Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Firefox baut unseriöse Verbindugen auf

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 12.11.2016, 13:09   #1
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Hallo erstmal!

Ich habe mal vor kurzem im sog. "Resourcenmonitor" von Windows geschaut wohin u.a. firefox seine Verbindungen aufbaut. Da habe ich gesehen, dass eine Verbindung zu hxxp://waw02s05-in-f4.e100.net aufgeabut wird. Ich kopierte diesen Link und öffnete ihm im Firefox, worauf sofort eine Meldung kam, dass diese Website gefährlich sei. Deswegen möchte ich wissen, ob ich einen Virus hab. Mfg Kev

OTL:
OTL Logfile:
Code:
ATTFilter
OTL logfile created on: 12.11.2016 11:56:40 - Run 8
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\kevin\Desktop\AV
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18524)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,93 Gb Total Physical Memory | 6,49 Gb Available Physical Memory | 81,77% Memory free
15,87 Gb Paging File | 14,37 Gb Available in Paging File | 90,56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 263,57 Gb Total Space | 81,28 Gb Free Space | 30,84% Space Free | Partition Type: NTFS
 
Computer Name: PC1-KK | User Name: kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2016.09.15 14:25:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\kevin\Desktop\AV\OTL.exe
PRC - [2016.06.03 04:19:32 | 000,426,040 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
PRC - [2015.09.10 19:05:30 | 004,691,384 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\kevin\AppData\Local\Akamai\netsession_win.exe
PRC - [2015.06.23 15:00:08 | 000,322,472 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2015.06.23 15:00:06 | 000,018,856 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2015.06.15 09:00:28 | 000,296,216 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2013.10.23 23:39:14 | 001,017,224 | ---- | M] (Flux Software LLC) -- C:\Users\kevin\AppData\Local\FluxSoftware\Flux\flux.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2016.06.17 15:46:15 | 001,102,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servf73e6522#\8e120675c80a179c177d6d9b5345e792\System.ServiceModel.Web.ni.dll
MOD - [2016.06.17 15:46:14 | 000,786,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\e2ab3c1c7be8727fb1f36945861e780b\System.ServiceModel.Internals.ni.dll
MOD - [2016.06.17 15:46:14 | 000,430,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv30e99c02#\fc811832eb4d1a081148bcb0128416f5\System.ServiceModel.Channels.ni.dll
MOD - [2016.06.17 15:46:12 | 019,426,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\a459f8b69edabf287d593a2a08c5c8d6\System.ServiceModel.ni.dll
MOD - [2016.06.17 15:46:04 | 002,772,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\ffbd00c458124054f2049e9a25a7cca8\System.Runtime.Serialization.ni.dll
MOD - [2016.06.17 15:46:00 | 002,937,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\c56cbffc8423ff484bf3f80aae1d5c24\System.IdentityModel.ni.dll
MOD - [2016.06.17 15:45:36 | 000,117,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\32b270a7b4daf4731cf1c36ecd660297\SMDiagnostics.ni.dll
MOD - [2016.06.17 14:23:25 | 012,945,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\7b437291b260f008653ebc86553ab462\System.Windows.Forms.ni.dll
MOD - [2016.06.17 14:23:25 | 007,378,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\36599a72e79974ff4c004c43df9fce2b\System.Xml.ni.dll
MOD - [2016.06.17 14:23:25 | 000,974,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\6b3bc806e6d6a2c73c6d9f1429395698\System.Configuration.ni.dll
MOD - [2016.06.17 14:23:23 | 007,518,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\a57805cc2d492d82e327b83ab24fad62\System.Core.ni.dll
MOD - [2016.06.17 14:23:22 | 001,876,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\347ba862763b7e7c80bdef8764ae72dc\System.Xaml.ni.dll
MOD - [2016.06.17 14:23:21 | 001,623,552 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\48453ce4573683172752f7fdc00f8820\System.Drawing.ni.dll
MOD - [2016.06.17 14:23:19 | 009,983,488 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\d03eb8a47500f40d5428f9c6875f8e56\System.ni.dll
MOD - [2016.06.17 14:23:16 | 018,111,488 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\affcb83bba04f782c2586a1788330891\mscorlib.ni.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2016.11.10 16:19:50 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2016.11.10 16:19:49 | 001,386,496 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:64bit: - [2015.05.07 14:00:20 | 000,271,632 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel(R)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2016.11.09 12:58:20 | 000,270,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2016.10.21 13:43:06 | 000,172,488 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2016.10.13 02:58:30 | 001,459,488 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2016.10.10 08:59:14 | 000,009,728 | ---- | M] (Hi-Rez Studios) [Auto | Paused] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2016.09.20 11:54:54 | 000,324,224 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2016.06.03 04:19:32 | 000,426,040 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe -- (Stereo Service)
SRV - [2015.11.05 19:36:48 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2015.07.02 21:21:26 | 000,356,808 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2015.06.23 15:00:06 | 000,018,856 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2014.10.25 11:59:46 | 000,016,064 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Mirillis\Action!\action_svc.exe -- (ACTION_SVC)
SRV - [2014.03.20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2016.11.12 11:38:26 | 000,192,216 | ---- | M] (Malwarebytes) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2016.11.12 11:38:10 | 000,109,272 | ---- | M] (Malwarebytes) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbamchameleon.sys -- (mbamchameleon)
DRV:64bit: - [2016.09.02 12:13:41 | 000,046,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2016.06.03 08:38:10 | 000,141,256 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2015.06.30 11:44:27 | 000,814,376 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2015.06.26 16:13:33 | 000,403,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2015.06.23 14:58:58 | 001,455,552 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2015.06.23 14:58:58 | 000,031,144 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:64bit: - [2015.06.18 17:50:06 | 000,501,216 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1d62x64.sys -- (e1dexpress)
DRV:64bit: - [2015.06.18 03:25:00 | 000,122,000 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouKE.Sys -- (LMouKE)
DRV:64bit: - [2015.06.18 03:25:00 | 000,099,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L8042mou.Sys -- (L8042mou)
DRV:64bit: - [2015.06.18 03:25:00 | 000,086,672 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2015.06.18 03:25:00 | 000,069,264 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2015.06.18 03:25:00 | 000,040,592 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV:64bit: - [2013.10.02 03:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.08.23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 15:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010.11.21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE12&ocid=UE12DHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D1 59 3C 7D 50 26 D2 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 3B 40 93 BB 58 0F D2 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
 
========== FireFox ==========
 
FF - prefs.js..browser.search.countryCode: "DE"
FF - prefs.js..browser.search.region: "DE"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.9.0.14
FF - prefs.js..extensions.enabledAddons: https-everywhere%40eff.org:5.2.7
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:49.0.2
FF - prefs.js..network.proxy.http: "209.150.253.84"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.111.2: C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.111.2: C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll ()
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016.06.11 08:21:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 49.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 49.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 49.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 49.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2016.05.17 19:57:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\Extensions
[2016.08.12 13:44:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\Firefox\Profiles\b8wlbzof.default\browser-extension-data
[2016.09.02 12:39:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\Firefox\Profiles\b8wlbzof.default\browser-extension-data\firefox@ghostery.com
[2016.11.12 11:51:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\Firefox\Profiles\b8wlbzof.default\extension-data
[2016.11.10 16:11:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\Firefox\Profiles\b8wlbzof.default\extensions
[2016.10.22 15:39:23 | 001,210,908 | ---- | M] () (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\firefox\profiles\b8wlbzof.default\extensions\firefox@ghostery.com.xpi
[2016.11.10 16:11:05 | 002,785,953 | ---- | M] () (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\firefox\profiles\b8wlbzof.default\extensions\https-everywhere@eff.org.xpi
[2016.10.25 17:03:46 | 001,517,755 | ---- | M] () (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\firefox\profiles\b8wlbzof.default\extensions\uBlock0@raymondhill.net.xpi
[2016.08.09 13:44:09 | 000,564,604 | ---- | M] () (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\firefox\profiles\b8wlbzof.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2016.10.11 15:35:54 | 000,734,889 | ---- | M] () (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\firefox\profiles\b8wlbzof.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
[2016.09.29 19:20:00 | 001,295,123 | ---- | M] () (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\firefox\profiles\b8wlbzof.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2016.10.27 17:03:46 | 000,005,389 | ---- | M] () (No name found) -- C:\Users\kevin\AppData\Roaming\mozilla\firefox\profiles\b8wlbzof.default\features\{70bd3440-eddf-48cb-a032-48d3f9a018ea}\asyncrendering@mozilla.org.xpi
[2016.10.21 13:43:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
 
O1 HOSTS File: ([2016.11.12 11:50:26 | 000,000,865 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.8.0_111\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Programme\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre1.8.0_111\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Programme\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Aeria Ignite] C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (Aeria Games & Entertainment)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\kevin\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [f.lux] C:\Users\kevin\AppData\Local\FluxSoftware\Flux\flux.exe (Flux Software LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aeriagames.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: aeriagames.com ([]https in Trusted sites)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1463598850208 (MUCatalogWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C2BCC291-8679-4E20-A2C8-5A503ED1A8F1}: DhcpNameServer = 192.168.0.254
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Programme\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7e80f4c7-1c51-11e6-973a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7e80f4c7-1c51-11e6-973a-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Run.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2016.11.10 16:18:40 | 006,047,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2016.11.10 16:18:39 | 001,386,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diagtrack.dll
[2016.11.10 16:18:39 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UtcResources.dll
[2016.11.10 16:18:38 | 005,547,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2016.11.10 16:18:37 | 001,462,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2016.11.10 16:18:35 | 001,732,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2016.11.10 16:18:35 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2016.11.10 16:18:35 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2016.11.10 16:18:35 | 000,756,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2016.11.10 16:18:35 | 000,706,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2016.11.10 16:18:35 | 000,631,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2016.11.10 16:18:35 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll
[2016.11.10 16:18:35 | 000,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll
[2016.11.10 16:18:34 | 004,000,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2016.11.10 16:18:34 | 003,944,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2016.11.10 16:18:34 | 002,131,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2016.11.10 16:18:34 | 002,055,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2016.11.10 16:18:34 | 000,806,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2016.11.10 16:18:34 | 000,725,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2016.11.10 16:18:34 | 000,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2016.11.10 16:18:34 | 000,382,696 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2016.11.10 16:18:34 | 000,308,456 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2016.11.10 16:18:34 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tintlgnt.ime
[2016.11.10 16:18:34 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cintlgnt.ime
[2016.11.10 16:18:34 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pintlgnt.ime
[2016.11.10 16:18:34 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tintlgnt.ime
[2016.11.10 16:18:34 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pintlgnt.ime
[2016.11.10 16:18:33 | 001,148,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10.IME
[2016.11.10 16:18:33 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll
[2016.11.10 16:18:33 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2016.11.10 16:18:33 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10K.DLL
[2016.11.10 16:18:33 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quick.ime
[2016.11.10 16:18:33 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qintlgnt.ime
[2016.11.10 16:18:33 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\phon.ime
[2016.11.10 16:18:33 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\chajei.ime
[2016.11.10 16:18:33 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cintlgnt.ime
[2016.11.10 16:18:32 | 001,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10.IME
[2016.11.10 16:18:32 | 000,877,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2016.11.10 16:18:32 | 000,701,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10K.DLL
[2016.11.10 16:18:32 | 000,457,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imkr80.ime
[2016.11.10 16:18:32 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imkr80.ime
[2016.11.10 16:18:32 | 000,246,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\input.dll
[2016.11.10 16:18:32 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\input.dll
[2016.11.10 16:18:32 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quick.ime
[2016.11.10 16:18:32 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qintlgnt.ime
[2016.11.10 16:18:32 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\phon.ime
[2016.11.10 16:18:32 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\chajei.ime
[2016.11.10 16:18:30 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2016.11.10 16:18:30 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2016.11.10 16:18:30 | 000,615,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2016.11.10 16:18:30 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2016.11.10 16:18:30 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2016.11.10 16:18:30 | 000,463,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2016.11.10 16:18:30 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2016.11.10 16:18:30 | 000,342,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2016.11.10 16:18:30 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2016.11.10 16:18:30 | 000,315,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2016.11.10 16:18:30 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2016.11.10 16:18:30 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2016.11.10 16:18:30 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2016.11.10 16:18:30 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2016.11.10 16:18:30 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2016.11.10 16:18:30 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2016.11.10 16:18:30 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2016.11.10 16:18:30 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2016.11.10 16:18:30 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2016.11.10 16:18:30 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2016.11.10 16:18:30 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2016.11.10 16:18:30 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2016.11.10 16:18:30 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2016.11.10 16:18:30 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2016.11.10 16:18:30 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2016.11.10 16:18:30 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2016.11.10 16:18:30 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2016.11.10 16:18:30 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2016.11.10 16:18:30 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2016.11.10 16:18:30 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2016.11.10 16:18:29 | 001,212,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2016.11.10 16:18:29 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2016.11.10 16:18:29 | 000,880,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2016.11.10 16:18:29 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2016.11.10 16:18:29 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2016.11.10 16:18:29 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2016.11.10 16:18:29 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2016.11.10 16:18:29 | 000,576,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2016.11.10 16:18:29 | 000,312,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2016.11.10 16:18:29 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2016.11.10 16:18:29 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2016.11.10 16:18:29 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2016.11.10 16:18:29 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2016.11.10 16:18:29 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\INETRES.dll
[2016.11.10 16:18:29 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpk.dll
[2016.11.10 16:18:29 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2016.11.10 16:18:28 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2016.11.10 16:18:28 | 000,419,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2016.11.10 16:18:28 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2016.11.10 16:18:28 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2016.11.10 16:18:28 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2016.11.10 16:18:28 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2016.11.10 16:18:28 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2016.11.10 16:18:28 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpchttp.dll
[2016.11.10 16:18:28 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidpolicyconverter.exe
[2016.11.10 16:18:28 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rpchttp.dll
[2016.11.10 16:18:28 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2016.11.10 16:18:28 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\auditpol.exe
[2016.11.10 16:18:28 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll
[2016.11.10 16:18:28 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidapi.dll
[2016.11.10 16:18:28 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appidapi.dll
[2016.11.10 16:18:28 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2016.11.10 16:18:28 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\auditpol.exe
[2016.11.10 16:18:28 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2016.11.10 16:18:28 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2016.11.10 16:18:28 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptbase.dll
[2016.11.10 16:18:28 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2016.11.10 16:18:28 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2016.11.10 16:18:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2016.11.10 16:18:28 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidcertstorecheck.exe
[2016.11.10 16:18:28 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2016.11.10 16:18:28 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2016.11.10 16:18:28 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dciman32.dll
[2016.11.10 16:18:28 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2016.11.10 16:18:28 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2016.11.10 16:18:28 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2016.11.10 16:18:28 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2016.11.10 16:18:28 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2016.11.10 16:18:28 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2016.11.10 16:18:28 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2016.11.10 16:18:28 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2016.11.10 16:18:28 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2016.11.10 16:18:28 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2016.11.10 16:18:28 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2016.11.10 16:18:28 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2016.11.10 16:18:27 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2016.11.10 16:18:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2016.11.10 16:18:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2016.11.10 16:18:27 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2016.11.10 16:18:27 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2016.11.10 16:18:27 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2016.11.10 16:18:27 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2016.11.10 16:18:27 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2016.11.10 16:18:27 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2016.11.10 16:18:27 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2016.11.10 16:18:27 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2016.11.10 16:18:27 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2016.11.10 16:18:27 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2016.11.10 16:18:27 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2016.11.10 16:18:26 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2016.11.10 16:18:26 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2016.11.10 16:18:26 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2016.11.10 16:18:26 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2016.11.10 16:18:26 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msobjs.dll
[2016.11.10 16:18:26 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msobjs.dll
[2016.11.09 13:55:03 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Local\Targem
[2016.11.01 19:32:53 | 000,000,000 | ---D | C] -- C:\Users\kevin\Desktop\1.10 Modding
[2016.10.31 22:22:18 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Local\Skyrim Special Edition
[2016.10.29 16:55:56 | 000,000,000 | ---D | C] -- C:\Users\kevin\flsongs
[2016.10.29 15:17:52 | 000,000,000 | ---D | C] -- C:\Users\kevin\Desktop\teeworlds-0.6.2-win64
[2016.10.29 14:51:04 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Roaming\Teeworlds
[2016.10.28 23:27:12 | 000,000,000 | ---D | C] -- C:\Users\kevin\Desktop\L ist ein Huso
[2016.10.28 23:20:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lame For Audacity
[2016.10.28 23:15:21 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Local\ElevatedDiagnostics
[2016.10.28 23:15:10 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Local\Diagnostics
[2016.10.28 23:11:46 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Roaming\DVDVideoSoft
[2016.10.28 17:44:23 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Roaming\Audacity
[2016.10.28 17:44:23 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Local\Audacity
[2016.10.28 17:44:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity
[2016.10.26 18:52:16 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Local\HirezLauncherUI
[2016.10.26 18:51:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2016.10.26 18:50:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2016.10.26 18:50:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Hi-Rez Studios
[2016.10.26 18:50:10 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2016.10.26 18:50:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hi-Rez Studios
[2016.10.23 19:55:05 | 000,000,000 | ---D | C] -- C:\Users\kevin\Tracing
[2016.10.23 19:54:53 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Roaming\Skype
[2016.10.23 19:54:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2016.10.23 19:54:47 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2016.10.23 19:54:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2016.10.23 19:54:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2016.10.22 18:06:39 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Roaming\obs-studio
[2016.10.22 18:04:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
[2016.10.22 18:04:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\obs-studio
[2016.10.22 13:40:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2016.10.21 16:49:12 | 000,000,000 | ---D | C] -- C:\Users\kevin\Desktop\org
[2016.10.21 13:43:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2016.10.17 15:24:14 | 000,000,000 | ---D | C] -- C:\Users\kevin\Desktop\AV
[2016.10.16 16:49:55 | 000,000,000 | ---D | C] -- C:\FRST
[2016.10.16 16:33:12 | 000,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe
[2016.10.16 16:33:12 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe
[2016.10.14 19:43:46 | 000,000,000 | ---D | C] -- C:\Users\kevin\Desktop\Virus
[2016.10.14 17:19:39 | 000,000,000 | ---D | C] -- C:\Users\kevin\Desktop\DPK TRAINING DU LOW GEHJ
[2016.10.14 13:34:25 | 000,000,000 | -H-D | C] -- C:\Users\kevin\Desktop\FL12
[2016.10.13 20:17:13 | 000,000,000 | ---D | C] -- C:\Users\kevin\AppData\Roaming\Bat To Exe Converter
[2016.10.13 20:17:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bat To Exe Converter
[2016.10.13 20:17:11 | 000,000,000 | ---D | C] -- C:\Program Files\Bat To Exe Converter
[2016.10.13 15:05:32 | 014,632,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2016.10.13 15:05:32 | 011,410,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2016.10.13 15:05:31 | 004,121,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2016.10.13 15:05:30 | 003,209,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2016.10.13 15:05:30 | 000,842,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll
[2016.10.13 15:05:30 | 000,744,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll
[2016.10.13 15:05:29 | 001,202,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmv2clt.dll
[2016.10.13 15:05:29 | 000,988,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmv2clt.dll
[2016.10.13 15:05:28 | 001,573,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2016.10.13 15:05:28 | 001,329,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2016.10.13 15:05:28 | 000,782,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll
[2016.10.13 15:05:28 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll
[2016.10.13 15:05:28 | 000,461,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scavengeui.dll
[2016.10.13 15:05:27 | 000,632,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll
[2016.10.13 15:05:27 | 000,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2016.10.13 15:05:27 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll
[2016.10.13 15:05:26 | 001,648,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2016.10.13 15:05:26 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll
[2016.10.13 15:05:26 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2016.10.13 15:05:26 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll
[2016.10.13 15:05:26 | 000,442,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
[2016.10.13 15:05:26 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll
[2016.10.13 15:05:26 | 000,371,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2016.10.13 15:05:26 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManMigrationPlugin.dll
[2016.10.13 15:05:26 | 000,310,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmWmiPl.dll
[2016.10.13 15:05:26 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManHTTPConfig.exe
[2016.10.13 15:05:25 | 000,440,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2016.10.13 15:05:25 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManMigrationPlugin.dll
[2016.10.13 15:05:25 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmWmiPl.dll
[2016.10.13 15:05:24 | 001,005,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll
[2016.10.13 15:05:24 | 000,433,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll
[2016.10.13 15:05:24 | 000,199,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManHTTPConfig.exe
[2016.10.13 15:05:23 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll
[2016.10.13 15:05:23 | 000,295,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2016.10.13 15:05:23 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll
[2016.10.13 15:05:23 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2016.10.13 15:05:23 | 000,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmAuto.dll
[2016.10.13 15:05:23 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAuto.dll
[2016.10.13 15:05:21 | 012,574,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2016.10.13 15:05:21 | 012,574,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2016.10.13 15:05:20 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2016.10.13 15:05:19 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2016.10.13 15:05:19 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptsp.dll
[2016.10.13 15:05:18 | 000,641,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll
[2016.10.13 15:05:18 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll
[2016.10.13 15:05:18 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll
[2016.10.13 15:05:18 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll
[2016.10.13 15:05:18 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll
[2016.10.13 15:05:18 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adsmsext.dll
[2016.10.13 15:05:18 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adsmsext.dll
[2016.10.13 15:05:18 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
[2016.10.13 15:05:18 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
[2016.10.13 15:05:18 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcadm.dll
[2016.10.13 15:05:18 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
[2016.10.13 15:05:18 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
[2016.10.13 15:05:18 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsmprovhost.exe
[2016.10.13 15:05:18 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsmplpxy.dll
[2016.10.13 15:05:18 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsmprovhost.exe
[2016.10.13 15:05:18 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcawrk.exe
[2016.10.13 15:05:18 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcalua.exe
[2016.10.13 15:05:17 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmmsp.dll
[2016.10.13 15:05:17 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsmplpxy.dll
[2016.10.13 15:05:17 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll
[2016.10.13 15:05:17 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcaevts.dll
[2016.10.13 15:05:17 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll
[2016.10.13 15:05:17 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx
[2016.10.13 15:05:17 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll
[2016.10.13 15:05:17 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx
[2016.10.13 15:05:17 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll
[2016.10.13 15:05:16 | 001,483,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2016.10.13 15:05:16 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2016.10.13 15:05:16 | 000,141,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2016.10.13 15:05:16 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmRes.dll
[2016.10.13 15:05:16 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmRes.dll
[2016.10.13 15:05:16 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
[2016.10.13 15:05:16 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
 
========== Files - Modified Within 30 Days ==========
 
[2016.11.12 11:57:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2016.11.12 11:52:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016.11.12 11:46:41 | 000,021,856 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016.11.12 11:46:41 | 000,021,856 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016.11.12 11:42:56 | 000,007,611 | ---- | M] () -- C:\Users\kevin\AppData\Local\Resmon.ResmonCfg
[2016.11.12 11:38:26 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2016.11.12 11:38:10 | 000,109,272 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2016.11.11 13:54:42 | 001,622,778 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2016.11.11 13:54:42 | 000,700,146 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2016.11.11 13:54:42 | 000,654,984 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2016.11.11 13:54:42 | 000,149,784 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2016.11.11 13:54:42 | 000,122,354 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2016.11.11 13:48:19 | 000,329,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2016.11.10 16:19:50 | 006,047,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2016.11.10 16:19:50 | 001,359,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2016.11.10 16:19:50 | 001,163,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2016.11.10 16:19:50 | 001,155,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2016.11.10 16:19:50 | 000,878,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10K.DLL
[2016.11.10 16:19:50 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2016.11.10 16:19:50 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2016.11.10 16:19:50 | 000,701,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10K.DLL
[2016.11.10 16:19:50 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2016.11.10 16:19:50 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2016.11.10 16:19:50 | 000,615,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2016.11.10 16:19:50 | 000,497,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2016.11.10 16:19:50 | 000,476,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2016.11.10 16:19:50 | 000,463,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2016.11.10 16:19:50 | 000,457,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imkr80.ime
[2016.11.10 16:19:50 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2016.11.10 16:19:50 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAnimation.dll
[2016.11.10 16:19:50 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2016.11.10 16:19:50 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2016.11.10 16:19:50 | 000,132,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pintlgnt.ime
[2016.11.10 16:19:50 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2016.11.10 16:19:50 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2016.11.10 16:19:50 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pintlgnt.ime
[2016.11.10 16:19:50 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\auditpol.exe
[2016.11.10 16:19:50 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2016.11.10 16:19:50 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msobjs.dll
[2016.11.10 16:19:50 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2016.11.10 16:19:50 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2016.11.10 16:19:50 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2016.11.10 16:19:50 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2016.11.10 16:19:50 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2016.11.10 16:19:49 | 005,547,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2016.11.10 16:19:49 | 004,000,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2016.11.10 16:19:49 | 003,944,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2016.11.10 16:19:49 | 002,131,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2016.11.10 16:19:49 | 002,055,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2016.11.10 16:19:49 | 001,732,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2016.11.10 16:19:49 | 001,462,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2016.11.10 16:19:49 | 001,386,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\diagtrack.dll
[2016.11.10 16:19:49 | 001,212,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2016.11.10 16:19:49 | 001,148,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10.IME
[2016.11.10 16:19:49 | 001,068,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll
[2016.11.10 16:19:49 | 001,027,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10.IME
[2016.11.10 16:19:49 | 000,968,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2016.11.10 16:19:49 | 000,880,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2016.11.10 16:19:49 | 000,877,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2016.11.10 16:19:49 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2016.11.10 16:19:49 | 000,806,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2016.11.10 16:19:49 | 000,756,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2016.11.10 16:19:49 | 000,725,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2016.11.10 16:19:49 | 000,710,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2016.11.10 16:19:49 | 000,706,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2016.11.10 16:19:49 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2016.11.10 16:19:49 | 000,663,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2016.11.10 16:19:49 | 000,631,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2016.11.10 16:19:49 | 000,576,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2016.11.10 16:19:49 | 000,503,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2016.11.10 16:19:49 | 000,489,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2016.11.10 16:19:49 | 000,430,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\imkr80.ime
[2016.11.10 16:19:49 | 000,419,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2016.11.10 16:19:49 | 000,417,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2016.11.10 16:19:49 | 000,382,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2016.11.10 16:19:49 | 000,362,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2016.11.10 16:19:49 | 000,342,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2016.11.10 16:19:49 | 000,341,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2016.11.10 16:19:49 | 000,338,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2016.11.10 16:19:49 | 000,315,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2016.11.10 16:19:49 | 000,312,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2016.11.10 16:19:49 | 000,308,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2016.11.10 16:19:49 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2016.11.10 16:19:49 | 000,246,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\input.dll
[2016.11.10 16:19:49 | 000,243,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2016.11.10 16:19:49 | 000,221,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UIAnimation.dll
[2016.11.10 16:19:49 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2016.11.10 16:19:49 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\input.dll
[2016.11.10 16:19:49 | 000,190,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rpchttp.dll
[2016.11.10 16:19:49 | 000,176,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tintlgnt.ime
[2016.11.10 16:19:49 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\quick.ime
[2016.11.10 16:19:49 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\qintlgnt.ime
[2016.11.10 16:19:49 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\phon.ime
[2016.11.10 16:19:49 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cintlgnt.ime
[2016.11.10 16:19:49 | 000,175,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\chajei.ime
[2016.11.10 16:19:49 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2016.11.10 16:19:49 | 000,148,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appidpolicyconverter.exe
[2016.11.10 16:19:49 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2016.11.10 16:19:49 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2016.11.10 16:19:49 | 000,141,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\rpchttp.dll
[2016.11.10 16:19:49 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2016.11.10 16:19:49 | 000,126,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tintlgnt.ime
[2016.11.10 16:19:49 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\quick.ime
[2016.11.10 16:19:49 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\qintlgnt.ime
[2016.11.10 16:19:49 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\phon.ime
[2016.11.10 16:19:49 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\cintlgnt.ime
[2016.11.10 16:19:49 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\chajei.ime
[2016.11.10 16:19:49 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2016.11.10 16:19:49 | 000,112,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2016.11.10 16:19:49 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2016.11.10 16:19:49 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2016.11.10 16:19:49 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2016.11.10 16:19:49 | 000,091,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2016.11.10 16:19:49 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2016.11.10 16:19:49 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\INETRES.dll
[2016.11.10 16:19:49 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2016.11.10 16:19:49 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2016.11.10 16:19:49 | 000,070,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2016.11.10 16:19:49 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2016.11.10 16:19:49 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2016.11.10 16:19:49 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll
[2016.11.10 16:19:49 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msobjs.dll
[2016.11.10 16:19:49 | 000,059,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appidapi.dll
[2016.11.10 16:19:49 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\appidapi.dll
[2016.11.10 16:19:49 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2016.11.10 16:19:49 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\auditpol.exe
[2016.11.10 16:19:49 | 000,046,080 | ---- | M] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2016.11.10 16:19:49 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2016.11.10 16:19:49 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cryptbase.dll
[2016.11.10 16:19:49 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\UtcResources.dll
[2016.11.10 16:19:49 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\lpk.dll
[2016.11.10 16:19:49 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2016.11.10 16:19:49 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2016.11.10 16:19:49 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2016.11.10 16:19:49 | 000,028,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2016.11.10 16:19:49 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2016.11.10 16:19:49 | 000,017,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appidcertstorecheck.exe
[2016.11.10 16:19:49 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2016.11.10 16:19:49 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2016.11.10 16:19:49 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dciman32.dll
[2016.11.10 16:19:49 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2016.11.10 16:19:49 | 000,007,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2016.11.10 16:19:49 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2016.11.10 16:19:49 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2016.11.10 16:19:49 | 000,006,144 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2016.11.10 16:19:49 | 000,006,144 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2016.11.10 16:19:49 | 000,005,120 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2016.11.10 16:19:49 | 000,005,120 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2016.11.10 16:19:49 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2016.11.10 16:19:49 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,608 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2016.11.10 16:19:49 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2016.11.10 16:19:49 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2016.11.10 16:19:49 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2016.11.09 17:06:40 | 011,935,655 | ---- | M] () -- C:\Users\kevin\Desktop\Fack.jar
[2016.11.09 12:58:20 | 000,796,352 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2016.11.09 12:58:20 | 000,142,528 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2016.11.09 12:09:00 | 000,000,222 | ---- | M] () -- C:\Users\kevin\Desktop\Star Conflict.url
[2016.11.03 13:57:21 | 000,000,890 | ---- | M] () -- C:\Users\Public\Desktop\Nexus Mod Manager.lnk
[2016.11.02 01:32:17 | 000,000,055 | ---- | M] () -- C:\Users\kevin\Desktop\file.json
[2016.10.31 21:44:59 | 000,018,960 | ---- | M] (Logitech, Inc.) -- C:\Windows\SysNative\drivers\LNonPnP.sys
[2016.10.30 18:06:11 | 000,000,222 | ---- | M] () -- C:\Users\kevin\Desktop\The Elder Scrolls V Skyrim Special Edition.url
[2016.10.30 18:05:27 | 000,001,561 | ---- | M] () -- C:\Users\kevin\AppData\Local\recently-used.xbel
[2016.10.30 01:01:28 | 000,000,005 | ---- | M] () -- C:\Users\kevin\Desktop\ccmd.bat
[2016.10.29 22:54:30 | 000,136,391 | ---- | M] () -- C:\Users\kevin\Desktop\fantastic.gif
[2016.10.28 17:44:13 | 000,001,011 | ---- | M] () -- C:\Users\Public\Desktop\Audacity.lnk
[2016.10.27 18:54:25 | 000,000,015 | ---- | M] () -- C:\Users\kevin\Desktop\absad.bat
[2016.10.26 18:10:27 | 000,000,222 | ---- | M] () -- C:\Users\kevin\Desktop\Paladins.url
[2016.10.23 19:54:48 | 000,002,699 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2016.10.23 17:15:51 | 000,028,492 | ---- | M] () -- C:\Users\kevin\Documents\cannabis.odt
[2016.10.22 19:10:33 | 000,000,189 | ---- | M] () -- C:\Users\kevin\Desktop\DosSelf.bat
[2016.10.22 18:04:55 | 000,001,202 | ---- | M] () -- C:\Users\Public\Desktop\OBS Studio.lnk
[2016.10.22 17:49:29 | 000,000,012 | ---- | M] () -- C:\Users\kevin\Desktop\000.vbs
[2016.10.22 13:40:30 | 000,110,144 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
[2016.10.21 16:58:09 | 000,000,707 | ---- | M] () -- C:\Users\kevin\AppData\Roaming\jd-gui.cfg
[2016.10.16 16:33:41 | 000,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe
[2016.10.16 16:33:41 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe
[2016.10.14 19:54:47 | 000,000,620 | ---- | M] () -- C:\Users\kevin\Desktop\tesst.bat
[2016.10.14 19:30:02 | 000,000,044 | ---- | M] () -- C:\Users\kevin\Desktop\asd.bat
[2016.10.14 14:38:04 | 000,002,242 | ---- | M] () -- C:\Users\kevin\Desktop\FL Studio 12 (64bit) - Kopie.bat
[2016.10.14 13:42:13 | 000,000,131 | ---- | M] () -- C:\Users\kevin\Desktop\tt.bat
[2016.10.14 13:34:23 | 000,000,076 | ---- | M] () -- C:\Users\kevin\Desktop\test.bat
[2016.10.13 20:17:11 | 000,000,956 | ---- | M] () -- C:\Users\Public\Desktop\Bat To Exe Converter.lnk
[2016.10.13 15:06:59 | 014,632,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2016.10.13 15:06:59 | 012,574,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2016.10.13 15:06:59 | 012,574,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2016.10.13 15:06:59 | 011,410,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2016.10.13 15:06:59 | 004,121,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2016.10.13 15:06:59 | 003,209,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2016.10.13 15:06:59 | 001,648,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2016.10.13 15:06:59 | 001,573,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2016.10.13 15:06:59 | 001,483,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2016.10.13 15:06:59 | 001,329,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2016.10.13 15:06:59 | 001,202,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drmv2clt.dll
[2016.10.13 15:06:59 | 001,068,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll
[2016.10.13 15:06:59 | 001,005,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll
[2016.10.13 15:06:59 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\drmv2clt.dll
[2016.10.13 15:06:59 | 000,842,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll
[2016.10.13 15:06:59 | 000,782,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll
[2016.10.13 15:06:59 | 000,744,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll
[2016.10.13 15:06:59 | 000,641,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll
[2016.10.13 15:06:59 | 000,632,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll
[2016.10.13 15:06:59 | 000,617,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll
[2016.10.13 15:06:59 | 000,519,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2016.10.13 15:06:59 | 000,504,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll
[2016.10.13 15:06:59 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2016.10.13 15:06:59 | 000,497,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll
[2016.10.13 15:06:59 | 000,489,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll
[2016.10.13 15:06:59 | 000,461,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\scavengeui.dll
[2016.10.13 15:06:59 | 000,442,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
[2016.10.13 15:06:59 | 000,440,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2016.10.13 15:06:59 | 000,433,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll
[2016.10.13 15:06:59 | 000,406,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll
[2016.10.13 15:06:59 | 000,371,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2016.10.13 15:06:59 | 000,354,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll
[2016.10.13 15:06:59 | 000,347,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSManMigrationPlugin.dll
[2016.10.13 15:06:59 | 000,325,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll
[2016.10.13 15:06:59 | 000,310,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WsmWmiPl.dll
[2016.10.13 15:06:59 | 000,295,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2016.10.13 15:06:59 | 000,284,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll
[2016.10.13 15:06:59 | 000,266,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WSManHTTPConfig.exe
[2016.10.13 15:06:59 | 000,265,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll
[2016.10.13 15:06:59 | 000,249,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManMigrationPlugin.dll
[2016.10.13 15:06:59 | 000,228,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2016.10.13 15:06:59 | 000,214,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmWmiPl.dll
[2016.10.13 15:06:59 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2016.10.13 15:06:59 | 000,199,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManHTTPConfig.exe
[2016.10.13 15:06:59 | 000,182,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WsmAuto.dll
[2016.10.13 15:06:59 | 000,146,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAuto.dll
[2016.10.13 15:06:59 | 000,141,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2016.10.13 15:06:59 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2016.10.13 15:06:59 | 000,108,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll
[2016.10.13 15:06:59 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\adsmsext.dll
[2016.10.13 15:06:59 | 000,103,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2016.10.13 15:06:59 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cryptsp.dll
[2016.10.13 15:06:59 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\adsmsext.dll
[2016.10.13 15:06:59 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
[2016.10.13 15:06:59 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmRes.dll
[2016.10.13 15:06:59 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WsmRes.dll
[2016.10.13 15:06:59 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
[2016.10.13 15:06:59 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pcadm.dll
[2016.10.13 15:06:59 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
[2016.10.13 15:06:59 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
[2016.10.13 15:06:59 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wsmprovhost.exe
[2016.10.13 15:06:59 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wsmplpxy.dll
[2016.10.13 15:06:59 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wsmprovhost.exe
[2016.10.13 15:06:59 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pcawrk.exe
[2016.10.13 15:06:59 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msmmsp.dll
[2016.10.13 15:06:59 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wsmplpxy.dll
[2016.10.13 15:06:59 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll
[2016.10.13 15:06:59 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pcalua.exe
[2016.10.13 15:06:59 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pcaevts.dll
[2016.10.13 15:06:59 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll
[2016.10.13 15:06:59 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx
[2016.10.13 15:06:59 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll
[2016.10.13 15:06:59 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx
[2016.10.13 15:06:59 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll
[2016.10.13 15:06:59 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
[2016.10.13 15:06:59 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
 
