-29 14:35 - 2015-05-03 12:38 - 00021331 _____ () C:\Users\Labrat\Desktop\Adressen_SJ.xlsx
2015-04-24 00:52 - 2015-04-24 00:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-22 20:46 - 2015-05-08 14:22 - 00004999 _____ () C:\Windows\setupact.log
2015-04-22 20:46 - 2015-04-22 20:46 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-22 09:28 - 2015-04-22 09:45 - 00074103 _____ () C:\Users\Labrat\Desktop\TEST_BIPLOT.xlsx
2015-04-15 15:40 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 15:40 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 15:40 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 15:40 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 15:40 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 15:40 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 15:40 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 15:40 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 15:40 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 15:40 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 15:40 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 15:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-15 15:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-15 15:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-15 15:40 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-15 15:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-15 15:40 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 15:40 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 15:40 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 15:40 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 15:40 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 15:40 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 15:40 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 15:40 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 15:40 - 2015-03-17 07:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 15:40 - 2015-03-17 07:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 15:40 - 2015-03-17 07:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 15:40 - 2015-03-17 07:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 15:40 - 2015-03-17 07:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-04-15 15:40 - 2015-03-17 07:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-04-15 15:40 - 2015-03-17 07:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 15:40 - 2015-03-17 07:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 15:40 - 2015-03-17 07:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 15:40 - 2015-03-17 07:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-04-15 15:40 - 2015-03-17 07:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-04-15 15:40 - 2015-03-17 07:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 15:40 - 2015-03-17 07:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 15:40 - 2015-03-17 07:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 15:40 - 2015-03-17 07:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-04-15 15:40 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-04-15 15:40 - 2015-03-17 06:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-04-15 15:40 - 2015-03-17 06:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-04-15 15:40 - 2015-03-17 06:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-04-15 15:40 - 2015-03-17 06:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-04-15 15:40 - 2015-03-17 06:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-04-15 15:40 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-04-15 15:40 - 2015-03-17 06:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-04-15 15:40 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-04-15 15:40 - 2015-03-17 06:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-04-15 15:40 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-04-15 15:40 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 05:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-04-15 15:40 - 2015-03-17 05:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-04-15 15:40 - 2015-03-17 05:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 05:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 15:40 - 2015-03-17 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-15 15:40 - 2015-03-10 05:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 15:40 - 2015-03-10 05:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-15 15:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-04-15 15:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-04-15 15:40 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 15:40 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-04-15 15:39 - 2015-04-02 02:17 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 15:39 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-04-15 15:39 - 2015-03-13 06:32 - 24980480 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 15:39 - 2015-03-13 06:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 15:39 - 2015-03-13 06:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 15:39 - 2015-03-13 06:09 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 15:39 - 2015-03-13 06:08 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 15:39 - 2015-03-13 06:08 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 15:39 - 2015-03-13 06:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 15:39 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 15:39 - 2015-03-13 06:06 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 15:39 - 2015-03-13 06:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 15:39 - 2015-03-13 05:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 15:39 - 2015-03-13 05:55 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 15:39 - 2015-03-13 05:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 15:39 - 2015-03-13 05:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 15:39 - 2015-03-13 05:53 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 15:39 - 2015-03-13 05:50 - 06025216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 15:39 - 2015-03-13 05:44 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 15:39 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-04-15 15:39 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-04-15 15:39 - 2015-03-13 05:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 15:39 - 2015-03-13 05:32 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 15:39 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-04-15 15:39 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-04-15 15:39 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-04-15 15:39 - 2015-03-13 05:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 15:39 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-04-15 15:39 - 2015-03-13 05:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 15:39 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-04-15 15:39 - 2015-03-13 05:23 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 15:39 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-04-15 15:39 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-04-15 15:39 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-04-15 15:39 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-04-15 15:39 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-04-15 15:39 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-04-15 15:39 - 2015-03-13 05:08 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 15:39 - 2015-03-13 05:07 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 15:39 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-04-15 15:39 - 2015-03-13 05:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 15:39 - 2015-03-13 05:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 15:39 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-04-15 15:39 - 2015-03-13 05:00 - 14397440 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 15:39 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-04-15 15:39 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-04-15 15:39 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-04-15 15:39 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-04-15 15:39 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 15:39 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-04-15 15:39 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-04-15 15:39 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-04-15 15:39 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-04-15 15:39 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 15:39 - 2015-03-13 04:22 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 15:39 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-04-15 15:39 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-04-15 15:39 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-04-15 15:39 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 15:37 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 15:37 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 15:37 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-14 23:22 - 2015-04-14 23:22 - 00000000 ____D () C:\Users\Labrat\AppData\Local\openvr
2015-04-09 19:22 - 2015-04-09 19:22 - 00000202 _____ () C:\Users\Labrat\Desktop\Pillars of Eternity.url
2015-04-08 19:53 - 2015-04-11 11:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2015-04-08 01:46 - 2015-04-08 01:46 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-08 01:46 - 2015-04-08 01:46 - 00000000 ___SD () C:\Windows\system32\GWX

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-08 14:40 - 2014-11-04 12:46 - 00000306 _____ () C:\Windows\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job
2015-05-08 14:40 - 2014-01-30 11:51 - 00000000 ____D () C:\Users\Labrat\AppData\Roaming\tor
2015-05-08 14:40 - 2014-01-30 11:51 - 00000000 ____D () C:\Users\Labrat\AppData\Local\Vidalia
2015-05-08 14:32 - 2012-04-02 10:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-08 14:31 - 2009-07-14 06:45 - 00025552 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-08 14:31 - 2009-07-14 06:45 - 00025552 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-08 14:22 - 2010-09-28 19:26 - 00000049 ___SH () C:\Windows\SysWOW64\mmf.sys
2015-05-08 14:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-08 08:49 - 2013-10-12 14:35 - 01398715 _____ () C:\Windows\WindowsUpdate.log
2015-05-06 22:48 - 2010-10-17 17:57 - 00000000 ____D () C:\Users\Labrat\Desktop\Programme
2015-05-06 21:32 - 2013-09-09 00:13 - 01594028 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-05-06 21:32 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2015-05-06 21:32 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2015-05-06 21:32 - 2009-07-14 07:13 - 01594028 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-06 11:40 - 2014-11-04 12:46 - 00002582 _____ () C:\Windows\System32\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c
2015-05-06 11:11 - 2010-03-09 11:30 - 00000000 ____D () C:\Users\Labrat\AppData\Roaming\Skype
2015-05-06 10:12 - 2015-01-14 00:31 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-05-06 01:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-05 11:06 - 2013-04-12 08:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-05-05 11:03 - 2013-04-12 08:56 - 00152744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-05-05 11:03 - 2013-04-12 08:56 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-05-04 08:35 - 2014-02-16 19:33 - 00000000 ____D () C:\Users\Labrat\Desktop\SlowFood
2015-04-28 18:43 - 2013-08-29 07:59 - 00000000 ____D () C:\Users\Labrat\Desktop\Zeug
2015-04-28 14:19 - 2014-06-03 13:54 - 00003856 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1379505506
2015-04-28 14:19 - 2010-03-09 11:29 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-04-28 14:11 - 2012-09-03 18:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-26 23:14 - 2014-06-10 09:56 - 00530966 _____ () C:\Users\Labrat\Desktop\Master_Lib.enl
2015-04-24 23:37 - 2014-07-07 18:07 - 00000000 ____D () C:\Users\Labrat\Desktop\Manuscript
2015-04-24 14:37 - 2011-07-17 15:13 - 00000000 ____D () C:\Users\Labrat\AppData\Roaming\vlc
2015-04-22 21:40 - 2014-02-28 19:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-04-22 21:38 - 2014-02-28 19:38 - 00000000 ____D () C:\Users\Labrat\AppData\Local\Battle.net
2015-04-22 10:49 - 2012-09-04 10:56 - 00001023 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-04-22 10:49 - 2010-03-09 11:35 - 00000000 ____D () C:\Program Files (x86)\CCleaner
2015-04-22 09:55 - 2015-01-14 16:05 - 00000000 ____D () C:\Users\Labrat\Desktop\LITERATUR_Dissertation
2015-04-22 08:57 - 2014-01-30 12:00 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-04-16 22:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2015-04-16 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2015-04-16 20:01 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-15 20:39 - 2012-04-02 10:28 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-15 20:39 - 2012-04-02 10:28 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-15 20:39 - 2011-05-14 11:31 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-15 16:07 - 2014-12-11 00:30 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-15 16:07 - 2014-05-06 13:34 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-15 16:02 - 2013-07-30 17:11 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 15:58 - 2010-03-08 19:44 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-09 16:04 - 2013-01-05 19:18 - 00000000 ____D () C:\Users\Labrat\Desktop\Rezepte
2015-04-09 15:58 - 2014-09-23 10:31 - 00000000 ____D () C:\Users\Labrat\Desktop\Doktorand
2015-04-09 15:56 - 2014-08-14 09:21 - 00001143 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-04-09 15:56 - 2014-08-14 09:20 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-09 15:56 - 2013-04-12 08:56 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-04-08 19:36 - 2015-01-14 01:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EndNote
2015-04-08 19:36 - 2015-01-14 01:47 - 00000000 ____D () C:\Program Files (x86)\EndNote X7
2015-04-08 19:36 - 2010-07-09 12:57 - 00000000 ____D () C:\ProgramData\Thomson.ResearchSoft.Installers
2015-04-08 19:36 - 2010-03-08 19:37 - 00000000 ____D () C:\Users\Labrat
2015-04-08 01:09 - 2013-04-12 09:02 - 00000000 ____D () C:\Users\Labrat\AppData\Roaming\Avira
2015-04-08 01:08 - 2013-04-12 08:56 - 00000000 ____D () C:\ProgramData\Avira

==================== Files in the root of some directories =======

2012-05-08 15:15 - 2012-05-08 15:15 - 0000005 _____ () C:\Program Files (x86)\basis-link
2012-08-13 11:57 - 2012-08-13 11:57 - 0012927 _____ () C:\Program Files (x86)\readme.html
2012-08-13 11:57 - 2012-08-13 11:57 - 0012558 _____ () C:\Program Files (x86)\readme.txt
2011-08-14 13:29 - 2011-08-14 13:29 - 0007605 _____ () C:\Users\Labrat\AppData\Local\Resmon.ResmonCfg
2010-03-09 11:31 - 2010-03-09 11:31 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2013-11-14 17:36 - 2014-03-13 09:44 - 0002345 _____ () C:\ProgramData\hpzinstall.log
2012-04-09 15:18 - 2012-04-09 21:04 - 0000040 _____ () C:\ProgramData\ra3.ini

Files to move or delete:
====================
C:\Users\Labrat\cc_20140526_224255.reg
C:\Users\Labrat\cc_20140602_191308.reg


Some content of TEMP:
====================
C:\Users\Labrat\AppData\Local\Temp\avgnt.exe
C:\Users\Labrat\AppData\Local\Temp\Quarantine.exe
C:\Users\Labrat\AppData\Local\Temp\sqlite3.dll
C:\Users\Labrat_Adm\AppData\Local\Temp\AskSLib.dll
C:\Users\Labrat_Adm\AppData\Local\Temp\avgnt.exe
C:\Users\Labrat_Adm\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Labrat_Adm\AppData\Local\Temp\nvStereoApiI64.dll
C:\Users\Labrat_Adm\AppData\Local\Temp\nvStInst.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-05 20:51

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Geändert von Labrat (08.05.2015 um 14:39 Uhr)

Alt 08.05.2015, 14:35   #2
Labrat
 
DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



FRST Addition:

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-05-2015 01
Ran by Labrat at 2015-05-08 15:18:16
Running from C:\Users\Labrat\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1690515653-3619170862-1892073707-500 - Administrator - Disabled)
Gast (S-1-5-21-1690515653-3619170862-1892073707-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1690515653-3619170862-1892073707-1002 - Limited - Enabled)
Labrat (S-1-5-21-1690515653-3619170862-1892073707-1001 - Administrator - Enabled) => C:\Users\Labrat
Labrat_Adm (S-1-5-21-1690515653-3619170862-1892073707-1005 - Administrator - Enabled) => C:\Users\Labrat_Adm

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 4.65 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0465-000001000000}) (Version: 4.65.00.0 - Igor Pavlov)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Photoshop Elements 5.0 (HKLM-x32\...\Adobe Photoshop Elements 5) (Version: 5.0 - Adobe Systems Inc.)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.03.0000 - Ubisoft)
Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden
Anno 2070 (HKLM-x32\...\Steam App 48240) (Version:  - BlueByte)
Apple Application Support (32-bit) (HKLM-x32\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ATI AVIVO64 Codecs (Version: 11.6.0.50730 - ATI Technologies Inc.) Hidden
ATI Catalyst Registration (x32 Version: 3.00.0000 - ATI Technologies Inc.) Hidden
Avira (HKLM-x32\...\{b5675cc4-ab8b-4945-8c1d-4c5479556d6a}) (Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.10.434 - Avira Operations GmbH & Co. KG)
Baldur's Gate II: Enhanced Edition (HKLM-x32\...\Steam App 257350) (Version:  - Beamdog)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.4.0.0 - Electronic Arts)
Battlefield 3™ (HKLM-x32\...\{77033683-0816-4D7D-8BF1-3949B4E9823D}) (Version: 1.0.0.0 - Electronic Arts)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
Bulletstorm (HKLM-x32\...\GFWL_{45410935-3E72-472B-8C35-AB1000008200}) (Version: 1.0.0000.130 - EA)
Bulletstorm (x32 Version: 1.0.0000.130 - EA) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.04 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05187 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05187 - Cisco Systems, Inc.) Hidden
Command & Conquer™ Alarmstufe Rot 3 - Englisches Sprachpaket (HKLM-x32\...\Red Alert 3 English Language Pack) (Version: 1.0 - Thundermods.net)
Command & Conquer™ Alarmstufe Rot 3 (HKLM-x32\...\{296D8550-CB06-48E4-9A8B-E5034FB64715}) (Version: 1.0.1.0 - Electronic Arts)
Command and Conquer 3: Tiberium Wars (HKLM-x32\...\Steam App 24790) (Version:  - EA Los Angeles)
Company of Heroes 2 (HKLM-x32\...\Steam App 231430) (Version:  - Relic Entertainment)
D7200 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
D7200_Help (x32 Version: 100.0.206.000 - Hewlett-Packard) Hidden
DarthMod Empire (HKLM-x32\...\DarthMod Empire8.0 Platinum) (Version: 8.0 Platinum - )
Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform)
Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version:  - Eidos Montreal)
DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Dragon Age Awakening Redesigned (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Awakening Redesigned) (Version:  - )
Dragon Age Awakening Velanna Redesigned© (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Awakening Velanna Redesigned©) (Version:  - )
Dragon Age Redesigned © Morrigan (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned © Morrigan) (Version:  - )
Dragon Age Redesigned Oghren© (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned Oghren©) (Version:  - )
Dragon Age Redesigned©  Zevran (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned©  Zevran) (Version:  - )
Dragon Age Redesigned© (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned©) (Version:  - )
Dragon Age Redesigned© Leliana (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned© Leliana) (Version:  - )
Dragon Age Redesigned© Sten (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned© Sten) (Version:  - )
Dragon Age Redesigned© Wynne (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dragon Age Redesigned© Wynne) (Version:  - )
DriverMax 7 (HKLM-x32\...\DMX5_is1) (Version: 7.44.0.738 - Innovative Solutions)
Dropbox (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 13.3.0.9066 - Landesfinanzdirektion Thüringen)
Empire: Total War (HKLM-x32\...\Steam App 10500) (Version:  - The Creative Assembly)
EndNote X7 (HKLM-x32\...\{86B3F2D6-AC2B-0017-8AE1-F2F77F781B0C}) (Version: 17.3.0.8536 - Thomson Reuters)
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
FAKEFACTORY Cinematic Mod V10 (HKLM-x32\...\FAKEFACTORY CM10V10.40) (Version: V10.40 - FAKEFACTORY)
Fallout 3 (HKLM-x32\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version:  - Bethesda Softworks)
Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version:  - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai)
Find and Mount 2.32 (HKLM\...\Find and Mount_is1) (Version: 2.32 - A-FF Data Recovery)
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Half-Life 2 (HKLM-x32\...\Steam App 220) (Version:  - Valve)
Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version:  - Valve)
Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version:  - Valve)
Half-Life: Source (HKLM-x32\...\Steam App 280) (Version:  - Valve)
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version:  - EFD Software)
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP)
HP Photosmart Printer Driver Software 13.0 Rel. 2 (HKLM\...\{F69E48F2-94B0-4272-845C-5F21F2A9815F}) (Version: 13.0 - HP)
HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM-x32\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HydraVision (x32 Version: 4.2.174.0 - ATI Technologies Inc.) Hidden
IBM SPSS Statistics 22 (HKLM\...\{104875A1-D083-4A34-BC4F-3F635B7F8EF7}) (Version: 22.0.0.0 - IBM Corp)
iTunes (HKLM\...\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.)
Japanese Fonts Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5760-0000-A00000000003}) (Version: 10.0.0 - Adobe Systems Incorporated)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Lexmark 7100 Series (HKLM\...\Lexmark 7100 Series) (Version:  - Lexmark International, Inc.)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Medieval II Total War (HKLM-x32\...\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}) (Version: 1.03.000 - SEGA)
Medieval II Total War : Kingdoms : Americas (HKLM-x32\...\{75983B66-804C-40D1-BA13-64DAF652A6F1}) (Version: 1.03.000 - SEGA)
Medieval II Total War : Kingdoms : Britannia (HKLM-x32\...\{CEDDEE73-3D36-41C2-AA40-29355D9FBD63}) (Version: 1.03.000 - SEGA)
Medieval II Total War : Kingdoms : Crusades (HKLM-x32\...\{02A10468-2F1C-447C-AD8E-4DEDDEA25AE2}) (Version: 1.03.000 - SEGA)
Medieval II Total War : Kingdoms : Teutonic (HKLM-x32\...\{7AEE1963-7001-4C37-BC20-2FAEB74AA41C}) (Version: 1.03.000 - SEGA)
Mendeley Desktop 1.12.3 (HKLM-x32\...\Mendeley Desktop) (Version: 1.12.3 - Mendeley Ltd.)
Metro 2033 (HKLM-x32\...\Steam App 43110) (Version:  - THQ)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4711.1003 - Microsoft Corporation)
Microsoft Office Proofing Tools 2013 - English (HKLM-x32\...\{90150000-001F-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM-x32\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 31.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.6.0 (x86 de)) (Version: 31.6.0 - Mozilla)
MSI Live Update (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.0.006 - MSI)
MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.025 - MSI)
MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.16.4 - Black Tree Gaming)
NVIDIA Grafiktreiber 344.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.75 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice.org 3.4.1 (HKLM-x32\...\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
Opera Stable 29.0.1795.47 (HKLM-x32\...\Opera 29.0.1795.47) (Version: 29.0.1795.47 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.3.7.2735 - Electronic Arts, Inc.)
PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
PDF Architect (HKLM-x32\...\{30B41B7A-3C9D-44DE-A7A1-949011F33CC3}) (Version: 1.0.41.8362 - pdfforge)
Pillars of Eternity (HKLM-x32\...\Steam App 291650) (Version:  - Obsidian Entertainment)
Portal 2 (HKLM-x32\...\Steam App 620) (Version:  - Valve)
PS_SF_02_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
PS_SF_02_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
PS_SF_02_Software_Min (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
R for Windows 2.15.3 (HKLM\...\R for Windows 2.15.3_is1) (Version: 2.15.3 - R Core Team)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.77.1126.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7111 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version:  - Thomson Reuters)
RStudio (HKLM-x32\...\RStudio) (Version: 0.97.332 - RStudio)
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.9.9216 - Skype Technologies S.A.)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Source SDK (HKLM-x32\...\Steam App 211) (Version:  - Valve)
Source SDK Base 2006 (HKLM-x32\...\Steam App 215) (Version:  - Valve)
Source SDK Base 2007 (HKLM-x32\...\Steam App 218) (Version:  - Valve)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.)
Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Lord of the Rings FREE Trial  (x32 Version: 1.00.0000 - ATI Technologies Inc.) Hidden
The Witcher 2: Assassins of Kings Enhanced Edition (HKLM-x32\...\Steam App 20920) (Version:  - CD Projekt RED)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
Tor 0.2.4.20 (HKLM-x32\...\Tor) (Version:  - )
Total War: ROME II (HKLM-x32\...\Steam App 214950) (Version:  - Creative Assembly)
TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 4.9 - Ubisoft)
Vidalia 0.2.21 (HKLM-x32\...\Vidalia) (Version:  - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Labrat\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)