========== Files Created - No Company Name ==========
 
[2016.11.09 12:08:59 | 000,000,222 | ---- | C] () -- C:\Users\kevin\Desktop\Star Conflict.url
[2016.11.02 01:32:04 | 000,000,055 | ---- | C] () -- C:\Users\kevin\Desktop\file.json
[2016.10.30 18:06:11 | 000,000,222 | ---- | C] () -- C:\Users\kevin\Desktop\The Elder Scrolls V Skyrim Special Edition.url
[2016.10.30 18:05:27 | 000,001,561 | ---- | C] () -- C:\Users\kevin\AppData\Local\recently-used.xbel
[2016.10.30 01:01:03 | 000,000,005 | ---- | C] () -- C:\Users\kevin\Desktop\ccmd.bat
[2016.10.29 22:54:29 | 000,136,391 | ---- | C] () -- C:\Users\kevin\Desktop\fantastic.gif
[2016.10.28 17:44:13 | 000,001,023 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2016.10.28 17:44:13 | 000,001,011 | ---- | C] () -- C:\Users\Public\Desktop\Audacity.lnk
[2016.10.27 18:54:02 | 000,000,015 | ---- | C] () -- C:\Users\kevin\Desktop\absad.bat
[2016.10.26 18:10:27 | 000,000,222 | ---- | C] () -- C:\Users\kevin\Desktop\Paladins.url
[2016.10.23 19:54:48 | 000,002,699 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2016.10.22 19:04:30 | 000,000,189 | ---- | C] () -- C:\Users\kevin\Desktop\DosSelf.bat
[2016.10.22 18:04:55 | 000,001,202 | ---- | C] () -- C:\Users\Public\Desktop\OBS Studio.lnk
[2016.10.22 17:49:29 | 000,000,012 | ---- | C] () -- C:\Users\kevin\Desktop\000.vbs
[2016.10.22 13:38:52 | 000,028,492 | ---- | C] () -- C:\Users\kevin\Documents\cannabis.odt
[2016.10.21 16:54:36 | 000,000,707 | ---- | C] () -- C:\Users\kevin\AppData\Roaming\jd-gui.cfg
[2016.10.15 16:10:10 | 011,935,655 | ---- | C] () -- C:\Users\kevin\Desktop\Fack.jar
[2016.10.14 19:54:40 | 000,000,620 | ---- | C] () -- C:\Users\kevin\Desktop\tesst.bat
[2016.10.14 19:29:30 | 000,000,044 | ---- | C] () -- C:\Users\kevin\Desktop\asd.bat
[2016.10.14 13:35:39 | 000,000,131 | ---- | C] () -- C:\Users\kevin\Desktop\tt.bat
[2016.10.14 13:04:42 | 000,000,076 | ---- | C] () -- C:\Users\kevin\Desktop\test.bat
[2016.10.13 20:17:11 | 000,000,956 | ---- | C] () -- C:\Users\Public\Desktop\Bat To Exe Converter.lnk
[2016.10.13 20:16:30 | 000,002,242 | ---- | C] () -- C:\Users\kevin\Desktop\FL Studio 12 (64bit) - Kopie.bat
[2016.09.16 22:20:01 | 000,007,611 | ---- | C] () -- C:\Users\kevin\AppData\Local\Resmon.ResmonCfg
[2016.09.09 17:38:07 | 016,815,104 | ---- | C] () -- C:\Users\kevin\BlockTank.exe
[2016.08.10 14:53:18 | 000,000,000 | ---- | C] () -- C:\Users\kevin\.node_repl_history
[2016.07.05 13:25:48 | 035,115,456 | ---- | C] () -- C:\Windows\SysWow64\nvcompiler.dll
[2016.07.05 13:25:48 | 008,733,608 | ---- | C] () -- C:\Windows\SysWow64\nvptxJitCompiler.dll
[2016.07.05 13:25:48 | 000,565,392 | ---- | C] () -- C:\Windows\SysWow64\nvfatbinaryLoader.dll
[2016.05.17 18:35:58 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2016.05.17 18:32:20 | 001,596,122 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2016.05.17 18:20:05 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015.08.06 19:04:07 | 014,176,768 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015.08.06 18:44:51 | 012,875,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
         
--- --- ---

Geändert von Kenko (12.11.2016 um 13:14 Uhr)

Alt 12.11.2016, 14:05   #2
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Die Extras.txt
Code:
ATTFilter
OTL Extras logfile created on: 12.11.2016 11:56:40 - Run 8
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\kevin\Desktop\AV
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18524)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
7,93 Gb Total Physical Memory | 6,49 Gb Available Physical Memory | 81,77% Memory free
15,87 Gb Paging File | 14,37 Gb Available in Paging File | 90,56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 263,57 Gb Total Space | 81,28 Gb Free Space | 30,84% Space Free | Partition Type: NTFS
 
Computer Name: PC1-KK | User Name: kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (All) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{069EF8D8-94B3-4D7D-823A-CCD5BFBE82C0}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{0779D457-1BF3-4324-8986-09B6A9DD6262}" = lport=139 | protocol=6 | dir=in | app=system | 
"{09C17D38-2555-4106-A26D-60C0BAAC0FF2}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{1286A58A-9D3B-4F99-97C7-C02F88443074}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{15BF12A2-46F9-4259-A72D-C7EBFB1CC031}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{1C052FEF-FC29-4F57-B76E-384040F1130B}" = lport=137 | protocol=17 | dir=in | app=system | 
"{22617A46-77FF-46BD-8754-F8D0AF8D373D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{250DA419-8938-49D2-80EF-367E3B7BE78B}" = rport=139 | protocol=6 | dir=out | app=system | 
"{2CCBC44D-5F37-43EA-B3FA-C658993D2C5B}" = lport=138 | protocol=17 | dir=in | app=system | 
"{301F6607-8916-4C5D-87EE-6AD630794C8E}" = lport=445 | protocol=6 | dir=in | app=system | 
"{3B579EA9-1571-4B81-8171-ABF567E4B815}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{6127AEDD-A0E7-4664-9D7A-808040F47DBB}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{7DEDFE5F-F819-4441-9557-714EFF1552F1}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{AD673D74-1A80-4343-9F33-A3133D895249}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{B5512D6A-A2D3-4CD2-97D9-956CE8C362D0}" = rport=445 | protocol=6 | dir=out | app=system | 
"{D2EA75FB-72DF-4CEF-B3EC-7DA9EF41F082}" = rport=137 | protocol=17 | dir=out | app=system | 
"{D8F1D54C-F21C-4C67-BB8C-B729B7C504F6}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{D9D90CED-C080-483F-9D69-8B0EE7F53B8D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{EEB2AE4B-7F1C-4368-9F7F-30F090AE3B65}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{FCC932A5-D9A3-4AE8-A1EB-A404B3D496BF}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{FF708587-9C27-45E2-93C1-28B4F7599E0C}" = rport=138 | protocol=17 | dir=out | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{058E7BC7-518B-4C80-8EB1-2E7D72E6642C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star conflict\game.exe | 
"{06EAE922-3CB0-4F73-B946-3E7B070F786F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{131CA21A-0E3B-4CD4-B15D-DA68E64C46C0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe | 
"{1418D824-FB73-47E5-B718-73AD85FA8BF5}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\av\avgmfapx.exe | 
"{1555F3EB-4B40-45A3-A7B4-02F888F8B9C6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\launchpad.exe | 
"{169B8042-4F5B-4475-BE0C-F830E00D29CD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim special edition\skyrimselauncher.exe | 
"{1E5DAA5C-9780-40BB-B9FB-6D23F7606D9C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unturned\unturned_be.exe | 
"{21BA250F-95D4-453B-B948-26C0FADAC5FE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe | 
"{21C3F05D-139D-4F5E-BD5A-52C2DCEFEF41}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{24DA4AD7-418A-47CE-9151-3C45EE91F2AD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{272D550B-9ADF-4216-9EFB-F21BC28B8CF6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{3857EDCB-EB54-4F43-99BF-250F0E5CC2D2}" = protocol=17 | dir=in | app=c:\aeriagames\edeneternal\_launcher.exe | 
"{3A0D33C2-6AEC-4F6E-9F0D-BF1F67344216}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{3A5DE157-2316-4F94-87D5-82D029E8A3F1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{3EAA7C9D-74AA-4EE9-962E-007A56F65B3B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim special edition\skyrimselauncher.exe | 
"{4278CE6D-4027-44E7-A50E-C55B1CD29AE0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{47B1DCE7-B481-4BEF-B0F8-4092401CBD85}" = protocol=6 | dir=in | app=c:\aeriagames\edeneternal\_launcher.exe | 
"{49948CC2-07E0-41EC-8371-B8BC5D4948E4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\launchpad.exe | 
"{54EA9FB7-80C5-4596-AA5C-22C5DAB1D01C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{570D9110-D341-4E62-B00C-C82ED7DA95ED}" = protocol=6 | dir=in | app=c:\aeriagames\edeneternal\_launcher.exe | 
"{5AADD1E2-75D6-468C-9616-6DADF9D79EE5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{5BEE0E89-00DC-48F5-89F5-D6921F946585}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{5CAAADE2-3BAE-40A2-AB5B-5499EEAF9BC3}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{5F872E1C-CEFD-48A3-A599-B1972955B641}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe | 
"{614F8EE9-7250-4FC5-A970-649E6592CC40}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{62466810-B99B-45D1-8676-221E4729CD7C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe | 
"{646C98CA-A8F0-43B6-B888-2D4BB4BDF645}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6sp.exe | 
"{6481DA60-BB0B-4F53-8C03-79E3ED290C57}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\hirezbridge.exe | 
"{6D86DA0E-DAA1-4E75-8E14-F4FD7760B78A}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe | 
"{70334719-F857-4D73-AFFB-197A4A13C585}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe | 
"{71F0FFF1-CD01-43ED-BB5E-2E4A41A24EAC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unturned\unturned.exe | 
"{7854E678-E4E1-40B0-B958-12E1ACB5EC38}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\hirezbridge.exe | 
"{7A5A7995-492D-407F-B94D-0247C7CE3765}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe | 
"{8452A4A3-C607-4324-8B53-382908C5D98F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{8AEFB74F-16CB-44E8-8164-DC0109B554E2}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe | 
"{8C741D4C-4851-4518-B7A3-0686023E2D68}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{9B1A188C-4A77-4584-87E5-46EE0B795725}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{A218AD4A-9066-4827-A82E-370F58B04EED}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skse_steam_boot.exe | 
"{A6D29422-F8BB-4BDB-BF93-809D07CD0464}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{AC11B48A-6E73-4884-A7B2-256216B9E009}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe | 
"{B0A1C31B-F5EF-4BE6-B5A7-096DFBB3AADB}" = protocol=6 | dir=out | app=system | 
"{B8CCFE9F-D690-42C2-8406-F19785DAC4F9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6mp.exe | 
"{BA0BF3E8-2F19-40FD-8F4A-021F1D00E0CE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{BFCCB5CF-7C00-4AEE-9E68-E100A2A04501}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\av\avgmfapx.exe | 
"{C3561511-4E15-4ABD-9153-32AE4DD6BF96}" = protocol=17 | dir=in | app=c:\aeriagames\edeneternal\_launcher.exe | 
"{C3C20348-4E62-4202-A916-437637DF9D0F}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | 
"{C7E77B54-854B-4331-8046-252935EA1648}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unturned\unturned.exe | 
"{CB70FCE8-B0C8-4534-854C-744C2CC70BF3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{CE7139C3-3FEC-453C-9BEC-4023A5B47193}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star conflict\game.exe | 
"{D0ACF12B-FCD3-4395-AD1D-A738539F7346}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skse_steam_boot.exe | 
"{D3B2ABA8-B706-4206-B6E7-474B31A5B37A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{D3FED0E2-6927-4056-B213-13C3D936B2BB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe | 
"{DB7BD69A-CB5F-4ACF-9EE5-4C14BA7AA911}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe | 
"{DD4EADC3-E9F0-40A0-94F1-338626969DFA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\youtuberslife\youtuberslife.exe | 
"{DD642D6E-EFC3-446B-9E92-A9D58F7F639B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{E93FFC1B-D6F4-4AA3-9D28-4AF724C91401}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops ii\t6zm.exe | 
"{ECB0A950-DD20-4A3F-92B3-71B3523D0772}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unturned\unturned_be.exe | 
"{F3832CD0-93D1-474C-ACCB-EFD99912099B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{FA6B302A-C57B-4169-B19E-86CEB1AA1BA9}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe | 
"{FD3F47B3-0D84-4EBC-AAB9-0372DE567C14}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\youtuberslife\youtuberslife.exe | 
"TCP Query User{0E31CE84-D6AD-4302-8701-B4D69829B2B9}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe | 
"TCP Query User{15E206EC-B00D-4D88-A097-FBD1083AF7F3}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe | 
"TCP Query User{161CEDAE-3216-46F6-AB18-CF550F5D475E}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe | 
"TCP Query User{17ED97ED-98C6-4F7D-9D44-0CC54A11F8AC}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe | 
"TCP Query User{4438CD16-6389-4268-A60A-454B03DC405F}C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe" = protocol=6 | dir=in | app=c:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe | 
"TCP Query User{46C1B2F8-5F2E-4EA2-9BB9-D6B839AA152D}C:\program files\java\jre1.8.0_111\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.8.0_111\bin\javaw.exe | 
"TCP Query User{5D36CC89-7F37-4D8A-A3AF-78F2A346365D}C:\program files\java\jre1.8.0_102\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre1.8.0_102\bin\javaw.exe | 
"TCP Query User{68BE29DD-8695-4CDA-9647-F338B1029184}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe | 
"TCP Query User{73C82B9C-FF17-457F-838E-93E5D1D4F54C}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe | 
"TCP Query User{95C3B7D8-F211-4C18-BF84-B17115F27337}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe | 
"TCP Query User{BE04F7B6-440D-4123-8A40-3981C3F8AC56}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe | 
"TCP Query User{D0A84128-D490-4332-B844-FE1D7050DC00}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe | 
"TCP Query User{D418244C-DF34-4828-A435-D791DDA3DA77}C:\program files (x86)\corelenda\block tank\blocktank.exe" = protocol=6 | dir=in | app=c:\program files (x86)\corelenda\block tank\blocktank.exe | 
"TCP Query User{E2E32A50-D36F-4665-A9B6-3609C895BE1A}C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe" = protocol=6 | dir=in | app=c:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe | 
"TCP Query User{F9995F98-8635-4021-A6E5-AE37E52C8AA1}C:\users\kevin\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\kevin\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{109E10E7-A71F-46BA-8388-1F6441CBA243}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe | 
"UDP Query User{2708C15A-7A4B-48DE-A5B0-FD2C581ACBC2}C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe" = protocol=17 | dir=in | app=c:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe | 
"UDP Query User{2F10C194-0DE6-4294-BA68-259E31834033}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe | 
"UDP Query User{4E5A6663-1F48-4ADD-98DF-2462740CAEFA}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe | 
"UDP Query User{67A1C249-381A-4E79-8D5B-752B7C2461E7}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe | 
"UDP Query User{6DFED79B-318D-47D2-8303-26288E83DA39}C:\program files\java\jre1.8.0_102\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.8.0_102\bin\javaw.exe | 
"UDP Query User{76B9D1FD-23E8-402B-840F-A7D530789F5E}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe | 
"UDP Query User{7C132854-F3EB-4CFB-B525-4F0649F95E51}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe | 
"UDP Query User{88B2ED59-B851-4AA3-A6CF-658D5D594233}C:\program files\java\jre1.8.0_111\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre1.8.0_111\bin\javaw.exe | 
"UDP Query User{9C275726-B139-4D7A-BDE3-138B6A2E3545}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe | 
"UDP Query User{A691C498-D267-45B8-A870-A65DAE85A357}C:\users\kevin\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\kevin\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{E1DB5A21-CF80-4A7C-B9C3-87A7FC209C98}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe | 
"UDP Query User{ED154A19-FB0C-4AD0-AB58-D8A7B748213A}C:\program files (x86)\corelenda\block tank\blocktank.exe" = protocol=17 | dir=in | app=c:\program files (x86)\corelenda\block tank\blocktank.exe | 
"UDP Query User{FA7B3586-0D33-4974-9989-57EA5637EEFF}C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe" = protocol=17 | dir=in | app=c:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe | 
"UDP Query User{FFF28113-59C5-4085-BB55-ED2518151544}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{205AE40D-8AD7-4F29-A430-DD2168DA562D}" = Intel(R) Rapid Storage Technology
"{26A24AE4-039D-4CA4-87B4-2F64180111F0}" = Java 8 Update 111 (64-bit)
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{55398EAC-F58E-4F19-B553-BDF8B9EFD839}" = Intel(R) Chipset Device Software
"{60C29EC2-33E8-45EE-87E4-31FA3E35C539}_is1" = Bat To Exe Converter Version 2.4.3
"{638A518B-0D2E-4143-ACF8-F3D83D822E85}" = Intel(R) Network Connections 20.2.3001.0
"{64A3A4F4-B792-11D6-A78A-00B0D0180102}" = Java SE Development Kit 8 Update 102 (64-bit)
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.6.1 (Deutsch)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.6.1
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95265B86-188E-3F62-9CDB-60FCE59EC721}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24210
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{AAC5C889-B75D-3368-BC63-CB660DE44C66}" = Microsoft .NET Framework 4.6.1 (DEU)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 368.39
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 368.39
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 368.39
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 364.44
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.16.0318
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.34.14
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.41
"{BD6F5371-DAC1-30F0-9DDE-CAC6791E28C3}" = Microsoft .NET Framework 4.6.1
"{C0B2C673-ECAA-372D-94E5-E89440D087AD}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24210
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{F2B1673B-11B9-4C69-871C-D303070ACFCB}" = AVG 2016
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"GIMP-2_is1" = GIMP 2.8.18
"PROSetDX" = Intel(R) Network Connections 20.2.3001.0
"sp6" = Logitech SetPoint 6.67
"Steam App 202970" = Call of Duty: Black Ops II
"Steam App 202990" = Call of Duty: Black Ops II - Multiplayer
"Steam App 212070" = Star Conflict
"Steam App 212910" = Call of Duty: Black Ops II - Zombies
"Steam App 218230" = PlanetSide 2
"Steam App 304930" = Unturned
"Steam App 365720" = Skyrim Script Extender (SKSE)
"Steam App 428690" = Youtubers Life
"Steam App 444090" = Paladins
"Steam App 489830" = The Elder Scrolls V: Skyrim Special Edition
"Steam App 72850" = The Elder Scrolls V: Skyrim
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}" = Minecraft
"{23658c02-145e-483d-ba6b-1eb82c580529}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{73973508-05CE-4F5B-920B-7FAF319F8FC6}" = Aeria Ignite
"{7C6B1560-A8B1-4AED-BF77-A43713C7726D}" = League of Legends
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8FD71E98-EE44-3844-9DAD-9CB0BBBC603C}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24210
"{900D9036-4EDA-45EC-A095-E8AFB25D807A}" = LibreOffice 5.0.6.3
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{c7f54569-0018-439c-809a-48046a4d4ebc}" = Intel® Chipsatz-Gerätesoftware
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{D8C8656B-0BD8-39C3-B741-F889B7C144E5}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24210
"{d94109b2-6f7d-49ca-85e7-7020e6a6c88d}" = osu!
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}" = Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210
"{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FC965A47-4839-40CA-B618-18F486F042C6}" = Skype™ 7.29
"Adobe Flash Player NPAPI" = Adobe Flash Player 23 NPAPI
"Aeria Ignite" = Aeria Ignite
"Aeria Ignite 1.13.3296" = Aeria Ignite
"ASIO4ALL" = ASIO4ALL
"Audacity®_is1" = Audacity 2.1.2
"Eden Eternal" = Eden Eternal
"FL Studio ASIO" = FL Studio ASIO
"LAME_is1" = LAME v3.99.3 (for Windows)
"League of Legends 4.1.2" = League of Legends
"Mozilla Firefox 49.0.2 (x86 de)" = Mozilla Firefox 49.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Notepad++" = Notepad++
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OBS Studio" = OBS Studio
"Steam" = Steam
"Uplay" = Uplay
"Uplay Install 273" = Assassin's Creed IV Black Flag
"VLC media player" = VLC media player
"WinRAR archiver" = WinRAR 5.40 (32-Bit)
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"DG0-PlanetSide 2" = PlanetSide 2
"Flux" = f.lux
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 03.11.2016 20:05:21 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 04.11.2016 13:44:47 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 05.11.2016 06:06:39 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 07.11.2016 13:40:01 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 09.11.2016 07:05:27 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 10.11.2016 11:11:17 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 11.11.2016 08:49:26 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 12.11.2016 07:03:49 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 12.11.2016 06:37:29 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
Error - 12.11.2016 06:54:10 | Computer Name = pc1-kk | Source = WinMgmt | ID = 10
Description = 
 
[ System Events ]
Error - 22.10.2016 12:03:29 | Computer Name = pc1-kk | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Users\kevin\AppData\Local\Temp\ehdrv.sys
 nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
 des Treibers zu erhalten.
 
Error - 22.10.2016 12:03:29 | Computer Name = pc1-kk | Source = Service Control Manager | ID = 7000
Description = Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet:
   %%1275
 
Error - 22.10.2016 12:03:30 | Computer Name = pc1-kk | Source = Application Popup | ID = 1060
Description = Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\Users\kevin\AppData\Local\Temp\ehdrv.sys
 nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version
 des Treibers zu erhalten.
 
Error - 22.10.2016 12:03:30 | Computer Name = pc1-kk | Source = Service Control Manager | ID = 7000
Description = Der Dienst "eapihdrv" wurde aufgrund folgenden Fehlers nicht gestartet:
   %%1275
 
Error - 28.10.2016 18:13:38 | Computer Name = pc1-kk | Source = Service Control Manager | ID = 7030
Description = Der Dienst "Digital Wave Update Service" ist als interaktiver Dienst
 gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste
 nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
 
Error - 29.10.2016 12:01:45 | Computer Name = pc1-kk | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
 
Error - 29.10.2016 12:01:46 | Computer Name = pc1-kk | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
 
Error - 29.10.2016 12:01:47 | Computer Name = pc1-kk | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
 
Error - 29.10.2016 12:01:47 | Computer Name = pc1-kk | Source = Disk | ID = 262155
Description = Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
 
Error - 03.11.2016 09:25:32 | Computer Name = pc1-kk | Source = volsnap | ID = 393252
Description = Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher
 nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.
 
 
< End of report >
         
MBAR Log
Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2016.11.12.05
  rootkit: v2016.10.31.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18524
kevin :: PC1-KK [administrator]

12.11.2016 12:47:26
mbar-log-2016-11-12 (12-47-26).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 325103
Time elapsed: 12 minute(s), 30 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         
__________________


Alt 12.11.2016, 14:46   #3
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Hallo und


+++ WICHTIGER HINWEIS +++


Während der Analyse und Bereinigung nimmst du KEINERLEI Änderungen auf eigene Faust vor, d.h. du installierst oder deinstallierst keine Software ohne Absprache.
Auch veränderst du keine Systemeinstellungen, solange wir deinen Fall bearbeiten. Änderungen, Installationen oder Deinstallationen machst du AUSSCHLIESSLICH nur auf Anweisung!
Es wird erforderlich sein, deinen Virenscanner zu deaktivieren und in bestimmten Fällen auch zu deinstallieren, damit vernünftig bereinigt werden kann. Dein System ist daher erst wenn wir hier fertig sind wieder für den alltäglichen Gebrauch wie surfen oder mailen von mir freigegeben.

Gelesen und verstanden?




Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!




Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________
__________________

Alt 12.11.2016, 15:04   #4
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Ok der erste Log on FRST:
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2016
durchgeführt von kevin (Administrator) auf PC1-KK (12-11-2016 13:09:16)
Gestartet von C:\Users\kevin\Desktop\AV
Geladene Profile: kevin (Verfügbare Profile: kevin & Kev)
Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Akamai Technologies, Inc.) C:\Users\kevin\AppData\Local\Akamai\netsession_win.exe
(Flux Software LLC) C:\Users\kevin\AppData\Local\FluxSoftware\Flux\flux.exe
(Akamai Technologies, Inc.) C:\Users\kevin\AppData\Local\Akamai\netsession_win.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-07-07] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-06-15] (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\Run: [Akamai NetSession Interface] => C:\Users\kevin\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\Run: [f.lux] => C:\Users\kevin\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\MountPoints2: {7e80f4c7-1c51-11e6-973a-806e6f6e6963} - D:\Run.exe
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [241664 2010-11-21] (Microsoft Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{C2BCC291-8679-4E20-A2C8-5A503ED1A8F1}: [DhcpNameServer] 192.168.0.254

Internet Explorer:
==================
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE12&ocid=UE12DHP
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE12&ocid=UE12DHP
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-10-22] (Oracle Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-22] (Oracle Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
Toolbar: HKU\S-1-5-21-3869536936-4182528847-1821436484-1001 -> Kein Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  Keine Datei
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1463598850208

FireFox:
========
FF DefaultProfile: b8wlbzof.default
FF ProfilePath: C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default [2016-11-12]
FF NetworkProxy: Mozilla\Firefox\Profiles\b8wlbzof.default -> http", "209.150.253.84"
FF NetworkProxy: Mozilla\Firefox\Profiles\b8wlbzof.default -> http_port", 80
FF NetworkProxy: Mozilla\Firefox\Profiles\b8wlbzof.default -> type", 0
FF Extension: (Ghostery) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\firefox@ghostery.com.xpi [2016-10-22]
FF Extension: (HTTPS Everywhere) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\https-everywhere@eff.org.xpi [2016-11-10]
FF Extension: (uBlock Origin) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\uBlock0@raymondhill.net.xpi [2016-10-25]
FF Extension: (NoScript) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-08-09]
FF Extension: (Video DownloadHelper) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-10-11]
FF Extension: (DownThemAll!) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-09-29]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-06-11] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-09] ()
FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-10-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-10-22] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-09] ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-03] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-03] (NVIDIA Corporation)

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ACTION_SVC; C:\Program Files (x86)\Mirillis\Action!\action_svc.exe [16064 2014-10-25] ()
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-10-10] (Hi-Rez Studios) [Datei ist nicht signiert]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [501216 2015-06-18] (Intel Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2015-06-23] (Intel Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-09-02] (NVIDIA Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20160731.001\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20160731.001\EX64.SYS [X]

========================== MD5 Treiber =======================

C:\Windows\system32\drivers\1394ohci.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\ACPI.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\adpahci.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\adpu320.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\afd.sys 9A4A1EEE802BF2F878EE8EAB407B21B7
C:\Windows\system32\drivers\agp440.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\aliide.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\amdide.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\amdk8.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\amdppm.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49
C:\Windows\system32\drivers\amdsbs.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048
C:\Windows\system32\drivers\appid.sys 0CD7BFDE151223C6976C5D1B3D49EB84
C:\Windows\system32\drivers\arc.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\arcsas.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\atapi.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\bxvbda.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\Beep.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\bowser.sys ABA3984C822E4D3F889699912D85D6C5
C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\bthmodem.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\circlass.sys ==> MD5 ist legitim
C:\Windows\System32\CLFS.sys 3891EA60B84EFE115CE070311FA83BBB
C:\Windows\system32\drivers\CmBatt.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\cmdide.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\cng.sys 3323F76352B0AF14B2CDC4DFBF3E980A
C:\Windows\system32\drivers\compbatt.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\crcdisk.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\csc.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\dfsc.sys 9B38580063D281A99E68EF5813022A5F
C:\Windows\System32\drivers\discache.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\disk.sys 616387BBD83372220B09DE95F4E67BBC
C:\Windows\system32\drivers\dmvsc.sys 5DB085A8A6600BE6401F2B24EECB5415
C:\Windows\system32\drivers\drmkaud.sys 26FE888505E5A945B0536AF9A2A27A6F
C:\Windows\System32\drivers\dxgkrnl.sys 3A9D7D464BDB3B70D7ECF689ADABBD4D
C:\Windows\System32\DRIVERS\e1d62x64.sys F2E765FA3A1261A11A6D51B7ED370727
C:\Windows\system32\drivers\evbda.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\elxstor.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\errdev.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\exfat.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\fdc.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\filetrace.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\flpydisk.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B
C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0
C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A
C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\HidBatt.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\hidbth.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\hidir.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\HTTP.sys F61634BEC53F73702A10DE69F6DCAF57
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\iaStorA.sys 12859E1215AA083A42E7ADCDE5C061D1
C:\Windows\System32\DRIVERS\iaStorF.sys 91F97C1A0ABCD7FA487E8EF7A249C15C
C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366
C:\Windows\system32\drivers\iirsp.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\RTKVHD64.sys D172E06EFE08DF148155A59DB716C1B6
C:\Windows\system32\drivers\intelide.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\ipnat.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\irenum.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\isapnp.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\msiscsi.sys 96BB922A0981BC7432C8CF52B5410FE6
C:\Windows\System32\DRIVERS\iusb3hub.sys A7A2E0D3932B1986990AC7077B1658CD
C:\Windows\System32\DRIVERS\iusb3xhc.sys FD9C74D20E6F97EDC442091F9DBC1189
C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\ksecdd.sys 1F4B52A496A43C65AB0F26169650FAF2
C:\Windows\System32\Drivers\ksecpkg.sys E4A599EDFAAB66C2BC17FB1593DC129B
C:\Windows\system32\drivers\ksthunk.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\L8042Kbd.sys 3447DD130A0F7ED9377878C7A0635BBD
C:\Windows\System32\DRIVERS\L8042mou.Sys 543C6619CEE79D0AFD0F89D929FBA10A
C:\Windows\System32\DRIVERS\LHidFilt.Sys AFDFA4A6B0F7B15AA38E494FD4595741
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\LMouFilt.Sys C3E82B320F34C97F32B8026F4C249BEF
C:\Windows\System32\DRIVERS\LMouKE.Sys B705D98F8FF847D270098DE6CE6EE1B4
C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\luafv.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\megasas.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\MegaSR.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\modem.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\mountmgr.sys 8ADB5445B29941CB41AF2846FD5C93C7
C:\Windows\system32\drivers\mpio.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\mrxdav.sys 98DB1790F0A584E0A2528B92B052417F
C:\Windows\System32\DRIVERS\mrxsmb.sys 25F918BB5D57C99FFEB0255143D0DF9A
C:\Windows\System32\DRIVERS\mrxsmb10.sys 8DF2B80510F438CFEC479181BD29C794
C:\Windows\System32\DRIVERS\mrxsmb20.sys F7622CFE3402A9BF10227BB124901E54
C:\Windows\System32\drivers\msahci.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\msdsm.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\MTConfig.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\mup.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\ndis.sys F7309F42555F8AAB7144A51A1F2585B0
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\netbt.sys E47D571FEC2C76E867935109AB2A770C
C:\Windows\system32\drivers\nfrd960.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\Ntfs.sys 47B2D0B31BDC3EBE6090228E2BA3764D
C:\Windows\System32\Drivers\Null.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\nvhda64v.sys 1F99AD85DC4F9E322CDE2363378CD374
C:\Windows\System32\DRIVERS\nvlddmkm.sys F1AD55BE455B70D8348C08EC891BA263
C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD
C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A
C:\Windows\System32\drivers\nvvad64v.sys C29547CB9B1ED535AE76384D888BB90C
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\parport.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C
C:\Windows\System32\drivers\pci.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\pciide.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\pcmcia.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\pcw.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\peauth.sys EA4D67448BE493D543F1730D6CD04694
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\processr.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\ql2300.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\ql40xx.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\rdpdr.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34
C:\Windows\System32\Drivers\RDPWD.sys FE571E088C2D83619D2D48D4E961BF41
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\vms3cap.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\serial.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\sermouse.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\sfloppy.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\sisraid4.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 ist legitim
C:\Windows\System32\Drivers\spldr.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\srv.sys EC666682FE8344CF7E6ED69E74FA9F4F
C:\Windows\System32\DRIVERS\srv2.sys E450C0318DCE8ED28ED272C8806B8495
C:\Windows\System32\DRIVERS\srvnet.sys 9C12C78AD36C23D925711A4640228225
C:\Windows\system32\drivers\stexstor.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\storvsc.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E
C:\Windows\System32\DRIVERS\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E
C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8
C:\Windows\System32\DRIVERS\tdx.sys AA77EB517D2F07A947294F260E3ACA83
C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\tssecsrv.sys 19BEDA57F3E0A06B8D5EB6D619BD5624
C:\Windows\System32\drivers\tsusbflt.sys E9981ECE8D894CEF7038FD1D040EB426
C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\uagp35.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\umpass.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A
C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31
C:\Windows\system32\drivers\usbehci.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA
C:\Windows\system32\drivers\usbohci.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\usbprint.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\USBSTOR.SYS D029DD09E22EB24318A8FC3D8138BA43
C:\Windows\system32\drivers\usbuhci.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\vga.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\viaide.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\vmbus.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\volmgr.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\volsnap.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\vsmraid.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\vwifibus.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\wacompen.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\wd.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\wimmount.sys ==> MD5 ist legitim
C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 ist legitim
C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D
C:\Windows\System32\DRIVERS\wmiacpi.sys ==> MD5 ist legitim
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 ist legitim
C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F
C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-11-11 17:52 - 2016-11-11 17:54 - 100250535 ____C C:\Users\kevin\Downloads\1-10 sauce.zip
2016-11-10 21:38 - 2016-11-10 21:38 - 02390376 ____C C:\Users\kevin\Downloads\datsauce_mpgh.net.zip
2016-11-10 21:38 - 2016-11-10 21:38 - 00000000 ___DC C:\Users\kevin\Downloads\datsauce_mpgh.net
2016-11-10 16:18 - 2016-11-10 16:19 - 25763328 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 20304896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 15257088 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 03649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 03219456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 02920448 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02896384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-11-10 16:18 - 2016-11-10 16:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-11-10 16:18 - 2016-11-10 16:19 - 02444800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02287616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-11-10 16:18 - 2016-11-10 16:19 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-11-10 16:18 - 2016-11-10 16:19 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01543680 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01462272 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2016-11-10 16:18 - 2016-11-10 16:19 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2016-11-10 16:18 - 2016-11-10 16:19 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2016-11-10 16:18 - 2016-11-10 16:19 - 00877056 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-11-10 16:18 - 2016-11-10 16:19 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2016-11-10 16:18 - 2016-11-10 16:19 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-11-10 16:18 - 2016-11-10 16:19 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-11-10 16:18 - 2016-11-10 16:19 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00394440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-11-10 16:18 - 2016-11-10 16:19 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-11-09 16:35 - 2016-11-09 16:35 - 12063071 ____C C:\Users\kevin\Downloads\nxwuag.zip
2016-11-09 16:35 - 2016-11-09 16:35 - 00000000 ___DC C:\Users\kevin\Downloads\nxwuag
2016-11-09 16:32 - 2016-11-09 16:32 - 00000000 ___DC C:\Users\kevin\Downloads\GCSRC
2016-11-09 16:31 - 2016-11-09 16:32 - 05206771 ____C C:\Users\kevin\Downloads\GCSRC.zip
2016-11-09 13:55 - 2016-11-09 13:55 - 00000000 ___DC C:\Users\kevin\AppData\Local\Targem
2016-11-09 12:08 - 2016-11-09 12:09 - 00000222 ____C C:\Users\kevin\Desktop\Star Conflict.url
2016-11-04 21:14 - 2016-11-04 21:15 - 63235648 ____C (Oracle Corporation) C:\Users\kevin\Downloads\jre-8u111-windows-x64.exe
2016-11-04 21:09 - 2016-11-04 21:09 - 01257462 ____C C:\Users\kevin\Downloads\LabyMod_v2.7.9_mc1.8.8(2).jar
2016-11-04 21:08 - 2016-11-04 21:08 - 00737344 ____C (Oracle Corporation) C:\Users\kevin\Downloads\jxpiinstall.exe
2016-11-04 20:54 - 2016-11-04 20:54 - 02089120 ____C C:\Users\kevin\Downloads\wrar540d.exe
2016-11-03 17:19 - 2016-11-03 17:19 - 02793470 ____C C:\Users\kevin\Downloads\Nicht bestätigt 927193.crdownload
2016-11-02 16:21 - 2016-11-02 16:32 - 00658819 ____C C:\Users\kevin\Downloads\Optifine SRC Version [1.8.8 HD U E1](1).rar
2016-11-02 01:32 - 2016-11-02 01:32 - 00000055 ____C C:\Users\kevin\Desktop\file.json
2016-11-01 19:32 - 2016-11-01 19:43 - 00000000 ___DC C:\Users\kevin\Desktop\1.10 Modding
2016-11-01 19:32 - 2016-11-01 19:33 - 00243031 ____C C:\Users\kevin\Downloads\forge-1.10.2-12.18.2.2099-mdk.zip
2016-11-01 13:15 - 2016-11-01 13:15 - 04925893 ____C C:\Users\kevin\Downloads\Crafteryada v0.11.2.zip
2016-10-31 22:25 - 2016-10-31 22:25 - 06449992 ____C (Black Tree Gaming ) C:\Users\kevin\Downloads\Nexus Mod Manager-0.63.5.exe
2016-10-31 22:22 - 2016-10-31 22:22 - 00000000 ___DC C:\Users\kevin\AppData\Local\Skyrim Special Edition
2016-10-31 00:08 - 2016-10-31 00:08 - 00000000 ___DC C:\Users\kevin\Downloads\TcpNoDelayMod-2.0
2016-10-31 00:07 - 2016-10-31 00:07 - 01257462 ____C C:\Users\kevin\Downloads\LabyMod_v2.7.9_mc1.8.8(1).jar
2016-10-31 00:03 - 2016-10-31 00:03 - 00003751 ____C C:\Users\kevin\Downloads\TcpNoDelayMod-2.0.zip
2016-10-31 00:02 - 2016-10-31 00:02 - 00001244 ____C C:\Users\kevin\Downloads\mcdnszeugs.rar
2016-10-31 00:02 - 2016-10-31 00:02 - 00000000 ___DC C:\Users\kevin\Downloads\mcdnszeugs
2016-10-30 20:48 - 2016-10-30 20:48 - 00000000 ___DC C:\Users\kevin\Downloads\saeubern
2016-10-30 19:20 - 2016-10-30 19:20 - 00000000 ___DC C:\Users\kevin\Downloads\Suicide
2016-10-30 19:17 - 2016-10-30 19:22 - 50343608 ____C (Hammer & Chisel, Inc.) C:\Users\kevin\Downloads\DiscordSetup.exe
2016-10-30 18:24 - 2016-10-30 18:27 - 12489484 ____C C:\Users\kevin\Downloads\Suicide.zip
2016-10-30 18:06 - 2016-10-30 18:06 - 00000222 ____C C:\Users\kevin\Desktop\The Elder Scrolls V Skyrim Special Edition.url
2016-10-30 18:05 - 2016-10-30 18:05 - 00001561 ____C C:\Users\kevin\AppData\Local\recently-used.xbel
2016-10-30 14:26 - 2016-10-30 14:26 - 00000000 ___DC C:\Users\kevin\Downloads\NewtonLeak
2016-10-30 14:25 - 2016-10-30 14:25 - 13033457 ____C C:\Users\kevin\Downloads\NewtonLeak.rar
2016-10-30 01:01 - 2016-10-30 01:01 - 00000005 ____C C:\Users\kevin\Desktop\ccmd.bat
2016-10-29 19:07 - 2016-10-29 19:07 - 00000000 ___DC C:\Users\kevin\AppData\LocalLow\Temp
2016-10-29 16:55 - 2016-10-29 16:56 - 00000000 ___DC C:\Users\kevin\flsongs
2016-10-29 15:17 - 2016-10-29 15:17 - 08098768 ____C C:\Users\kevin\Downloads\teeworlds-0.6.2-win64.zip
2016-10-29 15:17 - 2016-10-29 15:17 - 00000000 ___DC C:\Users\kevin\Downloads\teeworlds-0.6.2-win64
2016-10-29 15:17 - 2016-10-29 15:17 - 00000000 ___DC C:\Users\kevin\Desktop\teeworlds-0.6.2-win64
2016-10-29 14:51 - 2016-10-29 15:20 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Teeworlds
2016-10-29 14:37 - 2016-10-29 14:37 - 00000000 ___DC C:\Users\kevin\Downloads\ClientBase by Tru3
2016-10-28 23:27 - 2016-10-28 23:27 - 00000000 ___DC C:\Users\kevin\Desktop\L ist ein Huso
2016-10-28 23:20 - 2016-10-28 23:20 - 00527423 ____C ( ) C:\Users\kevin\Downloads\Lame_v3.99.3_for_Windows.exe
2016-10-28 23:15 - 2016-10-28 23:15 - 00000000 ___DC C:\Users\kevin\AppData\Local\ElevatedDiagnostics
2016-10-28 23:11 - 2016-10-28 23:14 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\DVDVideoSoft
2016-10-28 23:09 - 2016-10-28 23:10 - 31291888 ____C (Digital Wave Ltd ) C:\Users\kevin\Downloads\FreeVideoToMP3ConverterBase.exe
2016-10-28 17:56 - 2016-10-28 17:56 - 00003716 ____C C:\Users\kevin\Downloads\enbseries.ini
2016-10-28 17:45 - 2016-10-28 17:50 - 286117632 ____C (TechSmith Corporation) C:\Users\kevin\Downloads\camtasiade.exe
2016-10-28 17:44 - 2016-10-28 23:24 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Audacity
2016-10-28 17:44 - 2016-10-28 17:44 - 00000000 ___DC C:\Users\kevin\AppData\Local\Audacity
2016-10-28 17:38 - 2016-10-28 17:38 - 26496761 ____C (Audacity Team ) C:\Users\kevin\Downloads\audacity-win-2.1.2.exe
2016-10-28 13:36 - 2016-10-28 13:36 - 00000000 ___DC C:\Users\kevin\Downloads\Newton
2016-10-27 18:54 - 2016-10-27 18:54 - 00000015 ____C C:\Users\kevin\Desktop\absad.bat
2016-10-27 15:28 - 2016-10-27 15:32 - 14296561 ____C C:\Users\kevin\Downloads\Newton.rar
2016-10-26 18:52 - 2016-10-26 18:52 - 00000000 ___DC C:\Users\kevin\AppData\Local\HirezLauncherUI
2016-10-26 18:51 - 2016-10-31 22:22 - 00000000 ___DC C:\ProgramData\Package Cache
2016-10-26 18:50 - 2016-11-12 11:52 - 00000000 ___DC C:\Program Files (x86)\Hi-Rez Studios
2016-10-26 18:50 - 2016-10-26 18:54 - 00000000 ___DC C:\ProgramData\Hi-Rez Studios
2016-10-26 18:50 - 2016-10-26 18:50 - 00000000 __HDC C:\Program Files (x86)\InstallShield Installation Information
2016-10-26 18:50 - 2016-10-26 18:50 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
2016-10-26 18:23 - 2016-10-26 18:25 - 02563007 ____C C:\Users\kevin\Downloads\Abyss SRC.zip
2016-10-26 18:10 - 2016-10-26 18:10 - 00000222 ____C C:\Users\kevin\Desktop\Paladins.url
2016-10-25 16:59 - 2016-10-25 17:00 - 00020707 ____C C:\Users\kevin\Downloads\RenderHelper.java
2016-10-24 16:35 - 2016-10-24 16:35 - 00006221 ____C C:\Users\kevin\Downloads\FontUtils.txt
2016-10-23 20:39 - 2016-10-23 20:39 - 01339795 ____C C:\Users\kevin\Downloads\GommeHD.zip
2016-10-23 19:55 - 2016-10-23 19:55 - 00000000 ___DC C:\Users\kevin\Tracing
2016-10-23 19:54 - 2016-10-27 19:34 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Skype
2016-10-23 19:54 - 2016-10-23 19:54 - 00002699 ____C C:\Users\Public\Desktop\Skype.lnk
2016-10-23 19:54 - 2016-10-23 19:54 - 00000000 __RDC C:\Program Files (x86)\Skype
2016-10-23 19:54 - 2016-10-23 19:54 - 00000000 ___DC C:\ProgramData\Skype
2016-10-23 19:54 - 2016-10-23 19:54 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-10-23 19:53 - 2016-10-23 19:54 - 43760768 ____C (Skype Technologies S.A.) C:\Users\kevin\Downloads\SkypeSetupFull.exe
2016-10-23 19:45 - 2016-10-23 19:50 - 00000020 ____C C:\Users\kevin\Desktop\skype.txt
2016-10-22 19:04 - 2016-10-22 19:10 - 00000189 ____C C:\Users\kevin\Desktop\DosSelf.bat
2016-10-22 18:06 - 2016-10-27 19:29 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\obs-studio
2016-10-22 18:04 - 2016-10-22 18:04 - 00001202 ____C C:\Users\Public\Desktop\OBS Studio.lnk
2016-10-22 18:04 - 2016-10-22 18:04 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
2016-10-22 18:04 - 2016-10-22 18:04 - 00000000 ___DC C:\Program Files (x86)\obs-studio
2016-10-22 17:59 - 2016-10-22 18:02 - 97276344 ____C (obsproject.com) C:\Users\kevin\Downloads\OBS-Studio-0.16.2-Full-Installer.exe
2016-10-22 17:49 - 2016-10-22 17:49 - 00000012 ____C C:\Users\kevin\Desktop\000.vbs
2016-10-22 16:55 - 2016-10-22 16:55 - 03910208 ____C C:\Users\kevin\Downloads\adwcleaner_6.030.exe
2016-10-22 13:38 - 2016-10-23 17:15 - 00028492 ____C C:\Users\kevin\Documents\cannabis.odt
2016-10-21 23:14 - 2016-10-21 23:15 - 00000043 ____C C:\Users\kevin\Desktop\regedit.txt
2016-10-21 16:55 - 2016-10-21 16:55 - 05231873 ____C C:\Users\kevin\Downloads\Huzuni 1.6.2.zip
2016-10-21 16:54 - 2016-10-21 16:58 - 00000707 ____C C:\Users\kevin\AppData\Roaming\jd-gui.cfg
2016-10-21 16:50 - 2016-10-21 16:51 - 08764679 ____C C:\Users\kevin\Downloads\jd-gui-1.4.0.jar
2016-10-21 16:49 - 2013-06-03 21:12 - 00000000 ___DC C:\Users\kevin\Desktop\org
2016-10-21 13:43 - 2016-10-22 13:32 - 00000000 ___DC C:\Program Files (x86)\Mozilla Firefox
2016-10-20 21:04 - 2016-10-20 21:04 - 00376939 ____C C:\Users\kevin\Downloads\SpritecraftFull.zip
2016-10-20 21:04 - 2016-10-20 21:04 - 00000000 ___DC C:\Users\kevin\Downloads\SpritecraftFull
2016-10-20 16:33 - 2016-10-20 16:33 - 00003090 ____C C:\Users\kevin\Downloads\TowerBypass.txt
2016-10-19 18:24 - 2016-10-19 18:25 - 00000063 ____C C:\Users\kevin\Desktop\asd.txt
2016-10-17 21:40 - 2016-10-17 21:40 - 00000000 ____C C:\Users\kevin\Desktop\Idefix,Transformer,Minecraft.txt
2016-10-17 15:24 - 2016-11-12 11:41 - 00000000 ___DC C:\Users\kevin\Desktop\AV
2016-10-16 16:53 - 2016-10-16 17:00 - 00000259 ____C C:\Users\kevin\Downloads\SearchReg.txt
2016-10-16 16:52 - 2016-10-16 16:59 - 00000256 ____C C:\Users\kevin\Downloads\Search.txt
2016-10-16 16:50 - 2016-10-16 16:51 - 00124819 ____C C:\Users\kevin\Downloads\FRST.txt
2016-10-16 16:50 - 2016-10-16 16:51 - 00032592 ____C C:\Users\kevin\Downloads\Addition.txt
2016-10-16 16:49 - 2016-11-12 11:37 - 00000000 ___DC C:\FRST
2016-10-16 16:49 - 2016-10-16 16:49 - 02406912 ____C (Farbar) C:\Users\kevin\Downloads\FRST64.exe
2016-10-16 16:33 - 2016-10-16 16:33 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2016-10-16 16:33 - 2016-10-16 16:33 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2016-10-16 16:21 - 2016-10-16 16:22 - 03874368 ____C C:\Users\kevin\Downloads\adwcleaner_6.021.exe
2016-10-16 11:05 - 2016-10-18 13:00 - 00000494 ____C C:\Users\kevin\Desktop\AltListe.txt
2016-10-15 16:10 - 2016-11-09 17:06 - 11935655 ____C C:\Users\kevin\Desktop\Fack.jar
2016-10-15 14:37 - 2016-10-15 14:37 - 00000000 ___DC C:\Users\kevin\Downloads\Moto SS Tools
2016-10-15 14:36 - 2016-10-15 14:36 - 06402187 ____C C:\Users\kevin\Downloads\Moto SS Tools.zip
2016-10-14 23:54 - 2016-10-14 23:54 - 09459897 ____C C:\Users\kevin\Downloads\minecraft_server.1.10.2.jar
2016-10-14 23:44 - 2016-10-14 23:44 - 00000000 ___DC C:\Users\kevin\Downloads\1mcp931
2016-10-14 19:54 - 2016-10-14 19:54 - 00000620 ____C C:\Users\kevin\Desktop\tesst.bat
2016-10-14 19:43 - 2016-10-14 20:49 - 00000000 ___DC C:\Users\kevin\Desktop\Virus
2016-10-14 19:29 - 2016-10-14 19:30 - 00000044 ____C C:\Users\kevin\Desktop\asd.bat
2016-10-14 17:19 - 2016-10-14 17:19 - 00000000 ___DC C:\Users\kevin\Desktop\DPK TRAINING DU LOW GEHJ
2016-10-14 14:36 - 2016-10-14 14:36 - 00437760 ____C C:\Users\kevin\Downloads\Nicht bestätigt 493149.crdownload
2016-10-14 13:35 - 2016-10-14 13:42 - 00000131 ____C C:\Users\kevin\Desktop\tt.bat
2016-10-14 13:34 - 2016-10-14 13:34 - 00000000 __HDC C:\Users\kevin\Desktop\FL12
2016-10-14 13:04 - 2016-10-14 13:34 - 00000076 ____C C:\Users\kevin\Desktop\test.bat
2016-10-13 20:17 - 2016-10-13 20:17 - 00000956 ____C C:\Users\Public\Desktop\Bat To Exe Converter.lnk
2016-10-13 20:17 - 2016-10-13 20:17 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Bat To Exe Converter
2016-10-13 20:17 - 2016-10-13 20:17 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bat To Exe Converter
2016-10-13 20:17 - 2016-10-13 20:17 - 00000000 ___DC C:\Program Files\Bat To Exe Converter
2016-10-13 20:16 - 2016-10-14 14:38 - 00002242 ____C C:\Users\kevin\Desktop\FL Studio 12 (64bit) - Kopie.bat
2016-10-13 20:16 - 2016-10-13 20:16 - 04670366 ____C C:\Users\kevin\Downloads\Bat_To_Exe_Converter2430.zip
2016-10-13 20:16 - 2016-10-13 20:16 - 00000000 ___DC C:\Users\kevin\Downloads\Bat_To_Exe_Converter2430
2016-10-13 15:05 - 2016-10-13 15:06 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 12574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2016-10-13 15:05 - 2016-10-13 15:06 - 12574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2016-10-13 15:05 - 2016-10-13 15:06 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 02023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01483264 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2016-10-13 15:05 - 2016-10-13 15:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-10-13 15:05 - 2016-10-13 15:06 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-10-13 15:05 - 2016-10-13 15:06 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2016-10-13 15:05 - 2016-10-13 15:06 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2016-10-13 15:05 - 2016-10-13 15:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2016-10-13 15:05 - 2016-10-13 15:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-11-12 13:04 - 2016-09-15 14:47 - 00000000 ___DC C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-11-12 12:57 - 2016-10-10 15:15 - 00000884 ____C C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-11-12 12:47 - 2016-09-15 14:47 - 00192216 ____C (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-11-12 12:47 - 2016-09-15 14:47 - 00109272 ____C (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-11-12 12:47 - 2016-05-17 20:00 - 00000000 ___DC C:\Program Files (x86)\Steam
2016-11-12 12:15 - 2016-09-16 22:20 - 00007611 ____C C:\Users\kevin\AppData\Local\Resmon.ResmonCfg
2016-11-12 12:10 - 2016-10-12 17:10 - 00000000 ___DC C:\Program Files (x86)\Image-Line
2016-11-12 12:10 - 2016-10-06 17:56 - 00000000 ___DC C:\Users\kevin\AppData\Local\osu!
2016-11-12 12:00 - 2009-07-14 05:45 - 00021856 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-12 12:00 - 2009-07-14 05:45 - 00021856 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-12 11:59 - 2016-10-12 17:19 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2016-11-12 11:59 - 2016-10-12 17:19 - 00000000 ___DC C:\Program Files\Image-Line
2016-11-12 11:58 - 2016-05-17 18:20 - 00000000 ___DC C:\Program Files (x86)\Google
2016-11-12 11:57 - 2016-05-17 18:20 - 00000000 ___DC C:\Users\kevin\AppData\Local\Google
2016-11-12 11:52 - 2016-05-17 18:42 - 00000000 ___DC C:\ProgramData\NVIDIA
2016-11-12 11:52 - 2009-07-14 06:08 - 00000006 ___HC C:\Windows\Tasks\SA.DAT
2016-11-12 11:51 - 2016-07-09 12:20 - 00000000 ___DC C:\AdwCleaner
2016-11-12 11:50 - 2016-06-29 12:11 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\.minecraft
2016-11-11 19:33 - 2016-06-21 19:45 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\TS3Client
2016-11-11 14:29 - 2016-07-31 11:37 - 00000000 ___DC C:\Users\kevin\AppData\Local\Eclipse
2016-11-11 14:29 - 2016-07-31 11:35 - 00000000 ___DC C:\Users\kevin\.p2
2016-11-11 14:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2016-11-11 13:54 - 2010-11-21 07:50 - 00700146 ____C C:\Windows\system32\perfh007.dat
2016-11-11 13:54 - 2010-11-21 07:50 - 00149784 ____C C:\Windows\system32\perfc007.dat
2016-11-11 13:54 - 2009-07-14 06:13 - 01622778 ____C C:\Windows\system32\PerfStringBackup.INI
2016-11-11 13:54 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\inf
2016-11-11 13:48 - 2009-07-14 05:45 - 00329576 ____C C:\Windows\system32\FNTCACHE.DAT
2016-11-10 16:22 - 2016-06-11 06:26 - 00000000 ___DC C:\Windows\system32\MRT
2016-11-10 16:20 - 2016-06-11 06:26 - 141011376 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-11-09 21:55 - 2016-09-14 15:29 - 00000000 ___DC C:\Users\kevin\Saves
2016-11-09 21:55 - 2016-08-03 15:49 - 00000000 ___DC C:\Users\kevin\AppData\Local\CrashDumps
2016-11-09 21:55 - 2016-06-23 14:34 - 00000000 ___DC C:\Users\kevin\AppData\Local\GeometryDash
2016-11-09 21:55 - 2016-06-18 13:04 - 00000000 ___DC C:\Users\kevin\AppData\Local\Skyrim
2016-11-09 13:55 - 2016-06-16 13:46 - 00000000 ___DC C:\Users\kevin\Documents\My Games
2016-11-09 12:58 - 2016-10-10 15:15 - 00003822 ____C C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-11-09 12:58 - 2016-07-14 13:30 - 00796352 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-09 12:58 - 2016-07-14 13:30 - 00142528 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-09 12:58 - 2016-06-17 14:27 - 00000000 ___DC C:\Windows\SysWOW64\Macromed
2016-11-09 12:58 - 2016-06-17 14:27 - 00000000 ___DC C:\Windows\system32\Macromed
2016-11-09 12:09 - 2016-05-17 20:58 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-11-05 01:51 - 2016-09-16 16:01 - 00000000 ___DC C:\Users\kevin\AppData\Local\fabi.me
2016-11-03 13:57 - 2016-10-07 18:12 - 00000890 ____C C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2016-11-03 13:57 - 2016-06-20 18:44 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2016-11-03 13:57 - 2016-06-20 18:44 - 00000000 ___DC C:\Program Files\Nexus Mod Manager
2016-11-01 12:22 - 2016-06-20 18:53 - 00000000 ___DC C:\Users\kevin\AppData\Local\Ubisoft Game Launcher
2016-10-31 22:15 - 2016-06-20 18:44 - 00000000 ___DC C:\Users\kevin\Documents\Nexus Mod Manager
2016-10-31 21:44 - 2016-06-15 16:19 - 00018960 ____C (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2016-10-30 18:05 - 2016-09-25 17:51 - 00000000 ___DC C:\Users\kevin\.gimp-2.8
2016-10-29 16:55 - 2016-05-17 18:11 - 00000000 ___DC C:\Users\kevin
2016-10-29 13:11 - 2016-10-03 21:29 - 00000000 ___DC C:\Users\kevin\Downloads\SpeedAutoClicker-1.3.6
2016-10-28 23:15 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\system32\NDF
2016-10-27 16:39 - 2016-09-24 12:31 - 00000000 ___DC C:\Users\kevin\Desktop\mbar
2016-10-26 19:01 - 2016-06-19 00:41 - 00000000 ___DC C:\Users\Kev
2016-10-26 16:29 - 2010-11-21 04:27 - 00485032 ____C (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-10-22 17:00 - 2016-09-15 14:56 - 00000000 ___DC C:\Users\kevin\AppData\Local\ESET
2016-10-22 13:51 - 2016-06-17 15:07 - 00000000 ___DC C:\ProgramData\Oracle
2016-10-22 13:40 - 2016-07-31 11:34 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-10-22 13:40 - 2016-07-13 15:27 - 00110144 ____C (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2016-10-22 13:40 - 2016-07-13 15:27 - 00000000 ___DC C:\Program Files\Java
2016-10-22 13:40 - 2016-06-17 15:08 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-10-22 13:32 - 2016-05-17 19:56 - 00000000 ___DC C:\Program Files (x86)\Mozilla Maintenance Service
2016-10-16 16:34 - 2016-09-15 14:33 - 00185758 ____C C:\Users\kevin\Downloads\OTL.Txt
2016-10-16 16:18 - 2016-07-20 20:46 - 00000000 ___DC C:\Windows\EOONotify
2016-10-14 23:45 - 2016-09-19 15:41 - 00000000 ___DC C:\Users\kevin\Desktop\MCoding 1.10
2016-10-13 21:31 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\SysWOW64\Dism
2016-10-13 21:31 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\system32\Dism

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2016-10-21 16:54 - 2016-10-21 16:58 - 0000707 ____C () C:\Users\kevin\AppData\Roaming\jd-gui.cfg
2016-08-31 18:39 - 2016-08-31 18:40 - 0054784 __SHC () C:\Users\kevin\AppData\Roaming\Thumbs.db
2016-10-30 18:05 - 2016-10-30 18:05 - 0001561 ____C () C:\Users\kevin\AppData\Local\recently-used.xbel
2016-09-16 22:20 - 2016-11-12 12:15 - 0007611 ____C () C:\Users\kevin\AppData\Local\Resmon.ResmonCfg
2016-05-17 18:35 - 2016-05-17 18:35 - 0000000 ___HC () C:\ProgramData\DP45977C.lfl

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\kevin\BlockTank.exe


Einige Dateien in TEMP:
====================
C:\Users\kevin\AppData\Local\Temp\libeay32.dll
C:\Users\kevin\AppData\Local\Temp\msvcr120.dll
C:\Users\kevin\AppData\Local\Temp\Nexus Mod Manager-0.63.5.exe
C:\Users\kevin\AppData\Local\Temp\Nexus Mod Manager-0.63.6.exe
C:\Users\kevin\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert

==================== BCD ================================

Windows-Start-Manager
---------------------
Bezeichner              {bootmgr}
device                  partition=\Device\HarddiskVolume1
description             Windows Boot Manager
locale                  de-DE
inherit                 {globalsettings}
default                 {current}
resumeobject            {aea7d336-1c59-11e6-b297-a0daf33a3e8e}
displayorder            {current}
toolsdisplayorder       {memdiag}
timeout                 30

Windows-Startladeprogramm
-------------------------
Bezeichner              {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description             Windows 7
locale                  de-DE
inherit                 {bootloadersettings}
recoverysequence        {aea7d338-1c59-11e6-b297-a0daf33a3e8e}
recoveryenabled         Yes
osdevice                partition=C:
systemroot              \Windows
resumeobject            {aea7d336-1c59-11e6-b297-a0daf33a3e8e}
nx                      OptIn

Windows-Startladeprogramm
-------------------------
Bezeichner              {aea7d338-1c59-11e6-b297-a0daf33a3e8e}
device                  ramdisk=[C:]\Recovery\aea7d338-1c59-11e6-b297-a0daf33a3e8e\Winre.wim,{aea7d339-1c59-11e6-b297-a0daf33a3e8e}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment
inherit                 {bootloadersettings}
osdevice                ramdisk=[C:]\Recovery\aea7d338-1c59-11e6-b297-a0daf33a3e8e\Winre.wim,{aea7d339-1c59-11e6-b297-a0daf33a3e8e}
systemroot              \windows
nx                      OptIn
winpe                   Yes

Wiederaufnahme aus dem Ruhezustand
----------------------------------
Bezeichner              {aea7d336-1c59-11e6-b297-a0daf33a3e8e}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description             Windows Resume Application
locale                  de-DE
inherit                 {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
debugoptionenabled      No

Windows-Speichertestprogramm
----------------------------
Bezeichner              {memdiag}
device                  partition=\Device\HarddiskVolume1
path                    \boot\memtest.exe
description             Windows-Speicherdiagnose
locale                  de-DE
inherit                 {globalsettings}
badmemoryaccess         Yes

EMS-Einstellungen
-----------------
Bezeichner              {emssettings}
bootems                 Yes

Debuggereinstellungen
---------------------
Bezeichner              {dbgsettings}
debugtype               Serial
debugport               1
baudrate                115200

RAM-Defekte
-----------
Bezeichner              {badmemory}

Globale Einstellungen
---------------------
Bezeichner              {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}

Startladeprogramm-Einstellungen
-------------------------------
Bezeichner              {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}

Hypervisoreinstellungen
-------------------
Bezeichner              {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200

Einstellungen zur Ladeprogrammfortsetzung
-----------------------------------------
Bezeichner              {resumeloadersettings}
inherit                 {globalsettings}

Ger„teoptionen
--------------
Bezeichner              {aea7d339-1c59-11e6-b297-a0daf33a3e8e}
description             Ramdisk Options
ramdisksdidevice        partition=C:
ramdisksdipath          \Recovery\aea7d338-1c59-11e6-b297-a0daf33a3e8e\boot.sdi



LastRegBack: 2016-11-09 19:04

==================== Ende von FRST.txt ============================
         

Alt 12.11.2016, 15:06   #5
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Addition:
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 12-11-2016
durchgeführt von kevin (12-11-2016 13:09:58)
Gestartet von C:\Users\kevin\Desktop\AV
Windows 7 Professional Service Pack 1 (X64) (2016-05-17 17:10:17)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3869536936-4182528847-1821436484-500 - Administrator - Disabled)
Gast (S-1-5-21-3869536936-4182528847-1821436484-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3869536936-4182528847-1821436484-1003 - Limited - Enabled)
Kev (S-1-5-21-3869536936-4182528847-1821436484-1004 - Limited - Enabled) => C:\Users\Kev
kevin (S-1-5-21-3869536936-4182528847-1821436484-1001 - Administrator - Enabled) => C:\Users\kevin

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated)
Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
AVG 2016 (Version: 16.0.4649 - AVG Technologies) Hidden
Bat To Exe Converter Version 2.4.3 (HKLM\...\{60C29EC2-33E8-45EE-87E4-31FA3E35C539}_is1) (Version: 2.4.3 - Fatih Kodak)
Call of Duty: Black Ops II - Multiplayer (HKLM\...\Steam App 202990) (Version:  - Treyarch)
Call of Duty: Black Ops II - Zombies (HKLM\...\Steam App 212910) (Version:  - )
Call of Duty: Black Ops II (HKLM\...\Steam App 202970) (Version:  - Treyarch)
Eden Eternal (HKLM-x32\...\Eden Eternal) (Version:  - )
f.lux (HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\Flux) (Version:  - )
GIMP 2.8.18 (HKLM\...\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Intel(R) Network Connections 20.2.3001.0 (HKLM\...\PROSetDX) (Version: 20.2.3001.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.0.36 - Intel Corporation)
Intel® Chipsatz-Gerätesoftware (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
Java SE Development Kit 8 Update 102 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180102}) (Version: 8.0.1020.14 - Oracle Corporation)
League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden
LibreOffice 5.0.6.3 (HKLM-x32\...\{900D9036-4EDA-45EC-A095-E8AFB25D807A}) (Version: 5.0.6.3 - The Document Foundation)
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Mozilla Firefox 49.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 49.0.2 (x86 de)) (Version: 49.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2.6136 - Mozilla)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.63.6 - Black Tree Gaming)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.9.2 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 364.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.39 - NVIDIA Corporation)
NVIDIA Grafiktreiber 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.39 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.14 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.16.2 - OBS Project)
Paladins (HKLM\...\Steam App 444090) (Version:  - Hi-Rez Studios)
PlanetSide 2 (HKLM\...\Steam App 218230) (Version:  - Daybreak Game Company)
PlanetSide 2 (HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\DG0-PlanetSide 2) (Version:  - Sony Online Entertainment)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7553 - Realtek Semiconductor Corp.)
Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.)
Skyrim Script Extender (SKSE) (HKLM\...\Steam App 365720) (Version:  - The SKSE Team)
Star Conflict (HKLM\...\Steam App 212070) (Version:  - Star Gem Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
The Elder Scrolls V: Skyrim (HKLM\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Elder Scrolls V: Skyrim Special Edition (HKLM\...\Steam App 489830) (Version:  - Bethesda Game Studios)
Unturned (HKLM\...\Steam App 304930) (Version:  - Smartly Dressed Games)
Uplay (HKLM-x32\...\Uplay) (Version: 20.0 - Ubisoft)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
WinRAR 5.40 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Youtubers Life (HKLM\...\Steam App 428690) (Version:  - U-Play online)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {32B02B77-F14E-4224-B44D-DA66E122E273} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe
Task: {434ED099-C058-4B41-8362-5D4FFFC0AEF3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-09] (Adobe Systems Incorporated)
Task: {50A4E092-7C75-4B35-9765-E95E63C181C9} - System32\Tasks\{8E0A11AD-D2DA-482F-948E-DD19D5ACBDF9} => pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\redist\vcredist_x86.exe" -d "C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\redist"

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============

2016-05-17 18:42 - 2016-06-03 04:26 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll

==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)

HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Software\Classes\regfile: regedit.exe "%1" <===== ACHTUNG

==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\aeriagames.com -> hxxps://aeriagames.com
IE trusted site: HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\aeriagames.com -> hxxp://aeriagames.com

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2016-11-12 11:50 - 00000865 ___AC C:\Windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
DNS Servers: 192.168.0.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{C3C20348-4E62-4202-A916-437637DF9D0F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FA6B302A-C57B-4169-B19E-86CEB1AA1BA9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{F9995F98-8635-4021-A6E5-AE37E52C8AA1}C:\users\kevin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\kevin\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{A691C498-D267-45B8-A870-A65DAE85A357}C:\users\kevin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\kevin\appdata\local\akamai\netsession_win.exe
FirewallRules: [{5BEE0E89-00DC-48F5-89F5-D6921F946585}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3A0D33C2-6AEC-4F6E-9F0D-BF1F67344216}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{5F872E1C-CEFD-48A3-A599-B1972955B641}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{21BA250F-95D4-453B-B948-26C0FADAC5FE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{71F0FFF1-CD01-43ED-BB5E-2E4A41A24EAC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C7E77B54-854B-4331-8046-252935EA1648}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{47B1DCE7-B481-4BEF-B0F8-4092401CBD85}] => (Allow) C:\AeriaGames\EdenEternal\_Launcher.exe
FirewallRules: [{C3561511-4E15-4ABD-9153-32AE4DD6BF96}] => (Allow) C:\AeriaGames\EdenEternal\_Launcher.exe
FirewallRules: [{570D9110-D341-4E62-B00C-C82ED7DA95ED}] => (Allow) C:\AeriaGames\EdenEternal\_Launcher.exe
FirewallRules: [{3857EDCB-EB54-4F43-99BF-250F0E5CC2D2}] => (Allow) C:\AeriaGames\EdenEternal\_Launcher.exe
FirewallRules: [{62466810-B99B-45D1-8676-221E4729CD7C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{B8CCFE9F-D690-42C2-8406-F19785DAC4F9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{646C98CA-A8F0-43B6-B888-2D4BB4BDF645}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6sp.exe
FirewallRules: [{131CA21A-0E3B-4CD4-B15D-DA68E64C46C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6sp.exe
FirewallRules: [{E93FFC1B-D6F4-4AA3-9D28-4AF724C91401}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{D3FED0E2-6927-4056-B213-13C3D936B2BB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{DB7BD69A-CB5F-4ACF-9EE5-4C14BA7AA911}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{70334719-F857-4D73-AFFB-197A4A13C585}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [TCP Query User{161CEDAE-3216-46F6-AB18-CF550F5D475E}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [UDP Query User{76B9D1FD-23E8-402B-840F-A7D530789F5E}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [TCP Query User{BE04F7B6-440D-4123-8A40-3981C3F8AC56}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{FFF28113-59C5-4085-BB55-ED2518151544}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{D0ACF12B-FCD3-4395-AD1D-A738539F7346}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{A218AD4A-9066-4827-A82E-370F58B04EED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [TCP Query User{68BE29DD-8695-4CDA-9647-F338B1029184}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe
FirewallRules: [UDP Query User{67A1C249-381A-4E79-8D5B-752B7C2461E7}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe
FirewallRules: [TCP Query User{95C3B7D8-F211-4C18-BF84-B17115F27337}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{7C132854-F3EB-4CFB-B525-4F0649F95E51}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{0E31CE84-D6AD-4302-8701-B4D69829B2B9}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [UDP Query User{2F10C194-0DE6-4294-BA68-259E31834033}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [TCP Query User{17ED97ED-98C6-4F7D-9D44-0CC54A11F8AC}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe
FirewallRules: [UDP Query User{4E5A6663-1F48-4ADD-98DF-2462740CAEFA}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe
FirewallRules: [TCP Query User{5D36CC89-7F37-4D8A-A3AF-78F2A346365D}C:\program files\java\jre1.8.0_102\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_102\bin\javaw.exe
FirewallRules: [UDP Query User{6DFED79B-318D-47D2-8303-26288E83DA39}C:\program files\java\jre1.8.0_102\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_102\bin\javaw.exe
FirewallRules: [TCP Query User{E2E32A50-D36F-4665-A9B6-3609C895BE1A}C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe] => (Allow) C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe
FirewallRules: [UDP Query User{2708C15A-7A4B-48DE-A5B0-FD2C581ACBC2}C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe] => (Allow) C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe
FirewallRules: [{18D57BB1-61A1-41CD-81D0-9200EEC3AE65}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YoutubersLife\YoutubersLife.exe
FirewallRules: [{2623A2C9-5E03-4FB2-A121-530E268C8BCC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YoutubersLife\YoutubersLife.exe
FirewallRules: [{1418D824-FB73-47E5-B718-73AD85FA8BF5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{BFCCB5CF-7C00-4AEE-9E68-E100A2A04501}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{49948CC2-07E0-41EC-8371-B8BC5D4948E4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PlanetSide 2\LaunchPad.exe
FirewallRules: [{1555F3EB-4B40-45A3-A7B4-02F888F8B9C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PlanetSide 2\LaunchPad.exe
FirewallRules: [TCP Query User{15E206EC-B00D-4D88-A097-FBD1083AF7F3}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe
FirewallRules: [UDP Query User{109E10E7-A71F-46BA-8388-1F6441CBA243}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe
FirewallRules: [TCP Query User{D418244C-DF34-4828-A435-D791DDA3DA77}C:\program files (x86)\corelenda\block tank\blocktank.exe] => (Allow) C:\program files (x86)\corelenda\block tank\blocktank.exe
FirewallRules: [UDP Query User{ED154A19-FB0C-4AD0-AB58-D8A7B748213A}C:\program files (x86)\corelenda\block tank\blocktank.exe] => (Allow) C:\program files (x86)\corelenda\block tank\blocktank.exe
FirewallRules: [{AC11B48A-6E73-4884-A7B2-256216B9E009}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{8AEFB74F-16CB-44E8-8164-DC0109B554E2}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{6D86DA0E-DAA1-4E75-8E14-F4FD7760B78A}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{7A5A7995-492D-407F-B94D-0247C7CE3765}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [TCP Query User{73C82B9C-FF17-457F-838E-93E5D1D4F54C}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe
FirewallRules: [UDP Query User{E1DB5A21-CF80-4A7C-B9C3-87A7FC209C98}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe
FirewallRules: [{DD4EADC3-E9F0-40A0-94F1-338626969DFA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YoutubersLife\YoutubersLife.exe
FirewallRules: [{FD3F47B3-0D84-4EBC-AAB9-0372DE567C14}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YoutubersLife\YoutubersLife.exe
FirewallRules: [TCP Query User{46C1B2F8-5F2E-4EA2-9BB9-D6B839AA152D}C:\program files\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [UDP Query User{88B2ED59-B851-4AA3-A6CF-658D5D594233}C:\program files\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [{21C3F05D-139D-4F5E-BD5A-52C2DCEFEF41}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{6481DA60-BB0B-4F53-8C03-79E3ED290C57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe
FirewallRules: [{7854E678-E4E1-40B0-B958-12E1ACB5EC38}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe
FirewallRules: [TCP Query User{D0A84128-D490-4332-B844-FE1D7050DC00}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [UDP Query User{9C275726-B139-4D7A-BDE3-138B6A2E3545}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [TCP Query User{4438CD16-6389-4268-A60A-454B03DC405F}C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe] => (Block) C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe
FirewallRules: [UDP Query User{FA7B3586-0D33-4974-9989-57EA5637EEFF}C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe] => (Block) C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe
FirewallRules: [{169B8042-4F5B-4475-BE0C-F830E00D29CD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{3EAA7C9D-74AA-4EE9-962E-007A56F65B3B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{058E7BC7-518B-4C80-8EB1-2E7D72E6642C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\star conflict\game.exe
FirewallRules: [{CE7139C3-3FEC-453C-9BEC-4023A5B47193}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\star conflict\game.exe
FirewallRules: [{ECB0A950-DD20-4A3F-92B3-71B3523D0772}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
FirewallRules: [{1E5DAA5C-9780-40BB-B9FB-6D23F7606D9C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe

==================== Wiederherstellungspunkte =========================

10-11-2016 16:18:58 Windows Update

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Microsoft PS/2-Maus
Description: Microsoft PS/2-Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: PS/2 Keyboard
Description: PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: Logitech
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: PCI-Kommunikationscontroller (einfach)
Description: PCI-Kommunikationscontroller (einfach)
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (11/12/2016 11:54:10 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/12/2016 11:37:29 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/12/2016 12:03:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/11/2016 01:49:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/10/2016 04:11:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/09/2016 12:05:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/07/2016 06:40:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/05/2016 11:06:39 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/04/2016 06:44:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/04/2016 01:05:21 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.


Systemfehler:
=============
Error: (11/12/2016 11:51:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (11/12/2016 11:51:49 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "WSearch" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
Die Anforderung wird nicht unterstützt.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (11/12/2016 11:51:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Rapid Storage Technology" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/12/2016 11:51:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) PROSet Monitoring Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Hi-Rez Studios Authenticate and Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:18 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/12/2016 11:51:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Stereoscopic 3D Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Display Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i5-6500 CPU @ 3.20GHz
Prozentuale Nutzung des RAM: 44%
Installierter physikalischer RAM: 8125.05 MB
Verfügbarer physikalischer RAM: 4493.67 MB
Summe virtueller Speicher: 16248.28 MB
Verfügbarer virtueller Speicher: 11226.36 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:263.57 GB) (Free:83.27 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: FA9674A1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=263.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=652.1 GB) - (Type=05)

==================== Ende von Addition.txt ============================
         
Adw Cleaner hat was gefunden. Sollte aber nichts gefährliches gewesen sein
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v6.030 - Bericht erstellt am 12/11/2016 um 11:51:11
# Aktualisiert am 19/10/2016 von Malwarebytes
# Datenbank : 2016-11-12.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (X64)
# Benutzername : kevin - PC1-KK
# Gestartet von : C:\Users\kevin\Desktop\AV\adwcleaner_6.030.exe
# Modus: Suchlauf
# Unterstützung : https://www.malwarebytes.com/support



***** [ Dienste ] *****

Keine schädlichen Dienste gefunden.


***** [ Ordner ] *****

Keine schädlichen Ordner gefunden.


***** [ Dateien ] *****

Keine schädlichen Dateien gefunden.


***** [ DLL ] *****

Keine infizierten DLLs gefunden.


***** [ WMI ] *****

Keine schädlichen Schlüssel gefunden.


***** [ Verknüpfungen ] *****

Keine infizierten Verknüpfungen gefunden.


***** [ Aufgabenplanung ] *****

Keine schädlichen Aufgaben gefunden.


***** [ Registrierungsdatenbank ] *****

Keine schädlichen Elemente in der Registrierungsdatenbank gefunden.