==================== Restore Points  =========================

26-04-2015 21:59:43 Windows-Sicherung
28-04-2015 15:25:14 Windows Update
05-05-2015 18:24:11 Windows Update
06-05-2015 01:05:37 Windows Update
06-05-2015 11:15:04 Windows Update
06-05-2015 21:29:55 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2014-05-29 11:50 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {07FE1F6F-50EE-4A67-A1BB-3DAB9405320A} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {083BE7DA-05BF-4D16-BB76-380E5CCD0058} - System32\Tasks\{780A4746-ECD4-4336-9DC8-AA267CD256EF} => c:\program files (x86)\opera\launcher.exe [2015-04-17] (Opera Software)
Task: {17B28221-18C3-4FE9-A371-F4E7A284E36E} - System32\Tasks\{A9F80C0C-CE31-44A0-A326-1DA3C01652E7} => pcalua.exe -a "C:\Program Files (x86)\MSI\Live Update 4\LU4\DL_FILE\Realtek 8111 LAN Driver_6.241.0721.2010.exe" -d "C:\Program Files (x86)\MSI\Live Update 4\LU4\DL_FILE"
Task: {1DFACC64-0A3D-49BE-A05E-BD14F2937860} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {223FE3EB-059F-4B11-BD86-09B30AAA372C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {299F765B-D608-46CA-BB73-EEC726B5D903} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {2CCC2C4A-18C0-49E0-9DF7-8D052C0E86EA} - System32\Tasks\{7CEB5D3C-7692-4F24-A522-3A6259D427EB} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
Task: {360FA1DC-92DB-4648-ACAA-CF0E842C74FB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd)
Task: {4131AB68-C733-46F4-87BD-2D9CB1C4EF27} - System32\Tasks\{AF70E2D3-D93E-4A06-B1CD-261DA03EF3D2} => pcalua.exe -a C:\Users\Labrat\Downloads\jxpiinstall(1).exe -d C:\Windows\system32
Task: {468A3E8E-E82E-4A5C-B843-D7775C3350E8} - System32\Tasks\{5A303460-D157-4261-9868-6A7ECD4CF561} => pcalua.exe -a "C:\Program Files (x86)\program\\swriter.exe" -c -o "C:\Users\Labrat\Desktop\Personalfragebogen_neu.doc"
Task: {520BEA77-A0C8-49DF-9413-0E55EFD2C836} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {5B26E8BC-52FF-4A04-86D0-7163C91344FE} - System32\Tasks\{DED81D3D-8C1F-4EE9-B023-F6E8FBBEDAB6} => pcalua.exe -a "C:\Users\Labrat\Desktop\Adobe Creative Suit\PSE_5.0_WIN_ESD1_ENG.exe" -d "C:\Users\Labrat\Desktop\Adobe Creative Suit"
Task: {5D705D4F-AE60-49D5-8596-4DD8C7115457} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {63C8506B-CC70-48A6-A94E-C2EFE3CFF7D1} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {6458E1DD-975B-4D5E-AB5B-C99A2AD35405} - System32\Tasks\{1F46AE61-F0DD-428A-9B86-17F3C8F82001} => pcalua.exe -a "D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\_CommonRedist\vcredist\2008\vcredist_x64.exe" -d "D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\_CommonRedist\vcredist\2008"
Task: {6864F499-29DB-4518-9F53-DDFED77E63CA} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {71601CED-3FB1-42AC-B33C-E92D068FFFFC} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {72BC9135-7984-40DA-8066-9C9A6D668CAF} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {77EAFF06-B042-4BAA-8B58-81741EFB2DA1} - System32\Tasks\{DE7694B1-A656-48E9-B942-A5AD001BD27D} => pcalua.exe -a "D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\_CommonRedist\vcredist\2008\vcredist_x86.exe" -d "D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\_CommonRedist\vcredist\2008"
Task: {7C33F6E8-0264-40CD-ABE0-01E43C88115C} - System32\Tasks\{9A259AC2-61E9-43AF-A042-DB4D0E14263F} => pcalua.exe -a "D:\Spiele\MoH_beta\Support\Medal of Honor MP Beta_uninst.exe" -d D:\Spiele\MoH_beta\Support
Task: {9D82C999-660D-48B7-9C78-4EE914AB68DC} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2013-09-20] (Safer-Networking Ltd.)
Task: {A40A5266-8E9C-42CD-9A67-A105A15EB524} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {AC53B5DA-D300-4E7E-AA04-886ABDCBEBC7} - System32\Tasks\{261F7702-DAB9-4FC7-9014-B1F1A9745CF7} => pcalua.exe -a "D:\Steam\SteamApps\common\empire total war\Uninstall DarthMod Empire Enforced.exe" -d "D:\Steam\SteamApps\common\empire total war"
Task: {B45E68E1-0A06-45B6-A1FF-45A1254E6E7A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2013-09-20] (Safer-Networking Ltd.)
Task: {C9C1D77D-C196-4D49-ABA7-6AEE39627045} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2013-09-20] (Safer-Networking Ltd.)
Task: {D0143E59-8C4E-41D1-B6E1-877EF1CA6951} - System32\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c => C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe
Task: {D5938137-9D76-4D2D-9E17-2B894A186005} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {DB537226-1B45-4B2C-B6AE-2D5A73085D41} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {E173DBAE-934E-4AF1-A1F8-886025EDCED8} - System32\Tasks\{F21B8802-1E91-441D-92EB-4EA2A6765F00} => pcalua.exe -a C:\Users\Labrat\Desktop\Netfx2setup.exe -d C:\Users\Labrat\Desktop
Task: {E1E4DAAF-032E-4CCA-AD85-FDE0A78AC090} - System32\Tasks\{9B9BC100-4D97-4CA6-91CA-D53B74868084} => pcalua.exe -a C:\Users\Labrat\Desktop\avira_free_antivirus_de.exe -d C:\Users\Labrat\Desktop
Task: {E3ECC742-1491-405F-A761-7966349AB235} - System32\Tasks\{EE428E84-3D33-40C4-BE50-E19901A94EA4} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {F1D13230-23F5-48C6-8BAC-22637090A9AD} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {F7DE0614-1ECA-4EFD-A39D-903235B9A448} - System32\Tasks\Opera scheduled Autoupdate 1379505506 => C:\Program Files (x86)\Opera\launcher.exe [2015-04-17] (Opera Software)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job => C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe

==================== Loaded Modules (whitelisted) ==============

2013-09-26 17:19 - 2014-11-12 23:56 - 00118080 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2006-09-14 08:56 - 2006-09-14 08:56 - 00102400 _____ () C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
2012-05-04 15:41 - 2012-05-04 15:41 - 00211968 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2011-11-13 14:30 - 2011-11-13 14:30 - 00676864 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2011-11-13 14:31 - 2011-11-13 14:31 - 03643392 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-14 00:31 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2010-09-28 19:26 - 2010-09-28 19:26 - 00016384 _____ () C:\Windows\runservice.exe
2014-01-18 11:42 - 2014-01-18 11:42 - 06239727 _____ () C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe
2014-01-18 12:37 - 2014-01-18 12:37 - 03610126 _____ () C:\Program Files (x86)\Vidalia Bridge Bundle\Tor\tor.exe
2015-04-28 14:19 - 2015-04-28 14:18 - 00479352 _____ () C:\Program Files (x86)\Opera\29.0.1795.47\opera_crashreporter.exe
2014-10-16 02:48 - 2014-10-16 02:48 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2010-09-28 19:26 - 2010-09-28 19:26 - 00048640 _____ () C:\Windows\mmfs.dll
2014-01-30 12:00 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-01-30 12:00 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-01-30 12:00 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-01-30 12:00 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-01-30 12:00 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2009-06-23 04:42 - 2009-06-23 04:42 - 00043008 _____ () C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\libgcc_s_dw2-1.dll
2011-08-24 00:59 - 2011-08-24 00:59 - 00047972 _____ () C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\mingwm10.dll
2015-04-08 19:53 - 2015-04-08 19:53 - 03348592 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2015-04-08 19:53 - 2015-04-08 19:53 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2015-04-08 19:53 - 2015-04-08 19:53 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2015-04-28 14:19 - 2015-04-28 14:18 - 01576568 _____ () C:\Program Files (x86)\Opera\29.0.1795.47\libglesv2.dll
2015-04-28 14:19 - 2015-04-28 14:18 - 00081016 _____ () C:\Program Files (x86)\Opera\29.0.1795.47\libegl.dll
2015-04-15 20:39 - 2015-04-15 20:39 - 14980272 _____ () C:\Windows\SysWOW64\Macromed\Flash\pepflashplayer32_17_0_0_169.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\com -> hxxp://www.msi.com
IE trusted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\com.tw -> hxxp://asia.msi.com.tw

IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\...\123simsen.com -> www.123simsen.com

There are 7867 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Labrat\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Labrat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\Windows\pss\An OneNote senden.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Labrat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk => C:\Windows\pss\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk.Startup
MSCONFIG\startupreg: Adobe Photo Downloader => "C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\apdproxy.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ATICustomerCare => "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
MSCONFIG\startupreg: DriverMax => "C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe" -agent
MSCONFIG\startupreg: DriverMax_RESTART => "C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe" -RESTART
MSCONFIG\startupreg: EADM => "D:\Spiele\Origin\Origin.exe" -AutoStart
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: hpqSRMon => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Live Update => C:\Program Files (x86)\MSI\Live Update\StartLiveUpdate.exe /REMINDER
MSCONFIG\startupreg: NokiaMServer => C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
MSCONFIG\startupreg: NokiaSuite.exe => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: Steam => "d:\steam\steam.exe" -silent
MSCONFIG\startupreg: Super Charger => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe

==================== FirewallRules (whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{291E905E-EE00-4B3B-A66B-F471C9244C63}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{B2A53BC9-ACA4-481E-A652-29B34C096B74}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{A812A72F-79B8-4B59-9800-2C5D5D442C3D}] => (Allow) D:\Steam\steam.exe
FirewallRules: [{BFD6D713-C240-4E72-A3AC-D510DC6E4E09}] => (Allow) D:\Steam\steam.exe
FirewallRules: [{B2BB8029-D0F7-4F84-9031-0F8507C9CF7C}] => (Allow) D:\Spiele\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [{A003797F-474F-495C-B06E-66B6BC2EE233}] => (Allow) D:\Spiele\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [TCP Query User{0812C55C-9AEA-4BE1-ACBB-5F701F60AEB4}D:\spiele\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) D:\spiele\rockstar games\grand theft auto iv\gtaiv.exe
FirewallRules: [UDP Query User{3E8691B6-643C-43D4-B70A-F4ECC3ABC184}D:\spiele\rockstar games\grand theft auto iv\gtaiv.exe] => (Allow) D:\spiele\rockstar games\grand theft auto iv\gtaiv.exe
FirewallRules: [{ADB93B0C-F423-4707-94D1-D36A61281953}] => (Allow) D:\Spiele\Ubisoft\ANNO 1404\Anno4.exe
FirewallRules: [{D2427430-04F2-4EA4-AA99-F7D269DD0E4A}] => (Allow) D:\Spiele\Ubisoft\ANNO 1404\Anno4.exe
FirewallRules: [{D41162C9-38A8-4307-AD8B-4D32F88D86E2}] => (Allow) D:\Spiele\Ubisoft\ANNO 1404\tools\Anno4Web.exe
FirewallRules: [{3D2E0030-3800-453E-A3DB-4C8853F3D2EE}] => (Allow) D:\Spiele\Ubisoft\ANNO 1404\tools\Anno4Web.exe
FirewallRules: [TCP Query User{28C9ABE4-A536-462C-B329-6BFC1DBCA648}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{CE95AB74-6CF4-4766-916A-F39C35758C00}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [TCP Query User{02767BA0-D74A-49E2-AEF7-DBAAF2D3DAFD}C:\program files (x86)\opera\opera.exe] => (Allow) C:\program files (x86)\opera\opera.exe
FirewallRules: [UDP Query User{CC40C61C-C1EB-4366-AC6E-DF5C793AD9A2}C:\program files (x86)\opera\opera.exe] => (Allow) C:\program files (x86)\opera\opera.exe
FirewallRules: [{D0F1A911-E170-449A-BDF3-C080D6BABE56}] => (Allow) C:\Users\Labrat\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{598319BA-B0A9-4149-B070-739230CE1EEB}] => (Allow) C:\Users\Labrat\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{440A0224-6199-4E96-89ED-B7C9697929D0}] => (Allow) D:\Spiele\Bulletstorm\Binaries\Win32\ShippingPC-StormGame.exe
FirewallRules: [{ABC3E749-9D58-42C7-AE63-D78197F917F5}] => (Allow) D:\Spiele\Bulletstorm\Binaries\Win32\ShippingPC-StormGame.exe
FirewallRules: [{B21D7192-45D6-4BC5-802F-0D9796E3F69B}] => (Allow) D:\Steam\SteamApps\labrat69\half-life source\hl2.exe
FirewallRules: [{85A1063A-0D43-4621-83F4-D20818E41023}] => (Allow) D:\Steam\SteamApps\labrat69\half-life source\hl2.exe
FirewallRules: [{5D521022-484D-46F8-A4BF-97A0BB2EA8C7}] => (Block) D:\Spiele\Origin\Origin.exe
FirewallRules: [{89178815-2738-4649-934D-DC5817C03A48}] => (Allow) D:\Steam\SteamApps\common\Command and Conquer 3 Tiberium Wars\CNC3.exe
FirewallRules: [{37C999DB-0831-4F70-A286-F4EABF03DC3A}] => (Allow) D:\Steam\SteamApps\common\Command and Conquer 3 Tiberium Wars\CNC3.exe
FirewallRules: [{E10ED662-969E-472D-915E-8E0B5960A3BC}] => (Allow) D:\Steam\SteamApps\common\Command and Conquer 3 Tiberium Wars\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{4FCDEDE6-F460-4182-889D-DB65A8DCA30D}] => (Allow) D:\Steam\SteamApps\common\Command and Conquer 3 Tiberium Wars\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{E307EF1D-D2BB-466B-95FC-FB57239BFD64}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{B09E73A7-A707-4C1A-A037-74F7B65544C1}] => (Allow) C:\Windows\SysWOW64\lxbxcoms.exe
FirewallRules: [{895C1824-D6BA-4BBA-A188-754A881BA45B}] => (Allow) C:\Windows\SysWOW64\lxbxcoms.exe
FirewallRules: [{63FA5365-9E12-48C1-BDFB-B42D3201A04E}] => (Allow) D:\Spiele\Diablo III\Diablo III.exe
FirewallRules: [{5A74735D-64E8-44E4-907E-C6A3B8E887D2}] => (Allow) D:\Spiele\Diablo III\Diablo III.exe
FirewallRules: [{A0FA0445-EFCF-4589-A385-5ADDEC4BE285}] => (Allow) D:\Spiele\Battlefield 3\Battlefield 3\bf3.exe
FirewallRules: [{78F5A3A7-773B-4A48-9DAD-FCAECF928456}] => (Allow) D:\Spiele\Battlefield 3\Battlefield 3\bf3.exe
FirewallRules: [{D4703311-1015-4807-AC7E-0B5995BA0D82}] => (Allow) D:\Steam\SteamApps\common\deus ex - human revolution\dxhr.exe
FirewallRules: [{A02B2BFD-5FED-4515-AC4F-0EE5DCC97281}] => (Allow) D:\Steam\SteamApps\common\deus ex - human revolution\dxhr.exe
FirewallRules: [{89683748-D859-4B5C-B798-54F91994DDB7}] => (Allow) D:\Steam\SteamApps\common\Metro 2033\metro2033.exe
FirewallRules: [{2BADB2E2-E9A1-4A44-B4B2-BC948EE68496}] => (Allow) D:\Steam\SteamApps\common\Metro 2033\metro2033.exe
FirewallRules: [{D33032EB-C9E4-4A51-87C0-AFC51861001F}] => (Allow) C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe
FirewallRules: [{26ADDD14-9ED7-491C-87FF-10EBB81A27DE}] => (Allow) C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe
FirewallRules: [{9F5C64E7-2E82-447D-920A-87B8B39A87B4}] => (Allow) C:\Users\Labrat\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{ECC55AE8-39CD-45A3-A75A-C9B353AFF6BF}] => (Allow) D:\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe
FirewallRules: [{D1AD6B48-B833-45B6-8338-6A93997E6580}] => (Allow) D:\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe
FirewallRules: [TCP Query User{2140A85B-474B-448B-B0BA-F001F5C2771B}D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Allow) D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe
FirewallRules: [UDP Query User{4B2530F3-1474-4B3F-AD4E-B53D11CA9E7A}D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Allow) D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe
FirewallRules: [{7597E5E9-88B6-4545-A928-C439AED8A320}] => (Allow) D:\Steam\SteamApps\common\empire total war\Empire.exe
FirewallRules: [{3BF6963C-554F-46E0-8D15-5D73B50ABD6F}] => (Allow) D:\Steam\SteamApps\common\empire total war\Empire.exe
FirewallRules: [{2EB08BCB-C794-4089-A078-CBD343B17ECC}] => (Allow) D:\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{4FF19DA1-C94E-49EA-B0E6-6365BFC4A393}] => (Allow) D:\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{D9BA9A78-F11F-4FC8-A201-1C2961E56EDB}] => (Allow) D:\Steam\SteamApps\common\the witcher 2\Launcher.exe
FirewallRules: [{65698631-0608-479C-A101-A7B4C19FE62B}] => (Allow) D:\Steam\SteamApps\common\the witcher 2\Launcher.exe
FirewallRules: [TCP Query User{69D9A361-F300-4DDF-9FED-9BA439BD4B3D}D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [UDP Query User{8848E9EE-30EC-4BD5-AAEE-E58EBE023C69}D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Allow) D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe
FirewallRules: [{BB612E1E-76BE-4843-B40B-73E6AB383C69}] => (Allow) D:\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe
FirewallRules: [{7D73DA38-2248-4804-94B3-5BFBD60168A5}] => (Allow) D:\Steam\SteamApps\common\fallout new vegas\FalloutNVLauncher.exe
FirewallRules: [{C509595F-AC55-41AE-9479-88A4B873A69B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{A15E07EE-A643-4078-9C0F-89C01588ED1A}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{940CEF92-C3E2-4C65-A9A6-1361AD20861D}] => (Allow) D:\Steam\SteamApps\common\Anno 2070\Anno5.exe
FirewallRules: [{FFD4659C-9469-430A-A21A-2684BD3279DD}] => (Allow) D:\Steam\SteamApps\common\Anno 2070\Anno5.exe
FirewallRules: [TCP Query User{FBD85B1D-9BEE-4B0D-BB9F-6D78BCE461D1}D:\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) D:\steam\steamapps\common\total war rome ii\rome2.exe
FirewallRules: [UDP Query User{B686D8B7-9937-4237-AFBC-B77D3BC7B6A4}D:\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) D:\steam\steamapps\common\total war rome ii\rome2.exe
FirewallRules: [{1B8658A6-884D-4999-B4FC-45F4551CFB2F}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
FirewallRules: [{8E03D2ED-FA73-4C29-8764-A32F6CB0E3E2}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
FirewallRules: [{0BF89F08-A2E3-4A10-B375-2A8858128828}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\stats.com
FirewallRules: [{20C821A9-CE43-47C0-BEAE-071C5F6AC58F}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\stats.exe
FirewallRules: [{62231418-B861-42BB-8F52-1BA288D103F3}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\WinWrapIDE.exe
FirewallRules: [{5DB254A6-2ADD-416A-A628-0325A91F737A}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\stats.com
FirewallRules: [{DE43F1E5-A15C-4D00-9788-355F131EA554}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\stats.exe
FirewallRules: [{8849F072-7E49-4BCB-A7F4-20D6A89F2018}] => (Allow) C:\Program Files\IBM\SPSS\Statistics\22\WinWrapIDE.exe
FirewallRules: [TCP Query User{F5E7AB23-E173-4B6C-A22D-801C876A6A7E}C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe] => (Allow) C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe
FirewallRules: [UDP Query User{F10331A3-46C3-4146-8131-D263F07FF058}C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe] => (Allow) C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe
FirewallRules: [{6BD068B2-9A97-4246-9E7E-CBC406A27074}] => (Block) C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe
FirewallRules: [{CB2A68C4-332B-4538-A019-C9FC04671933}] => (Block) C:\program files\ibm\spss\statistics\22\jre\bin\javaw.exe
FirewallRules: [{051AD11F-C7BE-4136-ACCB-E554DFFEA9A8}] => (Allow) D:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{ABD71F08-17F0-4AF5-9A1B-C3D3FBFC91B2}] => (Allow) D:\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{0CF197B8-CA2A-4560-B915-4DCD44E58DFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{B8D13929-B6D3-4A00-B238-1E770C2FD2A8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{4914840A-7208-426B-9434-FE38C4163807}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{A302C88F-CD1B-4A2D-8A40-75D6D6A1F5E4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{6B2B461C-423F-4FF9-AD7C-7F958ABE1FBC}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe
FirewallRules: [{D6FECA2A-28D7-4E13-9EFA-F73A7B3D753B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe
FirewallRules: [{F338572E-8190-411B-BEC4-E32D6EC8DEE8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe
FirewallRules: [{61E3BF50-F810-44A0-A866-1BA35A5CA11F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe
FirewallRules: [{4C2505F2-012D-4FE1-BCBD-57B0507DB7BB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{5F1B4480-B0DA-430F-87A4-054B3B0BE968}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{3710E862-E4E5-4E72-B7FA-4D8FA6C175A8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{193B9EC0-3CF3-4267-A56E-97B03CE13E05}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{839012CD-F482-4D89-BCCA-29998C20D493}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{8DF18A5E-E5B7-4183-A8CD-6ACF46D46532}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{497F0BCD-8999-44F0-BB33-9155CE56E8EF}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe
FirewallRules: [{BFA4CAFD-735B-45DC-BDD3-0921CAA31B75}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe
FirewallRules: [{1D8C62EF-DD0F-45DA-A729-47EC42B48D2E}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe
FirewallRules: [{8BEA3B47-67CF-4CA3-9995-6D4EAB4EEA54}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe
FirewallRules: [{EEA9EE5A-745A-4AD7-9F87-CE7B14E58BB8}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{C1CE430A-9528-4BAC-BEC1-7D8D5B395FFE}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{628836D8-22CA-42C1-997F-E13E12AEC003}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{3316DE6E-A589-4E13-B0B7-227B275B1208}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{2A22422E-E424-45A6-BEEE-DE85E403BE2C}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{5B41C1CC-515E-450B-B1B6-1A60DFD1F1C2}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{ADBF29DB-7F30-49B3-822A-F7F4B24F3792}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{276FDF3F-EE62-4B04-A256-F5188483A507}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{DAC5D431-883F-489E-8D85-961BB2B091C8}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{DAABBEFE-29F6-4106-8FA0-C76C28A8C708}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{C25C4FC3-B032-454E-A1D5-99AFF73852D1}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{AC4D0620-85D3-415C-9B0E-CB7BA3136EE9}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{F26E54F4-AE74-48F3-B7F3-CF08B766B2A9}] => (Allow) D:\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{9FE55117-C929-4559-B464-8E64EB857130}] => (Allow) D:\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{C0ECDE46-1475-4F4B-989D-0D9866EFD4EB}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{326BD206-0B38-40B9-A2F7-A3569D096DB0}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{6B2A40C6-0963-405D-8170-B3CFB8BDA486}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{AE594FF8-3CD9-4669-B71A-67CE9EFB3A9B}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{796A3A4B-980D-4552-9E28-0BB0E1F7A09F}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{63CDB837-5F5E-4129-9120-D0442730D07D}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{2420C9AC-2D2E-48B3-B950-01236B4B7178}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{771018AC-71E0-499A-8C1D-5B9BE9026220}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{F11076A6-8853-4870-A7F4-9AFEDF28300C}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{C2F17E39-2912-4F8D-9EFE-C56EEC17068D}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{569D74D5-71AA-48B1-A825-F927C6F346EB}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{F90A15D2-9505-4E6B-99EB-972974DDFF0A}] => (Allow) D:\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{BC7A86E7-3D4F-492F-AB7A-44F5089098F0}] => (Allow) D:\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{ECA8E002-53EA-4F50-9BEC-11ADF2E6662B}] => (Allow) D:\Steam\SteamApps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [TCP Query User{E2050DFC-7C90-46B3-AA5F-CA2D6A57C945}D:\steam\steam.exe] => (Block) D:\steam\steam.exe
FirewallRules: [UDP Query User{77F341AF-2704-496F-96CD-41E4F8CB07E3}D:\steam\steam.exe] => (Block) D:\steam\steam.exe
FirewallRules: [{D7566D8F-04B7-464A-991F-B6FC8E6E55B5}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP1\WNt500x64\RpcSandraSrv.exe
FirewallRules: [{706579DA-6066-46AC-93CA-D477E58627E4}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{07BBEAF9-4842-4F7A-9A9C-A856F27546DE}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{563813B6-9B88-40DA-B6EB-A4703892566A}] => (Allow) C:\Windows\System32\lxbxcoms.exe
FirewallRules: [{C0B6DAC1-67F2-4B72-8FCB-43273DE532F9}] => (Allow) C:\Windows\System32\lxbxcoms.exe
FirewallRules: [{E908E21B-C6DC-4E37-81FD-6DD6D921C257}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{CCADD611-D51A-48D1-9BD7-A045405CF576}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{0F0F3420-1D30-4F36-899C-02DD20E53DDF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{D0B948E8-B62F-432A-ABC6-3EFDCFBCCDA7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [TCP Query User{F791548F-FD52-4135-AFB5-39991521FF61}D:\spiele\diablo iii\diablo iii.exe] => (Allow) D:\spiele\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{FD8776A8-DE52-4E42-8F02-4FDADE2ECF2E}D:\spiele\diablo iii\diablo iii.exe] => (Allow) D:\spiele\diablo iii\diablo iii.exe
FirewallRules: [TCP Query User{AA892CE1-EF61-4F68-9F1E-D91F1B7E43F3}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe] => (Allow) C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe
FirewallRules: [UDP Query User{0CFF3757-BC86-4C11-954E-CDB1101B157B}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe] => (Allow) C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe
FirewallRules: [{7C1143C5-6392-431A-80AB-436E188C4FAA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{A3F06CD0-05A7-41BB-8A6D-039F092D265F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{A3C85FBE-EE0B-4761-8B43-4BBAD87B6E5B}] => (Allow) D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\Baldur.exe
FirewallRules: [{615125E0-8145-4C71-AAE0-D9438169636E}] => (Allow) D:\Steam\SteamApps\common\Baldur's Gate II Enhanced Edition\Baldur.exe
FirewallRules: [{3B0F2D15-274E-4B18-8962-81AA97277C4D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{46C4B002-0843-4D7A-8228-16E63C6B2E44}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{FF8C746D-27AF-4788-B3E5-B7C4976BE2B3}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{008B3B0F-87FC-4B71-8CE8-342CDCC2D841}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{62803D62-B42E-4C55-AAA6-B667CBE3718C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe
FirewallRules: [{54F2096B-F1CC-49AB-B0CD-D6428CED22CC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe
FirewallRules: [{9C4F032B-4A4F-40AA-AAFC-1C86C623CD6E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3322\Agent.exe
FirewallRules: [{0833C379-BA4B-4071-8192-5609359AED29}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3322\Agent.exe
FirewallRules: [{9E0F3323-8886-4FC2-92D2-FD9E2BE48DAA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3323\Agent.exe
FirewallRules: [{58D9CFE9-8209-488B-914B-4A96C852557E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3323\Agent.exe
FirewallRules: [{77D32B21-6B34-4E67-95D6-701ABBA3D0FA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3332\Agent.exe
FirewallRules: [{D943169B-019D-45C4-BF40-63255F77F75B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3332\Agent.exe
FirewallRules: [{E872EACA-9FA3-48E5-8B5E-07D30C5F3038}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe
FirewallRules: [{5A50DE21-090C-4871-9476-2659EB7AF6C2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe
FirewallRules: [TCP Query User{C72F3FD4-ED57-49B2-9421-62D44F9AB1E8}C:\programdata\battle.net\agent\agent.3346\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3346\agent.exe
FirewallRules: [UDP Query User{94E56DCF-A785-4DE8-B7D8-C913CD5E2D26}C:\programdata\battle.net\agent\agent.3346\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3346\agent.exe
FirewallRules: [{99B59D30-55ED-4913-9498-F2BA56C471D8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7C28DA0A-889C-432E-998E-37B9254F3625}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2262B5AD-66DF-46CB-AF37-668982D3C491}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{23E62406-0337-47A1-9037-528C70D5487B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{ADEBC4B7-0702-40A4-A1BE-4EEEC4E99F18}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{70006993-4B02-413E-8993-2830A1E100D5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
FirewallRules: [{C2370EA4-859F-4B02-ABC3-5549BCEC37C5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe
FirewallRules: [{26114F00-FD61-451E-8896-521B83E87F42}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe
FirewallRules: [{A0D6A84E-BCD2-4145-8D24-3FB4A1E45C7A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe
FirewallRules: [{227D122C-C461-4320-95E1-378A7357E0F9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe
FirewallRules: [{E607223B-3A47-4DA5-BD00-14E0B3B4546E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [{4FA81B24-E4EA-4C41-BCE1-952BF0473A52}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [{FC8CD3EB-3027-45EB-AB22-D1C7CE89BF09}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe
FirewallRules: [{B20398C4-682A-43FF-9D2E-1C4F40126FEA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe
FirewallRules: [{593B72B5-96EC-485B-910B-87995F2E04A9}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{EE34EA22-F787-493A-AFEF-533C94C02128}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{38C3088C-D62F-45A1-922D-56869C203FEF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{7DD5EBDB-3C70-48E6-9364-E184F0FE818F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{62CDC4E1-D810-42CE-8F61-19CA616DDB7B}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{940846B8-B541-4A75-B30A-6E8E00F07B9A}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{2265DD61-5539-4146-B843-BFCEB7F18368}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{0D561DD6-E0BC-4401-A404-E010F6BAD927}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{22150C4B-5363-410F-8F75-68591CF74C97}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{8042C260-98F8-4663-A4CD-864D3F857455}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [TCP Query User{37FC6185-2132-4D36-8B17-DDC4DEF6E68D}D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Allow) D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe
FirewallRules: [UDP Query User{D7A28ABB-6B54-409B-B318-DECF70E536A9}D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe] => (Allow) D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{1F4C1C6B-16AA-4F89-A616-77F7CC21A650}] => (Allow) D:\Steam\SteamApps\common\SourceSDK\bin\SDKLauncher.exe
FirewallRules: [{4EAD0E61-AFCA-42F0-A850-22AF49B4CF77}] => (Allow) D:\Steam\SteamApps\common\SourceSDK\bin\SDKLauncher.exe
FirewallRules: [{E9BB4652-16C4-4058-925A-D7C6D18D82CF}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{488917D1-77F7-4097-A4BA-FAE2946F14DC}] => (Allow) D:\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{030A0317-1CC5-42E2-93AA-CF14EE9B32FD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe
FirewallRules: [{B44E02C5-BE95-4575-9196-ED7AE5F6E03C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe
FirewallRules: [{E27B94E2-DE92-468B-8B17-6C23A3863D3A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5A21C0E9-AA9E-44A2-86FE-A3E5FC3C825F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7F17D424-810D-41E5-B806-F8E1C6F65513}] => (Allow) D:\Steam\SteamApps\common\Company of Heroes 2\RelicCoH2.exe
FirewallRules: [{8E5881E6-A47F-4C5F-B816-8655DB279542}] => (Allow) D:\Steam\SteamApps\common\Company of Heroes 2\RelicCoH2.exe
FirewallRules: [{27253C9F-E037-4F00-AC4C-3F83DC87C743}] => (Allow) D:\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
FirewallRules: [{F7307748-B817-48BA-ABB5-5BE7AEA30C5D}] => (Allow) D:\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
FirewallRules: [{874E307C-8D1B-4920-9CBA-00CCB7B54B00}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{2CA58D27-BB1F-42C5-A216-9A4ACE2BF73E}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{D01A4E9D-F15B-4A81-A7E2-615B4C99C587}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{BBCFD502-3B9E-4CCA-A310-6F16078AE11C}] => (Allow) D:\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe
FirewallRules: [{8C3D5C0B-B6DE-4B52-8EE1-1EA40D79DB99}] => (Allow) D:\Steam\SteamApps\common\Pillars of Eternity\PillarsOfEternity.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot-S&D 2 Tray Icon
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Faulty Device Manager Devices =============

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/08/2015 03:17:07 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/08/2015 02:23:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SuperRAIDSvc.exe, Version: 2.0.0.6, Zeitstempel: 0x53605b30
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18798, Zeitstempel: 0x5507b485
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000c42d
ID des fehlerhaften Prozesses: 0xbec
Startzeit der fehlerhaften Anwendung: 0xSuperRAIDSvc.exe0
Pfad der fehlerhaften Anwendung: SuperRAIDSvc.exe1
Pfad des fehlerhaften Moduls: SuperRAIDSvc.exe2
Berichtskennung: SuperRAIDSvc.exe3

Error: (05/08/2015 02:23:24 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: SuperRAIDSvc.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
   bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
   bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
   bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance()
   bei SuperRAID.Common.SyncObject..ctor()
   bei SuperRAIDSvc.MainService.<OnStart>b__0()
   bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   bei System.Threading.ThreadHelper.ThreadStart()

Error: (05/08/2015 08:32:43 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (05/08/2015 08:09:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: spoolsv.exe, Version: 6.1.7601.17777, Zeitstempel: 0x4f35fc1d
Name des fehlerhaften Moduls: msvcrt.dll, Version: 7.0.7601.17744, Zeitstempel: 0x4eeb033f
Ausnahmecode: 0x40000015
Fehleroffset: 0x000000000002a84e
ID des fehlerhaften Prozesses: 0x618
Startzeit der fehlerhaften Anwendung: 0xspoolsv.exe0
Pfad der fehlerhaften Anwendung: spoolsv.exe1
Pfad des fehlerhaften Moduls: spoolsv.exe2
Berichtskennung: spoolsv.exe3

Error: (05/08/2015 08:09:36 AM) (Source: ATIeRecord) (EventID: 16386) (User: )
Description: ATI EEU Client has failed to start

Error: (05/08/2015 07:53:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SuperRAIDSvc.exe, Version: 2.0.0.6, Zeitstempel: 0x53605b30
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18798, Zeitstempel: 0x5507b485
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000c42d
ID des fehlerhaften Prozesses: 0xfe0
Startzeit der fehlerhaften Anwendung: 0xSuperRAIDSvc.exe0
Pfad der fehlerhaften Anwendung: SuperRAIDSvc.exe1
Pfad des fehlerhaften Moduls: SuperRAIDSvc.exe2
Berichtskennung: SuperRAIDSvc.exe3

Error: (05/08/2015 07:53:19 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: SuperRAIDSvc.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
   bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
   bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
   bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance()
   bei SuperRAID.Common.SyncObject..ctor()
   bei SuperRAIDSvc.MainService.<OnStart>b__0()
   bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   bei System.Threading.ThreadHelper.ThreadStart()

Error: (05/07/2015 11:23:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: SuperRAIDSvc.exe, Version: 2.0.0.6, Zeitstempel: 0x53605b30
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18798, Zeitstempel: 0x5507b485
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000c42d
ID des fehlerhaften Prozesses: 0xcc4
Startzeit der fehlerhaften Anwendung: 0xSuperRAIDSvc.exe0
Pfad der fehlerhaften Anwendung: SuperRAIDSvc.exe1
Pfad des fehlerhaften Moduls: SuperRAIDSvc.exe2
Berichtskennung: SuperRAIDSvc.exe3

Error: (05/07/2015 11:23:13 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: SuperRAIDSvc.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
   bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
   bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
   bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance()
   bei SuperRAID.Common.SyncObject..ctor()
   bei SuperRAIDSvc.MainService.<OnStart>b__0()
   bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   bei System.Threading.ThreadHelper.ThreadStart()


System errors:
=============
Error: (05/08/2015 03:18:28 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:17:27 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:15:33 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:15:30 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:15:26 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:15:22 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:15:19 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:14:57 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:14:42 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.

Error: (05/08/2015 03:14:36 PM) (Source: atapi) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort0 gefunden.


Microsoft Office Sessions:
=========================
Error: (05/08/2015 03:17:07 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Labrat\Downloads\esetsmartinstaller_deu.exe

Error: (05/08/2015 02:23:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: SuperRAIDSvc.exe2.0.0.653605b30KERNELBASE.dll6.1.7601.187985507b485e04343520000c42dbec01d08989c5c7bedeC:\MSI\Smart Utilities\SuperRAIDSvc.exeC:\Windows\syswow64\KERNELBASE.dll1097c21f-f57d-11e4-9d2f-0024211056dd

Error: (05/08/2015 02:23:24 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: SuperRAIDSvc.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
   bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
   bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
   bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance()
   bei SuperRAID.Common.SyncObject..ctor()
   bei SuperRAIDSvc.MainService.<OnStart>b__0()
   bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   bei System.Threading.ThreadHelper.ThreadStart()

Error: (05/08/2015 08:32:43 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: assemblyIdentityprocessorArchitecturex64c:\program files\R\r-2.15.3\Tcl\bin64\tk85.dllc:\program files\R\r-2.15.3\Tcl\bin64\tk85.dll9

Error: (05/08/2015 08:09:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: spoolsv.exe6.1.7601.177774f35fc1dmsvcrt.dll7.0.7601.177444eeb033f40000015000000000002a84e61801d089532780ee9bC:\Windows\System32\spoolsv.exeC:\Windows\system32\msvcrt.dlld7309a3c-f548-11e4-a775-0024211056dd

Error: (05/08/2015 08:09:36 AM) (Source: ATIeRecord) (EventID: 16386) (User: )
Description: 

Error: (05/08/2015 07:53:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: SuperRAIDSvc.exe2.0.0.653605b30KERNELBASE.dll6.1.7601.187985507b485e04343520000c42dfe001d0895348b3e20cC:\MSI\Smart Utilities\SuperRAIDSvc.exeC:\Windows\syswow64\KERNELBASE.dll9480372a-f546-11e4-a775-0024211056dd

Error: (05/08/2015 07:53:19 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: SuperRAIDSvc.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
   bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
   bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
   bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance()
   bei SuperRAID.Common.SyncObject..ctor()
   bei SuperRAIDSvc.MainService.<OnStart>b__0()
   bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   bei System.Threading.ThreadHelper.ThreadStart()

Error: (05/07/2015 11:23:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: SuperRAIDSvc.exe2.0.0.653605b30KERNELBASE.dll6.1.7601.187985507b485e04343520000c42dcc401d0890c059ae101C:\MSI\Smart Utilities\SuperRAIDSvc.exeC:\Windows\syswow64\KERNELBASE.dll515275a7-f4ff-11e4-8972-0024211056dd

Error: (05/07/2015 11:23:13 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: SuperRAIDSvc.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Reflection.TargetInvocationException
Stapel:
   bei System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
   bei System.Reflection.RuntimeConstructorInfo.Invoke(System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo)
   bei SuperRAID.Common.Singleton`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].get_Instance()
   bei SuperRAID.Common.SyncObject..ctor()
   bei SuperRAIDSvc.MainService.<OnStart>b__0()
   bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   bei System.Threading.ThreadHelper.ThreadStart()


CodeIntegrity Errors:
===================================
  Date: 2015-05-07 23:17:08.193
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\nvlddmkm.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-05-07 23:17:08.006
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\nvlddmkm.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-04-24 14:33:28.057
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-04-24 14:33:27.952
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-04-24 14:33:23.892
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-04-24 14:33:23.782
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-04-22 20:50:00.729
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-04-22 20:50:00.636
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-04-22 10:44:57.233
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2015-04-22 10:44:57.130
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\WUDFRd.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info =========================== 

Processor: AMD Phenom(tm) II X4 940 Processor
Percentage of memory in use: 62%
Total physical RAM: 6143.18 MB
Available physical RAM: 2273.74 MB
Total Pagefile: 12284.55 MB
Available Pagefile: 7161.74 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:195.31 GB) (Free:13.49 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:400.86 GB) (Free:60.68 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: D91548F4)
Partition 1: (Active) - (Size=195.3 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=400.9 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
Malwarebyte (bevor die Korrekturen angewandt wurden)

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 06-May-15
Suchlauf-Zeit: 11:54:12 AM
Logdatei: Malwarebyte.txt
Administrator: Ja

Version: 2.01.6.1022
Malware Datenbank: v2015.05.06.01
Rootkit Datenbank: v2015.04.21.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Labrat

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 425010
Verstrichene Zeit: 20 Min, 41 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente gefunden)

Module: 0
(Keine schädliche Elemente gefunden)

Registrierungsschlüssel: 1
PUP.Optional.PriceGong.A, HKU\S-1-5-21-1690515653-3619170862-1892073707-1001\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [acbdbed26624181e6e75b72d986b956b], 

Registrierungswerte: 0
(Keine schädliche Elemente gefunden)

Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)

Ordner: 2
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data, , [96d3fe927218ea4c2a65ff9ea95ac33d], 