***** [ Internetbrowser ] *****

Keine schädlichen Elemente in Firefox basierten Browsern gefunden.
Chrome pref Gefunden: [C:\Users\kevin\AppData\Local\Google\Chrome\User Data\Default\Web data] - vlc.de

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1554 Bytes] - [09/07/2016 12:43:50]
C:\AdwCleaner\AdwCleaner[C2].txt - [2809 Bytes] - [26/08/2016 19:07:46]
C:\AdwCleaner\AdwCleaner[C3].txt - [2808 Bytes] - [31/08/2016 23:29:18]
C:\AdwCleaner\AdwCleaner[C4].txt - [2952 Bytes] - [24/09/2016 12:37:05]
C:\AdwCleaner\AdwCleaner[S10].txt - [1580 Bytes] - [15/07/2016 17:28:00]
C:\AdwCleaner\AdwCleaner[S11].txt - [1654 Bytes] - [16/07/2016 11:43:31]
C:\AdwCleaner\AdwCleaner[S12].txt - [1728 Bytes] - [18/07/2016 15:15:28]
C:\AdwCleaner\AdwCleaner[S13].txt - [1802 Bytes] - [19/07/2016 20:11:20]
C:\AdwCleaner\AdwCleaner[S14].txt - [1877 Bytes] - [22/07/2016 20:34:47]
C:\AdwCleaner\AdwCleaner[S15].txt - [1951 Bytes] - [23/07/2016 14:40:45]
C:\AdwCleaner\AdwCleaner[S16].txt - [2025 Bytes] - [26/07/2016 16:16:04]
C:\AdwCleaner\AdwCleaner[S17].txt - [2099 Bytes] - [28/07/2016 18:21:44]
C:\AdwCleaner\AdwCleaner[S18].txt - [2173 Bytes] - [31/07/2016 11:28:03]
C:\AdwCleaner\AdwCleaner[S19].txt - [2604 Bytes] - [26/08/2016 09:16:58]
C:\AdwCleaner\AdwCleaner[S1].txt - [1123 Bytes] - [09/07/2016 12:20:56]
C:\AdwCleaner\AdwCleaner[S20].txt - [3037 Bytes] - [26/08/2016 19:07:03]
C:\AdwCleaner\AdwCleaner[S21].txt - [3020 Bytes] - [31/08/2016 23:28:34]
C:\AdwCleaner\AdwCleaner[S22].txt - [3111 Bytes] - [01/09/2016 12:12:11]
C:\AdwCleaner\AdwCleaner[S23].txt - [3185 Bytes] - [15/09/2016 14:31:05]
C:\AdwCleaner\AdwCleaner[S24].txt - [3259 Bytes] - [24/09/2016 12:36:43]
C:\AdwCleaner\AdwCleaner[S25].txt - [3406 Bytes] - [16/10/2016 16:33:08]
C:\AdwCleaner\AdwCleaner[S26].txt - [3481 Bytes] - [17/10/2016 15:29:58]
C:\AdwCleaner\AdwCleaner[S27].txt - [3555 Bytes] - [18/10/2016 12:36:30]
C:\AdwCleaner\AdwCleaner[S28].txt - [3629 Bytes] - [19/10/2016 12:38:37]
C:\AdwCleaner\AdwCleaner[S29].txt - [3716 Bytes] - [22/10/2016 17:19:28]
C:\AdwCleaner\AdwCleaner[S2].txt - [994 Bytes] - [10/07/2016 15:03:58]
C:\AdwCleaner\AdwCleaner[S30].txt - [3162 Bytes] - [12/11/2016 11:51:11]
C:\AdwCleaner\AdwCleaner[S3].txt - [1066 Bytes] - [12/07/2016 12:26:47]
C:\AdwCleaner\AdwCleaner[S4].txt - [1140 Bytes] - [12/07/2016 14:14:32]
C:\AdwCleaner\AdwCleaner[S5].txt - [1214 Bytes] - [12/07/2016 19:14:50]
C:\AdwCleaner\AdwCleaner[S6].txt - [1287 Bytes] - [12/07/2016 20:29:30]
C:\AdwCleaner\AdwCleaner[S7].txt - [1360 Bytes] - [13/07/2016 13:02:19]
C:\AdwCleaner\AdwCleaner[S8].txt - [1433 Bytes] - [13/07/2016 15:14:52]
C:\AdwCleaner\AdwCleaner[S9].txt - [1506 Bytes] - [13/07/2016 19:51:49]

########## EOF - C:\AdwCleaner\AdwCleaner[S30].txt - [3747 Bytes] ##########
         
--- --- ---


Alt 12.11.2016, 15:17   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



1. Schritt: Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers




2. Schritt: Kaspersky TDSS-Killer

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.




Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________
--> Firefox baut unseriöse Verbindugen auf

Alt 12.11.2016, 15:29   #7
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



So hier der Log von TDSKiller. Ich glaube kaum das die gefundene Datei ein Rootkit ist ( False-positive) Dies ist ein Updater vom Spiel Paladins.
Code:
ATTFilter
14:25:25.0170 0x1384  TDSS rootkit removing tool 3.1.0.12 Nov  7 2016 07:10:01
14:25:27.0818 0x1384  ============================================================
14:25:27.0818 0x1384  Current date / time: 2016/11/12 14:25:27.0818
14:25:27.0818 0x1384  SystemInfo:
14:25:27.0818 0x1384  
14:25:27.0818 0x1384  OS Version: 6.1.7601 ServicePack: 1.0
14:25:27.0818 0x1384  Product type: Workstation
14:25:27.0818 0x1384  ComputerName: PC1-KK
14:25:27.0818 0x1384  UserName: kevin
14:25:27.0818 0x1384  Windows directory: C:\Windows
14:25:27.0818 0x1384  System windows directory: C:\Windows
14:25:27.0818 0x1384  Running under WOW64
14:25:27.0818 0x1384  Processor architecture: Intel x64
14:25:27.0818 0x1384  Number of processors: 4
14:25:27.0818 0x1384  Page size: 0x1000
14:25:27.0818 0x1384  Boot type: Normal boot
14:25:27.0818 0x1384  CodeIntegrityOptions = 0x00000001
14:25:27.0818 0x1384  ============================================================
14:25:29.0620 0x1384  KLMD registered as C:\Windows\system32\drivers\32818886.sys
14:25:29.0620 0x1384  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.23569, osProperties = 0x1
14:25:29.0872 0x1384  System UUID: {910B2A11-C233-4F3F-6272-C9F69373CB2F}
14:25:30.0226 0x1384  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
14:25:30.0228 0x1384  ============================================================
14:25:30.0228 0x1384  \Device\Harddisk0\DR0:
14:25:30.0229 0x1384  MBR partitions:
14:25:30.0229 0x1384  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
14:25:30.0229 0x1384  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x20F25800
14:25:30.0270 0x1384  ============================================================
14:25:30.0300 0x1384  C: <-> \Device\Harddisk0\DR0\Partition2
14:25:30.0300 0x1384  ============================================================
14:25:30.0300 0x1384  Initialize success
14:25:30.0300 0x1384  ============================================================
14:26:01.0468 0x1124  ============================================================
14:26:01.0468 0x1124  Scan started
14:26:01.0468 0x1124  Mode: Manual; SigCheck; TDLFS; 
14:26:01.0468 0x1124  ============================================================
14:26:01.0468 0x1124  KSN ping started
14:26:01.0569 0x1124  KSN ping finished: true
14:26:02.0416 0x1124  ================ Scan system memory ========================
14:26:02.0416 0x1124  System memory - ok
14:26:02.0417 0x1124  ================ Scan services =============================
14:26:02.0545 0x1124  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
14:26:02.0573 0x1124  1394ohci - ok
14:26:02.0591 0x1124  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
14:26:02.0601 0x1124  ACPI - ok
14:26:02.0605 0x1124  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
14:26:02.0721 0x1124  AcpiPmi - ok
14:26:02.0943 0x1124  [ D08D2733615784B8072BEBA2A8CC45BB, 29BB59D866F8738609F8DC441F54423BB0A810B470C87AB7935E173D6E098C2A ] ACTION_SVC      C:\Program Files (x86)\Mirillis\Action!\action_svc.exe
14:26:02.0949 0x1124  ACTION_SVC - ok
14:26:03.0059 0x1124  [ 9BAF21BA600EC4E5FD9A66AD3E4FF5A6, 5E02E5E80557F6EC870EB7CC2DE95169D4225B87A2FE7E796736205F51C15816 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
14:26:03.0067 0x1124  AdobeFlashPlayerUpdateSvc - ok
14:26:03.0090 0x1124  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
14:26:03.0105 0x1124  adp94xx - ok
14:26:03.0123 0x1124  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci         C:\Windows\system32\drivers\adpahci.sys
14:26:03.0136 0x1124  adpahci - ok
14:26:03.0153 0x1124  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
14:26:03.0162 0x1124  adpu320 - ok
14:26:03.0189 0x1124  [ 262D7C87D0AC20B96EF9877D3CA478A0, 54F7E5A5F8991C5525500C1ECCF3D3135D13F48866C366E52DF1D052DB2EE15B ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
14:26:03.0197 0x1124  AeLookupSvc - ok
14:26:03.0228 0x1124  [ 9A4A1EEE802BF2F878EE8EAB407B21B7, 177EB7DF4B35FE4C0E45E775A0FD5D48D39B410052E3EE18BDEEC809E152D9D8 ] AFD             C:\Windows\system32\drivers\afd.sys
14:26:03.0257 0x1124  AFD - ok
14:26:03.0261 0x1124  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\drivers\agp440.sys
14:26:03.0268 0x1124  agp440 - ok
14:26:03.0285 0x1124  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG             C:\Windows\System32\alg.exe
14:26:03.0294 0x1124  ALG - ok
14:26:03.0321 0x1124  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
14:26:03.0327 0x1124  aliide - ok
14:26:03.0330 0x1124  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
14:26:03.0335 0x1124  amdide - ok
14:26:03.0353 0x1124  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
14:26:03.0361 0x1124  AmdK8 - ok
14:26:03.0383 0x1124  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
14:26:03.0391 0x1124  AmdPPM - ok
14:26:03.0414 0x1124  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
14:26:03.0422 0x1124  amdsata - ok
14:26:03.0428 0x1124  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
14:26:03.0437 0x1124  amdsbs - ok
14:26:03.0449 0x1124  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata         C:\Windows\system32\drivers\amdxata.sys
14:26:03.0454 0x1124  amdxata - ok
14:26:03.0489 0x1124  [ 0CD7BFDE151223C6976C5D1B3D49EB84, A16FAB4F77D03C0664CCE8082E40A7673BC7FA4E89854F9027D478CD99EB2088 ] AppID           C:\Windows\system32\drivers\appid.sys
14:26:03.0497 0x1124  AppID - ok
14:26:03.0507 0x1124  [ F9842669B31F20B8B157D33CCC457820, AC8FA65F0A3C479D3CFE10EFE9B3EC5BAE48059F57A12D8C2D7963A22EB043B8 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
14:26:03.0515 0x1124  AppIDSvc - ok
14:26:03.0535 0x1124  [ B46099A534B7989D80330EA82D9092D6, 0CAC09732FAFAE805E55428B6BE001DCC39EBC599539FADE7AA68571A8A554E5 ] Appinfo         C:\Windows\System32\appinfo.dll
14:26:03.0548 0x1124  Appinfo - ok
14:26:03.0568 0x1124  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt         C:\Windows\System32\appmgmts.dll
14:26:03.0584 0x1124  AppMgmt - ok
14:26:03.0598 0x1124  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc             C:\Windows\system32\drivers\arc.sys
14:26:03.0605 0x1124  arc - ok
14:26:03.0621 0x1124  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\drivers\arcsas.sys
14:26:03.0629 0x1124  arcsas - ok
14:26:03.0737 0x1124  [ 660D597B7A78256734D7F3230B21B355, CAA19E8EFAD63B8975A4CD8EFD5CE5F21E056856D36BC5A9E48517F1E574ABBA ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
14:26:03.0744 0x1124  aspnet_state - ok
14:26:03.0765 0x1124  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
14:26:03.0785 0x1124  AsyncMac - ok
14:26:03.0826 0x1124  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi           C:\Windows\system32\drivers\atapi.sys
14:26:03.0831 0x1124  atapi - ok
14:26:03.0878 0x1124  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:26:03.0896 0x1124  AudioEndpointBuilder - ok
14:26:03.0909 0x1124  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
14:26:03.0926 0x1124  AudioSrv - ok
14:26:03.0957 0x1124  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\Windows\System32\AxInstSV.dll
14:26:03.0969 0x1124  AxInstSV - ok
14:26:03.0997 0x1124  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
14:26:04.0027 0x1124  b06bdrv - ok
14:26:04.0042 0x1124  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
14:26:04.0055 0x1124  b57nd60a - ok
14:26:04.0059 0x1124  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
14:26:04.0068 0x1124  BDESVC - ok
14:26:04.0080 0x1124  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
14:26:04.0100 0x1124  Beep - ok
14:26:04.0120 0x1124  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE             C:\Windows\System32\bfe.dll
14:26:04.0149 0x1124  BFE - ok
14:26:04.0187 0x1124  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\System32\qmgr.dll
14:26:04.0220 0x1124  BITS - ok
14:26:04.0224 0x1124  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
14:26:04.0232 0x1124  blbdrive - ok
14:26:04.0265 0x1124  [ ABA3984C822E4D3F889699912D85D6C5, 2251FA135CC290DA13DAE4743F393C7CC9E6A737C054707CB8D72C369D1FFACB ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
14:26:04.0273 0x1124  bowser - ok
14:26:04.0286 0x1124  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
14:26:04.0295 0x1124  BrFiltLo - ok
14:26:04.0297 0x1124  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
14:26:04.0306 0x1124  BrFiltUp - ok
14:26:04.0330 0x1124  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser         C:\Windows\System32\browser.dll
14:26:04.0340 0x1124  Browser - ok
14:26:04.0348 0x1124  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
14:26:04.0361 0x1124  Brserid - ok
14:26:04.0364 0x1124  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
14:26:04.0373 0x1124  BrSerWdm - ok
14:26:04.0380 0x1124  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
14:26:04.0389 0x1124  BrUsbMdm - ok
14:26:04.0391 0x1124  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
14:26:04.0399 0x1124  BrUsbSer - ok
14:26:04.0411 0x1124  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
14:26:04.0421 0x1124  BTHMODEM - ok
14:26:04.0425 0x1124  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv         C:\Windows\system32\bthserv.dll
14:26:04.0446 0x1124  bthserv - ok
14:26:04.0463 0x1124  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
14:26:04.0483 0x1124  cdfs - ok
14:26:04.0495 0x1124  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
14:26:04.0504 0x1124  cdrom - ok
14:26:04.0514 0x1124  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc     C:\Windows\System32\certprop.dll
14:26:04.0533 0x1124  CertPropSvc - ok
14:26:04.0536 0x1124  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\drivers\circlass.sys
14:26:04.0543 0x1124  circlass - ok
14:26:04.0582 0x1124  [ 3891EA60B84EFE115CE070311FA83BBB, 2A30FB15C8D0C69289C087DFE1F822AB4F9C3F091DBB3FD2E99DC5B562E90DFB ] CLFS            C:\Windows\system32\CLFS.sys
14:26:04.0592 0x1124  CLFS - ok
14:26:04.0658 0x1124  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:26:04.0665 0x1124  clr_optimization_v2.0.50727_32 - ok
14:26:04.0704 0x1124  [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
14:26:04.0711 0x1124  clr_optimization_v2.0.50727_64 - ok
14:26:04.0778 0x1124  [ AB4CD527BEFCC43EE441E6C50CCE54C8, 13B776AE63049FFBA7E35EA0A4C26EBB57B10D973E05C4CF1214249754DC46E4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:26:04.0786 0x1124  clr_optimization_v4.0.30319_32 - ok
14:26:04.0829 0x1124  [ 1400C75FF021D6CFACE46AC41B60770E, 3FCB8D7714A79522F2738037D559F1FFFB2F05C5406D2A038EF5DDB4629CA1CE ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
14:26:04.0838 0x1124  clr_optimization_v4.0.30319_64 - ok
14:26:04.0840 0x1124  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
14:26:04.0848 0x1124  CmBatt - ok
14:26:04.0866 0x1124  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
14:26:04.0871 0x1124  cmdide - ok
14:26:04.0909 0x1124  [ 3323F76352B0AF14B2CDC4DFBF3E980A, F8E3C3508C37E647497B6889F26819B1DB30275F48A994D1BBFBAA9454E5FD70 ] CNG             C:\Windows\system32\Drivers\cng.sys
14:26:04.0923 0x1124  CNG - ok
14:26:04.0931 0x1124  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
14:26:04.0937 0x1124  Compbatt - ok
14:26:04.0953 0x1124  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
14:26:04.0963 0x1124  CompositeBus - ok
14:26:04.0965 0x1124  COMSysApp - ok
14:26:04.0968 0x1124  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
14:26:04.0974 0x1124  crcdisk - ok
14:26:04.0998 0x1124  [ BB724567892383010B8436DCC0A84628, 2768F5FD7A096CB1CEA33F8818EF16F9F5E3E07BB8442949A49A9CF24B62C6E6 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
14:26:05.0008 0x1124  CryptSvc - ok
14:26:05.0035 0x1124  [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC             C:\Windows\system32\drivers\csc.sys
14:26:05.0056 0x1124  CSC - ok
14:26:05.0076 0x1124  [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService      C:\Windows\System32\cscsvc.dll
14:26:05.0094 0x1124  CscService - ok
14:26:05.0136 0x1124  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] DcomLaunch      C:\Windows\system32\rpcss.dll
14:26:05.0163 0x1124  DcomLaunch - ok
14:26:05.0189 0x1124  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc       C:\Windows\System32\defragsvc.dll
14:26:05.0214 0x1124  defragsvc - ok
14:26:05.0271 0x1124  [ 9B38580063D281A99E68EF5813022A5F, D91676B0E0A8E2A090E3E5DD340ABCFC20AE0F55B4C82869D6CFB34239BD27DA ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
14:26:05.0279 0x1124  DfsC - ok
14:26:05.0305 0x1124  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
14:26:05.0332 0x1124  Dhcp - ok
14:26:05.0418 0x1124  [ EE9954237F15BE4DD9304D12E4D305ED, F295C9BAF20F0E669B673AFCC16B4969EE31B6A3808980DAB93D9B0F167DA3C0 ] DiagTrack       C:\Windows\system32\diagtrack.dll
14:26:05.0462 0x1124  DiagTrack - ok
14:26:05.0473 0x1124  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
14:26:05.0493 0x1124  discache - ok
14:26:05.0517 0x1124  [ 616387BBD83372220B09DE95F4E67BBC, 5E2D5280BB775576E7CDE3FA6BDE494E183123635E5908CF7EBF1FF52966D07D ] Disk            C:\Windows\system32\drivers\disk.sys
14:26:05.0523 0x1124  Disk - ok
14:26:05.0548 0x1124  [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc           C:\Windows\system32\drivers\dmvsc.sys
14:26:05.0570 0x1124  dmvsc - ok
14:26:05.0593 0x1124  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
14:26:05.0612 0x1124  Dnscache - ok
14:26:05.0632 0x1124  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc         C:\Windows\System32\dot3svc.dll
14:26:05.0656 0x1124  dot3svc - ok
14:26:05.0667 0x1124  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS             C:\Windows\system32\dps.dll
14:26:05.0689 0x1124  DPS - ok
14:26:05.0744 0x1124  [ 26FE888505E5A945B0536AF9A2A27A6F, A6B16ED498BAFE300E1F0E0A241E3D62F7A1C5973EE775904ED14F33A2BC08A6 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
14:26:05.0752 0x1124  drmkaud - ok
14:26:05.0793 0x1124  [ 3A9D7D464BDB3B70D7ECF689ADABBD4D, B4F5B23705EA1BA453FE30791CA245E1A5F7FBEABAD026E4A8A15A9FC44E8C9C ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
14:26:05.0814 0x1124  DXGKrnl - ok
14:26:05.0841 0x1124  [ F2E765FA3A1261A11A6D51B7ED370727, C4224D0BCD0FDB26CB6C8BCC018BD6E1B3CC0963924182A31E904C61E6E41D01 ] e1dexpress      C:\Windows\system32\DRIVERS\e1d62x64.sys
14:26:05.0861 0x1124  e1dexpress - ok
14:26:05.0866 0x1124  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost         C:\Windows\System32\eapsvc.dll
14:26:05.0890 0x1124  EapHost - ok
14:26:05.0954 0x1124  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv           C:\Windows\system32\drivers\evbda.sys
14:26:06.0035 0x1124  ebdrv - ok
14:26:06.0068 0x1124  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] EFS             C:\Windows\System32\lsass.exe
14:26:06.0093 0x1124  EFS - ok
14:26:06.0162 0x1124  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
14:26:06.0190 0x1124  ehRecvr - ok
14:26:06.0202 0x1124  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched         C:\Windows\ehome\ehsched.exe
14:26:06.0212 0x1124  ehSched - ok
14:26:06.0240 0x1124  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
14:26:06.0257 0x1124  elxstor - ok
14:26:06.0271 0x1124  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
14:26:06.0280 0x1124  ErrDev - ok
14:26:06.0299 0x1124  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem     C:\Windows\system32\es.dll
14:26:06.0326 0x1124  EventSystem - ok
14:26:06.0339 0x1124  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat           C:\Windows\system32\drivers\exfat.sys
14:26:06.0361 0x1124  exfat - ok
14:26:06.0379 0x1124  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
14:26:06.0402 0x1124  fastfat - ok
14:26:06.0443 0x1124  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax             C:\Windows\system32\fxssvc.exe
14:26:06.0461 0x1124  Fax - ok
14:26:06.0465 0x1124  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc             C:\Windows\system32\drivers\fdc.sys
14:26:06.0472 0x1124  fdc - ok
14:26:06.0478 0x1124  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost         C:\Windows\system32\fdPHost.dll
14:26:06.0498 0x1124  fdPHost - ok
14:26:06.0512 0x1124  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
14:26:06.0531 0x1124  FDResPub - ok
14:26:06.0545 0x1124  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
14:26:06.0550 0x1124  FileInfo - ok
14:26:06.0558 0x1124  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
14:26:06.0577 0x1124  Filetrace - ok
14:26:06.0579 0x1124  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
14:26:06.0586 0x1124  flpydisk - ok
14:26:06.0596 0x1124  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
14:26:06.0605 0x1124  FltMgr - ok
14:26:06.0661 0x1124  [ 700A5373FA66F1DAAECBD2CFB88C73ED, D6C1C4C846BC24EB6539ECC701A456FA53BB6679C79391F5B70580D47B6CE395 ] FontCache       C:\Windows\system32\FntCache.dll
14:26:06.0695 0x1124  FontCache - ok
14:26:06.0739 0x1124  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
14:26:06.0745 0x1124  FontCache3.0.0.0 - ok
14:26:06.0757 0x1124  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
14:26:06.0763 0x1124  FsDepends - ok
14:26:06.0775 0x1124  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
14:26:06.0781 0x1124  Fs_Rec - ok
14:26:06.0827 0x1124  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
14:26:06.0836 0x1124  fvevol - ok
14:26:06.0847 0x1124  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
14:26:06.0853 0x1124  gagp30kx - ok
14:26:06.0873 0x1124  gdrv - ok
14:26:06.0915 0x1124  [ E4AE497857409127ED57562AF913A903, 262ADD713B1FBF6200550967D1F8635B55D01BBD8FA2E753536E71A4EC87867B ] gpsvc           C:\Windows\System32\gpsvc.dll
14:26:06.0943 0x1124  gpsvc - ok
14:26:06.0954 0x1124  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
14:26:06.0962 0x1124  hcw85cir - ok
14:26:06.0987 0x1124  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:26:07.0001 0x1124  HdAudAddService - ok
14:26:07.0022 0x1124  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
14:26:07.0032 0x1124  HDAudBus - ok
14:26:07.0035 0x1124  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt         C:\Windows\system32\drivers\HidBatt.sys
14:26:07.0043 0x1124  HidBatt - ok
14:26:07.0058 0x1124  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
14:26:07.0069 0x1124  HidBth - ok
14:26:07.0072 0x1124  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr           C:\Windows\system32\drivers\hidir.sys
14:26:07.0081 0x1124  HidIr - ok
14:26:07.0108 0x1124  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv         C:\Windows\system32\hidserv.dll
14:26:07.0129 0x1124  hidserv - ok
14:26:07.0159 0x1124  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
14:26:07.0178 0x1124  HidUsb - ok
14:26:07.0242 0x1124  [ DA5FCD70EBE32E9DCF2DF5992FCFE59F, F07FF9364C8A94953B2E4545EE9715BEBB9D8C29C4964B1CBA8A9377115F6E42 ] HiPatchService  C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
14:26:07.0246 0x1124  HiPatchService - detected UnsignedFile.Multi.Generic ( 1 )
14:26:07.0359 0x1124  HiPatchService ( UnsignedFile.Multi.Generic ) - warning
14:26:07.0359 0x1124  Force sending object to P2P due to detect: HiPatchService
14:26:07.0570 0x1124  Object send P2P result: true
14:26:07.0748 0x1124  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
14:26:07.0770 0x1124  hkmsvc - ok
14:26:07.0788 0x1124  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
14:26:07.0803 0x1124  HomeGroupListener - ok
14:26:07.0819 0x1124  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
14:26:07.0830 0x1124  HomeGroupProvider - ok
14:26:07.0834 0x1124  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
14:26:07.0840 0x1124  HpSAMD - ok
14:26:07.0876 0x1124  [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
14:26:07.0905 0x1124  HTTP - ok
14:26:07.0918 0x1124  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
14:26:07.0923 0x1124  hwpolicy - ok
14:26:07.0935 0x1124  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
14:26:07.0944 0x1124  i8042prt - ok
14:26:08.0018 0x1124  [ 12859E1215AA083A42E7ADCDE5C061D1, 262F9C65C3FA7EB69C4FA7C6547E1C79DB49697A083309909BC78726A116557F ] iaStorA         C:\Windows\system32\DRIVERS\iaStorA.sys
14:26:08.0047 0x1124  iaStorA - ok
14:26:08.0139 0x1124  [ 14E3DB5ADA7E2187A404129F4E5CE336, 5925C8E9DC00A6C682D6A3B37C6EBF2C325D37C8E4BF584F0B5AAC5A7B666E47 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
14:26:08.0144 0x1124  IAStorDataMgrSvc - ok
14:26:08.0168 0x1124  [ 91F97C1A0ABCD7FA487E8EF7A249C15C, 834D85B7833DD1EDE0938320A68237315F60263ABCB6714974E711EBA91178E9 ] iaStorF         C:\Windows\system32\DRIVERS\iaStorF.sys
14:26:08.0174 0x1124  iaStorF - ok
14:26:08.0212 0x1124  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
14:26:08.0223 0x1124  iaStorV - ok
14:26:08.0269 0x1124  [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
14:26:08.0289 0x1124  idsvc - ok
14:26:08.0305 0x1124  IEEtwCollectorService - ok
14:26:08.0313 0x1124  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
14:26:08.0319 0x1124  iirsp - ok
14:26:08.0363 0x1124  [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT          C:\Windows\System32\ikeext.dll
14:26:08.0384 0x1124  IKEEXT - ok
14:26:08.0490 0x1124  [ D172E06EFE08DF148155A59DB716C1B6, F059B0B37C5E944D70626E9F029BC6311029E0A9D778C9C75DDDDC59A5AF1605 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
14:26:08.0595 0x1124  IntcAzAudAddService - ok
14:26:08.0618 0x1124  [ 03CD3245E52C8A87E3B14832DC8A6A7D, C2AAB4E754479F0AA0AE86D51E721E5A11624681D5EC823E25E460EE146E70E9 ] Intel(R) PROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
14:26:08.0629 0x1124  Intel(R) PROSet Monitoring Service - ok
14:26:08.0643 0x1124  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
14:26:08.0649 0x1124  intelide - ok
14:26:08.0678 0x1124  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
14:26:08.0687 0x1124  intelppm - ok
14:26:08.0702 0x1124  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
14:26:08.0724 0x1124  IPBusEnum - ok
14:26:08.0741 0x1124  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:26:08.0761 0x1124  IpFilterDriver - ok
14:26:08.0811 0x1124  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
14:26:08.0825 0x1124  iphlpsvc - ok
14:26:08.0838 0x1124  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
14:26:08.0846 0x1124  IPMIDRV - ok
14:26:08.0850 0x1124  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
14:26:08.0872 0x1124  IPNAT - ok
14:26:08.0882 0x1124  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
14:26:08.0893 0x1124  IRENUM - ok
14:26:08.0896 0x1124  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
14:26:08.0901 0x1124  isapnp - ok
14:26:08.0916 0x1124  [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
14:26:08.0927 0x1124  iScsiPrt - ok
14:26:08.0960 0x1124  [ A7A2E0D3932B1986990AC7077B1658CD, F8CC75A711E6C4E5299557F05C0C6B957E8508EA496BC74CCF4827385B046CB4 ] iusb3hub        C:\Windows\system32\DRIVERS\iusb3hub.sys
14:26:08.0978 0x1124  iusb3hub - ok
14:26:09.0024 0x1124  [ FD9C74D20E6F97EDC442091F9DBC1189, 01DD3D862FD7A429E9D79B3B1BC657594628747B0C4C124E976D733065498EDB ] iusb3xhc        C:\Windows\system32\DRIVERS\iusb3xhc.sys
14:26:09.0052 0x1124  iusb3xhc - ok
14:26:09.0067 0x1124  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
14:26:09.0074 0x1124  kbdclass - ok
14:26:09.0080 0x1124  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
14:26:09.0087 0x1124  kbdhid - ok
14:26:09.0101 0x1124  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] KeyIso          C:\Windows\system32\lsass.exe
14:26:09.0108 0x1124  KeyIso - ok
14:26:09.0142 0x1124  [ 1F4B52A496A43C65AB0F26169650FAF2, 6D6F3505997A7DDEE6F127B3FB537AFFDE687D4F34489679674DC12FB12B842C ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
14:26:09.0148 0x1124  KSecDD - ok
14:26:09.0174 0x1124  [ E4A599EDFAAB66C2BC17FB1593DC129B, 13098694B649E9146214D320FB14C3D305FCA155438CB531A8BAA4A70231D1A7 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
14:26:09.0182 0x1124  KSecPkg - ok
14:26:09.0193 0x1124  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
14:26:09.0214 0x1124  ksthunk - ok
14:26:09.0238 0x1124  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm           C:\Windows\system32\msdtckrm.dll
14:26:09.0264 0x1124  KtmRm - ok
14:26:09.0311 0x1124  [ 3447DD130A0F7ED9377878C7A0635BBD, BD701567D1144884320FF66A58AE3A4C26266D22979572D27AA93A75688BC957 ] L8042Kbd        C:\Windows\system32\DRIVERS\L8042Kbd.sys
14:26:09.0319 0x1124  L8042Kbd - ok
14:26:09.0372 0x1124  [ 543C6619CEE79D0AFD0F89D929FBA10A, 84BCDD65A816F959D4EBD49F9586EAF2FDC3F45C887E5C47AADD4ED103DEFA20 ] L8042mou        C:\Windows\system32\DRIVERS\L8042mou.Sys
14:26:09.0380 0x1124  L8042mou - ok
14:26:09.0404 0x1124  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\Windows\system32\srvsvc.dll
14:26:09.0428 0x1124  LanmanServer - ok
14:26:09.0440 0x1124  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:26:09.0461 0x1124  LanmanWorkstation - ok
14:26:09.0586 0x1124  [ 20EE2F2ADCF8DBD091E931593F5AC268, 5F053F8B7C8B340A0364CE37B25D68B6755C2CCDB050C02E9B4E0929DF587E0F ] LBTServ         C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
14:26:09.0597 0x1124  LBTServ - ok
14:26:09.0633 0x1124  [ AFDFA4A6B0F7B15AA38E494FD4595741, 0D89CCEBC816F4A3F6DDB093B3F8BB8B85293E94559085961DA31F9330D43C21 ] LHidFilt        C:\Windows\system32\DRIVERS\LHidFilt.Sys
14:26:09.0641 0x1124  LHidFilt - ok
14:26:09.0670 0x1124  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
14:26:09.0691 0x1124  lltdio - ok
14:26:09.0711 0x1124  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
14:26:09.0736 0x1124  lltdsvc - ok
14:26:09.0757 0x1124  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts         C:\Windows\System32\lmhsvc.dll
14:26:09.0777 0x1124  lmhosts - ok
14:26:09.0785 0x1124  [ C3E82B320F34C97F32B8026F4C249BEF, CAF53CD4738D2C92E4764372F75B5D0D74EBA896E59E685ED15B915F4E7223A0 ] LMouFilt        C:\Windows\system32\DRIVERS\LMouFilt.Sys
14:26:09.0792 0x1124  LMouFilt - ok
14:26:09.0812 0x1124  [ B705D98F8FF847D270098DE6CE6EE1B4, E8025884030230EC9A988E6406521FAD7BBC54475EE8F6C124398B112225BE2E ] LMouKE          C:\Windows\system32\DRIVERS\LMouKE.Sys
14:26:09.0820 0x1124  LMouKE - ok
14:26:09.0832 0x1124  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
14:26:09.0840 0x1124  LSI_FC - ok
14:26:09.0869 0x1124  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
14:26:09.0877 0x1124  LSI_SAS - ok
14:26:09.0889 0x1124  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
14:26:09.0896 0x1124  LSI_SAS2 - ok
14:26:09.0901 0x1124  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
14:26:09.0909 0x1124  LSI_SCSI - ok
14:26:09.0921 0x1124  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv           C:\Windows\system32\drivers\luafv.sys
14:26:09.0942 0x1124  luafv - ok
14:26:09.0962 0x1124  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
14:26:09.0972 0x1124  Mcx2Svc - ok
14:26:09.0985 0x1124  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas         C:\Windows\system32\drivers\megasas.sys
14:26:09.0991 0x1124  megasas - ok
14:26:10.0004 0x1124  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
14:26:10.0016 0x1124  MegaSR - ok
14:26:10.0044 0x1124  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS           C:\Windows\system32\mmcss.dll
14:26:10.0067 0x1124  MMCSS - ok
14:26:10.0074 0x1124  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem           C:\Windows\system32\drivers\modem.sys
14:26:10.0095 0x1124  Modem - ok
14:26:10.0113 0x1124  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
14:26:10.0122 0x1124  monitor - ok
14:26:10.0135 0x1124  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
14:26:10.0141 0x1124  mouclass - ok
14:26:10.0146 0x1124  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
14:26:10.0153 0x1124  mouhid - ok
14:26:10.0192 0x1124  [ 8ADB5445B29941CB41AF2846FD5C93C7, 689582430FE29EC0845B1DB841D3CC49D5D09DE264586E3999EEFE616986D12B ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
14:26:10.0198 0x1124  mountmgr - ok
14:26:10.0251 0x1124  [ 572BD5A99648652147A5D3C6DA946C99, FFDAD4A5682864977C926A5DDDB632CDB2A166BF025757801CC56F2828720023 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
14:26:10.0258 0x1124  MozillaMaintenance - ok
14:26:10.0276 0x1124  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
14:26:10.0285 0x1124  mpio - ok
14:26:10.0302 0x1124  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
14:26:10.0324 0x1124  mpsdrv - ok
14:26:10.0352 0x1124  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\Windows\system32\mpssvc.dll
14:26:10.0385 0x1124  MpsSvc - ok
14:26:10.0417 0x1124  [ 98DB1790F0A584E0A2528B92B052417F, 9AA04CA73AFE599810CD233B9CEC212E16D44DCEDF5C7D0181C7257F498068B5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
14:26:10.0440 0x1124  MRxDAV - ok
14:26:10.0477 0x1124  [ 25F918BB5D57C99FFEB0255143D0DF9A, E4BB656C3AEE19094B0F87828828DC73F248B45B30B678AA759DBAB3087399A2 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
14:26:10.0487 0x1124  mrxsmb - ok
14:26:10.0504 0x1124  [ 8DF2B80510F438CFEC479181BD29C794, ECA5BC17D1DB92B887D468B0FF1D6302518DBD7C3607B14FA291ECDA204D5E85 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:26:10.0515 0x1124  mrxsmb10 - ok
14:26:10.0519 0x1124  [ F7622CFE3402A9BF10227BB124901E54, 3EE6BA42E712505AED9D3920163814719FAC591FB5CFF589E230C7005CB598AF ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:26:10.0527 0x1124  mrxsmb20 - ok
14:26:10.0541 0x1124  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
14:26:10.0546 0x1124  msahci - ok
14:26:10.0575 0x1124  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
14:26:10.0582 0x1124  msdsm - ok
14:26:10.0594 0x1124  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC           C:\Windows\System32\msdtc.exe
14:26:10.0605 0x1124  MSDTC - ok
14:26:10.0609 0x1124  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
14:26:10.0628 0x1124  Msfs - ok
14:26:10.0638 0x1124  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
14:26:10.0657 0x1124  mshidkmdf - ok
14:26:10.0672 0x1124  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
14:26:10.0677 0x1124  msisadrv - ok
14:26:10.0696 0x1124  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
14:26:10.0718 0x1124  MSiSCSI - ok
14:26:10.0721 0x1124  msiserver - ok
14:26:10.0740 0x1124  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
14:26:10.0759 0x1124  MSKSSRV - ok
14:26:10.0762 0x1124  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
14:26:10.0781 0x1124  MSPCLOCK - ok
14:26:10.0786 0x1124  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
14:26:10.0805 0x1124  MSPQM - ok
14:26:10.0821 0x1124  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
14:26:10.0831 0x1124  MsRPC - ok
14:26:10.0846 0x1124  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
14:26:10.0851 0x1124  mssmbios - ok
14:26:10.0864 0x1124  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
14:26:10.0882 0x1124  MSTEE - ok
14:26:10.0897 0x1124  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
14:26:10.0903 0x1124  MTConfig - ok
14:26:10.0920 0x1124  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup             C:\Windows\system32\Drivers\mup.sys
14:26:10.0925 0x1124  Mup - ok
14:26:10.0943 0x1124  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
14:26:10.0971 0x1124  napagent - ok
14:26:10.0993 0x1124  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
14:26:11.0006 0x1124  NativeWifiP - ok
14:26:11.0015 0x1124  NAVENG - ok
14:26:11.0016 0x1124  NAVEX15 - ok
14:26:11.0048 0x1124  [ F7309F42555F8AAB7144A51A1F2585B0, 065277A8AFAEE3888C997A76D2F751070F92DF4C3354D16B194860B4BDAFF937 ] NDIS            C:\Windows\system32\drivers\ndis.sys
14:26:11.0067 0x1124  NDIS - ok
14:26:11.0074 0x1124  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
14:26:11.0093 0x1124  NdisCap - ok
14:26:11.0106 0x1124  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
14:26:11.0125 0x1124  NdisTapi - ok
14:26:11.0132 0x1124  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
14:26:11.0150 0x1124  Ndisuio - ok
14:26:11.0184 0x1124  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
14:26:11.0203 0x1124  NdisWan - ok
14:26:11.0219 0x1124  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
14:26:11.0237 0x1124  NDProxy - ok
14:26:11.0245 0x1124  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
14:26:11.0263 0x1124  NetBIOS - ok
14:26:11.0299 0x1124  [ E47D571FEC2C76E867935109AB2A770C, F349D25890B6F476B106FD75BFB081DB737CA9B224D95E44927942FFF2DF82CD ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
14:26:11.0317 0x1124  NetBT - ok
14:26:11.0334 0x1124  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] Netlogon        C:\Windows\system32\lsass.exe
14:26:11.0341 0x1124  Netlogon - ok
14:26:11.0362 0x1124  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
14:26:11.0388 0x1124  Netman - ok
14:26:11.0431 0x1124  [ 15CBA881E10968E33B43D31BE6097BA3, 69449ACA82B67F308C9F7DAB7A4C75BD88A95B98FC7F9102C72AD3D233A48346 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:26:11.0441 0x1124  NetMsmqActivator - ok
14:26:11.0445 0x1124  [ 15CBA881E10968E33B43D31BE6097BA3, 69449ACA82B67F308C9F7DAB7A4C75BD88A95B98FC7F9102C72AD3D233A48346 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:26:11.0453 0x1124  NetPipeActivator - ok
14:26:11.0504 0x1124  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
14:26:11.0532 0x1124  netprofm - ok
14:26:11.0537 0x1124  [ 15CBA881E10968E33B43D31BE6097BA3, 69449ACA82B67F308C9F7DAB7A4C75BD88A95B98FC7F9102C72AD3D233A48346 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:26:11.0544 0x1124  NetTcpActivator - ok
14:26:11.0549 0x1124  [ 15CBA881E10968E33B43D31BE6097BA3, 69449ACA82B67F308C9F7DAB7A4C75BD88A95B98FC7F9102C72AD3D233A48346 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:26:11.0556 0x1124  NetTcpPortSharing - ok
14:26:11.0578 0x1124  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
14:26:11.0584 0x1124  nfrd960 - ok
14:26:11.0606 0x1124  [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc          C:\Windows\System32\nlasvc.dll
14:26:11.0624 0x1124  NlaSvc - ok
14:26:11.0640 0x1124  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
14:26:11.0661 0x1124  Npfs - ok
14:26:11.0666 0x1124  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi             C:\Windows\system32\nsisvc.dll
14:26:11.0687 0x1124  nsi - ok
14:26:11.0693 0x1124  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
14:26:11.0713 0x1124  nsiproxy - ok
14:26:11.0773 0x1124  [ 47B2D0B31BDC3EBE6090228E2BA3764D, 984A4B38300954164BCBF57EC1A09C18B53779E60A26E9618B50E26016735787 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
14:26:11.0810 0x1124  Ntfs - ok
14:26:11.0827 0x1124  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
14:26:11.0847 0x1124  Null - ok
14:26:11.0860 0x1124  [ 1F99AD85DC4F9E322CDE2363378CD374, 5E80D10FF0BC46ECF6F1F2294F35A0A7FD76E6F0B4534FD45C9AA8C57AE97F68 ] NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
14:26:11.0869 0x1124  NVHDA - ok
14:26:12.0165 0x1124  [ F1AD55BE455B70D8348C08EC891BA263, 0F8FDF483B227A8CCA844D2E2039754B800137C588B67B32AC50DA891A88D8E7 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
14:26:12.0444 0x1124  nvlddmkm - ok
14:26:12.0497 0x1124  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
14:26:12.0504 0x1124  nvraid - ok
14:26:12.0545 0x1124  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
14:26:12.0552 0x1124  nvstor - ok
14:26:12.0593 0x1124  [ 27F1E6074709F1BEFE011DDEA6A11373, E4DDA22519C77165E3E02599338CCF213B4A0A21C1EFF471A4C9BFBBCD6F3334 ] nvsvc           C:\Windows\system32\nvvsvc.exe
14:26:12.0618 0x1124  nvsvc - ok
14:26:12.0631 0x1124  [ C29547CB9B1ED535AE76384D888BB90C, 63E4F5AE16EC13486340F73A3613038A0363C37E48B4F099B4CBBD476226E4DB ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
14:26:12.0637 0x1124  nvvad_WaveExtensible - ok
14:26:12.0668 0x1124  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
14:26:12.0674 0x1124  nv_agp - ok
14:26:12.0684 0x1124  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
14:26:12.0693 0x1124  ohci1394 - ok
14:26:12.0711 0x1124  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
14:26:12.0733 0x1124  p2pimsvc - ok
14:26:12.0742 0x1124  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
14:26:12.0756 0x1124  p2psvc - ok
14:26:12.0782 0x1124  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
14:26:12.0791 0x1124  Parport - ok
14:26:12.0811 0x1124  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr         C:\Windows\system32\drivers\partmgr.sys
14:26:12.0817 0x1124  partmgr - ok
14:26:12.0853 0x1124  [ 3CD83692C43D87088E85E3C916146FFB, 9E812535E8FBA045FDA30F68E9EB2031132C37721D542A2DC9D4C33E2B137FCF ] PcaSvc          C:\Windows\System32\pcasvc.dll
14:26:12.0879 0x1124  PcaSvc - ok
14:26:12.0892 0x1124  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci             C:\Windows\system32\drivers\pci.sys
14:26:12.0899 0x1124  pci - ok
14:26:12.0942 0x1124  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
14:26:12.0947 0x1124  pciide - ok
14:26:12.0963 0x1124  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
14:26:12.0972 0x1124  pcmcia - ok
14:26:12.0983 0x1124  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw             C:\Windows\system32\drivers\pcw.sys
14:26:12.0988 0x1124  pcw - ok
14:26:13.0117 0x1124  [ EA4D67448BE493D543F1730D6CD04694, 24717C5E41B7CA522F3330EF2228B6685E710A5259396E9887A1C1E7A413F8CA ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
14:26:13.0133 0x1124  PEAUTH - ok
14:26:13.0271 0x1124  [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
14:26:13.0308 0x1124  PeerDistSvc - ok
14:26:13.0361 0x1124  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
14:26:13.0370 0x1124  PerfHost - ok
14:26:13.0403 0x1124  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla             C:\Windows\system32\pla.dll
14:26:13.0444 0x1124  pla - ok
14:26:13.0501 0x1124  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
14:26:13.0514 0x1124  PlugPlay - ok
14:26:13.0529 0x1124  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
14:26:13.0536 0x1124  PNRPAutoReg - ok
14:26:13.0543 0x1124  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
14:26:13.0555 0x1124  PNRPsvc - ok
14:26:13.0591 0x1124  [ 80D6B0563ED2BF10656B1D4748331082, B7E6B5E1148B7EE537E8D5C3A65450876B61CD45A395267D08699746E98AD574 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
14:26:13.0615 0x1124  PolicyAgent - ok
14:26:13.0627 0x1124  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power           C:\Windows\system32\umpo.dll
14:26:13.0649 0x1124  Power - ok
14:26:13.0671 0x1124  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
14:26:13.0692 0x1124  PptpMiniport - ok
14:26:13.0704 0x1124  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor       C:\Windows\system32\drivers\processr.sys
14:26:13.0712 0x1124  Processor - ok
14:26:13.0739 0x1124  [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc         C:\Windows\system32\profsvc.dll
14:26:13.0761 0x1124  ProfSvc - ok
14:26:13.0767 0x1124  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] ProtectedStorage C:\Windows\system32\lsass.exe
14:26:13.0774 0x1124  ProtectedStorage - ok
14:26:13.0791 0x1124  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
14:26:13.0811 0x1124  Psched - ok
14:26:13.0859 0x1124  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
14:26:13.0885 0x1124  ql2300 - ok
14:26:13.0904 0x1124  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
14:26:13.0911 0x1124  ql40xx - ok
14:26:13.0929 0x1124  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE           C:\Windows\system32\qwave.dll
14:26:13.0943 0x1124  QWAVE - ok
14:26:13.0955 0x1124  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
14:26:13.0965 0x1124  QWAVEdrv - ok
14:26:13.0980 0x1124  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
14:26:14.0000 0x1124  RasAcd - ok
14:26:14.0025 0x1124  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
14:26:14.0046 0x1124  RasAgileVpn - ok
14:26:14.0057 0x1124  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto         C:\Windows\System32\rasauto.dll
14:26:14.0079 0x1124  RasAuto - ok
14:26:14.0086 0x1124  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
14:26:14.0108 0x1124  Rasl2tp - ok
14:26:14.0120 0x1124  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
14:26:14.0144 0x1124  RasMan - ok
14:26:14.0148 0x1124  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
14:26:14.0169 0x1124  RasPppoe - ok
14:26:14.0176 0x1124  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
14:26:14.0195 0x1124  RasSstp - ok
14:26:14.0219 0x1124  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
14:26:14.0241 0x1124  rdbss - ok
14:26:14.0263 0x1124  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
14:26:14.0270 0x1124  rdpbus - ok
14:26:14.0296 0x1124  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
14:26:14.0314 0x1124  RDPCDD - ok
14:26:14.0333 0x1124  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
14:26:14.0346 0x1124  RDPDR - ok
14:26:14.0354 0x1124  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
14:26:14.0372 0x1124  RDPENCDD - ok
14:26:14.0375 0x1124  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
14:26:14.0393 0x1124  RDPREFMP - ok
14:26:14.0457 0x1124  [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
14:26:14.0472 0x1124  RdpVideoMiniport - ok
14:26:14.0495 0x1124  [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
14:26:14.0516 0x1124  RDPWD - ok
14:26:14.0534 0x1124  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
14:26:14.0541 0x1124  rdyboost - ok
14:26:14.0548 0x1124  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
14:26:14.0570 0x1124  RemoteAccess - ok
14:26:14.0588 0x1124  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
14:26:14.0611 0x1124  RemoteRegistry - ok
14:26:14.0620 0x1124  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
14:26:14.0642 0x1124  RpcEptMapper - ok
14:26:14.0661 0x1124  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
14:26:14.0669 0x1124  RpcLocator - ok
14:26:14.0702 0x1124  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] RpcSs           C:\Windows\system32\rpcss.dll
14:26:14.0716 0x1124  RpcSs - ok
14:26:14.0731 0x1124  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
14:26:14.0752 0x1124  rspndr - ok
14:26:14.0768 0x1124  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
14:26:14.0775 0x1124  s3cap - ok
14:26:14.0790 0x1124  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] SamSs           C:\Windows\system32\lsass.exe
14:26:14.0797 0x1124  SamSs - ok
14:26:14.0808 0x1124  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
14:26:14.0815 0x1124  sbp2port - ok
14:26:14.0827 0x1124  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
14:26:14.0851 0x1124  SCardSvr - ok
14:26:14.0867 0x1124  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
14:26:14.0886 0x1124  scfilter - ok
14:26:14.0922 0x1124  [ 40686B59C127F0C93B4234E4A1E3472A, B2DD61CB796C6AA8AFD285D43472B94646CA6D331D282818E0FDC9DE28DDE9CF ] Schedule        C:\Windows\system32\schedsvc.dll
14:26:14.0951 0x1124  Schedule - ok
14:26:14.0980 0x1124  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc     C:\Windows\System32\certprop.dll
14:26:15.0001 0x1124  SCPolicySvc - ok
14:26:15.0017 0x1124  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
14:26:15.0028 0x1124  SDRSVC - ok
14:26:15.0047 0x1124  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
14:26:15.0058 0x1124  secdrv - ok
14:26:15.0084 0x1124  [ A19623BDD61E66A12AB53992002B4F3A, E351CEEC086084A417BA3BD0EEF46114D3147EC38E3EF8BE49B724F9D028CC56 ] seclogon        C:\Windows\system32\seclogon.dll
14:26:15.0098 0x1124  seclogon - ok
14:26:15.0110 0x1124  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\System32\sens.dll
14:26:15.0132 0x1124  SENS - ok
14:26:15.0140 0x1124  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
14:26:15.0147 0x1124  SensrSvc - ok
14:26:15.0181 0x1124  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
14:26:15.0188 0x1124  Serenum - ok
14:26:15.0200 0x1124  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\DRIVERS\serial.sys
14:26:15.0209 0x1124  Serial - ok
14:26:15.0245 0x1124  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\drivers\sermouse.sys
14:26:15.0252 0x1124  sermouse - ok
14:26:15.0270 0x1124  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
14:26:15.0292 0x1124  SessionEnv - ok
14:26:15.0295 0x1124  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
14:26:15.0303 0x1124  sffdisk - ok
14:26:15.0306 0x1124  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
14:26:15.0314 0x1124  sffp_mmc - ok
14:26:15.0317 0x1124  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
14:26:15.0325 0x1124  sffp_sd - ok
14:26:15.0328 0x1124  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
14:26:15.0335 0x1124  sfloppy - ok
14:26:15.0348 0x1124  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
14:26:15.0375 0x1124  SharedAccess - ok
14:26:15.0396 0x1124  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:26:15.0422 0x1124  ShellHWDetection - ok
14:26:15.0436 0x1124  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
14:26:15.0442 0x1124  SiSRaid2 - ok
14:26:15.0451 0x1124  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
14:26:15.0457 0x1124  SiSRaid4 - ok
14:26:15.0518 0x1124  [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate     C:\Program Files (x86)\Skype\Updater\Updater.exe
14:26:15.0529 0x1124  SkypeUpdate - ok
14:26:15.0540 0x1124  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
14:26:15.0561 0x1124  Smb - ok
14:26:15.0572 0x1124  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
14:26:15.0578 0x1124  SNMPTRAP - ok
14:26:15.0587 0x1124  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr           C:\Windows\system32\drivers\spldr.sys
14:26:15.0592 0x1124  spldr - ok
14:26:15.0613 0x1124  [ B96C17B5DC1424D56EEA3A99E97428CD, AF0A85066A7983878DC1C663811CE61C6CA1912DC956184F878B7B82DB93C651 ] Spooler         C:\Windows\System32\spoolsv.exe
14:26:15.0641 0x1124  Spooler - ok
14:26:15.0719 0x1124  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
14:26:15.0815 0x1124  sppsvc - ok
14:26:15.0828 0x1124  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
14:26:15.0848 0x1124  sppuinotify - ok
14:26:15.0879 0x1124  [ EC666682FE8344CF7E6ED69E74FA9F4F, DCD2A1C046425630689E2C9A6A6E356FE5A2A6664D12C20CFE236FCB32240DF9 ] srv             C:\Windows\system32\DRIVERS\srv.sys
14:26:15.0906 0x1124  srv - ok
14:26:15.0920 0x1124  [ E450C0318DCE8ED28ED272C8806B8495, D2FD459F8C5E42103EF2F71421FA175A4F0821F8C2A3763093122D433D1C50FB ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
14:26:15.0932 0x1124  srv2 - ok
14:26:15.0965 0x1124  [ 9C12C78AD36C23D925711A4640228225, FF72C23F2A08EDF0C41BAF1EB0245AB44FF91365C5466F09C47A8F0928D20994 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
14:26:15.0974 0x1124  srvnet - ok
14:26:15.0983 0x1124  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
14:26:16.0007 0x1124  SSDPSRV - ok
14:26:16.0022 0x1124  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc         C:\Windows\system32\sstpsvc.dll
14:26:16.0045 0x1124  SstpSvc - ok
14:26:16.0104 0x1124  [ 90E22D7CDE08E07446D238A569BCAB7C, 3D4F413D0B0C9CF28D06E0476F24AC6441C8678DF786D9971B39C91C9F9B8020 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
14:26:16.0139 0x1124  Steam Client Service - ok
14:26:16.0164 0x1124  [ E1AAD79D0C59C157258845C998715575, AF08F3DE709045E8E5B5EAC7D05F307C92AA031753CFE9ABB9A5A3B37FE392BA ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
14:26:16.0176 0x1124  Stereo Service - ok
14:26:16.0184 0x1124  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
14:26:16.0190 0x1124  stexstor - ok
14:26:16.0216 0x1124  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\Windows\System32\wiaservc.dll
14:26:16.0236 0x1124  stisvc - ok
14:26:16.0248 0x1124  [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
14:26:16.0254 0x1124  storflt - ok
14:26:16.0279 0x1124  [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc         C:\Windows\system32\storsvc.dll
14:26:16.0299 0x1124  StorSvc - ok
14:26:16.0313 0x1124  [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc         C:\Windows\system32\drivers\storvsc.sys
14:26:16.0318 0x1124  storvsc - ok
14:26:16.0330 0x1124  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
14:26:16.0336 0x1124  swenum - ok
14:26:16.0356 0x1124  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv           C:\Windows\System32\swprv.dll
14:26:16.0386 0x1124  swprv - ok
14:26:16.0441 0x1124  [ 2E730941CC5BF6200A4F56D1E9C24AAD, 758836D55DC84F3EBE9917DC6FAB8E6170A5B238FEDBCFDB6D7C5C6EA98E08B2 ] SysMain         C:\Windows\system32\sysmain.dll
14:26:16.0507 0x1124  SysMain - ok
14:26:16.0527 0x1124  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
14:26:16.0540 0x1124  TabletInputService - ok
14:26:16.0555 0x1124  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv         C:\Windows\System32\tapisrv.dll
14:26:16.0582 0x1124  TapiSrv - ok
14:26:16.0639 0x1124  [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
14:26:16.0671 0x1124  Tcpip - ok
14:26:16.0717 0x1124  [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
14:26:16.0750 0x1124  TCPIP6 - ok
14:26:16.0771 0x1124  [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
14:26:16.0777 0x1124  tcpipreg - ok
14:26:16.0789 0x1124  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
14:26:16.0800 0x1124  TDPIPE - ok
14:26:16.0823 0x1124  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
14:26:16.0830 0x1124  TDTCP - ok
14:26:16.0853 0x1124  [ AA77EB517D2F07A947294F260E3ACA83, B7A5DF3066830C0C2302B059778A67419792058A0D300C471DE40AB245EA7E58 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
14:26:16.0861 0x1124  tdx - ok
14:26:16.0883 0x1124  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
14:26:16.0890 0x1124  TermDD - ok
14:26:16.0926 0x1124  [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService     C:\Windows\System32\termsrv.dll
14:26:16.0945 0x1124  TermService - ok
14:26:16.0970 0x1124  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
14:26:16.0981 0x1124  Themes - ok
14:26:16.0988 0x1124  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER     C:\Windows\system32\mmcss.dll
14:26:17.0010 0x1124  THREADORDER - ok
14:26:17.0029 0x1124  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
14:26:17.0052 0x1124  TrkWks - ok
14:26:17.0096 0x1124  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:26:17.0120 0x1124  TrustedInstaller - ok
14:26:17.0144 0x1124  [ 19BEDA57F3E0A06B8D5EB6D619BD5624, 952D5FAFD662C93628C12A6F7EB8E240A44216C0A15CBD2F5016BC357CBFE821 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
14:26:17.0151 0x1124  tssecsrv - ok
14:26:17.0182 0x1124  [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
14:26:17.0189 0x1124  TsUsbFlt - ok
14:26:17.0222 0x1124  [ AD64450A4ABE076F5CB34CC08EEACB07, B5C386635441A19178E7FEEE299BA430C8D72F9110866C13A216B12A1080AD12 ] TsUsbGD         C:\Windows\system32\drivers\TsUsbGD.sys
14:26:17.0229 0x1124  TsUsbGD - ok
14:26:17.0244 0x1124  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
14:26:17.0265 0x1124  tunnel - ok
14:26:17.0279 0x1124  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
14:26:17.0285 0x1124  uagp35 - ok
14:26:17.0306 0x1124  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
14:26:17.0329 0x1124  udfs - ok
14:26:17.0334 0x1124  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect       C:\Windows\system32\UI0Detect.exe
14:26:17.0343 0x1124  UI0Detect - ok
14:26:17.0359 0x1124  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
14:26:17.0365 0x1124  uliagpkx - ok
14:26:17.0382 0x1124  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
14:26:17.0391 0x1124  umbus - ok
14:26:17.0401 0x1124  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\drivers\umpass.sys
14:26:17.0409 0x1124  UmPass - ok
14:26:17.0443 0x1124  [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService    C:\Windows\System32\umrdp.dll
14:26:17.0455 0x1124  UmRdpService - ok
14:26:17.0474 0x1124  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
14:26:17.0501 0x1124  upnphost - ok
14:26:17.0548 0x1124  [ DCA68B0943D6FA415F0C56C92158A83A, BEE5A5B33B22D1DF50B884D46D89FC3B8286EB16E38AD5A20F0A49E5C6766C57 ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
14:26:17.0569 0x1124  usbccgp - ok
14:26:17.0600 0x1124  [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir          C:\Windows\system32\drivers\usbcir.sys
14:26:17.0617 0x1124  usbcir - ok
14:26:17.0621 0x1124  [ 74EE782B1D9C241EFE425565854C661C, E8258EA65B0FCAD4E077B176E9D9324646B652D6E651241E397346A39770D065 ] usbehci         C:\Windows\system32\drivers\usbehci.sys
14:26:17.0629 0x1124  usbehci - ok
14:26:17.0647 0x1124  [ 8D1196CFBB223621F2C67D45710F25BA, B5D7AFE51833B24FC9576F3AED3D8A2B290E5846060E73F9FFFAC1890A8B6003 ] usbhub          C:\Windows\system32\drivers\usbhub.sys
14:26:17.0658 0x1124  usbhub - ok
14:26:17.0661 0x1124  [ 58E546BBAF87664FC57E0F6081E4F609, 1DD99D57369A0069654432AB5325AFD8F7D422D531E053EA05FF664BA6BDAEF9 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
14:26:17.0669 0x1124  usbohci - ok
14:26:17.0672 0x1124  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\drivers\usbprint.sys
14:26:17.0680 0x1124  usbprint - ok
14:26:17.0691 0x1124  [ D029DD09E22EB24318A8FC3D8138BA43, C95805E8BF75ECB939520AE86420B16467B0771C161C51C9F1A37649ADFADCD0 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:26:17.0705 0x1124  USBSTOR - ok
14:26:17.0708 0x1124  [ 81FB2216D3A60D1284455D511797DB3D, 121E52B18A1832E775EA0AE2E053BAA53E5A70E9754724B1449AE5992D63B13E ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
14:26:17.0715 0x1124  usbuhci - ok
14:26:17.0733 0x1124  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms           C:\Windows\System32\uxsms.dll
14:26:17.0754 0x1124  UxSms - ok
14:26:17.0767 0x1124  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] VaultSvc        C:\Windows\system32\lsass.exe
14:26:17.0774 0x1124  VaultSvc - ok
14:26:17.0789 0x1124  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
14:26:17.0795 0x1124  vdrvroot - ok
14:26:17.0818 0x1124  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds             C:\Windows\System32\vds.exe
14:26:17.0846 0x1124  vds - ok
14:26:17.0860 0x1124  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
14:26:17.0868 0x1124  vga - ok
14:26:17.0877 0x1124  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave         C:\Windows\System32\drivers\vga.sys
14:26:17.0898 0x1124  VgaSave - ok
14:26:17.0912 0x1124  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
14:26:17.0920 0x1124  vhdmp - ok
14:26:17.0954 0x1124  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\drivers\viaide.sys
14:26:17.0959 0x1124  viaide - ok
14:26:17.0987 0x1124  [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus           C:\Windows\system32\drivers\vmbus.sys
14:26:17.0995 0x1124  vmbus - ok
14:26:18.0006 0x1124  [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
14:26:18.0014 0x1124  VMBusHID - ok
14:26:18.0030 0x1124  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
14:26:18.0036 0x1124  volmgr - ok
14:26:18.0057 0x1124  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
14:26:18.0067 0x1124  volmgrx - ok
14:26:18.0080 0x1124  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap         C:\Windows\system32\drivers\volsnap.sys
14:26:18.0089 0x1124  volsnap - ok
14:26:18.0101 0x1124  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
14:26:18.0109 0x1124  vsmraid - ok
14:26:18.0153 0x1124  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS             C:\Windows\system32\vssvc.exe
14:26:18.0204 0x1124  VSS - ok
14:26:18.0222 0x1124  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
14:26:18.0230 0x1124  vwifibus - ok
14:26:18.0248 0x1124  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time         C:\Windows\system32\w32time.dll
14:26:18.0276 0x1124  W32Time - ok
14:26:18.0304 0x1124  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
14:26:18.0312 0x1124  WacomPen - ok
14:26:18.0382 0x1124  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
14:26:18.0402 0x1124  WANARP - ok
14:26:18.0443 0x1124  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
14:26:18.0463 0x1124  Wanarpv6 - ok
14:26:18.0488 0x1124  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\Windows\system32\wbengine.exe
14:26:18.0520 0x1124  wbengine - ok
14:26:18.0536 0x1124  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
14:26:18.0548 0x1124  WbioSrvc - ok
14:26:18.0556 0x1124  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
14:26:18.0571 0x1124  wcncsvc - ok
14:26:18.0585 0x1124  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:26:18.0597 0x1124  WcsPlugInService - ok
14:26:18.0610 0x1124  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\drivers\wd.sys
14:26:18.0615 0x1124  Wd - ok
14:26:18.0649 0x1124  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
14:26:18.0665 0x1124  Wdf01000 - ok
14:26:18.0676 0x1124  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost  C:\Windows\system32\wdi.dll
14:26:18.0705 0x1124  WdiServiceHost - ok
14:26:18.0708 0x1124  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost   C:\Windows\system32\wdi.dll
14:26:18.0718 0x1124  WdiSystemHost - ok
14:26:18.0751 0x1124  [ EE841B6D1F2B9508D3ABAE52AC05A94F, F1AE981FCDBFC4672A4EABABD41382E93762EFC2EDAD96E75530E7ACA5AF1FD8 ] WebClient       C:\Windows\System32\webclnt.dll
14:26:18.0761 0x1124  WebClient - ok
14:26:18.0773 0x1124  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\Windows\system32\wecsvc.dll
14:26:18.0797 0x1124  Wecsvc - ok
14:26:18.0806 0x1124  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
14:26:18.0827 0x1124  wercplsupport - ok
14:26:18.0854 0x1124  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
14:26:18.0874 0x1124  WerSvc - ok
14:26:18.0877 0x1124  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
14:26:18.0896 0x1124  WfpLwf - ok
14:26:18.0899 0x1124  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
14:26:18.0904 0x1124  WIMMount - ok
14:26:18.0915 0x1124  WinDefend - ok
14:26:18.0917 0x1124  WinHttpAutoProxySvc - ok
14:26:18.0973 0x1124  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
14:26:18.0997 0x1124  Winmgmt - ok
14:26:19.0055 0x1124  [ EBDA1B0F15CB9B2CBCC6C94824E4E054, C51314F7D611E4903DA00EFA8EB99365414436324D256083CE0B5A8E055E8E06 ] WinRM           C:\Windows\system32\WsmSvc.dll
14:26:19.0113 0x1124  WinRM - ok
14:26:19.0147 0x1124  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
14:26:19.0156 0x1124  WinUsb - ok
14:26:19.0182 0x1124  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc         C:\Windows\System32\wlansvc.dll
14:26:19.0207 0x1124  Wlansvc - ok
14:26:19.0221 0x1124  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
14:26:19.0229 0x1124  WmiAcpi - ok
14:26:19.0237 0x1124  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
14:26:19.0248 0x1124  wmiApSrv - ok
14:26:19.0264 0x1124  WMPNetworkSvc - ok
14:26:19.0286 0x1124  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
14:26:19.0301 0x1124  WPCSvc - ok
14:26:19.0318 0x1124  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
14:26:19.0328 0x1124  WPDBusEnum - ok
14:26:19.0341 0x1124  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
14:26:19.0361 0x1124  ws2ifsl - ok
14:26:19.0365 0x1124  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\System32\wscsvc.dll
14:26:19.0376 0x1124  wscsvc - ok
14:26:19.0378 0x1124  WSearch - ok
14:26:19.0452 0x1124  [ 31F32E0C1A8BA9A37EEC23DE5F27F847, 0180832BC6172C9A4C32B5B222BB3F91EA615A5EBDA98DB79ED4FED258C2D257 ] wuauserv        C:\Windows\system32\wuaueng.dll
14:26:19.0529 0x1124  wuauserv - ok
14:26:19.0558 0x1124  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
14:26:19.0579 0x1124  WudfPf - ok
14:26:19.0603 0x1124  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
14:26:19.0613 0x1124  WUDFRd - ok
14:26:19.0647 0x1124  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
14:26:19.0655 0x1124  wudfsvc - ok
14:26:19.0691 0x1124  [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc         C:\Windows\System32\wwansvc.dll
14:26:19.0710 0x1124  WwanSvc - ok
14:26:19.0731 0x1124  ================ Scan global ===============================
14:26:19.0748 0x1124  [ 168EA9CD9BD6056BB6F60B57D5304BBE, 5A2F98754F042A7D80E7483842967EB362F01D57CE9720B24C7EDAA047F24C6F ] C:\Windows\system32\basesrv.dll
14:26:19.0772 0x1124  [ A5794B1E3ACEF48E716F0A89C83C1AEA, B904C861CBDAF00341F8697BD05C2E66C23CF4D6C94E19AF464D898436F34D73 ] C:\Windows\system32\winsrv.dll
14:26:19.0781 0x1124  [ A5794B1E3ACEF48E716F0A89C83C1AEA, B904C861CBDAF00341F8697BD05C2E66C23CF4D6C94E19AF464D898436F34D73 ] C:\Windows\system32\winsrv.dll
14:26:19.0807 0x1124  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
14:26:19.0838 0x1124  [ 71C85477DF9347FE8E7BC55768473FCA, A86D6A6D1F5A0EFCD649792A06F3AE9B37158D48493D2ECA7F52DCC1CB9B6536 ] C:\Windows\system32\services.exe
14:26:19.0842 0x1124  [ Global ] - ok
14:26:19.0843 0x1124  ================ Scan MBR ==================================
14:26:19.0855 0x1124  [ EA923EB0EC0060F1451E9AD7B5762CFE ] \Device\Harddisk0\DR0
14:26:19.0966 0x1124  \Device\Harddisk0\DR0 - ok
14:26:19.0966 0x1124  ================ Scan VBR ==================================
14:26:19.0967 0x1124  [ 554243D2ABA7A16AC01FE5C4DE5EB9E0 ] \Device\Harddisk0\DR0\Partition1
14:26:19.0968 0x1124  \Device\Harddisk0\DR0\Partition1 - ok
14:26:19.0969 0x1124  [ 2ABC120A69E42FE6BBE9FA62C2CEF16F ] \Device\Harddisk0\DR0\Partition2
14:26:19.0970 0x1124  \Device\Harddisk0\DR0\Partition2 - ok
14:26:19.0970 0x1124  ================ Scan generic autorun ======================
14:26:20.0079 0x1124  [ BAEDADCD6509201F82CE5B404AB14814, 8C39C18CE00DB254F370D9C4AA80E88BF67C457240F3D30A58E39DBF9B96F44B ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
14:26:20.0103 0x1124  IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
14:26:20.0184 0x1124  Detect skipped due to KSN trusted
14:26:20.0184 0x1124  IAStorIcon - ok
14:26:20.0367 0x1124  [ 890C5393F1E7775A38FA73DC554A379E, 16A01ABF2E6C070156E0A92642496F33BE9A5A923B41FD538C532A52B92E74C4 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
14:26:20.0490 0x1124  RTHDVCPL - ok
14:26:20.0603 0x1124  [ 948EB9C552C05DF39F79587E6979D9F5, 402B155395C32005A8D78C8B0F00F2391542CB41188AF944FF17ADE6BE97A62D ] C:\Program Files\Logitech\SetPointP\SetPoint.exe
14:26:20.0650 0x1124  EvtMgr6 - ok
14:26:20.0708 0x1124  [ 80086ED442941DE2CA18CB6DAE8C1422, F7BE958F2E8E17970C238E3806F4A742B12DA09EB21093BD6371CF4B580C5BE4 ] C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
14:26:20.0758 0x1124  Aeria Ignite - ok
14:26:20.0808 0x1124  [ 5153C06FC9D4D094D1A785545928B134, 0037C935722663F9EF028F841DE222FC6418E9D60939AB60C965807E67A458DC ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
14:26:20.0820 0x1124  SunJavaUpdateSched - ok
14:26:20.0912 0x1124  [ CB46168FFDEA91E2B3435E51BB436558, 848D12E11B79722B07C42D848D831C6B782E1338B8F844924CB8938FE11F379D ] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
14:26:20.0921 0x1124  USB3MON - ok
14:26:20.0973 0x1124  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
14:26:21.0042 0x1124  Sidebar - ok
14:26:21.0066 0x1124  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
14:26:21.0077 0x1124  mctadmin - ok
14:26:21.0096 0x1124  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
14:26:21.0121 0x1124  Sidebar - ok
14:26:21.0125 0x1124  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
14:26:21.0135 0x1124  mctadmin - ok
14:26:21.0302 0x1124  [ F2AD1B265908797F8A5E21E0312F2F25, 2A6A612F7D52D297385C43E77AD0CD37B28F33ED2AF89098F5E66B812B838A52 ] C:\Users\kevin\AppData\Local\Akamai\netsession_win.exe
14:26:21.0372 0x1124  Akamai NetSession Interface - ok
14:26:21.0410 0x1124  [ 44A9229022A519ED45294A1934C05EEC, 6DEF0DB5F9B50E9B0AFEE1CF50066BEB4FB7E15E2DC829A499509925660D6992 ] C:\Users\kevin\AppData\Local\FluxSoftware\Flux\flux.exe
14:26:21.0428 0x1124  f.lux - ok
         