Dateien: 29
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\1.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\7031.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\a.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\b.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\c.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\d.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\e.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\f.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\g.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\h.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\i.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\j.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\k.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\l.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\m.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\n.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\o.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\p.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\q.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\r.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\s.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\t.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\u.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\v.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\w.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\wlu.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\x.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\y.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 
PUP.Optional.PriceGong.A, C:\Users\Labrat\AppData\LocalLow\PriceGong\Data\z.txt, , [96d3fe927218ea4c2a65ff9ea95ac33d], 

Physische Sektoren: 0
(Keine schädliche Elemente gefunden)


(end)
         
AdwCleaner (bevor die Korrekturen angewandt wurden)
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v4.203 - Bericht erstellt 06/05/2015 um 12:19:32
# Aktualisiert 30/04/2015 von Xplode
# Datenbank : 2015-05-05.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x64)
# Benutzername : Labrat - MAX_POWERS
# Gestarted von : C:\Users\Labrat\Downloads\AdwCleaner_4.203.exe
# Option : Suchlauf

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gefunden : C:\Program Files (x86)\Conduit
Ordner Gefunden : C:\Program Files (x86)\Innovative Solutions
Ordner Gefunden : C:\ProgramData\Ask
Ordner Gefunden : C:\ProgramData\Innovative Solutions
Ordner Gefunden : C:\ProgramData\Yahoo! Companion
Ordner Gefunden : C:\Users\Labrat\AppData\Local\Innovative Solutions
Ordner Gefunden : C:\Users\Labrat\AppData\LocalLow\Conduit
Ordner Gefunden : C:\Users\Labrat\AppData\LocalLow\HPAppData
Ordner Gefunden : C:\Users\Labrat\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gefunden : C:\Users\Labrat\AppData\Roaming\Innovative Solutions
Ordner Gefunden : C:\Users\Labrat_Adm\AppData\Local\Innovative Solutions
Ordner Gefunden : C:\Users\Labrat_Adm\AppData\Roaming\Innovative Solutions

***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Daten Gefunden : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\IGearSettings
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Schlüssel Gefunden : HKCU\Software\YahooPartnerToolbar
Schlüssel Gefunden : [x64] HKCU\Software\IGearSettings
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gefunden : [x64] HKCU\Software\YahooPartnerToolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gefunden : HKLM\SOFTWARE\Conduit
Schlüssel Gefunden : HKLM\SOFTWARE\dt soft\daemon tools toolbar
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494
Schlüssel Gefunden : HKU\.DEFAULT\Software\AVG Secure Search
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17728


-\\ Mozilla Firefox v37.0.2 (x86 de)

[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("avira.safe_search.installed", "[\"safesearch\"]");
[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"147d364d9f3122-0b5875d98fc388-42504136-0-147d364d9f4158\"");
[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.SAUTH_expires_at", "1430947836");
[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.SAUTH_rndsnr", "\"f3f3b3797c8e8c1b9c24f28568cfd789761483c1\"");
[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.SAUTH_userid", "5717590696");
[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.SAUTH_utoken", "\"e41a95ebf9142febd7b8a86a06660135877cddba\"");
[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.install", "1418741824383");
[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.safesearch.search_offer_disabled", "true");
[d5h5b9mo.default-1412722597851] - Zeile Gefunden : user_pref("extensions.xpiState", "{\"app-profile\":{\"safesearch@avira.com\":{\"d\":\"C:\\\\Users\\\\Labrat\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\d5h5b9mo.default-1412722597851\\\[...]

-\\ Google Chrome v


-\\ Chromium v


-\\ Opera v29.0.1795.47


*************************

AdwCleaner[R0].txt - [7049 Bytes] - [06/05/2015 12:19:32]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [7108 Bytes] ##########
         
--- --- ---

[/CODE]

JRT

JRT Logfile:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.7 (04.30.2015:1)
OS: Windows 7 Professional x64
Ran by Labrat on 06-May-15 at 12:26:38.45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88}