Alt 12.11.2016, 15:43   #8
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Teil 2 des Logs
Code:
ATTFilter
14:26:21.0430 0x1124  Waiting for KSN requests completion. In queue: 78
14:26:22.0451 0x1124  Win FW state via NFP2: enabled ( trusted )
14:26:22.0546 0x1124  ============================================================
14:26:22.0546 0x1124  Scan finished
14:26:22.0546 0x1124  ============================================================
14:26:22.0550 0x0460  Detected object count: 1
14:26:22.0550 0x0460  Actual detected object count: 1
14:26:36.0617 0x0460  HiPatchService ( UnsignedFile.Multi.Generic ) - skipped by user
14:26:36.0617 0x0460  HiPatchService ( UnsignedFile.Multi.Generic ) - User select action: Skip 
14:26:47.0475 0x063c  ============================================================
14:26:47.0475 0x063c  Scan started
14:26:47.0475 0x063c  Mode: Manual; SigCheck; TDLFS; 
14:26:47.0475 0x063c  ============================================================
14:26:47.0475 0x063c  KSN ping started
14:26:47.0537 0x063c  KSN ping finished: true
14:26:48.0223 0x063c  ================ Scan system memory ========================
14:26:48.0223 0x063c  System memory - ok
14:26:48.0223 0x063c  ================ Scan services =============================
14:26:48.0301 0x063c  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
14:26:48.0317 0x063c  1394ohci - ok
14:26:48.0333 0x063c  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
14:26:48.0348 0x063c  ACPI - ok
14:26:48.0348 0x063c  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
14:26:48.0348 0x063c  AcpiPmi - ok
14:26:48.0426 0x063c  [ D08D2733615784B8072BEBA2A8CC45BB, 29BB59D866F8738609F8DC441F54423BB0A810B470C87AB7935E173D6E098C2A ] ACTION_SVC      C:\Program Files (x86)\Mirillis\Action!\action_svc.exe
14:26:48.0426 0x063c  ACTION_SVC - ok
14:26:48.0520 0x063c  [ 9BAF21BA600EC4E5FD9A66AD3E4FF5A6, 5E02E5E80557F6EC870EB7CC2DE95169D4225B87A2FE7E796736205F51C15816 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
14:26:48.0535 0x063c  AdobeFlashPlayerUpdateSvc - ok
14:26:48.0551 0x063c  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
14:26:48.0567 0x063c  adp94xx - ok
14:26:48.0582 0x063c  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci         C:\Windows\system32\drivers\adpahci.sys
14:26:48.0598 0x063c  adpahci - ok
14:26:48.0613 0x063c  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
14:26:48.0613 0x063c  adpu320 - ok
14:26:48.0645 0x063c  [ 262D7C87D0AC20B96EF9877D3CA478A0, 54F7E5A5F8991C5525500C1ECCF3D3135D13F48866C366E52DF1D052DB2EE15B ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
14:26:48.0660 0x063c  AeLookupSvc - ok
14:26:48.0691 0x063c  [ 9A4A1EEE802BF2F878EE8EAB407B21B7, 177EB7DF4B35FE4C0E45E775A0FD5D48D39B410052E3EE18BDEEC809E152D9D8 ] AFD             C:\Windows\system32\drivers\afd.sys
14:26:48.0691 0x063c  AFD - ok
14:26:48.0707 0x063c  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\drivers\agp440.sys
14:26:48.0707 0x063c  agp440 - ok
14:26:48.0723 0x063c  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG             C:\Windows\System32\alg.exe
14:26:48.0738 0x063c  ALG - ok
14:26:48.0769 0x063c  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
14:26:48.0769 0x063c  aliide - ok
14:26:48.0769 0x063c  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
14:26:48.0785 0x063c  amdide - ok
14:26:48.0801 0x063c  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
14:26:48.0801 0x063c  AmdK8 - ok
14:26:48.0816 0x063c  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
14:26:48.0816 0x063c  AmdPPM - ok
14:26:48.0847 0x063c  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
14:26:48.0847 0x063c  amdsata - ok
14:26:48.0863 0x063c  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
14:26:48.0863 0x063c  amdsbs - ok
14:26:48.0879 0x063c  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata         C:\Windows\system32\drivers\amdxata.sys
14:26:48.0894 0x063c  amdxata - ok
14:26:48.0925 0x063c  [ 0CD7BFDE151223C6976C5D1B3D49EB84, A16FAB4F77D03C0664CCE8082E40A7673BC7FA4E89854F9027D478CD99EB2088 ] AppID           C:\Windows\system32\drivers\appid.sys
14:26:48.0925 0x063c  AppID - ok
14:26:48.0941 0x063c  [ F9842669B31F20B8B157D33CCC457820, AC8FA65F0A3C479D3CFE10EFE9B3EC5BAE48059F57A12D8C2D7963A22EB043B8 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
14:26:48.0941 0x063c  AppIDSvc - ok
14:26:48.0972 0x063c  [ B46099A534B7989D80330EA82D9092D6, 0CAC09732FAFAE805E55428B6BE001DCC39EBC599539FADE7AA68571A8A554E5 ] Appinfo         C:\Windows\System32\appinfo.dll
14:26:48.0988 0x063c  Appinfo - ok
14:26:49.0019 0x063c  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt         C:\Windows\System32\appmgmts.dll
14:26:49.0019 0x063c  AppMgmt - ok
14:26:49.0035 0x063c  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc             C:\Windows\system32\drivers\arc.sys
14:26:49.0035 0x063c  arc - ok
14:26:49.0050 0x063c  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\drivers\arcsas.sys
14:26:49.0066 0x063c  arcsas - ok
14:26:49.0144 0x063c  [ 660D597B7A78256734D7F3230B21B355, CAA19E8EFAD63B8975A4CD8EFD5CE5F21E056856D36BC5A9E48517F1E574ABBA ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
14:26:49.0159 0x063c  aspnet_state - ok
14:26:49.0159 0x063c  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
14:26:49.0191 0x063c  AsyncMac - ok
14:26:49.0222 0x063c  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi           C:\Windows\system32\drivers\atapi.sys
14:26:49.0222 0x063c  atapi - ok
14:26:49.0253 0x063c  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:26:49.0269 0x063c  AudioEndpointBuilder - ok
14:26:49.0284 0x063c  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
14:26:49.0300 0x063c  AudioSrv - ok
14:26:49.0331 0x063c  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\Windows\System32\AxInstSV.dll
14:26:49.0331 0x063c  AxInstSV - ok
14:26:49.0362 0x063c  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
14:26:49.0378 0x063c  b06bdrv - ok
14:26:49.0393 0x063c  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
14:26:49.0409 0x063c  b57nd60a - ok
14:26:49.0409 0x063c  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
14:26:49.0425 0x063c  BDESVC - ok
14:26:49.0440 0x063c  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
14:26:49.0456 0x063c  Beep - ok
14:26:49.0471 0x063c  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE             C:\Windows\System32\bfe.dll
14:26:49.0487 0x063c  BFE - ok
14:26:49.0534 0x063c  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\System32\qmgr.dll
14:26:49.0565 0x063c  BITS - ok
14:26:49.0565 0x063c  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
14:26:49.0581 0x063c  blbdrive - ok
14:26:49.0612 0x063c  [ ABA3984C822E4D3F889699912D85D6C5, 2251FA135CC290DA13DAE4743F393C7CC9E6A737C054707CB8D72C369D1FFACB ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
14:26:49.0612 0x063c  bowser - ok
14:26:49.0627 0x063c  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
14:26:49.0643 0x063c  BrFiltLo - ok
14:26:49.0643 0x063c  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
14:26:49.0643 0x063c  BrFiltUp - ok
14:26:49.0674 0x063c  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser         C:\Windows\System32\browser.dll
14:26:49.0690 0x063c  Browser - ok
14:26:49.0690 0x063c  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
14:26:49.0705 0x063c  Brserid - ok
14:26:49.0705 0x063c  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
14:26:49.0721 0x063c  BrSerWdm - ok
14:26:49.0721 0x063c  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
14:26:49.0721 0x063c  BrUsbMdm - ok
14:26:49.0721 0x063c  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
14:26:49.0737 0x063c  BrUsbSer - ok
14:26:49.0752 0x063c  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
14:26:49.0752 0x063c  BTHMODEM - ok
14:26:49.0768 0x063c  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv         C:\Windows\system32\bthserv.dll
14:26:49.0783 0x063c  bthserv - ok
14:26:49.0799 0x063c  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
14:26:49.0815 0x063c  cdfs - ok
14:26:49.0830 0x063c  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
14:26:49.0830 0x063c  cdrom - ok
14:26:49.0846 0x063c  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc     C:\Windows\System32\certprop.dll
14:26:49.0861 0x063c  CertPropSvc - ok
14:26:49.0877 0x063c  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\drivers\circlass.sys
14:26:49.0877 0x063c  circlass - ok
14:26:49.0908 0x063c  [ 3891EA60B84EFE115CE070311FA83BBB, 2A30FB15C8D0C69289C087DFE1F822AB4F9C3F091DBB3FD2E99DC5B562E90DFB ] CLFS            C:\Windows\system32\CLFS.sys
14:26:49.0924 0x063c  CLFS - ok
14:26:49.0986 0x063c  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:26:50.0002 0x063c  clr_optimization_v2.0.50727_32 - ok
14:26:50.0033 0x063c  [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
14:26:50.0049 0x063c  clr_optimization_v2.0.50727_64 - ok
14:26:50.0095 0x063c  [ AB4CD527BEFCC43EE441E6C50CCE54C8, 13B776AE63049FFBA7E35EA0A4C26EBB57B10D973E05C4CF1214249754DC46E4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:26:50.0111 0x063c  clr_optimization_v4.0.30319_32 - ok
14:26:50.0158 0x063c  [ 1400C75FF021D6CFACE46AC41B60770E, 3FCB8D7714A79522F2738037D559F1FFFB2F05C5406D2A038EF5DDB4629CA1CE ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
14:26:50.0158 0x063c  clr_optimization_v4.0.30319_64 - ok
14:26:50.0158 0x063c  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
14:26:50.0173 0x063c  CmBatt - ok
14:26:50.0173 0x063c  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
14:26:50.0189 0x063c  cmdide - ok
14:26:50.0220 0x063c  [ 3323F76352B0AF14B2CDC4DFBF3E980A, F8E3C3508C37E647497B6889F26819B1DB30275F48A994D1BBFBAA9454E5FD70 ] CNG             C:\Windows\system32\Drivers\cng.sys
14:26:50.0236 0x063c  CNG - ok
14:26:50.0236 0x063c  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
14:26:50.0251 0x063c  Compbatt - ok
14:26:50.0267 0x063c  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
14:26:50.0267 0x063c  CompositeBus - ok
14:26:50.0283 0x063c  COMSysApp - ok
14:26:50.0283 0x063c  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
14:26:50.0283 0x063c  crcdisk - ok
14:26:50.0314 0x063c  [ BB724567892383010B8436DCC0A84628, 2768F5FD7A096CB1CEA33F8818EF16F9F5E3E07BB8442949A49A9CF24B62C6E6 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
14:26:50.0314 0x063c  CryptSvc - ok
14:26:50.0345 0x063c  [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC             C:\Windows\system32\drivers\csc.sys
14:26:50.0361 0x063c  CSC - ok
14:26:50.0392 0x063c  [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService      C:\Windows\System32\cscsvc.dll
14:26:50.0407 0x063c  CscService - ok
14:26:50.0439 0x063c  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] DcomLaunch      C:\Windows\system32\rpcss.dll
14:26:50.0454 0x063c  DcomLaunch - ok
14:26:50.0485 0x063c  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc       C:\Windows\System32\defragsvc.dll
14:26:50.0501 0x063c  defragsvc - ok
14:26:50.0532 0x063c  [ 9B38580063D281A99E68EF5813022A5F, D91676B0E0A8E2A090E3E5DD340ABCFC20AE0F55B4C82869D6CFB34239BD27DA ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
14:26:50.0548 0x063c  DfsC - ok
14:26:50.0548 0x063c  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
14:26:50.0563 0x063c  Dhcp - ok
14:26:50.0641 0x063c  [ EE9954237F15BE4DD9304D12E4D305ED, F295C9BAF20F0E669B673AFCC16B4969EE31B6A3808980DAB93D9B0F167DA3C0 ] DiagTrack       C:\Windows\system32\diagtrack.dll
14:26:50.0673 0x063c  DiagTrack - ok
14:26:50.0688 0x063c  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
14:26:50.0704 0x063c  discache - ok
14:26:50.0735 0x063c  [ 616387BBD83372220B09DE95F4E67BBC, 5E2D5280BB775576E7CDE3FA6BDE494E183123635E5908CF7EBF1FF52966D07D ] Disk            C:\Windows\system32\drivers\disk.sys
14:26:50.0735 0x063c  Disk - ok
14:26:50.0766 0x063c  [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc           C:\Windows\system32\drivers\dmvsc.sys
14:26:50.0766 0x063c  dmvsc - ok
14:26:50.0782 0x063c  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
14:26:50.0797 0x063c  Dnscache - ok
14:26:50.0813 0x063c  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc         C:\Windows\System32\dot3svc.dll
14:26:50.0829 0x063c  dot3svc - ok
14:26:50.0844 0x063c  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS             C:\Windows\system32\dps.dll
14:26:50.0860 0x063c  DPS - ok
14:26:50.0907 0x063c  [ 26FE888505E5A945B0536AF9A2A27A6F, A6B16ED498BAFE300E1F0E0A241E3D62F7A1C5973EE775904ED14F33A2BC08A6 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
14:26:50.0907 0x063c  drmkaud - ok
14:26:50.0953 0x063c  [ 3A9D7D464BDB3B70D7ECF689ADABBD4D, B4F5B23705EA1BA453FE30791CA245E1A5F7FBEABAD026E4A8A15A9FC44E8C9C ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
14:26:50.0969 0x063c  DXGKrnl - ok
14:26:50.0985 0x063c  [ F2E765FA3A1261A11A6D51B7ED370727, C4224D0BCD0FDB26CB6C8BCC018BD6E1B3CC0963924182A31E904C61E6E41D01 ] e1dexpress      C:\Windows\system32\DRIVERS\e1d62x64.sys
14:26:51.0000 0x063c  e1dexpress - ok
14:26:51.0000 0x063c  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost         C:\Windows\System32\eapsvc.dll
14:26:51.0031 0x063c  EapHost - ok
14:26:51.0094 0x063c  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv           C:\Windows\system32\drivers\evbda.sys
14:26:51.0141 0x063c  ebdrv - ok
14:26:51.0172 0x063c  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] EFS             C:\Windows\System32\lsass.exe
14:26:51.0172 0x063c  EFS - ok
14:26:51.0234 0x063c  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
14:26:51.0250 0x063c  ehRecvr - ok
14:26:51.0265 0x063c  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched         C:\Windows\ehome\ehsched.exe
14:26:51.0265 0x063c  ehSched - ok
14:26:51.0297 0x063c  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
14:26:51.0312 0x063c  elxstor - ok
14:26:51.0312 0x063c  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
14:26:51.0328 0x063c  ErrDev - ok
14:26:51.0343 0x063c  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem     C:\Windows\system32\es.dll
14:26:51.0375 0x063c  EventSystem - ok
14:26:51.0390 0x063c  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat           C:\Windows\system32\drivers\exfat.sys
14:26:51.0406 0x063c  exfat - ok
14:26:51.0421 0x063c  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
14:26:51.0453 0x063c  fastfat - ok
14:26:51.0468 0x063c  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax             C:\Windows\system32\fxssvc.exe
14:26:51.0484 0x063c  Fax - ok
14:26:51.0484 0x063c  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc             C:\Windows\system32\drivers\fdc.sys
14:26:51.0499 0x063c  fdc - ok
14:26:51.0499 0x063c  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost         C:\Windows\system32\fdPHost.dll
14:26:51.0515 0x063c  fdPHost - ok
14:26:51.0531 0x063c  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
14:26:51.0546 0x063c  FDResPub - ok
14:26:51.0562 0x063c  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
14:26:51.0577 0x063c  FileInfo - ok
14:26:51.0577 0x063c  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
14:26:51.0593 0x063c  Filetrace - ok
14:26:51.0609 0x063c  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
14:26:51.0609 0x063c  flpydisk - ok
14:26:51.0624 0x063c  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
14:26:51.0640 0x063c  FltMgr - ok
14:26:51.0687 0x063c  [ 700A5373FA66F1DAAECBD2CFB88C73ED, D6C1C4C846BC24EB6539ECC701A456FA53BB6679C79391F5B70580D47B6CE395 ] FontCache       C:\Windows\system32\FntCache.dll
14:26:51.0718 0x063c  FontCache - ok
14:26:51.0765 0x063c  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
14:26:51.0765 0x063c  FontCache3.0.0.0 - ok
14:26:51.0780 0x063c  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
14:26:51.0780 0x063c  FsDepends - ok
14:26:51.0796 0x063c  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
14:26:51.0796 0x063c  Fs_Rec - ok
14:26:51.0843 0x063c  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
14:26:51.0843 0x063c  fvevol - ok
14:26:51.0858 0x063c  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
14:26:51.0858 0x063c  gagp30kx - ok
14:26:51.0858 0x063c  gdrv - ok
14:26:51.0905 0x063c  [ E4AE497857409127ED57562AF913A903, 262ADD713B1FBF6200550967D1F8635B55D01BBD8FA2E753536E71A4EC87867B ] gpsvc           C:\Windows\System32\gpsvc.dll
14:26:51.0921 0x063c  gpsvc - ok
14:26:51.0936 0x063c  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
14:26:51.0936 0x063c  hcw85cir - ok
14:26:51.0967 0x063c  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:26:51.0983 0x063c  HdAudAddService - ok
14:26:51.0983 0x063c  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
14:26:51.0999 0x063c  HDAudBus - ok
14:26:51.0999 0x063c  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt         C:\Windows\system32\drivers\HidBatt.sys
14:26:52.0014 0x063c  HidBatt - ok
14:26:52.0030 0x063c  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
14:26:52.0030 0x063c  HidBth - ok
14:26:52.0030 0x063c  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr           C:\Windows\system32\drivers\hidir.sys
14:26:52.0045 0x063c  HidIr - ok
14:26:52.0077 0x063c  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv         C:\Windows\system32\hidserv.dll
14:26:52.0092 0x063c  hidserv - ok
14:26:52.0123 0x063c  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
14:26:52.0139 0x063c  HidUsb - ok
14:26:52.0170 0x063c  [ DA5FCD70EBE32E9DCF2DF5992FCFE59F, F07FF9364C8A94953B2E4545EE9715BEBB9D8C29C4964B1CBA8A9377115F6E42 ] HiPatchService  C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
14:26:52.0186 0x063c  HiPatchService - detected UnsignedFile.Multi.Generic ( 1 )
14:26:52.0186 0x063c  HiPatchService ( UnsignedFile.Multi.Generic ) - warning
14:26:52.0295 0x063c  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
14:26:52.0311 0x063c  hkmsvc - ok
14:26:52.0326 0x063c  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
14:26:52.0342 0x063c  HomeGroupListener - ok
14:26:52.0373 0x063c  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
14:26:52.0389 0x063c  HomeGroupProvider - ok
14:26:52.0389 0x063c  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
14:26:52.0389 0x063c  HpSAMD - ok
14:26:52.0435 0x063c  [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
14:26:52.0451 0x063c  HTTP - ok
14:26:52.0467 0x063c  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
14:26:52.0467 0x063c  hwpolicy - ok
14:26:52.0482 0x063c  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
14:26:52.0482 0x063c  i8042prt - ok
14:26:52.0545 0x063c  [ 12859E1215AA083A42E7ADCDE5C061D1, 262F9C65C3FA7EB69C4FA7C6547E1C79DB49697A083309909BC78726A116557F ] iaStorA         C:\Windows\system32\DRIVERS\iaStorA.sys
14:26:52.0576 0x063c  iaStorA - ok
14:26:52.0654 0x063c  [ 14E3DB5ADA7E2187A404129F4E5CE336, 5925C8E9DC00A6C682D6A3B37C6EBF2C325D37C8E4BF584F0B5AAC5A7B666E47 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
14:26:52.0669 0x063c  IAStorDataMgrSvc - ok
14:26:52.0685 0x063c  [ 91F97C1A0ABCD7FA487E8EF7A249C15C, 834D85B7833DD1EDE0938320A68237315F60263ABCB6714974E711EBA91178E9 ] iaStorF         C:\Windows\system32\DRIVERS\iaStorF.sys
14:26:52.0685 0x063c  iaStorF - ok
14:26:52.0732 0x063c  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
14:26:52.0732 0x063c  iaStorV - ok
14:26:52.0779 0x063c  [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
14:26:52.0794 0x063c  idsvc - ok
14:26:52.0794 0x063c  IEEtwCollectorService - ok
14:26:52.0810 0x063c  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
14:26:52.0825 0x063c  iirsp - ok
14:26:52.0857 0x063c  [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT          C:\Windows\System32\ikeext.dll
14:26:52.0888 0x063c  IKEEXT - ok
14:26:52.0981 0x063c  [ D172E06EFE08DF148155A59DB716C1B6, F059B0B37C5E944D70626E9F029BC6311029E0A9D778C9C75DDDDC59A5AF1605 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
14:26:53.0059 0x063c  IntcAzAudAddService - ok
14:26:53.0075 0x063c  [ 03CD3245E52C8A87E3B14832DC8A6A7D, C2AAB4E754479F0AA0AE86D51E721E5A11624681D5EC823E25E460EE146E70E9 ] Intel(R) PROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
14:26:53.0091 0x063c  Intel(R) PROSet Monitoring Service - ok
14:26:53.0106 0x063c  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
14:26:53.0106 0x063c  intelide - ok
14:26:53.0122 0x063c  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
14:26:53.0137 0x063c  intelppm - ok
14:26:53.0153 0x063c  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
14:26:53.0169 0x063c  IPBusEnum - ok
14:26:53.0184 0x063c  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:26:53.0200 0x063c  IpFilterDriver - ok
14:26:53.0262 0x063c  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
14:26:53.0262 0x063c  iphlpsvc - ok
14:26:53.0278 0x063c  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
14:26:53.0293 0x063c  IPMIDRV - ok
14:26:53.0293 0x063c  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
14:26:53.0309 0x063c  IPNAT - ok
14:26:53.0325 0x063c  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
14:26:53.0340 0x063c  IRENUM - ok
14:26:53.0340 0x063c  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
14:26:53.0340 0x063c  isapnp - ok
14:26:53.0356 0x063c  [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
14:26:53.0371 0x063c  iScsiPrt - ok
14:26:53.0403 0x063c  [ A7A2E0D3932B1986990AC7077B1658CD, F8CC75A711E6C4E5299557F05C0C6B957E8508EA496BC74CCF4827385B046CB4 ] iusb3hub        C:\Windows\system32\DRIVERS\iusb3hub.sys
14:26:53.0418 0x063c  iusb3hub - ok
14:26:53.0465 0x063c  [ FD9C74D20E6F97EDC442091F9DBC1189, 01DD3D862FD7A429E9D79B3B1BC657594628747B0C4C124E976D733065498EDB ] iusb3xhc        C:\Windows\system32\DRIVERS\iusb3xhc.sys
14:26:53.0496 0x063c  iusb3xhc - ok
14:26:53.0496 0x063c  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
14:26:53.0512 0x063c  kbdclass - ok
14:26:53.0512 0x063c  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
14:26:53.0527 0x063c  kbdhid - ok
14:26:53.0527 0x063c  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] KeyIso          C:\Windows\system32\lsass.exe
14:26:53.0543 0x063c  KeyIso - ok
14:26:53.0574 0x063c  [ 1F4B52A496A43C65AB0F26169650FAF2, 6D6F3505997A7DDEE6F127B3FB537AFFDE687D4F34489679674DC12FB12B842C ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
14:26:53.0590 0x063c  KSecDD - ok
14:26:53.0590 0x063c  [ E4A599EDFAAB66C2BC17FB1593DC129B, 13098694B649E9146214D320FB14C3D305FCA155438CB531A8BAA4A70231D1A7 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
14:26:53.0605 0x063c  KSecPkg - ok
14:26:53.0621 0x063c  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
14:26:53.0637 0x063c  ksthunk - ok
14:26:53.0652 0x063c  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm           C:\Windows\system32\msdtckrm.dll
14:26:53.0683 0x063c  KtmRm - ok
14:26:53.0715 0x063c  [ 3447DD130A0F7ED9377878C7A0635BBD, BD701567D1144884320FF66A58AE3A4C26266D22979572D27AA93A75688BC957 ] L8042Kbd        C:\Windows\system32\DRIVERS\L8042Kbd.sys
14:26:53.0715 0x063c  L8042Kbd - ok
14:26:53.0746 0x063c  [ 543C6619CEE79D0AFD0F89D929FBA10A, 84BCDD65A816F959D4EBD49F9586EAF2FDC3F45C887E5C47AADD4ED103DEFA20 ] L8042mou        C:\Windows\system32\DRIVERS\L8042mou.Sys
14:26:53.0761 0x063c  L8042mou - ok
14:26:53.0777 0x063c  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\Windows\system32\srvsvc.dll
14:26:53.0808 0x063c  LanmanServer - ok
14:26:53.0824 0x063c  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:26:53.0839 0x063c  LanmanWorkstation - ok
14:26:53.0949 0x063c  [ 20EE2F2ADCF8DBD091E931593F5AC268, 5F053F8B7C8B340A0364CE37B25D68B6755C2CCDB050C02E9B4E0929DF587E0F ] LBTServ         C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
14:26:53.0964 0x063c  LBTServ - ok
14:26:53.0995 0x063c  [ AFDFA4A6B0F7B15AA38E494FD4595741, 0D89CCEBC816F4A3F6DDB093B3F8BB8B85293E94559085961DA31F9330D43C21 ] LHidFilt        C:\Windows\system32\DRIVERS\LHidFilt.Sys
14:26:53.0995 0x063c  LHidFilt - ok
14:26:54.0011 0x063c  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
14:26:54.0027 0x063c  lltdio - ok
14:26:54.0042 0x063c  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
14:26:54.0073 0x063c  lltdsvc - ok
14:26:54.0105 0x063c  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts         C:\Windows\System32\lmhsvc.dll
14:26:54.0120 0x063c  lmhosts - ok
14:26:54.0136 0x063c  [ C3E82B320F34C97F32B8026F4C249BEF, CAF53CD4738D2C92E4764372F75B5D0D74EBA896E59E685ED15B915F4E7223A0 ] LMouFilt        C:\Windows\system32\DRIVERS\LMouFilt.Sys
14:26:54.0136 0x063c  LMouFilt - ok
14:26:54.0151 0x063c  [ B705D98F8FF847D270098DE6CE6EE1B4, E8025884030230EC9A988E6406521FAD7BBC54475EE8F6C124398B112225BE2E ] LMouKE          C:\Windows\system32\DRIVERS\LMouKE.Sys
14:26:54.0151 0x063c  LMouKE - ok
14:26:54.0167 0x063c  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
14:26:54.0167 0x063c  LSI_FC - ok
14:26:54.0183 0x063c  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
14:26:54.0183 0x063c  LSI_SAS - ok
14:26:54.0198 0x063c  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
14:26:54.0214 0x063c  LSI_SAS2 - ok
14:26:54.0229 0x063c  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
14:26:54.0229 0x063c  LSI_SCSI - ok
14:26:54.0245 0x063c  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv           C:\Windows\system32\drivers\luafv.sys
14:26:54.0261 0x063c  luafv - ok
14:26:54.0292 0x063c  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
14:26:54.0292 0x063c  Mcx2Svc - ok
14:26:54.0307 0x063c  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas         C:\Windows\system32\drivers\megasas.sys
14:26:54.0307 0x063c  megasas - ok
14:26:54.0323 0x063c  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
14:26:54.0339 0x063c  MegaSR - ok
14:26:54.0354 0x063c  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS           C:\Windows\system32\mmcss.dll
14:26:54.0370 0x063c  MMCSS - ok
14:26:54.0385 0x063c  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem           C:\Windows\system32\drivers\modem.sys
14:26:54.0401 0x063c  Modem - ok
14:26:54.0417 0x063c  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
14:26:54.0417 0x063c  monitor - ok
14:26:54.0432 0x063c  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
14:26:54.0448 0x063c  mouclass - ok
14:26:54.0448 0x063c  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
14:26:54.0448 0x063c  mouhid - ok
14:26:54.0495 0x063c  [ 8ADB5445B29941CB41AF2846FD5C93C7, 689582430FE29EC0845B1DB841D3CC49D5D09DE264586E3999EEFE616986D12B ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
14:26:54.0495 0x063c  mountmgr - ok
14:26:54.0526 0x063c  [ 572BD5A99648652147A5D3C6DA946C99, FFDAD4A5682864977C926A5DDDB632CDB2A166BF025757801CC56F2828720023 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
14:26:54.0541 0x063c  MozillaMaintenance - ok
14:26:54.0557 0x063c  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
14:26:54.0557 0x063c  mpio - ok
14:26:54.0573 0x063c  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
14:26:54.0588 0x063c  mpsdrv - ok
14:26:54.0604 0x063c  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\Windows\system32\mpssvc.dll
14:26:54.0635 0x063c  MpsSvc - ok
14:26:54.0666 0x063c  [ 98DB1790F0A584E0A2528B92B052417F, 9AA04CA73AFE599810CD233B9CEC212E16D44DCEDF5C7D0181C7257F498068B5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
14:26:54.0666 0x063c  MRxDAV - ok
14:26:54.0697 0x063c  [ 25F918BB5D57C99FFEB0255143D0DF9A, E4BB656C3AEE19094B0F87828828DC73F248B45B30B678AA759DBAB3087399A2 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
14:26:54.0713 0x063c  mrxsmb - ok
14:26:54.0729 0x063c  [ 8DF2B80510F438CFEC479181BD29C794, ECA5BC17D1DB92B887D468B0FF1D6302518DBD7C3607B14FA291ECDA204D5E85 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:26:54.0744 0x063c  mrxsmb10 - ok
14:26:54.0744 0x063c  [ F7622CFE3402A9BF10227BB124901E54, 3EE6BA42E712505AED9D3920163814719FAC591FB5CFF589E230C7005CB598AF ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:26:54.0744 0x063c  mrxsmb20 - ok
14:26:54.0760 0x063c  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
14:26:54.0775 0x063c  msahci - ok
14:26:54.0791 0x063c  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
14:26:54.0807 0x063c  msdsm - ok
14:26:54.0822 0x063c  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC           C:\Windows\System32\msdtc.exe
14:26:54.0822 0x063c  MSDTC - ok
14:26:54.0822 0x063c  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
14:26:54.0853 0x063c  Msfs - ok
14:26:54.0853 0x063c  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
14:26:54.0885 0x063c  mshidkmdf - ok
14:26:54.0900 0x063c  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
14:26:54.0900 0x063c  msisadrv - ok
14:26:54.0916 0x063c  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
14:26:54.0947 0x063c  MSiSCSI - ok
14:26:54.0947 0x063c  msiserver - ok
14:26:54.0947 0x063c  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
14:26:54.0978 0x063c  MSKSSRV - ok
14:26:54.0978 0x063c  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
14:26:54.0994 0x063c  MSPCLOCK - ok
14:26:54.0994 0x063c  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
14:26:55.0009 0x063c  MSPQM - ok
14:26:55.0025 0x063c  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
14:26:55.0041 0x063c  MsRPC - ok
14:26:55.0056 0x063c  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
14:26:55.0056 0x063c  mssmbios - ok
14:26:55.0072 0x063c  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
14:26:55.0087 0x063c  MSTEE - ok
14:26:55.0103 0x063c  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
14:26:55.0119 0x063c  MTConfig - ok
14:26:55.0134 0x063c  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup             C:\Windows\system32\Drivers\mup.sys
14:26:55.0134 0x063c  Mup - ok
14:26:55.0150 0x063c  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
14:26:55.0181 0x063c  napagent - ok
14:26:55.0212 0x063c  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
14:26:55.0212 0x063c  NativeWifiP - ok
14:26:55.0228 0x063c  NAVENG - ok
14:26:55.0228 0x063c  NAVEX15 - ok
14:26:55.0259 0x063c  [ F7309F42555F8AAB7144A51A1F2585B0, 065277A8AFAEE3888C997A76D2F751070F92DF4C3354D16B194860B4BDAFF937 ] NDIS            C:\Windows\system32\drivers\ndis.sys
14:26:55.0275 0x063c  NDIS - ok
14:26:55.0290 0x063c  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
14:26:55.0306 0x063c  NdisCap - ok
14:26:55.0321 0x063c  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
14:26:55.0337 0x063c  NdisTapi - ok
14:26:55.0337 0x063c  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
14:26:55.0353 0x063c  Ndisuio - ok
14:26:55.0368 0x063c  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
14:26:55.0399 0x063c  NdisWan - ok
14:26:55.0399 0x063c  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
14:26:55.0415 0x063c  NDProxy - ok
14:26:55.0446 0x063c  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
14:26:55.0462 0x063c  NetBIOS - ok
14:26:55.0493 0x063c  [ E47D571FEC2C76E867935109AB2A770C, F349D25890B6F476B106FD75BFB081DB737CA9B224D95E44927942FFF2DF82CD ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
14:26:55.0509 0x063c  NetBT - ok
14:26:55.0524 0x063c  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] Netlogon        C:\Windows\system32\lsass.exe
14:26:55.0524 0x063c  Netlogon - ok
14:26:55.0555 0x063c  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
14:26:55.0571 0x063c  Netman - ok
14:26:55.0618 0x063c  [ 15CBA881E10968E33B43D31BE6097BA3, 69449ACA82B67F308C9F7DAB7A4C75BD88A95B98FC7F9102C72AD3D233A48346 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:26:55.0633 0x063c  NetMsmqActivator - ok
14:26:55.0633 0x063c  [ 15CBA881E10968E33B43D31BE6097BA3, 69449ACA82B67F308C9F7DAB7A4C75BD88A95B98FC7F9102C72AD3D233A48346 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:26:55.0633 0x063c  NetPipeActivator - ok
14:26:55.0665 0x063c  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
14:26:55.0680 0x063c  netprofm - ok
14:26:55.0696 0x063c  [ 15CBA881E10968E33B43D31BE6097BA3, 69449ACA82B67F308C9F7DAB7A4C75BD88A95B98FC7F9102C72AD3D233A48346 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:26:55.0696 0x063c  NetTcpActivator - ok
14:26:55.0711 0x063c  [ 15CBA881E10968E33B43D31BE6097BA3, 69449ACA82B67F308C9F7DAB7A4C75BD88A95B98FC7F9102C72AD3D233A48346 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
14:26:55.0711 0x063c  NetTcpPortSharing - ok
14:26:55.0727 0x063c  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
14:26:55.0727 0x063c  nfrd960 - ok
14:26:55.0743 0x063c  [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc          C:\Windows\System32\nlasvc.dll
14:26:55.0758 0x063c  NlaSvc - ok
14:26:55.0774 0x063c  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
14:26:55.0789 0x063c  Npfs - ok
14:26:55.0805 0x063c  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi             C:\Windows\system32\nsisvc.dll
14:26:55.0821 0x063c  nsi - ok
14:26:55.0821 0x063c  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
14:26:55.0852 0x063c  nsiproxy - ok
14:26:55.0899 0x063c  [ 47B2D0B31BDC3EBE6090228E2BA3764D, 984A4B38300954164BCBF57EC1A09C18B53779E60A26E9618B50E26016735787 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
14:26:55.0930 0x063c  Ntfs - ok
14:26:55.0945 0x063c  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
14:26:55.0977 0x063c  Null - ok
14:26:55.0977 0x063c  [ 1F99AD85DC4F9E322CDE2363378CD374, 5E80D10FF0BC46ECF6F1F2294F35A0A7FD76E6F0B4534FD45C9AA8C57AE97F68 ] NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
14:26:55.0992 0x063c  NVHDA - ok
14:26:56.0273 0x063c  [ F1AD55BE455B70D8348C08EC891BA263, 0F8FDF483B227A8CCA844D2E2039754B800137C588B67B32AC50DA891A88D8E7 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
14:26:56.0460 0x063c  nvlddmkm - ok
14:26:56.0507 0x063c  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
14:26:56.0523 0x063c  nvraid - ok
14:26:56.0554 0x063c  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
14:26:56.0569 0x063c  nvstor - ok
14:26:56.0616 0x063c  [ 27F1E6074709F1BEFE011DDEA6A11373, E4DDA22519C77165E3E02599338CCF213B4A0A21C1EFF471A4C9BFBBCD6F3334 ] nvsvc           C:\Windows\system32\nvvsvc.exe
14:26:56.0632 0x063c  nvsvc - ok
14:26:56.0647 0x063c  [ C29547CB9B1ED535AE76384D888BB90C, 63E4F5AE16EC13486340F73A3613038A0363C37E48B4F099B4CBBD476226E4DB ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
14:26:56.0663 0x063c  nvvad_WaveExtensible - ok
14:26:56.0663 0x063c  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
14:26:56.0679 0x063c  nv_agp - ok
14:26:56.0694 0x063c  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
14:26:56.0710 0x063c  ohci1394 - ok
14:26:56.0725 0x063c  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
14:26:56.0725 0x063c  p2pimsvc - ok
14:26:56.0741 0x063c  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
14:26:56.0757 0x063c  p2psvc - ok
14:26:56.0772 0x063c  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
14:26:56.0772 0x063c  Parport - ok
14:26:56.0803 0x063c  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr         C:\Windows\system32\drivers\partmgr.sys
14:26:56.0803 0x063c  partmgr - ok
14:26:56.0835 0x063c  [ 3CD83692C43D87088E85E3C916146FFB, 9E812535E8FBA045FDA30F68E9EB2031132C37721D542A2DC9D4C33E2B137FCF ] PcaSvc          C:\Windows\System32\pcasvc.dll
14:26:56.0850 0x063c  PcaSvc - ok
14:26:56.0866 0x063c  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci             C:\Windows\system32\drivers\pci.sys
14:26:56.0866 0x063c  pci - ok
14:26:56.0897 0x063c  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
14:26:56.0897 0x063c  pciide - ok
14:26:56.0913 0x063c  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
14:26:56.0928 0x063c  pcmcia - ok
14:26:56.0928 0x063c  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw             C:\Windows\system32\drivers\pcw.sys
14:26:56.0944 0x063c  pcw - ok
14:26:56.0991 0x063c  [ EA4D67448BE493D543F1730D6CD04694, 24717C5E41B7CA522F3330EF2228B6685E710A5259396E9887A1C1E7A413F8CA ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
14:26:56.0991 0x063c  PEAUTH - ok
14:26:57.0037 0x063c  [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
14:26:57.0069 0x063c  PeerDistSvc - ok
14:26:57.0131 0x063c  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
14:26:57.0131 0x063c  PerfHost - ok
14:26:57.0162 0x063c  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla             C:\Windows\system32\pla.dll
14:26:57.0209 0x063c  pla - ok
14:26:57.0240 0x063c  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
14:26:57.0240 0x063c  PlugPlay - ok
14:26:57.0256 0x063c  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
14:26:57.0271 0x063c  PNRPAutoReg - ok
14:26:57.0287 0x063c  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
14:26:57.0303 0x063c  PNRPsvc - ok
14:26:57.0334 0x063c  [ 80D6B0563ED2BF10656B1D4748331082, B7E6B5E1148B7EE537E8D5C3A65450876B61CD45A395267D08699746E98AD574 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
14:26:57.0349 0x063c  PolicyAgent - ok
14:26:57.0365 0x063c  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power           C:\Windows\system32\umpo.dll
14:26:57.0381 0x063c  Power - ok
14:26:57.0396 0x063c  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
14:26:57.0412 0x063c  PptpMiniport - ok
14:26:57.0427 0x063c  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor       C:\Windows\system32\drivers\processr.sys
14:26:57.0427 0x063c  Processor - ok
14:26:57.0459 0x063c  [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc         C:\Windows\system32\profsvc.dll
14:26:57.0474 0x063c  ProfSvc - ok
14:26:57.0474 0x063c  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] ProtectedStorage C:\Windows\system32\lsass.exe
14:26:57.0490 0x063c  ProtectedStorage - ok
14:26:57.0505 0x063c  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
14:26:57.0521 0x063c  Psched - ok
14:26:57.0568 0x063c  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
14:26:57.0599 0x063c  ql2300 - ok
14:26:57.0615 0x063c  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
14:26:57.0615 0x063c  ql40xx - ok
14:26:57.0646 0x063c  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE           C:\Windows\system32\qwave.dll
14:26:57.0646 0x063c  QWAVE - ok
14:26:57.0661 0x063c  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
14:26:57.0677 0x063c  QWAVEdrv - ok
14:26:57.0677 0x063c  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
14:26:57.0693 0x063c  RasAcd - ok
14:26:57.0724 0x063c  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
14:26:57.0739 0x063c  RasAgileVpn - ok
14:26:57.0755 0x063c  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto         C:\Windows\System32\rasauto.dll
14:26:57.0771 0x063c  RasAuto - ok
14:26:57.0786 0x063c  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
14:26:57.0802 0x063c  Rasl2tp - ok
14:26:57.0817 0x063c  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
14:26:57.0849 0x063c  RasMan - ok
14:26:57.0849 0x063c  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
14:26:57.0864 0x063c  RasPppoe - ok
14:26:57.0880 0x063c  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
14:26:57.0895 0x063c  RasSstp - ok
14:26:57.0911 0x063c  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
14:26:57.0927 0x063c  rdbss - ok
14:26:57.0942 0x063c  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
14:26:57.0942 0x063c  rdpbus - ok
14:26:57.0958 0x063c  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
14:26:57.0973 0x063c  RDPCDD - ok
14:26:57.0989 0x063c  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
14:26:57.0989 0x063c  RDPDR - ok
14:26:58.0005 0x063c  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
14:26:58.0020 0x063c  RDPENCDD - ok
14:26:58.0036 0x063c  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
14:26:58.0051 0x063c  RDPREFMP - ok
14:26:58.0129 0x063c  [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
14:26:58.0145 0x063c  RdpVideoMiniport - ok
14:26:58.0161 0x063c  [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
14:26:58.0176 0x063c  RDPWD - ok
14:26:58.0192 0x063c  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
14:26:58.0192 0x063c  rdyboost - ok
14:26:58.0207 0x063c  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
14:26:58.0223 0x063c  RemoteAccess - ok
14:26:58.0239 0x063c  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
14:26:58.0270 0x063c  RemoteRegistry - ok
14:26:58.0270 0x063c  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
14:26:58.0301 0x063c  RpcEptMapper - ok
14:26:58.0317 0x063c  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
14:26:58.0317 0x063c  RpcLocator - ok
14:26:58.0363 0x063c  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] RpcSs           C:\Windows\system32\rpcss.dll
14:26:58.0363 0x063c  RpcSs - ok
14:26:58.0395 0x063c  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
14:26:58.0410 0x063c  rspndr - ok
14:26:58.0410 0x063c  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
14:26:58.0426 0x063c  s3cap - ok
14:26:58.0441 0x063c  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] SamSs           C:\Windows\system32\lsass.exe
14:26:58.0441 0x063c  SamSs - ok
14:26:58.0457 0x063c  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
14:26:58.0457 0x063c  sbp2port - ok
14:26:58.0473 0x063c  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
14:26:58.0488 0x063c  SCardSvr - ok
14:26:58.0504 0x063c  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
14:26:58.0519 0x063c  scfilter - ok
14:26:58.0551 0x063c  [ 40686B59C127F0C93B4234E4A1E3472A, B2DD61CB796C6AA8AFD285D43472B94646CA6D331D282818E0FDC9DE28DDE9CF ] Schedule        C:\Windows\system32\schedsvc.dll
14:26:58.0582 0x063c  Schedule - ok
14:26:58.0597 0x063c  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc     C:\Windows\System32\certprop.dll
14:26:58.0629 0x063c  SCPolicySvc - ok
14:26:58.0644 0x063c  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
14:26:58.0644 0x063c  SDRSVC - ok
14:26:58.0660 0x063c  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
14:26:58.0660 0x063c  secdrv - ok
14:26:58.0691 0x063c  [ A19623BDD61E66A12AB53992002B4F3A, E351CEEC086084A417BA3BD0EEF46114D3147EC38E3EF8BE49B724F9D028CC56 ] seclogon        C:\Windows\system32\seclogon.dll
14:26:58.0707 0x063c  seclogon - ok
14:26:58.0707 0x063c  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\System32\sens.dll
14:26:58.0738 0x063c  SENS - ok
14:26:58.0738 0x063c  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
14:26:58.0753 0x063c  SensrSvc - ok
14:26:58.0753 0x063c  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
14:26:58.0769 0x063c  Serenum - ok
14:26:58.0769 0x063c  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\DRIVERS\serial.sys
14:26:58.0769 0x063c  Serial - ok
14:26:58.0785 0x063c  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\drivers\sermouse.sys
14:26:58.0800 0x063c  sermouse - ok
14:26:58.0816 0x063c  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
14:26:58.0831 0x063c  SessionEnv - ok
14:26:58.0831 0x063c  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
14:26:58.0847 0x063c  sffdisk - ok
14:26:58.0847 0x063c  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
14:26:58.0847 0x063c  sffp_mmc - ok
14:26:58.0863 0x063c  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
14:26:58.0863 0x063c  sffp_sd - ok
14:26:58.0863 0x063c  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
14:26:58.0878 0x063c  sfloppy - ok
14:26:58.0894 0x063c  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
14:26:58.0909 0x063c  SharedAccess - ok
14:26:58.0925 0x063c  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:26:58.0956 0x063c  ShellHWDetection - ok
14:26:58.0972 0x063c  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
14:26:58.0972 0x063c  SiSRaid2 - ok
14:26:58.0987 0x063c  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
14:26:58.0987 0x063c  SiSRaid4 - ok
14:26:59.0034 0x063c  [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate     C:\Program Files (x86)\Skype\Updater\Updater.exe
14:26:59.0034 0x063c  SkypeUpdate - ok
14:26:59.0050 0x063c  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
14:26:59.0065 0x063c  Smb - ok
14:26:59.0081 0x063c  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
14:26:59.0097 0x063c  SNMPTRAP - ok
14:26:59.0097 0x063c  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr           C:\Windows\system32\drivers\spldr.sys
14:26:59.0097 0x063c  spldr - ok
14:26:59.0128 0x063c  [ B96C17B5DC1424D56EEA3A99E97428CD, AF0A85066A7983878DC1C663811CE61C6CA1912DC956184F878B7B82DB93C651 ] Spooler         C:\Windows\System32\spoolsv.exe
14:26:59.0143 0x063c  Spooler - ok
14:26:59.0221 0x063c  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
14:26:59.0284 0x063c  sppsvc - ok
14:26:59.0299 0x063c  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
14:26:59.0315 0x063c  sppuinotify - ok
14:26:59.0346 0x063c  [ EC666682FE8344CF7E6ED69E74FA9F4F, DCD2A1C046425630689E2C9A6A6E356FE5A2A6664D12C20CFE236FCB32240DF9 ] srv             C:\Windows\system32\DRIVERS\srv.sys
14:26:59.0362 0x063c  srv - ok
14:26:59.0377 0x063c  [ E450C0318DCE8ED28ED272C8806B8495, D2FD459F8C5E42103EF2F71421FA175A4F0821F8C2A3763093122D433D1C50FB ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
14:26:59.0393 0x063c  srv2 - ok
14:26:59.0424 0x063c  [ 9C12C78AD36C23D925711A4640228225, FF72C23F2A08EDF0C41BAF1EB0245AB44FF91365C5466F09C47A8F0928D20994 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
14:26:59.0424 0x063c  srvnet - ok
14:26:59.0440 0x063c  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
14:26:59.0455 0x063c  SSDPSRV - ok
14:26:59.0471 0x063c  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc         C:\Windows\system32\sstpsvc.dll
14:26:59.0487 0x063c  SstpSvc - ok
14:26:59.0533 0x063c  [ 90E22D7CDE08E07446D238A569BCAB7C, 3D4F413D0B0C9CF28D06E0476F24AC6441C8678DF786D9971B39C91C9F9B8020 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
14:26:59.0565 0x063c  Steam Client Service - ok
14:26:59.0596 0x063c  [ E1AAD79D0C59C157258845C998715575, AF08F3DE709045E8E5B5EAC7D05F307C92AA031753CFE9ABB9A5A3B37FE392BA ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
14:26:59.0596 0x063c  Stereo Service - ok
14:26:59.0611 0x063c  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
14:26:59.0627 0x063c  stexstor - ok
14:26:59.0643 0x063c  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\Windows\System32\wiaservc.dll
14:26:59.0674 0x063c  stisvc - ok
14:26:59.0689 0x063c  [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
14:26:59.0689 0x063c  storflt - ok
14:26:59.0705 0x063c  [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc         C:\Windows\system32\storsvc.dll
14:26:59.0721 0x063c  StorSvc - ok
14:26:59.0736 0x063c  [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc         C:\Windows\system32\drivers\storvsc.sys
14:26:59.0736 0x063c  storvsc - ok
14:26:59.0752 0x063c  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
14:26:59.0752 0x063c  swenum - ok
14:26:59.0783 0x063c  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv           C:\Windows\System32\swprv.dll
14:26:59.0799 0x063c  swprv - ok
14:26:59.0845 0x063c  [ 2E730941CC5BF6200A4F56D1E9C24AAD, 758836D55DC84F3EBE9917DC6FAB8E6170A5B238FEDBCFDB6D7C5C6EA98E08B2 ] SysMain         C:\Windows\system32\sysmain.dll
14:26:59.0877 0x063c  SysMain - ok
14:26:59.0892 0x063c  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
14:26:59.0908 0x063c  TabletInputService - ok
14:26:59.0923 0x063c  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv         C:\Windows\System32\tapisrv.dll
14:26:59.0939 0x063c  TapiSrv - ok
14:26:59.0986 0x063c  [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
14:27:00.0017 0x063c  Tcpip - ok
14:27:00.0064 0x063c  [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
14:27:00.0111 0x063c  TCPIP6 - ok
14:27:00.0126 0x063c  [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
14:27:00.0126 0x063c  tcpipreg - ok
14:27:00.0142 0x063c  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
14:27:00.0157 0x063c  TDPIPE - ok
14:27:00.0173 0x063c  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
14:27:00.0173 0x063c  TDTCP - ok
14:27:00.0204 0x063c  [ AA77EB517D2F07A947294F260E3ACA83, B7A5DF3066830C0C2302B059778A67419792058A0D300C471DE40AB245EA7E58 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
14:27:00.0204 0x063c  tdx - ok
14:27:00.0220 0x063c  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
14:27:00.0220 0x063c  TermDD - ok
14:27:00.0251 0x063c  [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService     C:\Windows\System32\termsrv.dll
14:27:00.0267 0x063c  TermService - ok
14:27:00.0282 0x063c  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
14:27:00.0298 0x063c  Themes - ok
14:27:00.0298 0x063c  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER     C:\Windows\system32\mmcss.dll
14:27:00.0313 0x063c  THREADORDER - ok
14:27:00.0329 0x063c  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
14:27:00.0345 0x063c  TrkWks - ok
14:27:00.0391 0x063c  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:27:00.0407 0x063c  TrustedInstaller - ok
14:27:00.0438 0x063c  [ 19BEDA57F3E0A06B8D5EB6D619BD5624, 952D5FAFD662C93628C12A6F7EB8E240A44216C0A15CBD2F5016BC357CBFE821 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
14:27:00.0438 0x063c  tssecsrv - ok
14:27:00.0454 0x063c  [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
14:27:00.0469 0x063c  TsUsbFlt - ok
14:27:00.0501 0x063c  [ AD64450A4ABE076F5CB34CC08EEACB07, B5C386635441A19178E7FEEE299BA430C8D72F9110866C13A216B12A1080AD12 ] TsUsbGD         C:\Windows\system32\drivers\TsUsbGD.sys
14:27:00.0501 0x063c  TsUsbGD - ok
14:27:00.0516 0x063c  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
14:27:00.0547 0x063c  tunnel - ok
14:27:00.0563 0x063c  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
14:27:00.0563 0x063c  uagp35 - ok
14:27:00.0579 0x063c  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
14:27:00.0610 0x063c  udfs - ok
14:27:00.0610 0x063c  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect       C:\Windows\system32\UI0Detect.exe
14:27:00.0625 0x063c  UI0Detect - ok
14:27:00.0625 0x063c  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
14:27:00.0625 0x063c  uliagpkx - ok
14:27:00.0657 0x063c  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
14:27:00.0657 0x063c  umbus - ok
14:27:00.0672 0x063c  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\drivers\umpass.sys
14:27:00.0672 0x063c  UmPass - ok
14:27:00.0703 0x063c  [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService    C:\Windows\System32\umrdp.dll
14:27:00.0703 0x063c  UmRdpService - ok
14:27:00.0719 0x063c  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
14:27:00.0750 0x063c  upnphost - ok
14:27:00.0766 0x063c  [ DCA68B0943D6FA415F0C56C92158A83A, BEE5A5B33B22D1DF50B884D46D89FC3B8286EB16E38AD5A20F0A49E5C6766C57 ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
14:27:00.0781 0x063c  usbccgp - ok
14:27:00.0813 0x063c  [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir          C:\Windows\system32\drivers\usbcir.sys
14:27:00.0813 0x063c  usbcir - ok
14:27:00.0828 0x063c  [ 74EE782B1D9C241EFE425565854C661C, E8258EA65B0FCAD4E077B176E9D9324646B652D6E651241E397346A39770D065 ] usbehci         C:\Windows\system32\drivers\usbehci.sys
14:27:00.0828 0x063c  usbehci - ok
14:27:00.0844 0x063c  [ 8D1196CFBB223621F2C67D45710F25BA, B5D7AFE51833B24FC9576F3AED3D8A2B290E5846060E73F9FFFAC1890A8B6003 ] usbhub          C:\Windows\system32\drivers\usbhub.sys
14:27:00.0859 0x063c  usbhub - ok
14:27:00.0859 0x063c  [ 58E546BBAF87664FC57E0F6081E4F609, 1DD99D57369A0069654432AB5325AFD8F7D422D531E053EA05FF664BA6BDAEF9 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
14:27:00.0875 0x063c  usbohci - ok
14:27:00.0875 0x063c  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\drivers\usbprint.sys
14:27:00.0875 0x063c  usbprint - ok
14:27:00.0891 0x063c  [ D029DD09E22EB24318A8FC3D8138BA43, C95805E8BF75ECB939520AE86420B16467B0771C161C51C9F1A37649ADFADCD0 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:27:00.0891 0x063c  USBSTOR - ok
14:27:00.0906 0x063c  [ 81FB2216D3A60D1284455D511797DB3D, 121E52B18A1832E775EA0AE2E053BAA53E5A70E9754724B1449AE5992D63B13E ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
14:27:00.0906 0x063c  usbuhci - ok
14:27:00.0922 0x063c  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms           C:\Windows\System32\uxsms.dll
14:27:00.0937 0x063c  UxSms - ok
14:27:00.0953 0x063c  [ 92DAF7D21711117B007608CB50FBD2E2, 6C1FBCE3699C76BDACAC37C04002C85A6AF38BF610F579F6FFEC95302D449CDC ] VaultSvc        C:\Windows\system32\lsass.exe
14:27:00.0969 0x063c  VaultSvc - ok
14:27:00.0984 0x063c  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
14:27:00.0984 0x063c  vdrvroot - ok
14:27:01.0000 0x063c  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds             C:\Windows\System32\vds.exe
14:27:01.0031 0x063c  vds - ok
14:27:01.0047 0x063c  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
14:27:01.0062 0x063c  vga - ok
14:27:01.0062 0x063c  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave         C:\Windows\System32\drivers\vga.sys
14:27:01.0078 0x063c  VgaSave - ok
14:27:01.0093 0x063c  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
14:27:01.0109 0x063c  vhdmp - ok
14:27:01.0140 0x063c  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\drivers\viaide.sys
14:27:01.0156 0x063c  viaide - ok
14:27:01.0171 0x063c  [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus           C:\Windows\system32\drivers\vmbus.sys
14:27:01.0171 0x063c  vmbus - ok
14:27:01.0187 0x063c  [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
14:27:01.0187 0x063c  VMBusHID - ok
14:27:01.0203 0x063c  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
14:27:01.0218 0x063c  volmgr - ok
14:27:01.0234 0x063c  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
14:27:01.0249 0x063c  volmgrx - ok
14:27:01.0249 0x063c  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap         C:\Windows\system32\drivers\volsnap.sys
14:27:01.0265 0x063c  volsnap - ok
14:27:01.0281 0x063c  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
14:27:01.0281 0x063c  vsmraid - ok
14:27:01.0327 0x063c  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS             C:\Windows\system32\vssvc.exe
14:27:01.0374 0x063c  VSS - ok
14:27:01.0390 0x063c  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
14:27:01.0390 0x063c  vwifibus - ok
14:27:01.0421 0x063c  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time         C:\Windows\system32\w32time.dll
14:27:01.0437 0x063c  W32Time - ok
14:27:01.0452 0x063c  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
14:27:01.0452 0x063c  WacomPen - ok
14:27:01.0468 0x063c  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
14:27:01.0483 0x063c  WANARP - ok
14:27:01.0499 0x063c  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
14:27:01.0515 0x063c  Wanarpv6 - ok
14:27:01.0530 0x063c  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\Windows\system32\wbengine.exe
14:27:01.0561 0x063c  wbengine - ok
14:27:01.0577 0x063c  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
14:27:01.0593 0x063c  WbioSrvc - ok
14:27:01.0593 0x063c  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
14:27:01.0608 0x063c  wcncsvc - ok
14:27:01.0624 0x063c  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:27:01.0624 0x063c  WcsPlugInService - ok
14:27:01.0639 0x063c  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\drivers\wd.sys
14:27:01.0639 0x063c  Wd - ok
14:27:01.0671 0x063c  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
14:27:01.0686 0x063c  Wdf01000 - ok
14:27:01.0702 0x063c  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost  C:\Windows\system32\wdi.dll
14:27:01.0702 0x063c  WdiServiceHost - ok
14:27:01.0717 0x063c  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost   C:\Windows\system32\wdi.dll
14:27:01.0717 0x063c  WdiSystemHost - ok
14:27:01.0764 0x063c  [ EE841B6D1F2B9508D3ABAE52AC05A94F, F1AE981FCDBFC4672A4EABABD41382E93762EFC2EDAD96E75530E7ACA5AF1FD8 ] WebClient       C:\Windows\System32\webclnt.dll
14:27:01.0780 0x063c  WebClient - ok
14:27:01.0780 0x063c  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\Windows\system32\wecsvc.dll
14:27:01.0811 0x063c  Wecsvc - ok
14:27:01.0811 0x063c  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
14:27:01.0842 0x063c  wercplsupport - ok
14:27:01.0842 0x063c  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
14:27:01.0858 0x063c  WerSvc - ok
14:27:01.0873 0x063c  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
14:27:01.0889 0x063c  WfpLwf - ok
14:27:01.0889 0x063c  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
14:27:01.0889 0x063c  WIMMount - ok
14:27:01.0905 0x063c  WinDefend - ok
14:27:01.0905 0x063c  WinHttpAutoProxySvc - ok
14:27:01.0967 0x063c  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
14:27:01.0983 0x063c  Winmgmt - ok
14:27:02.0045 0x063c  [ EBDA1B0F15CB9B2CBCC6C94824E4E054, C51314F7D611E4903DA00EFA8EB99365414436324D256083CE0B5A8E055E8E06 ] WinRM           C:\Windows\system32\WsmSvc.dll
14:27:02.0076 0x063c  WinRM - ok
14:27:02.0107 0x063c  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
14:27:02.0107 0x063c  WinUsb - ok
14:27:02.0139 0x063c  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc         C:\Windows\System32\wlansvc.dll
14:27:02.0154 0x063c  Wlansvc - ok
14:27:02.0170 0x063c  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
14:27:02.0170 0x063c  WmiAcpi - ok
14:27:02.0185 0x063c  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
14:27:02.0185 0x063c  wmiApSrv - ok
14:27:02.0201 0x063c  WMPNetworkSvc - ok
14:27:02.0217 0x063c  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
14:27:02.0232 0x063c  WPCSvc - ok
14:27:02.0248 0x063c  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
14:27:02.0248 0x063c  WPDBusEnum - ok
14:27:02.0263 0x063c  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
14:27:02.0279 0x063c  ws2ifsl - ok
14:27:02.0279 0x063c  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\System32\wscsvc.dll
14:27:02.0295 0x063c  wscsvc - ok
14:27:02.0295 0x063c  WSearch - ok
14:27:02.0357 0x063c  [ 31F32E0C1A8BA9A37EEC23DE5F27F847, 0180832BC6172C9A4C32B5B222BB3F91EA615A5EBDA98DB79ED4FED258C2D257 ] wuauserv        C:\Windows\system32\wuaueng.dll
14:27:02.0404 0x063c  wuauserv - ok
14:27:02.0435 0x063c  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
14:27:02.0435 0x063c  WudfPf - ok
14:27:02.0466 0x063c  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
14:27:02.0466 0x063c  WUDFRd - ok
14:27:02.0497 0x063c  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
14:27:02.0497 0x063c  wudfsvc - ok
14:27:02.0529 0x063c  [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc         C:\Windows\System32\wwansvc.dll
14:27:02.0544 0x063c  WwanSvc - ok
14:27:02.0560 0x063c  ================ Scan global ===============================
14:27:02.0575 0x063c  [ 168EA9CD9BD6056BB6F60B57D5304BBE, 5A2F98754F042A7D80E7483842967EB362F01D57CE9720B24C7EDAA047F24C6F ] C:\Windows\system32\basesrv.dll
14:27:02.0591 0x063c  [ A5794B1E3ACEF48E716F0A89C83C1AEA, B904C861CBDAF00341F8697BD05C2E66C23CF4D6C94E19AF464D898436F34D73 ] C:\Windows\system32\winsrv.dll
14:27:02.0607 0x063c  [ A5794B1E3ACEF48E716F0A89C83C1AEA, B904C861CBDAF00341F8697BD05C2E66C23CF4D6C94E19AF464D898436F34D73 ] C:\Windows\system32\winsrv.dll
14:27:02.0622 0x063c  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
14:27:02.0653 0x063c  [ 71C85477DF9347FE8E7BC55768473FCA, A86D6A6D1F5A0EFCD649792A06F3AE9B37158D48493D2ECA7F52DCC1CB9B6536 ] C:\Windows\system32\services.exe
14:27:02.0653 0x063c  [ Global ] - ok
14:27:02.0653 0x063c  ================ Scan MBR ==================================
14:27:02.0669 0x063c  [ EA923EB0EC0060F1451E9AD7B5762CFE ] \Device\Harddisk0\DR0
14:27:02.0778 0x063c  \Device\Harddisk0\DR0 - ok
14:27:02.0778 0x063c  ================ Scan VBR ==================================
14:27:02.0778 0x063c  [ 554243D2ABA7A16AC01FE5C4DE5EB9E0 ] \Device\Harddisk0\DR0\Partition1
14:27:02.0778 0x063c  \Device\Harddisk0\DR0\Partition1 - ok
14:27:02.0778 0x063c  [ 2ABC120A69E42FE6BBE9FA62C2CEF16F ] \Device\Harddisk0\DR0\Partition2
14:27:02.0778 0x063c  \Device\Harddisk0\DR0\Partition2 - ok
14:27:02.0778 0x063c  ================ Scan generic autorun ======================
14:27:02.0887 0x063c  [ BAEDADCD6509201F82CE5B404AB14814, 8C39C18CE00DB254F370D9C4AA80E88BF67C457240F3D30A58E39DBF9B96F44B ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
14:27:02.0887 0x063c  IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
14:27:02.0887 0x063c  Detect skipped due to KSN trusted
14:27:02.0887 0x063c  IAStorIcon - ok
14:27:03.0059 0x063c  [ 890C5393F1E7775A38FA73DC554A379E, 16A01ABF2E6C070156E0A92642496F33BE9A5A923B41FD538C532A52B92E74C4 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
14:27:03.0184 0x063c  RTHDVCPL - ok
14:27:03.0293 0x063c  [ 948EB9C552C05DF39F79587E6979D9F5, 402B155395C32005A8D78C8B0F00F2391542CB41188AF944FF17ADE6BE97A62D ] C:\Program Files\Logitech\SetPointP\SetPoint.exe
14:27:03.0340 0x063c  EvtMgr6 - ok
14:27:03.0402 0x063c  [ 80086ED442941DE2CA18CB6DAE8C1422, F7BE958F2E8E17970C238E3806F4A742B12DA09EB21093BD6371CF4B580C5BE4 ] C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
14:27:03.0433 0x063c  Aeria Ignite - ok
14:27:03.0480 0x063c  [ 5153C06FC9D4D094D1A785545928B134, 0037C935722663F9EF028F841DE222FC6418E9D60939AB60C965807E67A458DC ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
14:27:03.0480 0x063c  SunJavaUpdateSched - ok
14:27:03.0543 0x063c  [ CB46168FFDEA91E2B3435E51BB436558, 848D12E11B79722B07C42D848D831C6B782E1338B8F844924CB8938FE11F379D ] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
14:27:03.0558 0x063c  USB3MON - ok
14:27:03.0605 0x063c  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
14:27:03.0621 0x063c  Sidebar - ok
14:27:03.0652 0x063c  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
14:27:03.0667 0x063c  mctadmin - ok
14:27:03.0699 0x063c  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
14:27:03.0714 0x063c  Sidebar - ok
14:27:03.0714 0x063c  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
14:27:03.0730 0x063c  mctadmin - ok
14:27:03.0886 0x063c  [ F2AD1B265908797F8A5E21E0312F2F25, 2A6A612F7D52D297385C43E77AD0CD37B28F33ED2AF89098F5E66B812B838A52 ] C:\Users\kevin\AppData\Local\Akamai\netsession_win.exe
14:27:03.0948 0x063c  Akamai NetSession Interface - ok
14:27:03.0995 0x063c  [ 44A9229022A519ED45294A1934C05EEC, 6DEF0DB5F9B50E9B0AFEE1CF50066BEB4FB7E15E2DC829A499509925660D6992 ] C:\Users\kevin\AppData\Local\FluxSoftware\Flux\flux.exe
14:27:04.0011 0x063c  f.lux - ok
14:27:04.0026 0x063c  Win FW state via NFP2: enabled ( trusted )
14:27:04.0135 0x063c  ============================================================
14:27:04.0135 0x063c  Scan finished
14:27:04.0135 0x063c  ============================================================
14:27:04.0135 0x10a8  Detected object count: 1
14:27:04.0135 0x10a8  Actual detected object count: 1
14:27:11.0717 0x10a8  HiPatchService ( UnsignedFile.Multi.Generic ) - skipped by user
14:27:11.0717 0x10a8  HiPatchService ( UnsignedFile.Multi.Generic ) - User select action: Skip
         
Aktueller MBAR Log
Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2016.11.12.05
  rootkit: v2016.10.31.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18524
kevin :: PC1-KK [administrator]

12.11.2016 14:30:23
mbar-log-2016-11-12 (14-30-23).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 325274
Time elapsed: 12 minute(s), 20 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         

Alt 12.11.2016, 15:50   #9
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Adware/Junkware/Toolbars entfernen

Alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!
Virenscanner jetzt vor dem Einsatz dieser Tools bitte komplett deaktivieren!


1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 12.11.2016, 15:59   #10
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



JRT.txt
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 7 Professional x64 
Ran by kevin (Administrator) on 12.11.2016 at 14:54:34,23
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 56 

Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NGIHFQ3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NEBBSER (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\427XDYKT (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5TUE5JA8 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\671QMR3Y (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J957HZD (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7O1F2AF9 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\COBO4YGZ (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CVMGU1FJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DGF305X9 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HB75UAFI (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I54NL9I0 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J8YK8556 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KL661KZU (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N3IIWY10 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NITY6P92 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P35W4YAI (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PGCMVT5E (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V0BGTKM1 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VW7G7BDM (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDD15LQ3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y4EVD1ZA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZE4GUSRG (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZXJFPNQW (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NGIHFQ3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NEBBSER (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\427XDYKT (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5TUE5JA8 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\671QMR3Y (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J957HZD (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7O1F2AF9 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\COBO4YGZ (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CVMGU1FJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DGF305X9 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HB75UAFI (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I54NL9I0 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J8YK8556 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KL661KZU (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N3IIWY10 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NITY6P92 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P35W4YAI (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PGCMVT5E (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V0BGTKM1 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VW7G7BDM (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WDD15LQ3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y4EVD1ZA (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZE4GUSRG (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZXJFPNQW (Temporary Internet Files Folder) 

Deleted the following from C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\prefs.js
user_pref(browser.urlbar.suggest.searches, true);



Registry: 0 





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.11.2016 at 14:56:15,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
Adwcleaner log
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v6.030 - Bericht erstellt am 12/11/2016 um 14:58:55
# Aktualisiert am 19/10/2016 von Malwarebytes
# Datenbank : 2016-11-12.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (X64)
# Benutzername : kevin - PC1-KK
# Gestartet von : C:\Users\kevin\Desktop\AV\adwcleaner_6.030.exe
# Modus: Suchlauf
# Unterstützung : https://www.malwarebytes.com/support



***** [ Dienste ] *****

Keine schädlichen Dienste gefunden.


***** [ Ordner ] *****

Keine schädlichen Ordner gefunden.


***** [ Dateien ] *****

Keine schädlichen Dateien gefunden.


***** [ DLL ] *****

Keine infizierten DLLs gefunden.


***** [ WMI ] *****

Keine schädlichen Schlüssel gefunden.


***** [ Verknüpfungen ] *****

Keine infizierten Verknüpfungen gefunden.


***** [ Aufgabenplanung ] *****

Keine schädlichen Aufgaben gefunden.


***** [ Registrierungsdatenbank ] *****

Keine schädlichen Elemente in der Registrierungsdatenbank gefunden.


***** [ Internetbrowser ] *****

Keine schädlichen Elemente in Firefox basierten Browsern gefunden.
Keine schädlichen Elemente in Chrome basierten Browsern gefunden.

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1554 Bytes] - [09/07/2016 12:43:50]
C:\AdwCleaner\AdwCleaner[C2].txt - [2809 Bytes] - [26/08/2016 19:07:46]
C:\AdwCleaner\AdwCleaner[C3].txt - [2808 Bytes] - [31/08/2016 23:29:18]
C:\AdwCleaner\AdwCleaner[C4].txt - [2952 Bytes] - [24/09/2016 12:37:05]
C:\AdwCleaner\AdwCleaner[C5].txt - [3597 Bytes] - [12/11/2016 11:51:24]
C:\AdwCleaner\AdwCleaner[S10].txt - [1580 Bytes] - [15/07/2016 17:28:00]
C:\AdwCleaner\AdwCleaner[S11].txt - [1654 Bytes] - [16/07/2016 11:43:31]
C:\AdwCleaner\AdwCleaner[S12].txt - [1728 Bytes] - [18/07/2016 15:15:28]
C:\AdwCleaner\AdwCleaner[S13].txt - [1802 Bytes] - [19/07/2016 20:11:20]
C:\AdwCleaner\AdwCleaner[S14].txt - [1877 Bytes] - [22/07/2016 20:34:47]
C:\AdwCleaner\AdwCleaner[S15].txt - [1951 Bytes] - [23/07/2016 14:40:45]
C:\AdwCleaner\AdwCleaner[S16].txt - [2025 Bytes] - [26/07/2016 16:16:04]
C:\AdwCleaner\AdwCleaner[S17].txt - [2099 Bytes] - [28/07/2016 18:21:44]
C:\AdwCleaner\AdwCleaner[S18].txt - [2173 Bytes] - [31/07/2016 11:28:03]
C:\AdwCleaner\AdwCleaner[S19].txt - [2604 Bytes] - [26/08/2016 09:16:58]
C:\AdwCleaner\AdwCleaner[S1].txt - [1123 Bytes] - [09/07/2016 12:20:56]
C:\AdwCleaner\AdwCleaner[S20].txt - [3037 Bytes] - [26/08/2016 19:07:03]
C:\AdwCleaner\AdwCleaner[S21].txt - [3020 Bytes] - [31/08/2016 23:28:34]
C:\AdwCleaner\AdwCleaner[S22].txt - [3111 Bytes] - [01/09/2016 12:12:11]
C:\AdwCleaner\AdwCleaner[S23].txt - [3185 Bytes] - [15/09/2016 14:31:05]
C:\AdwCleaner\AdwCleaner[S24].txt - [3259 Bytes] - [24/09/2016 12:36:43]
C:\AdwCleaner\AdwCleaner[S25].txt - [3406 Bytes] - [16/10/2016 16:33:08]
C:\AdwCleaner\AdwCleaner[S26].txt - [3481 Bytes] - [17/10/2016 15:29:58]
C:\AdwCleaner\AdwCleaner[S27].txt - [3555 Bytes] - [18/10/2016 12:36:30]
C:\AdwCleaner\AdwCleaner[S28].txt - [3629 Bytes] - [19/10/2016 12:38:37]
C:\AdwCleaner\AdwCleaner[S29].txt - [3716 Bytes] - [22/10/2016 17:19:28]
C:\AdwCleaner\AdwCleaner[S2].txt - [994 Bytes] - [10/07/2016 15:03:58]
C:\AdwCleaner\AdwCleaner[S30].txt - [3827 Bytes] - [12/11/2016 11:51:11]
C:\AdwCleaner\AdwCleaner[S31].txt - [3273 Bytes] - [12/11/2016 14:58:55]
C:\AdwCleaner\AdwCleaner[S3].txt - [1066 Bytes] - [12/07/2016 12:26:47]
C:\AdwCleaner\AdwCleaner[S4].txt - [1140 Bytes] - [12/07/2016 14:14:32]
C:\AdwCleaner\AdwCleaner[S5].txt - [1214 Bytes] - [12/07/2016 19:14:50]
C:\AdwCleaner\AdwCleaner[S6].txt - [1287 Bytes] - [12/07/2016 20:29:30]
C:\AdwCleaner\AdwCleaner[S7].txt - [1360 Bytes] - [13/07/2016 13:02:19]
C:\AdwCleaner\AdwCleaner[S8].txt - [1433 Bytes] - [13/07/2016 15:14:52]
C:\AdwCleaner\AdwCleaner[S9].txt - [1506 Bytes] - [13/07/2016 19:51:49]

########## EOF - C:\AdwCleaner\AdwCleaner[S31].txt - [3858 Bytes] ##########
         
--- --- ---

Alt 12.11.2016, 16:04   #11
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Untersuchen klicken

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 12.11.2016, 20:35   #12
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Davor eine kurze Frage: Was ist mit den Verbindungen über Firefox? Wurde da was gefunden? Ich kenn mich da nicht aus :/
FRST
[code]
k
FRST Logfile:
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2016
durchgeführt von kevin (Administrator) auf PC1-KK (12-11-2016 15:04:47)
Gestartet von C:\Users\kevin\Desktop\AV
Geladene Profile: kevin (Verfügbare Profile: kevin & Kev)
Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-07-07] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-06-15] (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\Run: [Akamai NetSession Interface] => C:\Users\kevin\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\Run: [f.lux] => C:\Users\kevin\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\MountPoints2: {7e80f4c7-1c51-11e6-973a-806e6f6e6963} - D:\Run.exe
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [241664 2010-11-21] (Microsoft Corporation)

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{C2BCC291-8679-4E20-A2C8-5A503ED1A8F1}: [DhcpNameServer] 192.168.0.254

Internet Explorer:
==================
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE12&ocid=UE12DHP
HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?pc=UE12&ocid=UE12DHP
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-10-22] (Oracle Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-22] (Oracle Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
Toolbar: HKU\S-1-5-21-3869536936-4182528847-1821436484-1001 -> Kein Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  Keine Datei
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1463598850208

FireFox:
========
FF DefaultProfile: b8wlbzof.default
FF ProfilePath: C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default [2016-11-12]
FF NetworkProxy: Mozilla\Firefox\Profiles\b8wlbzof.default -> http", "209.150.253.84"
FF NetworkProxy: Mozilla\Firefox\Profiles\b8wlbzof.default -> http_port", 80
FF NetworkProxy: Mozilla\Firefox\Profiles\b8wlbzof.default -> type", 0
FF Extension: (Ghostery) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\firefox@ghostery.com.xpi [2016-10-22]
FF Extension: (HTTPS Everywhere) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\https-everywhere@eff.org.xpi [2016-11-10]
FF Extension: (uBlock Origin) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\uBlock0@raymondhill.net.xpi [2016-10-25]
FF Extension: (NoScript) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-08-09]
FF Extension: (Video DownloadHelper) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-10-11]
FF Extension: (DownThemAll!) - C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\b8wlbzof.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-09-29]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-06-11] [ist nicht signiert]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-09] ()
FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-10-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-10-22] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-09] ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-03] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-03] (NVIDIA Corporation)