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3A2D5EBA-F86D-4BD3-A177-019765996711}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] C:\Program Files (x86)\conduit
Successfully deleted: [Folder] C:\Users\Labrat\appdata\locallow\conduit
Successfully deleted: [Folder] C:\Users\Labrat\AppData\Roaming\dvdvideosoftiehelpers



~~~ FireFox

Successfully deleted: [File] C:\Users\Labrat\AppData\Roaming\mozilla\firefox\profiles\d5h5b9mo.default-1412722597851\searchplugins\avira-safesearch.xml
Successfully deleted: [Folder] C:\Users\Labrat\AppData\Roaming\mozilla\firefox\profiles\d5h5b9mo.default-1412722597851\extensions\safesearch@avira.com
Successfully deleted the following from C:\Users\Labrat\AppData\Roaming\mozilla\firefox\profiles\d5h5b9mo.default-1412722597851\prefs.js

user_pref(avira.safe_search.installed, [\safesearch\]);
user_pref(avira.safe_search.search_was_active, false);
user_pref(browser.uiCustomization.state, {\placements\:{\PanelUI-contents\:[\edit-controls\,\zoom-controls\,\new-window-button\,\privatebrowsing-button\,\save-
user_pref(extensions.bootstrappedAddons, {\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\:{\version\:\2.6.9\,\type\:\extension\,\descriptor\:\C:\\\\Users\\\\Labrat\\\
user_pref(extensions.safesearch.MP_DISTINCT_ID, \147d364d9f3122-0b5875d98fc388-42504136-0-147d364d9f4158\);
user_pref(extensions.safesearch.SAUTH_expires_at, 1430947836);
user_pref(extensions.safesearch.SAUTH_rndsnr, \f3f3b3797c8e8c1b9c24f28568cfd789761483c1\);
user_pref(extensions.safesearch.SAUTH_userid, 5717590696);
user_pref(extensions.safesearch.SAUTH_utoken, \e41a95ebf9142febd7b8a86a06660135877cddba\);
user_pref(extensions.safesearch.install, 1418741824383);
user_pref(extensions.safesearch.search_offer_disabled, true);
user_pref(extensions.xpiState, {\app-profile\:{\safesearch@avira.com\:{\d\:\C:\\\\Users\\\\Labrat\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\d5h5b9mo
Emptied folder: C:\Users\Labrat\AppData\Roaming\mozilla\firefox\profiles\d5h5b9mo.default-1412722597851\minidumps [45 files]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06-May-15 at 12:29:10.77
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
--- --- ---
__________________


Alt 08.05.2015, 15:54   #3
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



Hi,

die ZIP muss entpackt und ausgeführt werden, erst dann passiert was
__________________
__________________

Alt 08.05.2015, 18:23   #4
Labrat
 
DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



Hallo schrauber,

verzeih mir meine Paranoia! Danke fürs Beruhigen

Eine Frage noch: Was hat der zweite Kapersky Scan da gefunden? Im Internet habe ich erfahren das es sich um eine Windows Treiberdatei handelt. Es ist ja nur als "medium risk" eingeordnet worden.

Pax,
Stefan

Alt 09.05.2015, 16:26   #5
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



Ich sehe kein Log von Kaspersky. Was wurde denn genau gefunden?

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 10.05.2015, 11:37   #6
Labrat
 
DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



Der "normale" Kaspersky-Scan hatte nichts gefunden erst nachdem ich das Häckchen bei "Verify digital signature" gemacht und dann findet er zumindest einen "suspicious file": Service:WUDFRd...!?

Code:
ATTFilter
12:34:23.0917 0x1f3c  TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
12:34:28.0251 0x1f3c  ============================================================
12:34:28.0251 0x1f3c  Current date / time: 2015/05/10 12:34:28.0251
12:34:28.0252 0x1f3c  SystemInfo:
12:34:28.0252 0x1f3c  
12:34:28.0252 0x1f3c  OS Version: 6.1.7601 ServicePack: 1.0
12:34:28.0252 0x1f3c  Product type: Workstation
12:34:28.0252 0x1f3c  ComputerName: MAX_POWERS
12:34:28.0252 0x1f3c  UserName: Labrat
12:34:28.0252 0x1f3c  Windows directory: C:\Windows
12:34:28.0253 0x1f3c  System windows directory: C:\Windows
12:34:28.0253 0x1f3c  Running under WOW64
12:34:28.0253 0x1f3c  Processor architecture: Intel x64
12:34:28.0253 0x1f3c  Number of processors: 4
12:34:28.0253 0x1f3c  Page size: 0x1000
12:34:28.0253 0x1f3c  Boot type: Normal boot
12:34:28.0253 0x1f3c  ============================================================
12:34:32.0891 0x1f3c  KLMD registered as C:\Windows\system32\drivers\04246906.sys
12:34:33.0364 0x1f3c  System UUID: {4552459F-87A3-1086-4CE0-A18B4A2CB915}
12:34:34.0368 0x1f3c  Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 ( 596.17 Gb ), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:34:34.0387 0x1f3c  ============================================================
12:34:34.0387 0x1f3c  \Device\Harddisk0\DR0:
12:34:34.0393 0x1f3c  MBR partitions:
12:34:34.0393 0x1f3c  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x186A0000
12:34:34.0393 0x1f3c  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x186A0800, BlocksNum 0x321B7000
12:34:34.0393 0x1f3c  ============================================================
12:34:34.0415 0x1f3c  C: <-> \Device\Harddisk0\DR0\Partition1
12:34:34.0475 0x1f3c  D: <-> \Device\Harddisk0\DR0\Partition2
12:34:34.0476 0x1f3c  ============================================================
12:34:34.0476 0x1f3c  Initialize success
12:34:34.0476 0x1f3c  ============================================================
12:34:40.0107 0x0ddc  ============================================================
12:34:40.0107 0x0ddc  Scan started
12:34:40.0107 0x0ddc  Mode: Manual; SigCheck; 
12:34:40.0107 0x0ddc  ============================================================
12:34:40.0107 0x0ddc  KSN ping started
12:34:43.0430 0x0ddc  KSN ping finished: true
12:34:48.0129 0x0ddc  ================ Scan system memory ========================
12:34:48.0129 0x0ddc  System memory - ok
12:34:48.0130 0x0ddc  ================ Scan services =============================
12:34:48.0432 0x0ddc  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
12:34:49.0000 0x0ddc  1394ohci - ok
12:34:49.0266 0x0ddc  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
12:34:49.0409 0x0ddc  ACPI - ok
12:34:49.0480 0x0ddc  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
12:34:50.0327 0x0ddc  AcpiPmi - ok
12:34:50.0673 0x0ddc  [ D0B11E40EA74A98A5E133DF1F5276240, BAD5885CD8CC271D59DFA95159EFC3AC36D2BA11B6DA593AAED0C45F1C2F280F ] acsock          C:\Windows\system32\DRIVERS\acsock64.sys
12:34:51.0402 0x0ddc  acsock - ok
12:34:52.0190 0x0ddc  [ 177FF6608B48638D4066726F3A3F8444, D0D7B7EAEFDF30210CE4D31E9C7AB349CEB862A452D5925E698B60204AAE8A49 ] AdobeActiveFileMonitor5.0 C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
12:34:52.0594 0x0ddc  AdobeActiveFileMonitor5.0 - detected UnsignedFile.Multi.Generic ( 1 )
12:34:55.0014 0x0ddc  Detect skipped due to KSN trusted
12:34:55.0014 0x0ddc  AdobeActiveFileMonitor5.0 - ok
12:34:55.0295 0x0ddc  [ FC5B75CA6A1DA31EDD4F8D53F5540B98, CDC445F2790ADFC4C5568C40D4DA8BB95CD71991665B38AEC3D84571C99C3520 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
12:34:55.0343 0x0ddc  AdobeARMservice - ok
12:34:55.0619 0x0ddc  [ AAF87A1B230B1E5585EA742C633A5414, 181E3E8EB91BF411C527C07F67AE47938740CBC2DADFC22053A25FEB842D5EFA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:34:55.0633 0x0ddc  AdobeFlashPlayerUpdateSvc - ok
12:34:55.0756 0x0ddc  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
12:34:55.0826 0x0ddc  adp94xx - ok
12:34:55.0894 0x0ddc  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
12:34:55.0965 0x0ddc  adpahci - ok
12:34:55.0988 0x0ddc  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
12:34:56.0023 0x0ddc  adpu320 - ok
12:34:56.0054 0x0ddc  [ 83BFCCAC53795E8A5055A93672D0C46C, B2B03473D950A5BA9DE59D81E7B14C1FAFF17B2A4D8A5808588F5CC21D63B291 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
12:34:56.0162 0x0ddc  AeLookupSvc - ok
12:34:56.0305 0x0ddc  [ FA886682CFC5D36718D3E436AACF10B9, F80AB4F91AA6B5C7ECCB000D8E1BC2CF776DC3D69B3D9EBC2558C19035A6B3AB ] AFD             C:\Windows\system32\drivers\afd.sys
12:34:56.0510 0x0ddc  AFD - ok
12:34:56.0574 0x0ddc  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\drivers\agp440.sys
12:34:56.0676 0x0ddc  agp440 - ok
12:34:56.0715 0x0ddc  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG             C:\Windows\System32\alg.exe
12:34:56.0857 0x0ddc  ALG - ok
12:34:56.0892 0x0ddc  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
12:34:56.0918 0x0ddc  aliide - ok
12:34:56.0966 0x0ddc  [ 5C8C9AAB596582AFFD94939917D8FB13, 3F9BC512E41D14AC35F7035D5E2B4ADDA1948488DA2822C692E612CF3FF3DAEA ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
12:34:57.0096 0x0ddc  AMD External Events Utility - ok
12:34:57.0171 0x0ddc  AMD FUEL Service - ok
12:34:57.0194 0x0ddc  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
12:34:57.0233 0x0ddc  amdide - ok
12:34:57.0307 0x0ddc  [ 35D34AD337A1AC46F74C3377B4CCA88E, 046695BDF540EDCA87C36EDC725615ACA99DA57558A54CAC1B49F245D702B406 ] amdide64        C:\Windows\system32\DRIVERS\amdide64.sys
12:34:57.0329 0x0ddc  amdide64 - ok
12:34:57.0493 0x0ddc  [ 6A2EEB0C4133B20773BB3DD0B7B377B4, E4CB35C6937C70A145A13E5AE5B34A271B49101DA623171ACBFDA8601E5A70EA ] amdiox64        C:\Windows\system32\DRIVERS\amdiox64.sys
12:34:57.0558 0x0ddc  amdiox64 - ok
12:34:57.0625 0x0ddc  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
12:34:57.0774 0x0ddc  AmdK8 - ok
12:34:57.0904 0x0ddc  [ F2FF8C1B41B3784EDBD5C6D5397F403C, 104873700D2BDF4812DC48200B4609F46A63E7A50594A0599100EF1438863708 ] amdkmafd        C:\Windows\system32\DRIVERS\amdkmafd.sys
12:34:57.0966 0x0ddc  amdkmafd - ok
12:34:59.0335 0x0ddc  [ 538B0A6E89ACA1929668F9EB95D3C0BC, 1447EA64848F7B90F0963E8B7016687E93CCF19E2DE912B4ED71AF96C0BEA45A ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
12:35:00.0045 0x0ddc  amdkmdag - ok
12:35:00.0183 0x0ddc  [ 977286B382FE0920F379A69C351A7AF4, 0EB260640825A3F04D2A0B687CF0D3BC54CB36BDD8BA23057AF99984ADE1AAF3 ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
12:35:00.0493 0x0ddc  amdkmdap - ok
12:35:00.0589 0x0ddc  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
12:35:00.0639 0x0ddc  AmdPPM - ok
12:35:00.0743 0x0ddc  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
12:35:00.0798 0x0ddc  amdsata - ok
12:35:00.0964 0x0ddc  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
12:35:01.0053 0x0ddc  amdsbs - ok
12:35:01.0083 0x0ddc  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata         C:\Windows\system32\drivers\amdxata.sys
12:35:01.0139 0x0ddc  amdxata - ok
12:35:01.0711 0x0ddc  [ D908096B873B940BB438CE63BA35BD1E, F1C79C907E6CDBC2770C16AFFAE0D6F9B9B7DA21F5074D602AC5FE1597975748 ] AntiVirMailService C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
12:35:01.0770 0x0ddc  AntiVirMailService - ok
12:35:02.0041 0x0ddc  [ EC705D6ED3A7F3D9AE42F6239707D9FE, B50F6BB0FC308E7403B1807DF2AAF87BEDE0B044128C580970A26801CCABC43F ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
12:35:02.0076 0x0ddc  AntiVirSchedulerService - ok
12:35:02.0478 0x0ddc  [ EC705D6ED3A7F3D9AE42F6239707D9FE, B50F6BB0FC308E7403B1807DF2AAF87BEDE0B044128C580970A26801CCABC43F ] AntiVirService  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
12:35:02.0502 0x0ddc  AntiVirService - ok
12:35:02.0854 0x0ddc  [ 0F3D12E5FAE0082DB3F306095CA6B027, 726D054357031F45B43C87D798E84FA93439ECA6C691EB8C76FE524B50C25B32 ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
12:35:02.0981 0x0ddc  AntiVirWebService - ok
12:35:03.0092 0x0ddc  [ D7253A1A7A49FA40EF0BA1955AAFB346, 0C84A844F06D414F1A6793C9330B7B1474641B569EFEB5F64F29C0D11E59E631 ] AODDriver4.1    C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
12:35:03.0119 0x0ddc  AODDriver4.1 - ok
12:35:03.0196 0x0ddc  [ 90C53BD47979FB8814F465A08B885102, 5EDFC1909FC1FF9133A534DFCC5408CF3A777AC41FB21FAD375436E3D86C02EC ] AppID           C:\Windows\system32\drivers\appid.sys
12:35:03.0303 0x0ddc  AppID - ok
12:35:03.0326 0x0ddc  [ 72D4757510FDA69D729169C00AFC211E, FB9686D0D94EE7C19A3994C29E8331A6EC3020B2980B2CC75F72F3AB25512C15 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
12:35:03.0365 0x0ddc  AppIDSvc - ok
12:35:03.0407 0x0ddc  [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo         C:\Windows\System32\appinfo.dll
12:35:03.0509 0x0ddc  Appinfo - ok
12:35:03.0693 0x0ddc  [ 612CB66D93ED0F2F21BB109840C7D813, 75484123DA27B8942B13148FCF061C75A08A50386A095143736B593E9C772173 ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
12:35:03.0726 0x0ddc  Apple Mobile Device Service - ok
12:35:03.0816 0x0ddc  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt         C:\Windows\System32\appmgmts.dll
12:35:03.0982 0x0ddc  AppMgmt - ok
12:35:04.0036 0x0ddc  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc             C:\Windows\system32\DRIVERS\arc.sys
12:35:04.0067 0x0ddc  arc - ok
12:35:04.0084 0x0ddc  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
12:35:04.0111 0x0ddc  arcsas - ok
12:35:04.0872 0x0ddc  [ F15AB80B867D3332D5DDFB0A05B9CE04, 5A16577106246AB5DCC04FE0A0B00B7C5702557B75F958721E4C00383AB99809 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
12:35:04.0985 0x0ddc  aspnet_state - ok
12:35:05.0056 0x0ddc  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
12:35:07.0019 0x0ddc  AsyncMac - ok
12:35:07.0067 0x0ddc  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi           C:\Windows\system32\drivers\atapi.sys
12:35:07.0081 0x0ddc  atapi - ok
12:35:07.0194 0x0ddc  [ CBE5F8B3E54198F5DFE403A55A95DE08, A0A67A277CAEE39E401BFBE5EA51643EB67A0B5B742B30F24EFC1558BE8999E8 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
12:35:07.0224 0x0ddc  AtiHDAudioService - ok
12:35:07.0305 0x0ddc  [ 77C149E6D702737B2E372DEE166FAEF8, D18FEAE9D915D5F25B787B755F9C6321A9C9506D4F563DD637E3586401E36053 ] AtiHdmiService  C:\Windows\system32\drivers\AtiHdmi.sys
12:35:07.0401 0x0ddc  AtiHdmiService - ok
12:35:08.0547 0x0ddc  [ 538B0A6E89ACA1929668F9EB95D3C0BC, 1447EA64848F7B90F0963E8B7016687E93CCF19E2DE912B4ED71AF96C0BEA45A ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
12:35:08.0723 0x0ddc  atikmdag - ok
12:35:08.0850 0x0ddc  [ E82E61F46D1336447F4DEFF8C074F13E, 9FC152B33F1D9F5684B687743E943AA26AC17A1093F4C31A43C7012E70BC302E ] AtiPcie         C:\Windows\system32\DRIVERS\AtiPcie64.sys
12:35:08.0899 0x0ddc  AtiPcie - ok
12:35:08.0977 0x0ddc  [ B07E6681D303A612680223C729B021E2, DEF063A2A45B5FAF3B676AD5025417B9437A073D9BB2A47F57A0FCCBC78C2FEE ] ATITool         C:\Windows\system32\DRIVERS\ATITool64.sys
12:35:09.0041 0x0ddc  ATITool - detected UnsignedFile.Multi.Generic ( 1 )
12:35:11.0444 0x0ddc  Detect skipped due to KSN trusted
12:35:11.0444 0x0ddc  ATITool - ok
12:35:11.0496 0x0ddc  [ FC0E8778C000291CAF60EB88C011E931, 09BCCA3DE01021AEF76DFB46F01D21BA6FF409E816FA7547E5C3DFBF3A615ED2 ] atksgt          C:\Windows\system32\DRIVERS\atksgt.sys
12:35:11.0520 0x0ddc  atksgt - ok
12:35:11.0569 0x0ddc  [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:35:11.0623 0x0ddc  AudioEndpointBuilder - ok
12:35:11.0640 0x0ddc  [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioSrv        C:\Windows\System32\Audiosrv.dll
12:35:11.0664 0x0ddc  AudioSrv - ok
12:35:11.0718 0x0ddc  [ 43B6D229C7DBA9F0FC0FC0C318DB5350, F5A525DBD71FC4A323E92839C6D27F323FB304B7E9FFA35E89E9B419570AA4C8 ] avgntflt        C:\Windows\system32\DRIVERS\avgntflt.sys
12:35:11.0737 0x0ddc  avgntflt - ok
12:35:11.0799 0x0ddc  [ 626D1BAD7A1975A8FEE8876A8AD0EEA7, 59772746A2DF3B7E8D021756B8A64569AC8468CA1C802EB594494224354F1E60 ] avipbb          C:\Windows\system32\DRIVERS\avipbb.sys
12:35:11.0817 0x0ddc  avipbb - ok
12:35:11.0875 0x0ddc  [ 0D32033DCB359FD98B4C3513EF849FE6, 5870D67526BC29D888DAF8DBAB04B1E97ED5C7C51484ED400A5E65D0EB61576A ] Avira.OE.ServiceHost C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
12:35:11.0931 0x0ddc  Avira.OE.ServiceHost - ok
12:35:11.0970 0x0ddc  [ 390184FAD8FCC1B6DA25AEBAE928C3B6, 537B0E0FAE080B55D70E990BBA0F7F22903CA340F6A42039BAD617A8ECF59119 ] avkmgr          C:\Windows\system32\DRIVERS\avkmgr.sys
12:35:11.0986 0x0ddc  avkmgr - ok
12:35:12.0029 0x0ddc  [ 13253E5E3B6BDF945B63B336A8C9489B, 671C716E43F89D4BDDAA2BE045CDEBBB569C85BC2BA334E1F550187B79A7740D ] avnetflt        C:\Windows\system32\DRIVERS\avnetflt.sys
12:35:12.0072 0x0ddc  avnetflt - ok
12:35:12.0106 0x0ddc  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\Windows\System32\AxInstSV.dll
12:35:12.0185 0x0ddc  AxInstSV - ok
12:35:12.0229 0x0ddc  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbda.sys
12:35:12.0301 0x0ddc  b06bdrv - ok
12:35:12.0334 0x0ddc  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
12:35:12.0376 0x0ddc  b57nd60a - ok
12:35:12.0421 0x0ddc  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
12:35:12.0519 0x0ddc  BDESVC - ok
12:35:12.0543 0x0ddc  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
12:35:12.0618 0x0ddc  Beep - ok
12:35:12.0692 0x0ddc  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE             C:\Windows\System32\bfe.dll
12:35:12.0779 0x0ddc  BFE - ok
12:35:12.0846 0x0ddc  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\System32\qmgr.dll
12:35:12.0987 0x0ddc  BITS - ok
12:35:13.0024 0x0ddc  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
12:35:13.0050 0x0ddc  blbdrive - ok
12:35:13.0134 0x0ddc  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
12:35:13.0177 0x0ddc  Bonjour Service - ok
12:35:13.0210 0x0ddc  [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
12:35:13.0251 0x0ddc  bowser - ok
12:35:13.0274 0x0ddc  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:35:13.0330 0x0ddc  BrFiltLo - ok
12:35:13.0343 0x0ddc  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:35:13.0357 0x0ddc  BrFiltUp - ok
12:35:13.0379 0x0ddc  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser         C:\Windows\System32\browser.dll
12:35:13.0423 0x0ddc  Browser - ok
12:35:13.0438 0x0ddc  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
12:35:13.0508 0x0ddc  Brserid - ok
12:35:13.0522 0x0ddc  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
12:35:13.0550 0x0ddc  BrSerWdm - ok
12:35:13.0568 0x0ddc  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
12:35:13.0593 0x0ddc  BrUsbMdm - ok
12:35:13.0609 0x0ddc  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
12:35:13.0638 0x0ddc  BrUsbSer - ok
12:35:13.0653 0x0ddc  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
12:35:13.0705 0x0ddc  BTHMODEM - ok
12:35:13.0731 0x0ddc  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv         C:\Windows\system32\bthserv.dll
12:35:13.0800 0x0ddc  bthserv - ok
12:35:13.0829 0x0ddc  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
12:35:13.0872 0x0ddc  cdfs - ok
12:35:13.0906 0x0ddc  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
12:35:13.0971 0x0ddc  cdrom - ok
12:35:14.0008 0x0ddc  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc     C:\Windows\System32\certprop.dll
12:35:14.0061 0x0ddc  CertPropSvc - ok
12:35:14.0098 0x0ddc  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
12:35:14.0151 0x0ddc  circlass - ok
12:35:14.0224 0x0ddc  [ 404B7DF9CA4D1CB675045AF220FF3285, 91FFADE2ABE5C48849E63134D5FFD20671FE0D1720F7D486F904391B3D142C96 ] CLFS            C:\Windows\system32\CLFS.sys
12:35:14.0281 0x0ddc  CLFS - ok
12:35:14.0881 0x0ddc  [ 1352A95AD8150440E0A5DD9745154D74, CF78A6267A246F747844FFA255783B5867B0A7232C65AF6224B25B2FBB893313 ] ClickToRunSvc   C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
12:35:15.0046 0x0ddc  ClickToRunSvc - ok
12:35:15.0108 0x0ddc  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:35:15.0126 0x0ddc  clr_optimization_v2.0.50727_32 - ok
12:35:15.0169 0x0ddc  [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:35:15.0220 0x0ddc  clr_optimization_v2.0.50727_64 - ok
12:35:15.0294 0x0ddc  [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:35:15.0336 0x0ddc  clr_optimization_v4.0.30319_32 - ok
12:35:15.0365 0x0ddc  [ 9ACBE5EC13C2CC95833BFB7636CA8B1A, 6224DA9FB335D2A8374C60B8DEA539DD3A0E43230DB888B137B71A56EC57D6AF ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:35:15.0395 0x0ddc  clr_optimization_v4.0.30319_64 - ok
12:35:15.0429 0x0ddc  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
12:35:15.0459 0x0ddc  CmBatt - ok
12:35:15.0493 0x0ddc  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
12:35:15.0551 0x0ddc  cmdide - ok
12:35:15.0584 0x0ddc  [ 27667A788130A7F7A5858DE27572E6D7, 5501D80BCCB7A811ECCED3828DFD0A5D948BBED8504E9BCC4A3BFB840DD41CBC ] CNG             C:\Windows\system32\Drivers\cng.sys
12:35:15.0618 0x0ddc  CNG - ok
12:35:15.0628 0x0ddc  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
12:35:15.0642 0x0ddc  Compbatt - ok
12:35:15.0692 0x0ddc  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
12:35:15.0739 0x0ddc  CompositeBus - ok
12:35:15.0757 0x0ddc  COMSysApp - ok
12:35:15.0769 0x0ddc  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
12:35:15.0783 0x0ddc  crcdisk - ok
12:35:15.0831 0x0ddc  [ 1CD76A83B9E8E9A5A3519B39E28354D9, F9931743B99820FFBFB13136DFFD92F86802D543F9D8478648CDC554FB38899D ] CryptSvc        C:\Windows\system32\cryptsvc.dll
12:35:15.0892 0x0ddc  CryptSvc - ok
12:35:15.0927 0x0ddc  [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC             C:\Windows\system32\drivers\csc.sys
12:35:15.0989 0x0ddc  CSC - ok
12:35:16.0048 0x0ddc  [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService      C:\Windows\System32\cscsvc.dll
12:35:16.0092 0x0ddc  CscService - ok
12:35:16.0133 0x0ddc  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch      C:\Windows\system32\rpcss.dll
12:35:16.0186 0x0ddc  DcomLaunch - ok
12:35:16.0226 0x0ddc  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc       C:\Windows\System32\defragsvc.dll
12:35:16.0320 0x0ddc  defragsvc - ok
12:35:16.0381 0x0ddc  [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
12:35:16.0489 0x0ddc  DfsC - ok
12:35:16.0517 0x0ddc  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
12:35:16.0557 0x0ddc  Dhcp - ok
12:35:16.0577 0x0ddc  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
12:35:16.0613 0x0ddc  discache - ok
12:35:16.0654 0x0ddc  [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
12:35:16.0702 0x0ddc  Disk - ok
12:35:16.0749 0x0ddc  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
12:35:16.0832 0x0ddc  Dnscache - ok
12:35:16.0856 0x0ddc  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc         C:\Windows\System32\dot3svc.dll
12:35:16.0899 0x0ddc  dot3svc - ok
12:35:17.0014 0x0ddc  [ B42ED0320C6E41102FDE0005154849BB, 4DB872E23AD049C3C9FDC0759FC58BFA60DA91B18BC82B611BFA300D26DDFC7A ] Dot4            C:\Windows\system32\DRIVERS\Dot4.sys
12:35:17.0039 0x0ddc  Dot4 - ok
12:35:17.0148 0x0ddc  [ E9F5969233C5D89F3C35E3A66A52A361, C4BD35795C78FB11E6022372CB25DEB570730EFDAD3DC1584368235FF622638C ] Dot4Print       C:\Windows\system32\DRIVERS\Dot4Prt.sys
12:35:17.0188 0x0ddc  Dot4Print - ok
12:35:17.0211 0x0ddc  [ FD05A02B0370BC3000F402E543CA5814, 089B1113E640F495F470E8F57060B89546270481B309DC8ED3C3D13A849076A3 ] dot4usb         C:\Windows\system32\DRIVERS\dot4usb.sys
12:35:17.0241 0x0ddc  dot4usb - ok
12:35:17.0290 0x0ddc  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS             C:\Windows\system32\dps.dll
12:35:17.0377 0x0ddc  DPS - ok
12:35:17.0422 0x0ddc  [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
12:35:17.0477 0x0ddc  drmkaud - ok
12:35:17.0506 0x0ddc  [ 0040A0132AAC1004E50055F8FBB14C08, A336CA41DA09AC749242852827C1F2FB645E8E81A707217C360C5E4ACD1760BA ] dsNcAdpt        C:\Windows\system32\DRIVERS\dsNcAdpt.sys
12:35:17.0527 0x0ddc  dsNcAdpt - detected UnsignedFile.Multi.Generic ( 1 )
12:35:19.0923 0x0ddc  Detect skipped due to KSN trusted
12:35:19.0924 0x0ddc  dsNcAdpt - ok
12:35:20.0018 0x0ddc  [ 87CE5C8965E101CCCED1F4675557E868, 077D98F0F130B2FC710208BA34016EF2B2506EE2BD71740B228145E34A3046F1 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
12:35:20.0095 0x0ddc  DXGKrnl - ok
12:35:20.0137 0x0ddc  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost         C:\Windows\System32\eapsvc.dll
12:35:20.0208 0x0ddc  EapHost - ok
12:35:20.0479 0x0ddc  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv           C:\Windows\system32\DRIVERS\evbda.sys
12:35:20.0640 0x0ddc  ebdrv - ok
12:35:20.0713 0x0ddc  [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] EFS             C:\Windows\System32\lsass.exe
12:35:20.0929 0x0ddc  EFS - ok
12:35:21.0085 0x0ddc  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
12:35:21.0161 0x0ddc  ehRecvr - ok
12:35:21.0183 0x0ddc  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched         C:\Windows\ehome\ehsched.exe
12:35:21.0261 0x0ddc  ehSched - ok
12:35:21.0358 0x0ddc  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
12:35:21.0409 0x0ddc  elxstor - ok
12:35:21.0436 0x0ddc  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
12:35:21.0487 0x0ddc  ErrDev - ok
12:35:21.0539 0x0ddc  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem     C:\Windows\system32\es.dll
12:35:21.0587 0x0ddc  EventSystem - ok
12:35:21.0602 0x0ddc  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat           C:\Windows\system32\drivers\exfat.sys
12:35:21.0648 0x0ddc  exfat - ok
12:35:21.0671 0x0ddc  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
12:35:21.0785 0x0ddc  fastfat - ok
12:35:21.0830 0x0ddc  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax             C:\Windows\system32\fxssvc.exe
12:35:21.0879 0x0ddc  Fax - ok
12:35:21.0890 0x0ddc  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
12:35:21.0920 0x0ddc  fdc - ok
12:35:21.0934 0x0ddc  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost         C:\Windows\system32\fdPHost.dll
12:35:21.0961 0x0ddc  fdPHost - ok
12:35:21.0969 0x0ddc  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
12:35:22.0013 0x0ddc  FDResPub - ok
12:35:22.0033 0x0ddc  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
12:35:22.0095 0x0ddc  FileInfo - ok
12:35:22.0121 0x0ddc  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
12:35:22.0192 0x0ddc  Filetrace - ok
12:35:22.0267 0x0ddc  FLASHSYS - ok
12:35:22.0290 0x0ddc  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
12:35:22.0335 0x0ddc  flpydisk - ok
12:35:22.0396 0x0ddc  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
12:35:22.0433 0x0ddc  FltMgr - ok
12:35:22.0496 0x0ddc  [ C4C183E6551084039EC862DA1C945E3D, 0874A2ACDD24D64965AA9A76E9C818E216880AE4C9A2E07ED932EE404585CEE6 ] FontCache       C:\Windows\system32\FntCache.dll
12:35:22.0653 0x0ddc  FontCache - ok
12:35:22.0702 0x0ddc  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:35:22.0718 0x0ddc  FontCache3.0.0.0 - ok
12:35:22.0736 0x0ddc  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
12:35:22.0752 0x0ddc  FsDepends - ok
12:35:22.0790 0x0ddc  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
12:35:22.0892 0x0ddc  Fs_Rec - ok
12:35:23.0068 0x0ddc  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
12:35:23.0164 0x0ddc  fvevol - ok
12:35:23.0180 0x0ddc  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
12:35:23.0209 0x0ddc  gagp30kx - ok
12:35:23.0235 0x0ddc  [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
12:35:23.0246 0x0ddc  GEARAspiWDM - ok
12:35:23.0308 0x0ddc  [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc           C:\Windows\System32\gpsvc.dll
12:35:23.0398 0x0ddc  gpsvc - ok
12:35:23.0407 0x0ddc  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
12:35:23.0469 0x0ddc  hcw85cir - ok
12:35:23.0593 0x0ddc  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:35:23.0643 0x0ddc  HdAudAddService - ok
12:35:23.0677 0x0ddc  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
12:35:23.0707 0x0ddc  HDAudBus - ok
12:35:23.0724 0x0ddc  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
12:35:23.0750 0x0ddc  HidBatt - ok
12:35:23.0770 0x0ddc  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
12:35:23.0805 0x0ddc  HidBth - ok
12:35:23.0819 0x0ddc  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
12:35:23.0849 0x0ddc  HidIr - ok
12:35:23.0872 0x0ddc  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv         C:\Windows\system32\hidserv.dll
12:35:23.0920 0x0ddc  hidserv - ok
12:35:23.0956 0x0ddc  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
12:35:23.0998 0x0ddc  HidUsb - ok
12:35:24.0042 0x0ddc  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
12:35:24.0158 0x0ddc  hkmsvc - ok
12:35:24.0185 0x0ddc  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
12:35:24.0208 0x0ddc  HomeGroupListener - ok
12:35:24.0227 0x0ddc  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
12:35:24.0256 0x0ddc  HomeGroupProvider - ok
12:35:24.0354 0x0ddc  [ 1DAE5C46D42B02A6D5862E1482EFB390, 90B14E0A8376AE51872D89C141E88AE144B742805F94B4F7948E295322C78B9D ] hpqcxs08        C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
12:35:24.0363 0x0ddc  hpqcxs08 - detected UnsignedFile.Multi.Generic ( 1 )
12:35:26.0767 0x0ddc  Detect skipped due to KSN trusted
12:35:26.0767 0x0ddc  hpqcxs08 - ok
12:35:26.0853 0x0ddc  [ 99E8EEF42FE2F4AF29B08C3355DD7685, D57BC2148653DA5596FB49F1086D165B11C9F6C644608202C08305D3C8499CFE ] hpqddsvc        C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
12:35:26.0890 0x0ddc  hpqddsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:35:29.0291 0x0ddc  Detect skipped due to KSN trusted
12:35:29.0294 0x0ddc  hpqddsvc - ok
12:35:29.0322 0x0ddc  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
12:35:29.0347 0x0ddc  HpSAMD - ok
12:35:29.0442 0x0ddc  [ F37882F128EFACEFE353E0BAE2766909, 2F9D21613500F092DFC0DB879180B549EE615D9B07408A5CC1A7F84663B2F47A ] HPSLPSVC        C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
12:35:29.0482 0x0ddc  HPSLPSVC - detected UnsignedFile.Multi.Generic ( 1 )
12:35:31.0896 0x0ddc  Detect skipped due to KSN trusted
12:35:31.0897 0x0ddc  HPSLPSVC - ok
12:35:31.0982 0x0ddc  [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
12:35:32.0054 0x0ddc  HTTP - ok
12:35:32.0077 0x0ddc  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
12:35:32.0089 0x0ddc  hwpolicy - ok
12:35:32.0109 0x0ddc  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
12:35:32.0127 0x0ddc  i8042prt - ok
12:35:32.0164 0x0ddc  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
12:35:32.0190 0x0ddc  iaStorV - ok
12:35:32.0275 0x0ddc  [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT        C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
12:35:32.0321 0x0ddc  IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
12:35:34.0734 0x0ddc  Detect skipped due to KSN trusted
12:35:34.0734 0x0ddc  IDriverT - ok
12:35:34.0826 0x0ddc  [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:35:34.0874 0x0ddc  idsvc - ok
12:35:34.0913 0x0ddc  IEEtwCollectorService - ok
12:35:34.0935 0x0ddc  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
12:35:34.0975 0x0ddc  iirsp - ok
12:35:35.0024 0x0ddc  [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT          C:\Windows\System32\ikeext.dll
12:35:35.0080 0x0ddc  IKEEXT - ok
12:35:35.0253 0x0ddc  [ 02674201AD9FE19AC3376705077882C6, 9AA800AA77EBA488FA537FF47D361F6B09E8063A99CCBF5AE2F754A6A648DF84 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
12:35:35.0378 0x0ddc  IntcAzAudAddService - ok
12:35:35.0400 0x0ddc  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
12:35:35.0413 0x0ddc  intelide - ok
12:35:35.0432 0x0ddc  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
12:35:35.0448 0x0ddc  intelppm - ok
12:35:35.0471 0x0ddc  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
12:35:35.0524 0x0ddc  IPBusEnum - ok
12:35:35.0553 0x0ddc  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:35:35.0597 0x0ddc  IpFilterDriver - ok
12:35:35.0636 0x0ddc  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
12:35:35.0718 0x0ddc  iphlpsvc - ok
12:35:35.0750 0x0ddc  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
12:35:35.0782 0x0ddc  IPMIDRV - ok
12:35:35.0803 0x0ddc  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
12:35:35.0836 0x0ddc  IPNAT - ok
12:35:35.0937 0x0ddc  [ A4857E8B1DEB9740FB5ADEDF05ED69E0, 24FC7A188D32B08CE4F10EEEF17F37C45DB5433158A7A97A07D43F6BEE58DFFC ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
12:35:35.0966 0x0ddc  iPod Service - ok
12:35:35.0988 0x0ddc  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
12:35:36.0046 0x0ddc  IRENUM - ok
12:35:36.0057 0x0ddc  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
12:35:36.0070 0x0ddc  isapnp - ok
12:35:36.0093 0x0ddc  [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
12:35:36.0116 0x0ddc  iScsiPrt - ok
12:35:36.0170 0x0ddc  [ 6B37B542157C2EFA3BDA5F87428FE588, 61BD79573B4764F8CAC1BA5224EF0B82E9D2916AC32B62A1DC880641128A25F3 ] johci           C:\Windows\system32\DRIVERS\johci.sys
12:35:36.0204 0x0ddc  johci - ok
12:35:36.0235 0x0ddc  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
12:35:36.0271 0x0ddc  kbdclass - ok
12:35:36.0289 0x0ddc  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
12:35:36.0331 0x0ddc  kbdhid - ok
12:35:36.0363 0x0ddc  [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] KeyIso          C:\Windows\system32\lsass.exe
12:35:36.0377 0x0ddc  KeyIso - ok
12:35:36.0406 0x0ddc  [ 063C09DB965E3DFD6F4F08416F6DB8F5, 0BE015C59288397536B3941BA55EFE0CF06714BC43FF3A33A1D844B4E0F16097 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
12:35:36.0424 0x0ddc  KSecDD - ok
12:35:36.0437 0x0ddc  [ 1FA627E63195BF3BF636BFEF0D7190D4, 794456605303F4916E81BE899E0B05CB070094E719ADA8BE8072A761E35CA8E9 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
12:35:36.0455 0x0ddc  KSecPkg - ok
12:35:36.0472 0x0ddc  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
12:35:36.0501 0x0ddc  ksthunk - ok
12:35:36.0525 0x0ddc  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm           C:\Windows\system32\msdtckrm.dll
12:35:36.0582 0x0ddc  KtmRm - ok
12:35:36.0610 0x0ddc  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\Windows\system32\srvsvc.dll
12:35:36.0648 0x0ddc  LanmanServer - ok
12:35:36.0672 0x0ddc  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:35:36.0707 0x0ddc  LanmanWorkstation - ok
12:35:36.0752 0x0ddc  [ 47901EADCA0971A997ED926F0EC316C4, 727654BDCD2D2911CEF14C9C1BA161309A2E3D260BF58C77A406E218BE886E26 ] LicCtrlService  C:\Windows\runservice.exe
12:35:36.0775 0x0ddc  LicCtrlService - detected UnsignedFile.Multi.Generic ( 1 )
12:35:39.0196 0x0ddc  Detect skipped due to KSN trusted
12:35:39.0196 0x0ddc  LicCtrlService - ok
12:35:39.0231 0x0ddc  [ 156AB2E56DC3CA0B582E3362E07CDED7, 7B03929273861690DC42E4C686E655BE5A1C60136AE5E739D7E62306AFD4AB9A ] lirsgt          C:\Windows\system32\DRIVERS\lirsgt.sys
12:35:39.0266 0x0ddc  lirsgt - ok
12:35:39.0290 0x0ddc  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
12:35:39.0354 0x0ddc  lltdio - ok
12:35:39.0390 0x0ddc  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
12:35:39.0477 0x0ddc  lltdsvc - ok
12:35:39.0494 0x0ddc  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts         C:\Windows\System32\lmhsvc.dll
12:35:39.0536 0x0ddc  lmhosts - ok
12:35:39.0569 0x0ddc  [ 81C0817E8D4FEF2EC38300B31070D67F, 249AD6731161B9BDFD57D0267ED9206AD24CF7EA688B54685ED5EF54511E6BD7 ] LPCFilter       C:\Windows\system32\DRIVERS\LPCFilter.sys
12:35:39.0582 0x0ddc  LPCFilter - ok
12:35:39.0609 0x0ddc  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
12:35:39.0626 0x0ddc  LSI_FC - ok
12:35:39.0641 0x0ddc  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
12:35:39.0657 0x0ddc  LSI_SAS - ok
12:35:39.0670 0x0ddc  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:35:39.0685 0x0ddc  LSI_SAS2 - ok
12:35:39.0700 0x0ddc  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:35:39.0716 0x0ddc  LSI_SCSI - ok
12:35:39.0743 0x0ddc  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv           C:\Windows\system32\drivers\luafv.sys
12:35:39.0796 0x0ddc  luafv - ok
12:35:39.0816 0x0ddc  lxbx_device - ok
12:35:39.0881 0x0ddc  [ 1E9E32AEC3E1EB1B31B8169F33168B56, 39114585E1FDBBA31E1F781C6A627281907183F94626EB347B08D1F78992ED2A ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
12:35:39.0919 0x0ddc  MBAMProtector - ok
12:35:40.0040 0x0ddc  [ 516E29AD03BDF610CC36A95AE692FE42, 09F913B169AD775FF587AE59AEC5DD2A2D8646803F48BF616C74EEC0DE3BE7A2 ] MBAMScheduler   C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
12:35:40.0105 0x0ddc  MBAMScheduler - ok
12:35:40.0152 0x0ddc  [ 2B983F067AEE3F9EB4DF5E97F45D21D1, 0B9ED0E91FF01A5445927650113E320C3C0EA16F1401AA55A509DDBF704DF22F ] MBAMService     C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
12:35:40.0200 0x0ddc  MBAMService - ok
12:35:40.0261 0x0ddc  [ E9CD058C79EA15B4AA93E259FA713B07, 2B09F65188D8782F9C797545F2F791EC7EAB85D8914B2C0B30BD869C412E3980 ] MBAMSwissArmy   C:\Windows\system32\drivers\MBAMSwissArmy.sys
12:35:40.0287 0x0ddc  MBAMSwissArmy - ok
12:35:40.0308 0x0ddc  [ F49FB3C88E263AE9A246593B0BB29294, FB53D6FA4A98B98334DCFF81E40712265256D31A9E9FF36022887BABD50F39EB ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
12:35:40.0320 0x0ddc  MBAMWebAccessControl - ok
12:35:40.0338 0x0ddc  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
12:35:40.0363 0x0ddc  Mcx2Svc - ok
12:35:40.0377 0x0ddc  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
12:35:40.0394 0x0ddc  megasas - ok
12:35:40.0450 0x0ddc  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
12:35:40.0504 0x0ddc  MegaSR - ok
12:35:40.0528 0x0ddc  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS           C:\Windows\system32\mmcss.dll
12:35:40.0576 0x0ddc  MMCSS - ok
12:35:40.0595 0x0ddc  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem           C:\Windows\system32\drivers\modem.sys
12:35:40.0669 0x0ddc  Modem - ok
12:35:40.0698 0x0ddc  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
12:35:40.0719 0x0ddc  monitor - ok
12:35:40.0767 0x0ddc  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
12:35:40.0813 0x0ddc  mouclass - ok
12:35:40.0831 0x0ddc  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
12:35:40.0864 0x0ddc  mouhid - ok
12:35:40.0892 0x0ddc  [ 87BCD1034CBF33537D4D4C251D39BA26, CB9DD235B62B79383F99873D75E26EEA5EE7914CA89E4B75992207F83420437F ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
12:35:40.0916 0x0ddc  mountmgr - ok
12:35:40.0985 0x0ddc  [ 03D14BF1DC59130002F6B8BA3AD89DB9, 1729CCD8AAF51CDB86ED67569974D0B6B1CFFA5F90EF6E6004B0D8A305D88C27 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
12:35:41.0024 0x0ddc  MozillaMaintenance - ok
12:35:41.0036 0x0ddc  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
12:35:41.0047 0x0ddc  mpio - ok
12:35:41.0072 0x0ddc  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
12:35:41.0106 0x0ddc  mpsdrv - ok
12:35:41.0146 0x0ddc  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\Windows\system32\mpssvc.dll
12:35:41.0196 0x0ddc  MpsSvc - ok
12:35:41.0216 0x0ddc  [ AE3334958D8F631FF14A0AEB3D7EFB3A, F5FD6B61F896104C20DFC43FEE2FCE6930B73F78DF876BD19A333EABB9139C6D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
12:35:41.0268 0x0ddc  MRxDAV - ok
12:35:41.0304 0x0ddc  [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
12:35:41.0358 0x0ddc  mrxsmb - ok
12:35:41.0398 0x0ddc  [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:35:41.0499 0x0ddc  mrxsmb10 - ok
12:35:41.0608 0x0ddc  [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:35:41.0697 0x0ddc  mrxsmb20 - ok
12:35:41.0736 0x0ddc  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
12:35:41.0778 0x0ddc  msahci - ok
12:35:41.0804 0x0ddc  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
12:35:41.0832 0x0ddc  msdsm - ok
12:35:41.0845 0x0ddc  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC           C:\Windows\System32\msdtc.exe
12:35:41.0885 0x0ddc  MSDTC - ok
12:35:41.0914 0x0ddc  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
12:35:41.0961 0x0ddc  Msfs - ok
12:35:41.0977 0x0ddc  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
12:35:42.0048 0x0ddc  mshidkmdf - ok
12:35:42.0069 0x0ddc  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
12:35:42.0082 0x0ddc  msisadrv - ok
12:35:42.0103 0x0ddc  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
12:35:42.0143 0x0ddc  MSiSCSI - ok
12:35:42.0145 0x0ddc  msiserver - ok
12:35:42.0219 0x0ddc  [ 2C7CCCAF8630827EFB8F1939F61EA508, ABA53947A08BFFDF02C2383666E9E9CF7A45030513BE64AF955D84BEE590777C ] MSI_LiveUpdate_Service C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
12:35:42.0265 0x0ddc  MSI_LiveUpdate_Service - ok
12:35:42.0320 0x0ddc  [ 6AFCD25B843D0C731B6987E39995AE72, FD0F2E15B0CEB1E558BD8A02D59B9002706A003049678281A446BC4398862B70 ] MSI_SuperCharger C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
12:35:42.0354 0x0ddc  MSI_SuperCharger - ok
12:35:42.0372 0x0ddc  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
12:35:42.0426 0x0ddc  MSKSSRV - ok
12:35:42.0447 0x0ddc  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
12:35:42.0491 0x0ddc  MSPCLOCK - ok
12:35:42.0502 0x0ddc  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
12:35:42.0598 0x0ddc  MSPQM - ok
12:35:42.0626 0x0ddc  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
12:35:42.0654 0x0ddc  MsRPC - ok
12:35:42.0666 0x0ddc  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
12:35:42.0675 0x0ddc  mssmbios - ok
12:35:42.0685 0x0ddc  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
12:35:42.0729 0x0ddc  MSTEE - ok
12:35:42.0742 0x0ddc  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
12:35:42.0767 0x0ddc  MTConfig - ok
12:35:42.0786 0x0ddc  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup             C:\Windows\system32\Drivers\mup.sys
12:35:42.0801 0x0ddc  Mup - ok
12:35:42.0864 0x0ddc  [ 08835780CC6A5CFF5275101B5A9D17A4, 0D07860EAB6C26BF13D7FDB53A8A663D6F2C8C139D7B3B3AD36210A650C43826 ] MxEFUF          C:\Windows\system32\DRIVERS\MxEFUF64.sys
12:35:42.0949 0x0ddc  MxEFUF - ok
12:35:43.0007 0x0ddc  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
12:35:43.0053 0x0ddc  napagent - ok
12:35:43.0085 0x0ddc  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
12:35:43.0120 0x0ddc  NativeWifiP - ok
12:35:43.0167 0x0ddc  [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS            C:\Windows\system32\drivers\ndis.sys
12:35:43.0195 0x0ddc  NDIS - ok
12:35:43.0209 0x0ddc  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
12:35:43.0251 0x0ddc  NdisCap - ok
12:35:43.0278 0x0ddc  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
12:35:43.0345 0x0ddc  NdisTapi - ok
12:35:43.0374 0x0ddc  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
12:35:43.0418 0x0ddc  Ndisuio - ok
12:35:43.0476 0x0ddc  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
12:35:43.0549 0x0ddc  NdisWan - ok
12:35:43.0581 0x0ddc  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
12:35:43.0643 0x0ddc  NDProxy - ok
12:35:43.0692 0x0ddc  [ 2334DC48997BA203B794DF3EE70521DB, 832F4EC1586C9669F2D54AB3B212943E43B87A33B24DCC8CDAD6A0264291EE2F ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
12:35:43.0726 0x0ddc  Net Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
12:35:46.0134 0x0ddc  Detect skipped due to KSN trusted
12:35:46.0134 0x0ddc  Net Driver HPZ12 - ok
12:35:46.0164 0x0ddc  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
12:35:46.0223 0x0ddc  NetBIOS - ok
12:35:46.0257 0x0ddc  [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
12:35:46.0306 0x0ddc  NetBT - ok
12:35:46.0330 0x0ddc  [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] Netlogon        C:\Windows\system32\lsass.exe
12:35:46.0340 0x0ddc  Netlogon - ok
12:35:46.0372 0x0ddc  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
12:35:46.0413 0x0ddc  Netman - ok
12:35:46.0447 0x0ddc  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:35:46.0487 0x0ddc  NetMsmqActivator - ok
12:35:46.0492 0x0ddc  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:35:46.0506 0x0ddc  NetPipeActivator - ok
12:35:46.0531 0x0ddc  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
12:35:46.0585 0x0ddc  netprofm - ok
12:35:46.0604 0x0ddc  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:35:46.0616 0x0ddc  NetTcpActivator - ok
12:35:46.0620 0x0ddc  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:35:46.0633 0x0ddc  NetTcpPortSharing - ok
12:35:46.0654 0x0ddc  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
12:35:46.0699 0x0ddc  nfrd960 - ok
12:35:46.0783 0x0ddc  [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc          C:\Windows\System32\nlasvc.dll
12:35:46.0872 0x0ddc  NlaSvc - ok
12:35:46.0904 0x0ddc  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
12:35:46.0990 0x0ddc  Npfs - ok
12:35:47.0012 0x0ddc  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi             C:\Windows\system32\nsisvc.dll
12:35:47.0079 0x0ddc  nsi - ok
12:35:47.0082 0x0ddc  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
12:35:47.0130 0x0ddc  nsiproxy - ok
12:35:47.0202 0x0ddc  [ 1A29A59A4C5BA6F8C85062A613B7E2B2, CC137F499A12C724D4166C2D85E9F447413419A0683DAC6F1A802B7F210C77F1 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
12:35:47.0266 0x0ddc  Ntfs - ok
12:35:47.0308 0x0ddc  [ 23CF3DA010497EB2BF39A5C5A57E437C, 39CFDE7D401EFCE4F550E0A9461F5FC4D71FA07235E1336E4F0B4882BD76550E ] NTIOLib_1_0_3   C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys
12:35:47.0316 0x0ddc  NTIOLib_1_0_3 - ok
12:35:47.0350 0x0ddc  [ 1B32C54B95121AB1683C7B83B2DB4B96, 99F4994A0E5BD1BF6E3F637D3225C69FF4CD620557E23637533E7F18D7D6CBA1 ] NTIOLib_1_0_4   C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys
12:35:47.0362 0x0ddc  NTIOLib_1_0_4 - ok
12:35:47.0407 0x0ddc  [ C6F8983DD3D75640C072A8459B8FA55A, 101402D4F5D1AE413DED499C78A5FCBBC7E3BAE9B000D64C1DD64E3C48C37558 ] NTIOLib_MSI_RAID C:\MSI\Smart Utilities\NTIOLib_X64.sys
12:35:47.0441 0x0ddc  NTIOLib_MSI_RAID - ok
12:35:47.0462 0x0ddc  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
12:35:47.0540 0x0ddc  Null - ok
12:35:47.0601 0x0ddc  [ C87B11EB78428853F9E8495C47E53C10, FAE479DB0812967B3FF968773BA998591B4F50BE4329B8349BCA7E6EAB1B0474 ] NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
12:35:47.0646 0x0ddc  NVHDA - ok
12:35:48.0052 0x0ddc  [ 185B4FFECD886A424B57B58AE173FBBE, 7CFD51694091035639B900EC64FAD62CC1E5F3DC520F59CC27540B170A957C60 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
12:35:48.0507 0x0ddc  nvlddmkm - ok
12:35:48.0553 0x0ddc  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
12:35:48.0585 0x0ddc  nvraid - ok
12:35:48.0616 0x0ddc  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
12:35:48.0631 0x0ddc  nvstor - ok
12:35:48.0725 0x0ddc  [ E1CE82592245B9E9621F17FBF457DB4E, 98B021623B10EBF7ED370BC2516D8377C09E9E2BB49BD96F492F55006B1B8CC4 ] nvsvc           C:\Windows\system32\nvvsvc.exe
12:35:48.0756 0x0ddc  nvsvc - ok
12:35:48.0772 0x0ddc  nvvad_WaveExtensible - ok
12:35:48.0787 0x0ddc  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
12:35:48.0850 0x0ddc  nv_agp - ok
12:35:48.0881 0x0ddc  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
12:35:48.0928 0x0ddc  ohci1394 - ok
12:35:48.0975 0x0ddc  [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:35:49.0021 0x0ddc  ose - ok
12:35:49.0271 0x0ddc  [ FE9C0029E1AF26350D9985D00520E5C8, 967079CCF7B2CBD4B48C9F076675C26AF93A1CEC26C96811F279414E34004EE6 ] osppsvc         C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
12:35:49.0427 0x0ddc  osppsvc - ok
12:35:49.0458 0x0ddc  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
12:35:49.0505 0x0ddc  p2pimsvc - ok
12:35:49.0552 0x0ddc  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
12:35:49.0583 0x0ddc  p2psvc - ok
12:35:49.0614 0x0ddc  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
12:35:49.0645 0x0ddc  Parport - ok
12:35:49.0661 0x0ddc  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr         C:\Windows\system32\drivers\partmgr.sys
12:35:49.0677 0x0ddc  partmgr - ok
12:35:49.0708 0x0ddc  [ DB2D62AA2DF6B1F3D690A9EC9701AA2C, BEAC55E1AA0494565F1547DF5E6FE20FCEA66461764C016FCB68D8BFF0F0C375 ] PcaSvc          C:\Windows\System32\pcasvc.dll
12:35:49.0786 0x0ddc  PcaSvc - ok
12:35:49.0833 0x0ddc  [ 3FDE033DFB0D07F8B7D5C9A3044AA121, 2C23B4FA34BA3060884B0168A830DD395A3853855CD6DF4065FBB303DFB4A87E ] pccsmcfd        C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
12:35:49.0911 0x0ddc  pccsmcfd - ok
12:35:49.0942 0x0ddc  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci             C:\Windows\system32\drivers\pci.sys
12:35:49.0973 0x0ddc  pci - ok
12:35:50.0004 0x0ddc  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
12:35:50.0020 0x0ddc  pciide - ok
12:35:50.0035 0x0ddc  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
12:35:50.0051 0x0ddc  pcmcia - ok
12:35:50.0067 0x0ddc  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw             C:\Windows\system32\drivers\pcw.sys
12:35:50.0067 0x0ddc  pcw - ok
12:35:50.0160 0x0ddc  [ 98655F862BB07CFB1CCC9262DA621AE1, 6903FA802D73A2450DE29BBA9283EC9C256C4C08D848201952D51DBBD9630A9A ] PDF Architect Helper Service C:\Program Files (x86)\PDF Architect\HelperService.exe
12:35:50.0223 0x0ddc  PDF Architect Helper Service - ok
12:35:50.0254 0x0ddc  [ 73406F96E946F2B38615375269EF286F, 28170FF1F3B641B013DDB57582F8D9E6ED4205D8C63C89EA685FEC1E42833309 ] PDF Architect Service C:\Program Files (x86)\PDF Architect\ConversionService.exe
12:35:50.0301 0x0ddc  PDF Architect Service - ok
12:35:50.0379 0x0ddc  [ ED6E75158D28D33A2E2A020AC5B2B59D, 0F364D9A88304C45F31318605C417A70A9D0E4CF087D73E949B42C12CC76CD6C ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
12:35:50.0457 0x0ddc  PEAUTH - ok
12:35:50.0535 0x0ddc  [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
12:35:50.0628 0x0ddc  PeerDistSvc - ok
12:35:50.0722 0x0ddc  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
12:35:50.0769 0x0ddc  PerfHost - ok
12:35:50.0817 0x0ddc  [ 096E2BE69F61CFA7AC47EA4F4637BEA6, 369DBE623897AF65AC1605883B37556F152EB5021FAE0C2512DB617D3629B0F1 ] pikbd           C:\Windows\system32\DRIVERS\pikbd.sys
12:35:50.0849 0x0ddc  pikbd - ok
12:35:50.0942 0x0ddc  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla             C:\Windows\system32\pla.dll
12:35:51.0036 0x0ddc  pla - ok
12:35:51.0083 0x0ddc  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
12:35:51.0129 0x0ddc  PlugPlay - ok
12:35:51.0192 0x0ddc  [ AC78DF349F0E4CFB8B667C0CFFF83CCE, 7E635AA2E7350FCA0C954E697F1480A6204920AEFBCF06B90FFA02398DA82822 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
12:35:51.0223 0x0ddc  Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
12:35:53.0688 0x0ddc  Detect skipped due to KSN trusted
12:35:53.0688 0x0ddc  Pml Driver HPZ12 - ok
12:35:53.0703 0x0ddc  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
12:35:53.0750 0x0ddc  PNRPAutoReg - ok
12:35:53.0781 0x0ddc  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
12:35:53.0813 0x0ddc  PNRPsvc - ok
12:35:53.0828 0x0ddc  [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
12:35:53.0891 0x0ddc  PolicyAgent - ok
12:35:53.0937 0x0ddc  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power           C:\Windows\system32\umpo.dll
12:35:54.0000 0x0ddc  Power - ok
12:35:54.0015 0x0ddc  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
12:35:54.0062 0x0ddc  PptpMiniport - ok
12:35:54.0093 0x0ddc  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor       C:\Windows\system32\DRIVERS\processr.sys
12:35:54.0125 0x0ddc  Processor - ok
12:35:54.0156 0x0ddc  [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc         C:\Windows\system32\profsvc.dll
12:35:54.0218 0x0ddc  ProfSvc - ok
12:35:54.0234 0x0ddc  [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] ProtectedStorage C:\Windows\system32\lsass.exe
12:35:54.0265 0x0ddc  ProtectedStorage - ok
12:35:54.0296 0x0ddc  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
12:35:54.0327 0x0ddc  Psched - ok
12:35:54.0390 0x0ddc  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
12:35:54.0437 0x0ddc  ql2300 - ok
12:35:54.0452 0x0ddc  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
12:35:54.0468 0x0ddc  ql40xx - ok
12:35:54.0499 0x0ddc  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE           C:\Windows\system32\qwave.dll
12:35:54.0530 0x0ddc  QWAVE - ok
12:35:54.0546 0x0ddc  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
12:35:54.0561 0x0ddc  QWAVEdrv - ok
12:35:54.0561 0x0ddc  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
12:35:54.0639 0x0ddc  RasAcd - ok
12:35:54.0671 0x0ddc  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
12:35:54.0733 0x0ddc  RasAgileVpn - ok
12:35:54.0749 0x0ddc  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto         C:\Windows\System32\rasauto.dll
12:35:54.0795 0x0ddc  RasAuto - ok
12:35:54.0827 0x0ddc  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
12:35:54.0905 0x0ddc  Rasl2tp - ok
12:35:54.0936 0x0ddc  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
12:35:54.0983 0x0ddc  RasMan - ok
12:35:54.0998 0x0ddc  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
12:35:55.0029 0x0ddc  RasPppoe - ok
12:35:55.0045 0x0ddc  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
12:35:55.0076 0x0ddc  RasSstp - ok
12:35:55.0107 0x0ddc  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
12:35:55.0170 0x0ddc  rdbss - ok
12:35:55.0185 0x0ddc  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
12:35:55.0217 0x0ddc  rdpbus - ok
12:35:55.0232 0x0ddc  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
12:35:55.0310 0x0ddc  RDPCDD - ok
12:35:55.0326 0x0ddc  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
12:35:55.0357 0x0ddc  RDPDR - ok
12:35:55.0373 0x0ddc  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
12:35:55.0451 0x0ddc  RDPENCDD - ok
12:35:55.0451 0x0ddc  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
12:35:55.0482 0x0ddc  RDPREFMP - ok
12:35:55.0529 0x0ddc  [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
12:35:55.0607 0x0ddc  RdpVideoMiniport - ok
12:35:55.0653 0x0ddc  [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
12:35:55.0716 0x0ddc  RDPWD - ok
12:35:55.0747 0x0ddc  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
12:35:55.0778 0x0ddc  rdyboost - ok
12:35:55.0794 0x0ddc  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
12:35:55.0841 0x0ddc  RemoteAccess - ok
12:35:55.0872 0x0ddc  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
12:35:55.0919 0x0ddc  RemoteRegistry - ok
12:35:55.0950 0x0ddc  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
12:35:56.0012 0x0ddc  RpcEptMapper - ok
12:35:56.0028 0x0ddc  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
12:35:56.0059 0x0ddc  RpcLocator - ok
12:35:56.0106 0x0ddc  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs           C:\Windows\system32\rpcss.dll
12:35:56.0137 0x0ddc  RpcSs - ok
12:35:56.0168 0x0ddc  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
12:35:56.0215 0x0ddc  rspndr - ok
12:35:56.0262 0x0ddc  [ AC0E048F44BB30B96B81075A2455F0F7, D2BE8A9303AEDD9DC4F407A69C52F906F1A29EEC809E6A40F1A36873E3C276D6 ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys
12:35:56.0277 0x0ddc  RTHDMIAzAudService - ok
12:35:56.0324 0x0ddc  [ D2D055E7ED70A5EE885D17D35DF97E80, 51781E55EEE111140A261822D3F78D76AD288E9DDF8578E236358E0AEB872C2F ] RTL8167         C:\Windows\system32\DRIVERS\Rt64win7.sys
12:35:56.0371 0x0ddc  RTL8167 - ok
12:35:56.0402 0x0ddc  [ B263B3AEBCDE2210D1CC25756601B8EA, 85395F55555BC846397BB5F4FE5DE90EC7A12B629B339758F969B5B4AE6C8ADA ] RTL8169         C:\Windows\system32\DRIVERS\Rtlh64.sys
12:35:56.0418 0x0ddc  RTL8169 - ok
12:35:56.0480 0x0ddc  [ 496043BAD6FBFAAF5280C9EB41920684, E9ECFE2527A020FED1E6BDBE7D82BA977F7A03968A3F2A9897321CB0472F6087 ] RTLE8023x64     C:\Windows\system32\DRIVERS\Rtenic64.sys
12:35:56.0527 0x0ddc  RTLE8023x64 - ok
12:35:56.0558 0x0ddc  [ 2B38C905492F36FE42B59DA52D6B4EB7, 966AA4E15A4BB079E91C1900AB2B565DC0BEFCDCBFD49CDD480CE9348BFCB73B ] RtNdPt60        C:\Windows\system32\DRIVERS\RtNdPt60.sys
12:35:56.0636 0x0ddc  RtNdPt60 - ok
12:35:56.0652 0x0ddc  [ F3F166CA4283FF6F5F2C0D883D475CF8, 1F0DE9C082D5BB817557DB99827D0E912FBF2BCA53BDB6C64438A48214F92FC0 ] RTTEAMPT        C:\Windows\system32\DRIVERS\RtTeam60.sys
12:35:56.0667 0x0ddc  RTTEAMPT - ok
12:35:56.0683 0x0ddc  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
12:35:56.0714 0x0ddc  s3cap - ok
12:35:56.0730 0x0ddc  [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] SamSs           C:\Windows\system32\lsass.exe
12:35:56.0730 0x0ddc  SamSs - ok
12:35:56.0745 0x0ddc  SANDRA - ok
12:35:56.0761 0x0ddc  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
12:35:56.0777 0x0ddc  sbp2port - ok
12:35:56.0808 0x0ddc  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
12:35:56.0839 0x0ddc  SCardSvr - ok
12:35:56.0870 0x0ddc  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
12:35:56.0948 0x0ddc  scfilter - ok
12:35:57.0073 0x0ddc  [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule        C:\Windows\system32\schedsvc.dll
12:35:57.0151 0x0ddc  Schedule - ok
12:35:57.0182 0x0ddc  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc     C:\Windows\System32\certprop.dll
12:35:57.0245 0x0ddc  SCPolicySvc - ok
12:35:57.0276 0x0ddc  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
12:35:57.0338 0x0ddc  SDRSVC - ok
12:35:57.0557 0x0ddc  [ 98EF79CC2B07398AC525F9EA1AE0366F, D0D5D69696ED339F363024AF3271867F4C55572C67FD0F2AA27D24B37982E39A ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
12:35:57.0666 0x0ddc  SDScannerService - ok
12:35:57.0759 0x0ddc  [ 14BF6B3AB327D519ED007CDDC56F6900, 4E5DC4AF45347C885E0E87F205EE1F95BB4713A0B581CD7317FBEEE2A9628982 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
12:35:57.0822 0x0ddc  SDUpdateService - ok
12:35:57.0837 0x0ddc  [ 820EBE67AB99F033FDE25B2692157991, A9E86FE6EFD3CFD4EA1A26121C706335A6791CC6F81EE98AE2BE7EA566ECFEBB ] SDWSCService    C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
12:35:57.0853 0x0ddc  SDWSCService - ok
12:35:57.0900 0x0ddc  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
12:35:57.0978 0x0ddc  secdrv - ok
12:35:58.0009 0x0ddc  [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon        C:\Windows\system32\seclogon.dll
12:35:58.0071 0x0ddc  seclogon - ok
12:35:58.0087 0x0ddc  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\System32\sens.dll
12:35:58.0134 0x0ddc  SENS - ok
12:35:58.0165 0x0ddc  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
12:35:58.0227 0x0ddc  SensrSvc - ok
12:35:58.0227 0x0ddc  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
12:35:58.0243 0x0ddc  Serenum - ok
12:35:58.0259 0x0ddc  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\DRIVERS\serial.sys
12:35:58.0305 0x0ddc  Serial - ok
12:35:58.0321 0x0ddc  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
12:35:58.0461 0x0ddc  sermouse - ok
12:35:58.0586 0x0ddc  [ 78F7BB9F4924BE164294C59B8C3FC096, 75051A6A8B0DBB16CD70855A408134270EEAF0C127BAAE5B592DB53BB87C085B ] ServiceLayer    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
12:35:58.0617 0x0ddc  ServiceLayer - ok
12:35:58.0649 0x0ddc  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
12:35:58.0695 0x0ddc  SessionEnv - ok
12:35:58.0727 0x0ddc  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
12:35:58.0773 0x0ddc  sffdisk - ok
12:35:58.0789 0x0ddc  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
12:35:58.0851 0x0ddc  sffp_mmc - ok
12:35:58.0851 0x0ddc  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
12:35:58.0898 0x0ddc  sffp_sd - ok
12:35:58.0914 0x0ddc  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
12:35:58.0929 0x0ddc  sfloppy - ok
12:35:58.0992 0x0ddc  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
12:35:59.0070 0x0ddc  SharedAccess - ok
12:35:59.0085 0x0ddc  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:35:59.0132 0x0ddc  ShellHWDetection - ok
12:35:59.0163 0x0ddc  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:35:59.0179 0x0ddc  SiSRaid2 - ok
12:35:59.0195 0x0ddc  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
12:35:59.0210 0x0ddc  SiSRaid4 - ok
12:35:59.0273 0x0ddc  [ F6EF225A23D336CA30001E5007644C24, B0A4B1256C1074F1B4F73E3BBA16FD4683D6EEA583DEEF8E11EFD29BA7541F2A ] SkypeUpdate     C:\Program Files (x86)\Skype\Updater\Updater.exe
12:35:59.0319 0x0ddc  SkypeUpdate - ok
12:35:59.0382 0x0ddc  [ BA8B51F09A17A14D11A26289AE2858B6, 9006E47EABDA122C0401DFCFA764524FB58BDD484DF713C387D64D9558CE19D3 ] SliceDisk5      C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys
12:35:59.0429 0x0ddc  SliceDisk5 - detected UnsignedFile.Multi.Generic ( 1 )
12:36:01.0893 0x0ddc  Detect skipped due to KSN trusted
12:36:01.0893 0x0ddc  SliceDisk5 - ok
12:36:01.0925 0x0ddc  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
12:36:02.0003 0x0ddc  Smb - ok
12:36:02.0034 0x0ddc  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
12:36:02.0065 0x0ddc  SNMPTRAP - ok
12:36:02.0096 0x0ddc  [ 5F9785E7535F8F602CB294A54962C9E7, 22BE050955347661685A4343C51F11C7811674E030386D2264CD12ECBF544B7C ] speedfan        C:\Windows\syswow64\speedfan.sys
12:36:02.0112 0x0ddc  speedfan - ok
12:36:02.0127 0x0ddc  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr           C:\Windows\system32\drivers\spldr.sys
12:36:02.0159 0x0ddc  spldr - ok
12:36:02.0190 0x0ddc  [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler         C:\Windows\System32\spoolsv.exe
12:36:02.0237 0x0ddc  Spooler - ok
12:36:02.0377 0x0ddc  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
12:36:02.0471 0x0ddc  sppsvc - ok
12:36:02.0486 0x0ddc  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
12:36:02.0517 0x0ddc  sppuinotify - ok
12:36:02.0549 0x0ddc  [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv             C:\Windows\system32\DRIVERS\srv.sys
12:36:02.0627 0x0ddc  srv - ok
12:36:02.0673 0x0ddc  [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
12:36:02.0720 0x0ddc  srv2 - ok
12:36:02.0736 0x0ddc  [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
12:36:02.0783 0x0ddc  srvnet - ok
12:36:02.0829 0x0ddc  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
12:36:02.0876 0x0ddc  SSDPSRV - ok
12:36:02.0907 0x0ddc  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc         C:\Windows\system32\sstpsvc.dll
12:36:02.0954 0x0ddc  SstpSvc - ok
12:36:02.0985 0x0ddc  StarOpen - ok
12:36:03.0063 0x0ddc  [ EBAA82F7C9B97C0E450449178E007340, D470927CC216C4E3EA23236E6C6464187CD3A49C3A4A456F488FEC8E713EA31B ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
12:36:03.0173 0x0ddc  Steam Client Service - ok
12:36:03.0188 0x0ddc  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
12:36:03.0219 0x0ddc  stexstor - ok
12:36:03.0251 0x0ddc  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\Windows\System32\wiaservc.dll
12:36:03.0297 0x0ddc  stisvc - ok
12:36:03.0313 0x0ddc  [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
12:36:03.0329 0x0ddc  storflt - ok
12:36:03.0344 0x0ddc  [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc         C:\Windows\system32\storsvc.dll
12:36:03.0407 0x0ddc  StorSvc - ok
12:36:03.0422 0x0ddc  [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc         C:\Windows\system32\drivers\storvsc.sys
12:36:03.0453 0x0ddc  storvsc - ok
12:36:03.0500 0x0ddc  [ 1DA090D603EBAC2658CC895B1C6AC399, E803ED08C0531CCFCF6454E96F1F96146D8894D09D51AEE42AF9542C2C3DF01C ] SuperRAIDSvc    C:\MSI\Smart Utilities\SuperRAIDSvc.exe
12:36:03.0531 0x0ddc  SuperRAIDSvc - ok
12:36:03.0563 0x0ddc  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\drivers\swenum.sys
12:36:03.0594 0x0ddc  swenum - ok
12:36:03.0656 0x0ddc  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv           C:\Windows\System32\swprv.dll
12:36:03.0719 0x0ddc  swprv - ok
12:36:03.0797 0x0ddc  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain         C:\Windows\system32\sysmain.dll
12:36:03.0859 0x0ddc  SysMain - ok
12:36:03.0890 0x0ddc  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
12:36:03.0921 0x0ddc  TabletInputService - ok
12:36:03.0953 0x0ddc  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv         C:\Windows\System32\tapisrv.dll
12:36:03.0999 0x0ddc  TapiSrv - ok
12:36:04.0015 0x0ddc  [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS             C:\Windows\System32\tbssvc.dll
12:36:04.0046 0x0ddc  TBS - ok
12:36:04.0124 0x0ddc  [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
12:36:04.0202 0x0ddc  Tcpip - ok
12:36:04.0249 0x0ddc  [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
12:36:04.0296 0x0ddc  TCPIP6 - ok
12:36:04.0327 0x0ddc  [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
12:36:04.0358 0x0ddc  tcpipreg - ok
12:36:04.0389 0x0ddc  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
12:36:04.0436 0x0ddc  TDPIPE - ok
12:36:04.0467 0x0ddc  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
12:36:04.0514 0x0ddc  TDTCP - ok
12:36:04.0561 0x0ddc  [ 70988118145F5F10EF24720B97F35F65, F80C806417A68047FFB3D63214BC4AE5445315219AC594E043293006B704A63D ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
12:36:04.0655 0x0ddc  tdx - ok
12:36:04.0670 0x0ddc  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\Windows\system32\drivers\termdd.sys
12:36:04.0717 0x0ddc  TermDD - ok
12:36:04.0795 0x0ddc  [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService     C:\Windows\System32\termsrv.dll
12:36:04.0842 0x0ddc  TermService - ok
12:36:04.0857 0x0ddc  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
12:36:04.0889 0x0ddc  Themes - ok
12:36:04.0904 0x0ddc  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER     C:\Windows\system32\mmcss.dll
12:36:04.0935 0x0ddc  THREADORDER - ok
12:36:04.0951 0x0ddc  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
12:36:05.0013 0x0ddc  TrkWks - ok
12:36:05.0060 0x0ddc  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:36:05.0123 0x0ddc  TrustedInstaller - ok
12:36:05.0169 0x0ddc  [ E232A3B43A894BB327FC161529BD9ED1, F2673DA8C920F21ACCECC25F7C59A05822E5E577D47F126EDF9C94FEB4B30C5F ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
12:36:05.0169 0x0ddc  tssecsrv - ok
12:36:05.0216 0x0ddc  [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
12:36:05.0263 0x0ddc  TsUsbFlt - ok
12:36:05.0310 0x0ddc  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
12:36:05.0372 0x0ddc  tunnel - ok
12:36:05.0403 0x0ddc  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
12:36:05.0419 0x0ddc  uagp35 - ok
12:36:05.0450 0x0ddc  [ 632AA439691CF71F544567C3D6458A2A, 69CA9C5BB7D6FA3F361318985DB5DEF832B6151A43E99D344585291675ED4EF9 ] ubohci          C:\Windows\system32\DRIVERS\ubohci.sys
12:36:05.0528 0x0ddc  ubohci - ok
12:36:05.0559 0x0ddc  [ E1AFED5E72113D552B2E2ADEFC8A7CE9, FD471B256ED6A505957EB12E3E3B04869831E2F52F596922D999392669A562BC ] ubsbm           C:\Windows\system32\DRIVERS\ubsbm.sys
12:36:05.0575 0x0ddc  ubsbm - ok
12:36:05.0606 0x0ddc  [ F188ECC28D9685F32A0286D66B94B01A, 50DC4A621DDC347497E3C4181D5E2A2648A019B9EE294A28AE9814DDE7869675 ] ubumapi         C:\Windows\system32\DRIVERS\ubumapi.sys
12:36:05.0622 0x0ddc  ubumapi - ok
12:36:05.0669 0x0ddc  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
12:36:05.0715 0x0ddc  udfs - ok
12:36:05.0731 0x0ddc  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect       C:\Windows\system32\UI0Detect.exe
12:36:05.0778 0x0ddc  UI0Detect - ok
12:36:05.0809 0x0ddc  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
12:36:05.0856 0x0ddc  uliagpkx - ok
12:36:05.0887 0x0ddc  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus           C:\Windows\system32\drivers\umbus.sys
12:36:05.0949 0x0ddc  umbus - ok
12:36:05.0965 0x0ddc  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
12:36:05.0996 0x0ddc  UmPass - ok
12:36:06.0027 0x0ddc  [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService    C:\Windows\System32\umrdp.dll
12:36:06.0074 0x0ddc  UmRdpService - ok
12:36:06.0090 0x0ddc  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
12:36:06.0152 0x0ddc  upnphost - ok
12:36:06.0199 0x0ddc  [ 54D4B48D443E7228BF64CF7CDC3118AC, 4C953166EAECFD217218E386B411A4BDDA86AE65DCF352D271DF8E3D7DECC85F ] USBAAPL64       C:\Windows\system32\Drivers\usbaapl64.sys
12:36:06.0246 0x0ddc  USBAAPL64 - detected UnsignedFile.Multi.Generic ( 1 )
12:36:08.0711 0x0ddc  Detect skipped due to KSN trusted
12:36:08.0711 0x0ddc  USBAAPL64 - ok
12:36:08.0789 0x0ddc  [ B0435098C81D04CAFFF80DDB746CD3A2, A17B207740382E38729571F0B0BC98FF874E856A7C7CE9EB930328A2AD88F52A ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
12:36:08.0867 0x0ddc  usbaudio - ok
12:36:08.0898 0x0ddc  [ DCA68B0943D6FA415F0C56C92158A83A, BEE5A5B33B22D1DF50B884D46D89FC3B8286EB16E38AD5A20F0A49E5C6766C57 ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
12:36:08.0976 0x0ddc  usbccgp - ok
12:36:09.0007 0x0ddc  [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir          C:\Windows\system32\drivers\usbcir.sys
12:36:09.0038 0x0ddc  usbcir - ok
12:36:09.0054 0x0ddc  [ 18A85013A3E0F7E1755365D287443965, 811C5EDF38C765BCF71BCE25CB6626FF6988C3699F5EF1846240EA0052F34C33 ] usbehci         C:\Windows\system32\drivers\usbehci.sys
12:36:09.0069 0x0ddc  usbehci - ok
12:36:09.0101 0x0ddc  [ 76E2FFAD301490BA27B947C6507752FB, A4C6FC5C3BF428C624D0792873CB01C8F16F49B0E8B36422025A1094F0AAE231 ] usbfilter       C:\Windows\system32\DRIVERS\usbfilter.sys
12:36:09.0116 0x0ddc  usbfilter - ok
12:36:09.0163 0x0ddc  [ 8D1196CFBB223621F2C67D45710F25BA, B5D7AFE51833B24FC9576F3AED3D8A2B290E5846060E73F9FFFAC1890A8B6003 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
12:36:09.0241 0x0ddc  usbhub - ok
12:36:09.0257 0x0ddc  [ 765A92D428A8DB88B960DA5A8D6089DC, 56DE8A2ED58E53B202C399CA7BACB1551136303C2EE0AB426BDBBF880E3C542C ] usbohci         C:\Windows\system32\DRIVERS\usbohci.sys
12:36:09.0272 0x0ddc  usbohci - ok
12:36:09.0303 0x0ddc  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
12:36:09.0335 0x0ddc  usbprint - ok
12:36:09.0366 0x0ddc  [ 9661DA76B4531B2DA272ECCE25A8AF24, FEA93254A21E71A7EB8AD35FCCAD2C1E41F7329EC33B1734F5B41307A34D8637 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
12:36:09.0413 0x0ddc  usbscan - ok
12:36:09.0444 0x0ddc  [ B57B4F0BEC4270A281B9F8537EB2FA04, 554273482EE85F010DC62E412C9933E65BD63AA09911BD25D86F86D2618EF382 ] usbser          C:\Windows\system32\DRIVERS\usbser.sys
12:36:09.0506 0x0ddc  usbser - ok
12:36:09.0537 0x0ddc  [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:36:09.0600 0x0ddc  USBSTOR - ok
12:36:09.0615 0x0ddc  [ DD253AFC3BC6CBA412342DE60C3647F3, 146F8613F1057AC054DC3593E84BC52899DA27EA33B0E72ACFB78C3699ADCDE7 ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
12:36:09.0662 0x0ddc  usbuhci - ok
12:36:09.0709 0x0ddc  [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
12:36:09.0756 0x0ddc  usbvideo - ok
12:36:09.0771 0x0ddc  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms           C:\Windows\System32\uxsms.dll
12:36:09.0834 0x0ddc  UxSms - ok
12:36:09.0849 0x0ddc  [ CA4FC33FB22D92368A0B221092B46374, 2FB8C496216E5D11627F7832B3B8ABE486E71DF4EC28EABE33F89847BFC5E591 ] VaultSvc        C:\Windows\system32\lsass.exe
12:36:09.0865 0x0ddc  VaultSvc - ok
12:36:09.0881 0x0ddc  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
12:36:09.0927 0x0ddc  vdrvroot - ok
12:36:09.0974 0x0ddc  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds             C:\Windows\System32\vds.exe
12:36:10.0021 0x0ddc  vds - ok
12:36:10.0052 0x0ddc  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
12:36:10.0068 0x0ddc  vga - ok
12:36:10.0083 0x0ddc  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave         C:\Windows\System32\drivers\vga.sys
12:36:10.0130 0x0ddc  VgaSave - ok
12:36:10.0146 0x0ddc  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
12:36:10.0161 0x0ddc  vhdmp - ok
12:36:10.0193 0x0ddc  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\drivers\viaide.sys
12:36:10.0208 0x0ddc  viaide - ok
12:36:10.0224 0x0ddc  [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus           C:\Windows\system32\drivers\vmbus.sys
12:36:10.0239 0x0ddc  vmbus - ok
12:36:10.0255 0x0ddc  [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
12:36:10.0271 0x0ddc  VMBusHID - ok
12:36:10.0286 0x0ddc  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
12:36:10.0302 0x0ddc  volmgr - ok
12:36:10.0333 0x0ddc  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
12:36:10.0364 0x0ddc  volmgrx - ok
12:36:10.0380 0x0ddc  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap         C:\Windows\system32\drivers\volsnap.sys
12:36:10.0395 0x0ddc  volsnap - ok
12:36:10.0473 0x0ddc  [ 6C60B5B5E6510BBC0CC3BA78722E8C80, F9E445566C314FF2F22382C051A090083741E86986729E905F07767DD9B84ABE ] vpnagent        C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
12:36:10.0520 0x0ddc  vpnagent - ok
12:36:10.0551 0x0ddc  [ 0F42C39016F82F345C0F2DB2D5B90EB4, 2E957E72BB8D0293F61FA7385BA9400DF7759E1E3D35FE24F3877A6460988F4D ] vpnva           C:\Windows\system32\DRIVERS\vpnva64-6.sys
12:36:10.0598 0x0ddc  vpnva - ok
12:36:10.0614 0x0ddc  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
12:36:10.0629 0x0ddc  vsmraid - ok
12:36:10.0739 0x0ddc  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS             C:\Windows\system32\vssvc.exe
12:36:10.0848 0x0ddc  VSS - ok
12:36:10.0863 0x0ddc  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
12:36:10.0879 0x0ddc  vwifibus - ok
12:36:10.0910 0x0ddc  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time         C:\Windows\system32\w32time.dll
12:36:10.0941 0x0ddc  W32Time - ok
12:36:10.0957 0x0ddc  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
12:36:10.0973 0x0ddc  WacomPen - ok
12:36:11.0019 0x0ddc  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
12:36:11.0051 0x0ddc  WANARP - ok
12:36:11.0051 0x0ddc  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
12:36:11.0082 0x0ddc  Wanarpv6 - ok
12:36:11.0175 0x0ddc  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE5B8D27DCDCAB61 ] WatAdminSvc     C:\Windows\system32\Wat\WatAdminSvc.exe
12:36:11.0238 0x0ddc  WatAdminSvc - ok
12:36:11.0331 0x0ddc  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\Windows\system32\wbengine.exe
12:36:11.0409 0x0ddc  wbengine - ok
12:36:11.0425 0x0ddc  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
12:36:11.0472 0x0ddc  WbioSrvc - ok
12:36:11.0503 0x0ddc  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
12:36:11.0534 0x0ddc  wcncsvc - ok
12:36:11.0534 0x0ddc  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:36:11.0612 0x0ddc  WcsPlugInService - ok
12:36:11.0643 0x0ddc  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\DRIVERS\wd.sys
12:36:11.0675 0x0ddc  Wd - ok
12:36:11.0721 0x0ddc  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
12:36:11.0753 0x0ddc  Wdf01000 - ok
12:36:11.0784 0x0ddc  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost  C:\Windows\system32\wdi.dll
12:36:11.0815 0x0ddc  WdiServiceHost - ok
12:36:11.0815 0x0ddc  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost   C:\Windows\system32\wdi.dll
12:36:11.0831 0x0ddc  WdiSystemHost - ok
12:36:11.0862 0x0ddc  [ 0EB0E5D22B1760F2DBCE632F2DD7A54D, B8A4CC62F88768947FB0A161CF9564DB28FD9C1C037B5475DF192982DE035C22 ] WebClient       C:\Windows\System32\webclnt.dll
12:36:11.0893 0x0ddc  WebClient - ok
12:36:11.0909 0x0ddc  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\Windows\system32\wecsvc.dll
12:36:11.0971 0x0ddc  Wecsvc - ok
12:36:11.0987 0x0ddc  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
12:36:12.0033 0x0ddc  wercplsupport - ok
12:36:12.0065 0x0ddc  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
12:36:12.0096 0x0ddc  WerSvc - ok
12:36:12.0127 0x0ddc  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
12:36:12.0158 0x0ddc  WfpLwf - ok
12:36:12.0158 0x0ddc  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
12:36:12.0174 0x0ddc  WIMMount - ok
12:36:12.0205 0x0ddc  WinDefend - ok
12:36:12.0205 0x0ddc  WinHttpAutoProxySvc - ok
12:36:12.0283 0x0ddc  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
12:36:12.0361 0x0ddc  Winmgmt - ok
12:36:12.0486 0x0ddc  [ D929ABD465A2DED963DA8B30946A8D5C, DE8DBFB01C11D2AE903CBD6A974D6F995E9813CE2D6484B7DA06EAE4C545842A ] WinRM           C:\Windows\system32\WsmSvc.dll
12:36:12.0611 0x0ddc  WinRM - ok
12:36:12.0673 0x0ddc  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\Windows\system32\drivers\WinUsb.sys
12:36:12.0720 0x0ddc  WinUsb - ok
12:36:12.0782 0x0ddc  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc         C:\Windows\System32\wlansvc.dll
12:36:12.0829 0x0ddc  Wlansvc - ok
12:36:13.0032 0x0ddc  [ 98F138897EF4246381D197CB81846D62, A9FA88475AFBB8883297708608EC7C1AC29F229C3299A84D557172604813A18C ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
12:36:13.0125 0x0ddc  wlidsvc - ok
12:36:13.0157 0x0ddc  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
12:36:13.0203 0x0ddc  WmiAcpi - ok
12:36:13.0250 0x0ddc  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
12:36:13.0297 0x0ddc  wmiApSrv - ok
12:36:13.0330 0x0ddc  WMPNetworkSvc - ok
12:36:13.0330 0x0ddc  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
12:36:13.0393 0x0ddc  WPCSvc - ok
12:36:13.0426 0x0ddc  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
12:36:13.0490 0x0ddc  WPDBusEnum - ok
12:36:13.0521 0x0ddc  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
12:36:13.0599 0x0ddc  ws2ifsl - ok
12:36:13.0631 0x0ddc  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\System32\wscsvc.dll
12:36:13.0655 0x0ddc  wscsvc - ok
12:36:13.0658 0x0ddc  WSearch - ok
12:36:13.0791 0x0ddc  [ 0814A74C853F50B354F08F83DDA9F7FB, 0A63BAA8DE451B8C2C71FEF961718E769B9BAC305C76D24048C664CB27D0DF28 ] wuauserv        C:\Windows\system32\wuaueng.dll
12:36:13.0918 0x0ddc  wuauserv - ok
12:36:13.0949 0x0ddc  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
12:36:14.0000 0x0ddc  WudfPf - ok
12:36:14.0016 0x0ddc  [ 834469525EE22EFF3F411014E31B3E7B, 923499AFFAC47857EE7DADA747A6008C5ADE81C4B04A13E00A1879728ABE957E ] WUDFRd          C:\Windows\system32\drivers\WUDFRd.sys
12:36:14.0031 0x0ddc  WUDFRd - detected UnsignedFile.Multi.Generic ( 1 )
12:36:16.0559 0x0ddc  Object is SCO, delete is not allowed
12:36:16.0559 0x0ddc  WUDFRd ( UnsignedFile.Multi.Generic ) - warning
12:36:19.0051 0x0ddc  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
12:36:19.0088 0x0ddc  wudfsvc - ok
12:36:19.0126 0x0ddc  [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc         C:\Windows\System32\wwansvc.dll
12:36:19.0238 0x0ddc  WwanSvc - ok
12:36:19.0272 0x0ddc  [ D0352B3BD81565F97978128A308ED541, 330565435F7C7149EFEF17112FAF54B2F155736904F32D18A41EAA907AD4EF0D ] ZCLDRV          C:\Windows\system32\DRIVERS\ZclDrv64.sys
12:36:19.0438 0x0ddc  ZCLDRV - ok
12:36:19.0508 0x0ddc  ================ Scan global ===============================
12:36:19.0559 0x0ddc  [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll
12:36:19.0688 0x0ddc  [ EA32F4EA3AE06EDD122FBCD5A489E457, C6E464170121D1714A367CFC80C5EA15D42AD34909039FDB114EAD3B878A47F6 ] C:\Windows\system32\winsrv.dll
12:36:19.0783 0x0ddc  [ EA32F4EA3AE06EDD122FBCD5A489E457, C6E464170121D1714A367CFC80C5EA15D42AD34909039FDB114EAD3B878A47F6 ] C:\Windows\system32\winsrv.dll
12:36:19.0820 0x0ddc  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
12:36:19.0926 0x0ddc  [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe
12:36:19.0974 0x0ddc  [ Global ] - ok
12:36:19.0974 0x0ddc  ================ Scan MBR ==================================
12:36:19.0991 0x0ddc  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:36:23.0268 0x0ddc  \Device\Harddisk0\DR0 - ok
12:36:23.0269 0x0ddc  ================ Scan VBR ==================================
12:36:23.0282 0x0ddc  [ 6C14845D90610B9AF624B26F6D8FB3E8 ] \Device\Harddisk0\DR0\Partition1
12:36:23.0290 0x0ddc  \Device\Harddisk0\DR0\Partition1 - ok
12:36:23.0309 0x0ddc  [ 1E26BF6F68737874C1D4231B149B3BF9 ] \Device\Harddisk0\DR0\Partition2
12:36:23.0321 0x0ddc  \Device\Harddisk0\DR0\Partition2 - ok
12:36:23.0322 0x0ddc  ================ Scan generic autorun ======================
12:36:25.0801 0x0ddc  [ BF5ECAC9B15AF1424EC4E7B3280537EB, B39FD921978EB1929F016B81498DA962BB3D597A593B2E5D992490A74CCBF62D ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
12:36:26.0145 0x0ddc  RtHDVCpl - ok
12:36:26.0223 0x0ddc  [ D0B542256A968DFCB8896C140FCE6047, 3F92A9871B521BCCCDFE6D9BFF88930B26C5DB86F6F6578554A3F2ECC5C5EBA0 ] C:\Program Files\iTunes\iTunesHelper.exe
12:36:26.0254 0x0ddc  iTunesHelper - ok
12:36:26.0394 0x0ddc  [ 66177D4C99FD8B578C7C56DE445E4D5D, 003D0254D7C693A72DE84CB76858F8D67D9FD62206F1B56DF7F5D0FA834C3BA7 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
12:36:26.0410 0x0ddc  avgnt - ok
12:36:26.0644 0x0ddc  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
12:36:26.0815 0x0ddc  Sidebar - ok
12:36:26.0862 0x0ddc  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
12:36:26.0925 0x0ddc  mctadmin - ok
12:36:26.0971 0x0ddc  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
12:36:27.0003 0x0ddc  Sidebar - ok
12:36:27.0018 0x0ddc  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
12:36:27.0018 0x0ddc  mctadmin - ok
12:36:27.0424 0x0ddc  [ 5D566601E0F94B70946C15B66DE1CE9A, DD3006EC080B62A8FD943916CB451A55C9BFD7D9DBCA2956078EEC7D167052CF ] C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe
12:36:27.0658 0x0ddc  Vidalia - detected UnsignedFile.Multi.Generic ( 1 )
12:36:30.0123 0x0ddc  Detect skipped due to KSN trusted
12:36:30.0123 0x0ddc  Vidalia - ok
12:36:31.0137 0x0ddc  [ 771293BC7EACB6FB7A78F8B7A954F019, DF06F0D0C8E38F17AD155CAB009A5A2969E7638B88AFBC2A75450EB1239ECAB4 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe
12:36:31.0324 0x0ddc  Spybot-S&D Cleaning - ok
12:36:31.0355 0x0ddc  OscarEditor - ok
12:36:31.0605 0x0ddc  [ 5D566601E0F94B70946C15B66DE1CE9A, DD3006EC080B62A8FD943916CB451A55C9BFD7D9DBCA2956078EEC7D167052CF ] C:\Program Files (x86)\Vidalia Bridge Bundle\Vidalia\vidalia.exe
12:36:31.0745 0x0ddc  Vidalia - detected UnsignedFile.Multi.Generic ( 1 )
12:36:31.0745 0x0ddc  Detect skipped due to KSN trusted
12:36:31.0745 0x0ddc  Vidalia - ok
12:36:31.0995 0x0ddc  [ 771293BC7EACB6FB7A78F8B7A954F019, DF06F0D0C8E38F17AD155CAB009A5A2969E7638B88AFBC2A75450EB1239ECAB4 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe
12:36:32.0085 0x0ddc  Spybot-S&D Cleaning - ok
12:36:32.0092 0x0ddc  Adobe Speed Launcher - ok
12:36:32.0093 0x0ddc  Waiting for KSN requests completion. In queue: 2
12:36:33.0093 0x0ddc  Waiting for KSN requests completion. In queue: 2
12:36:34.0096 0x0ddc  Waiting for KSN requests completion. In queue: 2
12:36:35.0208 0x0ddc  AV detected via SS2: Avira Antivirus, C:\Program Files (x86)\Avira\AntiVir Desktop\wsctool.exe ( 15.0.10.414 ), 0x41000 ( enabled : updated )
12:36:35.0288 0x0ddc  Win FW state via NFP2: enabled
12:36:37.0673 0x0ddc  ============================================================
12:36:37.0673 0x0ddc  Scan finished
12:36:37.0673 0x0ddc  ============================================================
12:36:37.0676 0x10d0  Detected object count: 1
12:36:37.0676 0x10d0  Actual detected object count: 1
12:36:45.0173 0x10d0  WUDFRd ( UnsignedFile.Multi.Generic ) - skipped by user
12:36:45.0173 0x10d0  WUDFRd ( UnsignedFile.Multi.Generic ) - User select action: Skip
         

Alt 11.05.2015, 06:06   #7
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



ist legitim
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 11.05.2015, 09:04   #8
Labrat
 
DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



Vielen dank! Toll das ihr dieses Forum betreibt!

Alt 11.05.2015, 13:23   #9
schrauber
/// the machine
/// TB-Ausbilder
 

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Standard

DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht
adobe, antivir, avira, bonjour, browser, converter, defender, desktop, fehler, flash player, google, kaspersky, launch, log file, mozilla, phishing, realtek, registry, rundll, scan, services.exe, software, super, system, trojaner, trojaner board, windows



Ähnliche Themen: DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht


  1. Phishing Mail unter Android angeklickt und ZIP-Datei geöffnet / XPERIA Z1
    Smartphone, Tablet & Handy Security - 03.06.2015 (1)
  2. DHL E-mail geöffnet und link angeklickt
    Log-Analyse und Auswertung - 08.05.2015 (14)
  3. Phishing Mail DHL Link angeklickt
    Log-Analyse und Auswertung - 26.03.2015 (13)
  4. DHL Phishing Mail Link angeklickt
    Plagegeister aller Art und deren Bekämpfung - 15.03.2015 (7)
  5. Windows 7: DHL-Phishing-Mail geöffnet, auf den Link geklickt, .zip-File nicht heruntergeladen
    Log-Analyse und Auswertung - 10.03.2015 (13)
  6. DHL Mail bekommen und den Link angeklickt / geöffnet :(
    Log-Analyse und Auswertung - 05.03.2015 (13)
  7. Phishing-Mail-Link angeklickt (Paypal-Phishing-Mail)
    Plagegeister aller Art und deren Bekämpfung - 29.11.2014 (9)
  8. Link in Phishing mail geöffnet
    Log-Analyse und Auswertung - 10.08.2014 (3)
  9. Amazon Phishing Mail Link angeklickt
    Plagegeister aller Art und deren Bekämpfung - 24.06.2014 (11)
  10. Telekom - Link in gefälschter Rechnung angeklickt und zip-Datei geöffnet
    Plagegeister aller Art und deren Bekämpfung - 15.06.2014 (15)
  11. Windows 7: Amazon Phishing-Mail Link angeklickt
    Log-Analyse und Auswertung - 16.02.2014 (11)
  12. Spam/Phishing-Mail von Amazon in Thunderbird angeklickt und in Firefox geöffnet
    Log-Analyse und Auswertung - 15.02.2014 (16)
  13. Win7: Link in Phishing Mail zur Abmeldung von Newsletter angeklickt
    Plagegeister aller Art und deren Bekämpfung - 18.12.2013 (14)
  14. Phishing Mail von WoW Link angeklickt!
    Plagegeister aller Art und deren Bekämpfung - 07.07.2013 (4)
  15. Link in Phishing-Mail angeklickt: Malware eingefangen?
    Log-Analyse und Auswertung - 21.05.2013 (5)
  16. Link in Mastercard Phishing mail angeklickt -Virus o. Ä. ?
    Plagegeister aller Art und deren Bekämpfung - 10.05.2013 (20)
  17. In Phishing-Mail den Link angeklickt :( Panik
    Plagegeister aller Art und deren Bekämpfung - 19.02.2013 (34)

Zum Thema DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht - Hallo liebes Trojaner Board, ich habe, wie viele andere auch diese vorgebliche DHL-Mail bekommen und da ich auf eine Lieferung gewartet habe, habe ich im Affekt auf den link geklickt. - DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht...
Archiv
Du betrachtest: DHL Phishing Mail - Link angeklickt - ZIP-Datei NICHT geöffnet / gelöscht auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.