==================== Dienste (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S3 ACTION_SVC; C:\Program Files (x86)\Mirillis\Action!\action_svc.exe [16064 2014-10-25] ()
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-10-10] (Hi-Rez Studios) [Datei ist nicht signiert]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Treiber (Nicht auf der Ausnahmeliste) ======================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [501216 2015-06-18] (Intel Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2015-06-23] (Intel Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-09-02] (NVIDIA Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20160731.001\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20160731.001\EX64.SYS [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-11-12 14:56 - 2016-11-12 14:56 - 00009902 ____C C:\Users\kevin\Desktop\JRT.txt
2016-11-12 14:54 - 2016-11-12 14:54 - 01631928 ____C (Malwarebytes) C:\Users\kevin\Downloads\JRT.exe
2016-11-12 14:25 - 2016-11-12 14:30 - 00382668 ____C C:\TDSSKiller.3.1.0.12_12.11.2016_14.25.25_log.txt
2016-11-12 14:25 - 2016-11-12 14:25 - 04747704 ____C (AO Kaspersky Lab) C:\Users\kevin\Downloads\tdsskiller.exe
2016-11-11 17:52 - 2016-11-11 17:54 - 100250535 ____C C:\Users\kevin\Downloads\1-10 sauce.zip
2016-11-10 21:38 - 2016-11-10 21:38 - 02390376 ____C C:\Users\kevin\Downloads\datsauce_mpgh.net.zip
2016-11-10 21:38 - 2016-11-10 21:38 - 00000000 ___DC C:\Users\kevin\Downloads\datsauce_mpgh.net
2016-11-10 16:18 - 2016-11-10 16:19 - 25763328 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 20304896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 15257088 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 03649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 03219456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 02920448 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02896384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-11-10 16:18 - 2016-11-10 16:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-11-10 16:18 - 2016-11-10 16:19 - 02444800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02287616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-11-10 16:18 - 2016-11-10 16:19 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-11-10 16:18 - 2016-11-10 16:19 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01543680 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01462272 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2016-11-10 16:18 - 2016-11-10 16:19 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2016-11-10 16:18 - 2016-11-10 16:19 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2016-11-10 16:18 - 2016-11-10 16:19 - 00877056 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-11-10 16:18 - 2016-11-10 16:19 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2016-11-10 16:18 - 2016-11-10 16:19 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-11-10 16:18 - 2016-11-10 16:19 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-11-10 16:18 - 2016-11-10 16:19 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00394440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-11-10 16:18 - 2016-11-10 16:19 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2016-11-10 16:18 - 2016-11-10 16:19 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-11-10 16:18 - 2016-11-10 16:19 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-11-10 16:18 - 2016-11-10 16:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-11-10 16:18 - 2016-11-10 16:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-11-09 16:35 - 2016-11-09 16:35 - 12063071 ____C C:\Users\kevin\Downloads\nxwuag.zip
2016-11-09 16:35 - 2016-11-09 16:35 - 00000000 ___DC C:\Users\kevin\Downloads\nxwuag
2016-11-09 16:32 - 2016-11-09 16:32 - 00000000 ___DC C:\Users\kevin\Downloads\GCSRC
2016-11-09 16:31 - 2016-11-09 16:32 - 05206771 ____C C:\Users\kevin\Downloads\GCSRC.zip
2016-11-09 13:55 - 2016-11-09 13:55 - 00000000 ___DC C:\Users\kevin\AppData\Local\Targem
2016-11-09 12:08 - 2016-11-09 12:09 - 00000222 ____C C:\Users\kevin\Desktop\Star Conflict.url
2016-11-04 21:14 - 2016-11-04 21:15 - 63235648 ____C (Oracle Corporation) C:\Users\kevin\Downloads\jre-8u111-windows-x64.exe
2016-11-04 21:09 - 2016-11-04 21:09 - 01257462 ____C C:\Users\kevin\Downloads\LabyMod_v2.7.9_mc1.8.8(2).jar
2016-11-04 21:08 - 2016-11-04 21:08 - 00737344 ____C (Oracle Corporation) C:\Users\kevin\Downloads\jxpiinstall.exe
2016-11-04 20:54 - 2016-11-04 20:54 - 02089120 ____C C:\Users\kevin\Downloads\wrar540d.exe
2016-11-03 17:19 - 2016-11-03 17:19 - 02793470 ____C C:\Users\kevin\Downloads\Nicht bestätigt 927193.crdownload
2016-11-02 16:21 - 2016-11-02 16:32 - 00658819 ____C C:\Users\kevin\Downloads\Optifine SRC Version [1.8.8 HD U E1](1).rar
2016-11-02 01:32 - 2016-11-02 01:32 - 00000055 ____C C:\Users\kevin\Desktop\file.json
2016-11-01 19:32 - 2016-11-01 19:43 - 00000000 ___DC C:\Users\kevin\Desktop\1.10 Modding
2016-11-01 19:32 - 2016-11-01 19:33 - 00243031 ____C C:\Users\kevin\Downloads\forge-1.10.2-12.18.2.2099-mdk.zip
2016-11-01 13:15 - 2016-11-01 13:15 - 04925893 ____C C:\Users\kevin\Downloads\Crafteryada v0.11.2.zip
2016-10-31 22:25 - 2016-10-31 22:25 - 06449992 ____C (Black Tree Gaming ) C:\Users\kevin\Downloads\Nexus Mod Manager-0.63.5.exe
2016-10-31 22:22 - 2016-10-31 22:22 - 00000000 ___DC C:\Users\kevin\AppData\Local\Skyrim Special Edition
2016-10-31 00:08 - 2016-10-31 00:08 - 00000000 ___DC C:\Users\kevin\Downloads\TcpNoDelayMod-2.0
2016-10-31 00:07 - 2016-10-31 00:07 - 01257462 ____C C:\Users\kevin\Downloads\LabyMod_v2.7.9_mc1.8.8(1).jar
2016-10-31 00:03 - 2016-10-31 00:03 - 00003751 ____C C:\Users\kevin\Downloads\TcpNoDelayMod-2.0.zip
2016-10-31 00:02 - 2016-10-31 00:02 - 00001244 ____C C:\Users\kevin\Downloads\mcdnszeugs.rar
2016-10-31 00:02 - 2016-10-31 00:02 - 00000000 ___DC C:\Users\kevin\Downloads\mcdnszeugs
2016-10-30 20:48 - 2016-10-30 20:48 - 00000000 ___DC C:\Users\kevin\Downloads\saeubern
2016-10-30 19:20 - 2016-10-30 19:20 - 00000000 ___DC C:\Users\kevin\Downloads\Suicide
2016-10-30 19:17 - 2016-10-30 19:22 - 50343608 ____C (Hammer & Chisel, Inc.) C:\Users\kevin\Downloads\DiscordSetup.exe
2016-10-30 18:24 - 2016-10-30 18:27 - 12489484 ____C C:\Users\kevin\Downloads\Suicide.zip
2016-10-30 18:06 - 2016-10-30 18:06 - 00000222 ____C C:\Users\kevin\Desktop\The Elder Scrolls V Skyrim Special Edition.url
2016-10-30 18:05 - 2016-10-30 18:05 - 00001561 ____C C:\Users\kevin\AppData\Local\recently-used.xbel
2016-10-30 14:26 - 2016-10-30 14:26 - 00000000 ___DC C:\Users\kevin\Downloads\NewtonLeak
2016-10-30 14:25 - 2016-10-30 14:25 - 13033457 ____C C:\Users\kevin\Downloads\NewtonLeak.rar
2016-10-30 01:01 - 2016-10-30 01:01 - 00000005 ____C C:\Users\kevin\Desktop\ccmd.bat
2016-10-29 19:07 - 2016-10-29 19:07 - 00000000 ___DC C:\Users\kevin\AppData\LocalLow\Temp
2016-10-29 16:55 - 2016-10-29 16:56 - 00000000 ___DC C:\Users\kevin\flsongs
2016-10-29 15:17 - 2016-10-29 15:17 - 08098768 ____C C:\Users\kevin\Downloads\teeworlds-0.6.2-win64.zip
2016-10-29 15:17 - 2016-10-29 15:17 - 00000000 ___DC C:\Users\kevin\Downloads\teeworlds-0.6.2-win64
2016-10-29 15:17 - 2016-10-29 15:17 - 00000000 ___DC C:\Users\kevin\Desktop\teeworlds-0.6.2-win64
2016-10-29 14:51 - 2016-10-29 15:20 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Teeworlds
2016-10-29 14:37 - 2016-10-29 14:37 - 00000000 ___DC C:\Users\kevin\Downloads\ClientBase by Tru3
2016-10-28 23:27 - 2016-10-28 23:27 - 00000000 ___DC C:\Users\kevin\Desktop\L ist ein Huso
2016-10-28 23:20 - 2016-10-28 23:20 - 00527423 ____C ( ) C:\Users\kevin\Downloads\Lame_v3.99.3_for_Windows.exe
2016-10-28 23:15 - 2016-10-28 23:15 - 00000000 ___DC C:\Users\kevin\AppData\Local\ElevatedDiagnostics
2016-10-28 23:11 - 2016-10-28 23:14 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\DVDVideoSoft
2016-10-28 23:09 - 2016-10-28 23:10 - 31291888 ____C (Digital Wave Ltd ) C:\Users\kevin\Downloads\FreeVideoToMP3ConverterBase.exe
2016-10-28 17:56 - 2016-10-28 17:56 - 00003716 ____C C:\Users\kevin\Downloads\enbseries.ini
2016-10-28 17:45 - 2016-10-28 17:50 - 286117632 ____C (TechSmith Corporation) C:\Users\kevin\Downloads\camtasiade.exe
2016-10-28 17:44 - 2016-10-28 23:24 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Audacity
2016-10-28 17:44 - 2016-10-28 17:44 - 00000000 ___DC C:\Users\kevin\AppData\Local\Audacity
2016-10-28 17:38 - 2016-10-28 17:38 - 26496761 ____C (Audacity Team ) C:\Users\kevin\Downloads\audacity-win-2.1.2.exe
2016-10-28 13:36 - 2016-10-28 13:36 - 00000000 ___DC C:\Users\kevin\Downloads\Newton
2016-10-27 18:54 - 2016-10-27 18:54 - 00000015 ____C C:\Users\kevin\Desktop\absad.bat
2016-10-27 15:28 - 2016-10-27 15:32 - 14296561 ____C C:\Users\kevin\Downloads\Newton.rar
2016-10-26 18:52 - 2016-10-26 18:52 - 00000000 ___DC C:\Users\kevin\AppData\Local\HirezLauncherUI
2016-10-26 18:51 - 2016-10-31 22:22 - 00000000 ___DC C:\ProgramData\Package Cache
2016-10-26 18:50 - 2016-11-12 11:52 - 00000000 ___DC C:\Program Files (x86)\Hi-Rez Studios
2016-10-26 18:50 - 2016-10-26 18:54 - 00000000 ___DC C:\ProgramData\Hi-Rez Studios
2016-10-26 18:50 - 2016-10-26 18:50 - 00000000 __HDC C:\Program Files (x86)\InstallShield Installation Information
2016-10-26 18:50 - 2016-10-26 18:50 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
2016-10-26 18:23 - 2016-10-26 18:25 - 02563007 ____C C:\Users\kevin\Downloads\Abyss SRC.zip
2016-10-26 18:10 - 2016-10-26 18:10 - 00000222 ____C C:\Users\kevin\Desktop\Paladins.url
2016-10-25 16:59 - 2016-10-25 17:00 - 00020707 ____C C:\Users\kevin\Downloads\RenderHelper.java
2016-10-24 16:35 - 2016-10-24 16:35 - 00006221 ____C C:\Users\kevin\Downloads\FontUtils.txt
2016-10-23 20:39 - 2016-10-23 20:39 - 01339795 ____C C:\Users\kevin\Downloads\GommeHD.zip
2016-10-23 19:55 - 2016-10-23 19:55 - 00000000 ___DC C:\Users\kevin\Tracing
2016-10-23 19:54 - 2016-10-27 19:34 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Skype
2016-10-23 19:54 - 2016-10-23 19:54 - 00002699 ____C C:\Users\Public\Desktop\Skype.lnk
2016-10-23 19:54 - 2016-10-23 19:54 - 00000000 __RDC C:\Program Files (x86)\Skype
2016-10-23 19:54 - 2016-10-23 19:54 - 00000000 ___DC C:\ProgramData\Skype
2016-10-23 19:54 - 2016-10-23 19:54 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-10-23 19:53 - 2016-10-23 19:54 - 43760768 ____C (Skype Technologies S.A.) C:\Users\kevin\Downloads\SkypeSetupFull.exe
2016-10-23 19:45 - 2016-10-23 19:50 - 00000020 ____C C:\Users\kevin\Desktop\skype.txt
2016-10-22 19:04 - 2016-10-22 19:10 - 00000189 ____C C:\Users\kevin\Desktop\DosSelf.bat
2016-10-22 18:06 - 2016-10-27 19:29 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\obs-studio
2016-10-22 18:04 - 2016-10-22 18:04 - 00001202 ____C C:\Users\Public\Desktop\OBS Studio.lnk
2016-10-22 18:04 - 2016-10-22 18:04 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
2016-10-22 18:04 - 2016-10-22 18:04 - 00000000 ___DC C:\Program Files (x86)\obs-studio
2016-10-22 17:59 - 2016-10-22 18:02 - 97276344 ____C (obsproject.com) C:\Users\kevin\Downloads\OBS-Studio-0.16.2-Full-Installer.exe
2016-10-22 17:49 - 2016-10-22 17:49 - 00000012 ____C C:\Users\kevin\Desktop\000.vbs
2016-10-22 16:55 - 2016-10-22 16:55 - 03910208 ____C C:\Users\kevin\Downloads\adwcleaner_6.030.exe
2016-10-22 13:38 - 2016-10-23 17:15 - 00028492 ____C C:\Users\kevin\Documents\cannabis.odt
2016-10-21 23:14 - 2016-10-21 23:15 - 00000043 ____C C:\Users\kevin\Desktop\regedit.txt
2016-10-21 16:55 - 2016-10-21 16:55 - 05231873 ____C C:\Users\kevin\Downloads\Huzuni 1.6.2.zip
2016-10-21 16:54 - 2016-10-21 16:58 - 00000707 ____C C:\Users\kevin\AppData\Roaming\jd-gui.cfg
2016-10-21 16:50 - 2016-10-21 16:51 - 08764679 ____C C:\Users\kevin\Downloads\jd-gui-1.4.0.jar
2016-10-21 16:49 - 2013-06-03 21:12 - 00000000 ___DC C:\Users\kevin\Desktop\org
2016-10-21 13:43 - 2016-10-22 13:32 - 00000000 ___DC C:\Program Files (x86)\Mozilla Firefox
2016-10-20 21:04 - 2016-10-20 21:04 - 00376939 ____C C:\Users\kevin\Downloads\SpritecraftFull.zip
2016-10-20 21:04 - 2016-10-20 21:04 - 00000000 ___DC C:\Users\kevin\Downloads\SpritecraftFull
2016-10-20 16:33 - 2016-10-20 16:33 - 00003090 ____C C:\Users\kevin\Downloads\TowerBypass.txt
2016-10-19 18:24 - 2016-10-19 18:25 - 00000063 ____C C:\Users\kevin\Desktop\asd.txt
2016-10-17 21:40 - 2016-10-17 21:40 - 00000000 ____C C:\Users\kevin\Desktop\Idefix,Transformer,Minecraft.txt
2016-10-17 15:24 - 2016-11-12 13:13 - 00000000 ___DC C:\Users\kevin\Desktop\AV
2016-10-16 16:53 - 2016-10-16 17:00 - 00000259 ____C C:\Users\kevin\Downloads\SearchReg.txt
2016-10-16 16:52 - 2016-10-16 16:59 - 00000256 ____C C:\Users\kevin\Downloads\Search.txt
2016-10-16 16:50 - 2016-10-16 16:51 - 00124819 ____C C:\Users\kevin\Downloads\FRST.txt
2016-10-16 16:50 - 2016-10-16 16:51 - 00032592 ____C C:\Users\kevin\Downloads\Addition.txt
2016-10-16 16:49 - 2016-11-12 15:04 - 00000000 ___DC C:\FRST
2016-10-16 16:49 - 2016-10-16 16:49 - 02406912 ____C (Farbar) C:\Users\kevin\Downloads\FRST64.exe
2016-10-16 16:33 - 2016-10-16 16:33 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2016-10-16 16:33 - 2016-10-16 16:33 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2016-10-16 16:21 - 2016-10-16 16:22 - 03874368 ____C C:\Users\kevin\Downloads\adwcleaner_6.021.exe
2016-10-16 11:05 - 2016-10-18 13:00 - 00000494 ____C C:\Users\kevin\Desktop\AltListe.txt
2016-10-15 16:10 - 2016-11-09 17:06 - 11935655 ____C C:\Users\kevin\Desktop\Fack.jar
2016-10-15 14:37 - 2016-10-15 14:37 - 00000000 ___DC C:\Users\kevin\Downloads\Moto SS Tools
2016-10-15 14:36 - 2016-10-15 14:36 - 06402187 ____C C:\Users\kevin\Downloads\Moto SS Tools.zip
2016-10-14 23:54 - 2016-10-14 23:54 - 09459897 ____C C:\Users\kevin\Downloads\minecraft_server.1.10.2.jar
2016-10-14 23:44 - 2016-10-14 23:44 - 00000000 ___DC C:\Users\kevin\Downloads\1mcp931
2016-10-14 19:54 - 2016-10-14 19:54 - 00000620 ____C C:\Users\kevin\Desktop\tesst.bat
2016-10-14 19:43 - 2016-10-14 20:49 - 00000000 ___DC C:\Users\kevin\Desktop\Virus
2016-10-14 19:29 - 2016-10-14 19:30 - 00000044 ____C C:\Users\kevin\Desktop\asd.bat
2016-10-14 17:19 - 2016-10-14 17:19 - 00000000 ___DC C:\Users\kevin\Desktop\DPK TRAINING DU LOW GEHJ
2016-10-14 14:36 - 2016-10-14 14:36 - 00437760 ____C C:\Users\kevin\Downloads\Nicht bestätigt 493149.crdownload
2016-10-14 13:35 - 2016-10-14 13:42 - 00000131 ____C C:\Users\kevin\Desktop\tt.bat
2016-10-14 13:34 - 2016-10-14 13:34 - 00000000 __HDC C:\Users\kevin\Desktop\FL12
2016-10-14 13:04 - 2016-10-14 13:34 - 00000076 ____C C:\Users\kevin\Desktop\test.bat
2016-10-13 20:17 - 2016-10-13 20:17 - 00000956 ____C C:\Users\Public\Desktop\Bat To Exe Converter.lnk
2016-10-13 20:17 - 2016-10-13 20:17 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Bat To Exe Converter
2016-10-13 20:17 - 2016-10-13 20:17 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bat To Exe Converter
2016-10-13 20:17 - 2016-10-13 20:17 - 00000000 ___DC C:\Program Files\Bat To Exe Converter
2016-10-13 20:16 - 2016-10-14 14:38 - 00002242 ____C C:\Users\kevin\Desktop\FL Studio 12 (64bit) - Kopie.bat
2016-10-13 20:16 - 2016-10-13 20:16 - 04670366 ____C C:\Users\kevin\Downloads\Bat_To_Exe_Converter2430.zip
2016-10-13 20:16 - 2016-10-13 20:16 - 00000000 ___DC C:\Users\kevin\Downloads\Bat_To_Exe_Converter2430
2016-10-13 15:05 - 2016-10-13 15:06 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 12574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2016-10-13 15:05 - 2016-10-13 15:06 - 12574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2016-10-13 15:05 - 2016-10-13 15:06 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 02023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01483264 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2016-10-13 15:05 - 2016-10-13 15:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-10-13 15:05 - 2016-10-13 15:06 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-10-13 15:05 - 2016-10-13 15:06 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2016-10-13 15:05 - 2016-10-13 15:06 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2016-10-13 15:05 - 2016-10-13 15:06 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2016-10-13 15:05 - 2016-10-13 15:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2016-10-13 15:05 - 2016-10-13 15:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2016-10-13 15:05 - 2016-10-13 15:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2016-11-12 14:58 - 2016-07-09 12:20 - 00000000 ___DC C:\AdwCleaner
2016-11-12 14:57 - 2016-10-10 15:15 - 00000884 ____C C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-11-12 14:43 - 2016-09-15 14:47 - 00000000 ___DC C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-11-12 14:30 - 2016-09-15 14:47 - 00192216 ____C (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-11-12 14:30 - 2016-09-15 14:47 - 00109272 ____C (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-11-12 13:27 - 2016-06-29 12:11 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\.minecraft
2016-11-12 12:47 - 2016-05-17 20:00 - 00000000 ___DC C:\Program Files (x86)\Steam
2016-11-12 12:15 - 2016-09-16 22:20 - 00007611 ____C C:\Users\kevin\AppData\Local\Resmon.ResmonCfg
2016-11-12 12:10 - 2016-10-12 17:10 - 00000000 ___DC C:\Program Files (x86)\Image-Line
2016-11-12 12:10 - 2016-10-06 17:56 - 00000000 ___DC C:\Users\kevin\AppData\Local\osu!
2016-11-12 12:00 - 2009-07-14 05:45 - 00021856 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-12 12:00 - 2009-07-14 05:45 - 00021856 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-12 11:59 - 2016-10-12 17:19 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2016-11-12 11:59 - 2016-10-12 17:19 - 00000000 ___DC C:\Program Files\Image-Line
2016-11-12 11:58 - 2016-05-17 18:20 - 00000000 ___DC C:\Program Files (x86)\Google
2016-11-12 11:57 - 2016-05-17 18:20 - 00000000 ___DC C:\Users\kevin\AppData\Local\Google
2016-11-12 11:52 - 2016-05-17 18:42 - 00000000 ___DC C:\ProgramData\NVIDIA
2016-11-12 11:52 - 2009-07-14 06:08 - 00000006 ___HC C:\Windows\Tasks\SA.DAT
2016-11-11 19:33 - 2016-06-21 19:45 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\TS3Client
2016-11-11 14:29 - 2016-07-31 11:37 - 00000000 ___DC C:\Users\kevin\AppData\Local\Eclipse
2016-11-11 14:29 - 2016-07-31 11:35 - 00000000 ___DC C:\Users\kevin\.p2
2016-11-11 14:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2016-11-11 13:54 - 2010-11-21 07:50 - 00700146 ____C C:\Windows\system32\perfh007.dat
2016-11-11 13:54 - 2010-11-21 07:50 - 00149784 ____C C:\Windows\system32\perfc007.dat
2016-11-11 13:54 - 2009-07-14 06:13 - 01622778 ____C C:\Windows\system32\PerfStringBackup.INI
2016-11-11 13:54 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\inf
2016-11-11 13:48 - 2009-07-14 05:45 - 00329576 ____C C:\Windows\system32\FNTCACHE.DAT
2016-11-10 16:22 - 2016-06-11 06:26 - 00000000 ___DC C:\Windows\system32\MRT
2016-11-10 16:20 - 2016-06-11 06:26 - 141011376 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-11-09 21:55 - 2016-09-14 15:29 - 00000000 ___DC C:\Users\kevin\Saves
2016-11-09 21:55 - 2016-08-03 15:49 - 00000000 ___DC C:\Users\kevin\AppData\Local\CrashDumps
2016-11-09 21:55 - 2016-06-23 14:34 - 00000000 ___DC C:\Users\kevin\AppData\Local\GeometryDash
2016-11-09 21:55 - 2016-06-18 13:04 - 00000000 ___DC C:\Users\kevin\AppData\Local\Skyrim
2016-11-09 13:55 - 2016-06-16 13:46 - 00000000 ___DC C:\Users\kevin\Documents\My Games
2016-11-09 12:58 - 2016-10-10 15:15 - 00003822 ____C C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-11-09 12:58 - 2016-07-14 13:30 - 00796352 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-09 12:58 - 2016-07-14 13:30 - 00142528 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-09 12:58 - 2016-06-17 14:27 - 00000000 ___DC C:\Windows\SysWOW64\Macromed
2016-11-09 12:58 - 2016-06-17 14:27 - 00000000 ___DC C:\Windows\system32\Macromed
2016-11-09 12:09 - 2016-05-17 20:58 - 00000000 ___DC C:\Users\kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-11-05 01:51 - 2016-09-16 16:01 - 00000000 ___DC C:\Users\kevin\AppData\Local\fabi.me
2016-11-03 13:57 - 2016-10-07 18:12 - 00000890 ____C C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2016-11-03 13:57 - 2016-06-20 18:44 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2016-11-03 13:57 - 2016-06-20 18:44 - 00000000 ___DC C:\Program Files\Nexus Mod Manager
2016-11-01 12:22 - 2016-06-20 18:53 - 00000000 ___DC C:\Users\kevin\AppData\Local\Ubisoft Game Launcher
2016-10-31 22:15 - 2016-06-20 18:44 - 00000000 ___DC C:\Users\kevin\Documents\Nexus Mod Manager
2016-10-31 21:44 - 2016-06-15 16:19 - 00018960 ____C (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2016-10-30 18:05 - 2016-09-25 17:51 - 00000000 ___DC C:\Users\kevin\.gimp-2.8
2016-10-29 16:55 - 2016-05-17 18:11 - 00000000 ___DC C:\Users\kevin
2016-10-29 13:11 - 2016-10-03 21:29 - 00000000 ___DC C:\Users\kevin\Downloads\SpeedAutoClicker-1.3.6
2016-10-28 23:15 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\system32\NDF
2016-10-27 16:39 - 2016-09-24 12:31 - 00000000 ___DC C:\Users\kevin\Desktop\mbar
2016-10-26 19:01 - 2016-06-19 00:41 - 00000000 ___DC C:\Users\Kev
2016-10-26 16:29 - 2010-11-21 04:27 - 00485032 ____C (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-10-22 17:00 - 2016-09-15 14:56 - 00000000 ___DC C:\Users\kevin\AppData\Local\ESET
2016-10-22 13:51 - 2016-06-17 15:07 - 00000000 ___DC C:\ProgramData\Oracle
2016-10-22 13:40 - 2016-07-31 11:34 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-10-22 13:40 - 2016-07-13 15:27 - 00110144 ____C (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2016-10-22 13:40 - 2016-07-13 15:27 - 00000000 ___DC C:\Program Files\Java
2016-10-22 13:40 - 2016-06-17 15:08 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-10-22 13:32 - 2016-05-17 19:56 - 00000000 ___DC C:\Program Files (x86)\Mozilla Maintenance Service
2016-10-16 16:34 - 2016-09-15 14:33 - 00185758 ____C C:\Users\kevin\Downloads\OTL.Txt
2016-10-16 16:18 - 2016-07-20 20:46 - 00000000 ___DC C:\Windows\EOONotify
2016-10-14 23:45 - 2016-09-19 15:41 - 00000000 ___DC C:\Users\kevin\Desktop\MCoding 1.10
2016-10-13 21:31 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\SysWOW64\Dism
2016-10-13 21:31 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\system32\Dism

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2016-10-21 16:54 - 2016-10-21 16:58 - 0000707 ____C () C:\Users\kevin\AppData\Roaming\jd-gui.cfg
2016-08-31 18:39 - 2016-08-31 18:40 - 0054784 __SHC () C:\Users\kevin\AppData\Roaming\Thumbs.db
2016-10-30 18:05 - 2016-10-30 18:05 - 0001561 ____C () C:\Users\kevin\AppData\Local\recently-used.xbel
2016-09-16 22:20 - 2016-11-12 12:15 - 0007611 ____C () C:\Users\kevin\AppData\Local\Resmon.ResmonCfg
2016-05-17 18:35 - 2016-05-17 18:35 - 0000000 ___HC () C:\ProgramData\DP45977C.lfl

Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\Users\kevin\BlockTank.exe


Einige Dateien in TEMP:
====================
C:\Users\kevin\AppData\Local\Temp\Nexus Mod Manager-0.63.5.exe
C:\Users\kevin\AppData\Local\Temp\Nexus Mod Manager-0.63.6.exe


==================== Bamital & volsnap ======================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2016-11-09 19:04

==================== Ende von FRST.txt ============================
         
--- --- ---


Addition
Code:
ATTFilter
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 12-11-2016
durchgeführt von kevin (12-11-2016 15:05:20)
Gestartet von C:\Users\kevin\Desktop\AV
Windows 7 Professional Service Pack 1 (X64) (2016-05-17 17:10:17)
Start-Modus: Normal
==========================================================


==================== Konten: =============================

Administrator (S-1-5-21-3869536936-4182528847-1821436484-500 - Administrator - Disabled)
Gast (S-1-5-21-3869536936-4182528847-1821436484-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3869536936-4182528847-1821436484-1003 - Limited - Enabled)
Kev (S-1-5-21-3869536936-4182528847-1821436484-1004 - Limited - Enabled) => C:\Users\Kev
kevin (S-1-5-21-3869536936-4182528847-1821436484-1001 - Administrator - Enabled) => C:\Users\kevin

==================== Sicherheits-Center ========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installierte Programme ======================

(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)

Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated)
Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version:  - Ubisoft)
AVG 2016 (Version: 16.0.4649 - AVG Technologies) Hidden
Bat To Exe Converter Version 2.4.3 (HKLM\...\{60C29EC2-33E8-45EE-87E4-31FA3E35C539}_is1) (Version: 2.4.3 - Fatih Kodak)
Call of Duty: Black Ops II - Multiplayer (HKLM\...\Steam App 202990) (Version:  - Treyarch)
Call of Duty: Black Ops II - Zombies (HKLM\...\Steam App 212910) (Version:  - )
Call of Duty: Black Ops II (HKLM\...\Steam App 202970) (Version:  - Treyarch)
Eden Eternal (HKLM-x32\...\Eden Eternal) (Version:  - )
f.lux (HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\Flux) (Version:  - )
GIMP 2.8.18 (HKLM\...\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Intel(R) Network Connections 20.2.3001.0 (HKLM\...\PROSetDX) (Version: 20.2.3001.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.0.36 - Intel Corporation)
Intel® Chipsatz-Gerätesoftware (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
Java SE Development Kit 8 Update 102 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180102}) (Version: 8.0.1020.14 - Oracle Corporation)
League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden
LibreOffice 5.0.6.3 (HKLM-x32\...\{900D9036-4EDA-45EC-A095-E8AFB25D807A}) (Version: 5.0.6.3 - The Document Foundation)
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
Microsoft .NET Framework 4.6.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Mozilla Firefox 49.0.2 (x86 de) (HKLM-x32\...\Mozilla Firefox 49.0.2 (x86 de)) (Version: 49.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2.6136 - Mozilla)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.63.6 - Black Tree Gaming)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.9.2 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 364.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.39 - NVIDIA Corporation)
NVIDIA Grafiktreiber 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.39 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.14 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 0.16.2 - OBS Project)
Paladins (HKLM\...\Steam App 444090) (Version:  - Hi-Rez Studios)
PlanetSide 2 (HKLM\...\Steam App 218230) (Version:  - Daybreak Game Company)
PlanetSide 2 (HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\DG0-PlanetSide 2) (Version:  - Sony Online Entertainment)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7553 - Realtek Semiconductor Corp.)
Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.)
Skyrim Script Extender (SKSE) (HKLM\...\Steam App 365720) (Version:  - The SKSE Team)
Star Conflict (HKLM\...\Steam App 212070) (Version:  - Star Gem Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
The Elder Scrolls V: Skyrim (HKLM\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Elder Scrolls V: Skyrim Special Edition (HKLM\...\Steam App 489830) (Version:  - Bethesda Game Studios)
Unturned (HKLM\...\Steam App 304930) (Version:  - Smartly Dressed Games)
Uplay (HKLM-x32\...\Uplay) (Version: 20.0 - Ubisoft)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
WinRAR 5.40 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Youtubers Life (HKLM\...\Steam App 428690) (Version:  - U-Play online)

==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

Task: {32B02B77-F14E-4224-B44D-DA66E122E273} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe
Task: {434ED099-C058-4B41-8362-5D4FFFC0AEF3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-09] (Adobe Systems Incorporated)
Task: {50A4E092-7C75-4B35-9765-E95E63C181C9} - System32\Tasks\{8E0A11AD-D2DA-482F-948E-DD19D5ACBDF9} => pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\redist\vcredist_x86.exe" -d "C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\redist"

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Verknüpfungen =============================

(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)

==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============


==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)


==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)


==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)

HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Software\Classes\regfile: regedit.exe "%1" <===== ACHTUNG

==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)

IE trusted site: HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\aeriagames.com -> hxxps://aeriagames.com
IE trusted site: HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\...\aeriagames.com -> hxxp://aeriagames.com

==================== Hosts Inhalt: ===============================

(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)

2009-07-14 03:34 - 2016-11-12 11:50 - 00000865 ___AC C:\Windows\system32\Drivers\etc\hosts


==================== Andere Bereiche ============================

(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)

HKU\S-1-5-21-3869536936-4182528847-1821436484-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
DNS Servers: 192.168.0.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.

==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==

MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{C3C20348-4E62-4202-A916-437637DF9D0F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FA6B302A-C57B-4169-B19E-86CEB1AA1BA9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{F9995F98-8635-4021-A6E5-AE37E52C8AA1}C:\users\kevin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\kevin\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{A691C498-D267-45B8-A870-A65DAE85A357}C:\users\kevin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\kevin\appdata\local\akamai\netsession_win.exe
FirewallRules: [{5BEE0E89-00DC-48F5-89F5-D6921F946585}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3A0D33C2-6AEC-4F6E-9F0D-BF1F67344216}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{5F872E1C-CEFD-48A3-A599-B1972955B641}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{21BA250F-95D4-453B-B948-26C0FADAC5FE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{71F0FFF1-CD01-43ED-BB5E-2E4A41A24EAC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C7E77B54-854B-4331-8046-252935EA1648}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{47B1DCE7-B481-4BEF-B0F8-4092401CBD85}] => (Allow) C:\AeriaGames\EdenEternal\_Launcher.exe
FirewallRules: [{C3561511-4E15-4ABD-9153-32AE4DD6BF96}] => (Allow) C:\AeriaGames\EdenEternal\_Launcher.exe
FirewallRules: [{570D9110-D341-4E62-B00C-C82ED7DA95ED}] => (Allow) C:\AeriaGames\EdenEternal\_Launcher.exe
FirewallRules: [{3857EDCB-EB54-4F43-99BF-250F0E5CC2D2}] => (Allow) C:\AeriaGames\EdenEternal\_Launcher.exe
FirewallRules: [{62466810-B99B-45D1-8676-221E4729CD7C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{B8CCFE9F-D690-42C2-8406-F19785DAC4F9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{646C98CA-A8F0-43B6-B888-2D4BB4BDF645}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6sp.exe
FirewallRules: [{131CA21A-0E3B-4CD4-B15D-DA68E64C46C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6sp.exe
FirewallRules: [{E93FFC1B-D6F4-4AA3-9D28-4AF724C91401}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{D3FED0E2-6927-4056-B213-13C3D936B2BB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{DB7BD69A-CB5F-4ACF-9EE5-4C14BA7AA911}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{70334719-F857-4D73-AFFB-197A4A13C585}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [TCP Query User{161CEDAE-3216-46F6-AB18-CF550F5D475E}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [UDP Query User{76B9D1FD-23E8-402B-840F-A7D530789F5E}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [TCP Query User{BE04F7B6-440D-4123-8A40-3981C3F8AC56}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{FFF28113-59C5-4085-BB55-ED2518151544}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{D0ACF12B-FCD3-4395-AD1D-A738539F7346}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{A218AD4A-9066-4827-A82E-370F58B04EED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [TCP Query User{68BE29DD-8695-4CDA-9647-F338B1029184}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe
FirewallRules: [UDP Query User{67A1C249-381A-4E79-8D5B-752B7C2461E7}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe
FirewallRules: [TCP Query User{95C3B7D8-F211-4C18-BF84-B17115F27337}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{7C132854-F3EB-4CFB-B525-4F0649F95E51}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{0E31CE84-D6AD-4302-8701-B4D69829B2B9}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [UDP Query User{2F10C194-0DE6-4294-BA68-259E31834033}C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\win64\aces.exe
FirewallRules: [TCP Query User{17ED97ED-98C6-4F7D-9D44-0CC54A11F8AC}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe
FirewallRules: [UDP Query User{4E5A6663-1F48-4ADD-98DF-2462740CAEFA}C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\deu_deu\tera\tera-launcher.exe
FirewallRules: [TCP Query User{5D36CC89-7F37-4D8A-A3AF-78F2A346365D}C:\program files\java\jre1.8.0_102\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_102\bin\javaw.exe
FirewallRules: [UDP Query User{6DFED79B-318D-47D2-8303-26288E83DA39}C:\program files\java\jre1.8.0_102\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_102\bin\javaw.exe
FirewallRules: [TCP Query User{E2E32A50-D36F-4665-A9B6-3609C895BE1A}C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe] => (Allow) C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe
FirewallRules: [UDP Query User{2708C15A-7A4B-48DE-A5B0-FD2C581ACBC2}C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe] => (Allow) C:\users\kevin\eclipse\jee-neon\eclipse\eclipse.exe
FirewallRules: [{18D57BB1-61A1-41CD-81D0-9200EEC3AE65}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YoutubersLife\YoutubersLife.exe
FirewallRules: [{2623A2C9-5E03-4FB2-A121-530E268C8BCC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YoutubersLife\YoutubersLife.exe
FirewallRules: [{1418D824-FB73-47E5-B718-73AD85FA8BF5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{BFCCB5CF-7C00-4AEE-9E68-E100A2A04501}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{49948CC2-07E0-41EC-8371-B8BC5D4948E4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PlanetSide 2\LaunchPad.exe
FirewallRules: [{1555F3EB-4B40-45A3-A7B4-02F888F8B9C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PlanetSide 2\LaunchPad.exe
FirewallRules: [TCP Query User{15E206EC-B00D-4D88-A097-FBD1083AF7F3}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe
FirewallRules: [UDP Query User{109E10E7-A71F-46BA-8388-1F6441CBA243}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe
FirewallRules: [TCP Query User{D418244C-DF34-4828-A435-D791DDA3DA77}C:\program files (x86)\corelenda\block tank\blocktank.exe] => (Allow) C:\program files (x86)\corelenda\block tank\blocktank.exe
FirewallRules: [UDP Query User{ED154A19-FB0C-4AD0-AB58-D8A7B748213A}C:\program files (x86)\corelenda\block tank\blocktank.exe] => (Allow) C:\program files (x86)\corelenda\block tank\blocktank.exe
FirewallRules: [{AC11B48A-6E73-4884-A7B2-256216B9E009}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{8AEFB74F-16CB-44E8-8164-DC0109B554E2}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{6D86DA0E-DAA1-4E75-8E14-F4FD7760B78A}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{7A5A7995-492D-407F-B94D-0247C7CE3765}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [TCP Query User{73C82B9C-FF17-457F-838E-93E5D1D4F54C}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe
FirewallRules: [UDP Query User{E1DB5A21-CF80-4A7C-B9C3-87A7FC209C98}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2_x64.exe
FirewallRules: [{DD4EADC3-E9F0-40A0-94F1-338626969DFA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YoutubersLife\YoutubersLife.exe
FirewallRules: [{FD3F47B3-0D84-4EBC-AAB9-0372DE567C14}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YoutubersLife\YoutubersLife.exe
FirewallRules: [TCP Query User{46C1B2F8-5F2E-4EA2-9BB9-D6B839AA152D}C:\program files\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [UDP Query User{88B2ED59-B851-4AA3-A6CF-658D5D594233}C:\program files\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [{21C3F05D-139D-4F5E-BD5A-52C2DCEFEF41}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{6481DA60-BB0B-4F53-8C03-79E3ED290C57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe
FirewallRules: [{7854E678-E4E1-40B0-B958-12E1ACB5EC38}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe
FirewallRules: [TCP Query User{D0A84128-D490-4332-B844-FE1D7050DC00}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [UDP Query User{9C275726-B139-4D7A-BDE3-138B6A2E3545}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [TCP Query User{4438CD16-6389-4268-A60A-454B03DC405F}C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe] => (Block) C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe
FirewallRules: [UDP Query User{FA7B3586-0D33-4974-9989-57EA5637EEFF}C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe] => (Block) C:\users\kevin\desktop\teeworlds-0.6.2-win64\teeworlds_srv.exe
FirewallRules: [{169B8042-4F5B-4475-BE0C-F830E00D29CD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{3EAA7C9D-74AA-4EE9-962E-007A56F65B3B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{058E7BC7-518B-4C80-8EB1-2E7D72E6642C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\star conflict\game.exe
FirewallRules: [{CE7139C3-3FEC-453C-9BEC-4023A5B47193}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\star conflict\game.exe
FirewallRules: [{ECB0A950-DD20-4A3F-92B3-71B3523D0772}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
FirewallRules: [{1E5DAA5C-9780-40BB-B9FB-6D23F7606D9C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe

==================== Wiederherstellungspunkte =========================

10-11-2016 16:18:58 Windows Update
12-11-2016 14:54:34 JRT Pre-Junkware Removal

==================== Fehlerhafte Geräte im Gerätemanager =============

Name: Microsoft PS/2-Maus
Description: Microsoft PS/2-Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: PS/2 Keyboard
Description: PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: Logitech
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: PCI-Kommunikationscontroller (einfach)
Description: PCI-Kommunikationscontroller (einfach)
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Fehlereinträge in der Ereignisanzeige: =========================

Applikationsfehler:
==================
Error: (11/12/2016 11:54:10 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/12/2016 11:37:29 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/12/2016 12:03:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/11/2016 01:49:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/10/2016 04:11:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/09/2016 12:05:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/07/2016 06:40:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/05/2016 11:06:39 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/04/2016 06:44:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.

Error: (11/04/2016 01:05:21 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Ereignisfilter mit Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" nicht reaktiviert werden aufgrund des Fehlers 0x80041003. Ereignisse können nicht durch diesen Filter geschickt werden, bis dieses Problem gelöst ist.


Systemfehler:
=============
Error: (11/12/2016 11:51:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst konnte wegen einer fehlerhaften Anmeldung nicht gestartet werden.

Error: (11/12/2016 11:51:49 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "WSearch" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
Die Anforderung wird nicht unterstützt.


Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (11/12/2016 11:51:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Rapid Storage Technology" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/12/2016 11:51:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) PROSet Monitoring Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Hi-Rez Studios Authenticate and Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:18 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/12/2016 11:51:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Stereoscopic 3D Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/12/2016 11:51:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Display Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


==================== Speicherinformationen =========================== 

Prozessor: Intel(R) Core(TM) i5-6500 CPU @ 3.20GHz
Prozentuale Nutzung des RAM: 27%
Installierter physikalischer RAM: 8125.05 MB
Verfügbarer physikalischer RAM: 5894.33 MB
Summe virtueller Speicher: 16248.28 MB
Verfügbarer virtueller Speicher: 13947.85 MB

==================== Laufwerke ================================

Drive c: () (Fixed) (Total:263.57 GB) (Free:82.1 GB) NTFS

==================== MBR & Partitionstabelle ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: FA9674A1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=263.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=652.1 GB) - (Type=05)

==================== Ende von Addition.txt ============================
         
Könnte auch sein, dass ich mich verschrieben habe. Wenn man vor e100.net eine 1 anhängt kommat man zu google

Geändert von Kenko (12.11.2016 um 21:01 Uhr)

Alt 12.11.2016, 21:02   #13
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



FRST-Fix

Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!


Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
C:\Users\kevin\BlockTank.exe
emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Alt 12.11.2016, 21:08   #14
Kenko
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Dies ist kein Virus, aber ich kann es mal gerne bei FRST eingeben. Ist ein Spiel, welches mit Unity gemacht wurde

So hier die Fixlog
Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 12-11-2016
durchgeführt von kevin (12-11-2016 20:03:45) Run:1
Gestartet von C:\Users\kevin\Desktop\AV
Geladene Profile: kevin (Verfügbare Profile: kevin & Kev)
Start-Modus: Normal
==============================================

fixlist Inhalt:
*****************
C:\Users\kevin\BlockTank.exe
emptytemp:
         
*****************

C:\Users\kevin\BlockTank.exe => erfolgreich verschoben

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 34637476 B
Java, Flash, Steam htmlcache => 379784606 B
Windows/system/drivers => 2647332 B
Edge => 0 B
Chrome => 0 B
Firefox => 387300591 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 66356 B
systemprofile32 => 66088 B
LocalService => 66228 B
NetworkService => 127866 B
kevin => 1097573390 B
Kev => 71753 B

RecycleBin => 0 B
EmptyTemp: => 1.8 GB temporäre Dateien entfernt.

================================


Das System musste neu gestartet werden.

==== Ende von Fixlog 20:04:11 ====
         

Alt 12.11.2016, 21:41   #15
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Firefox baut unseriöse Verbindugen auf - Standard

Firefox baut unseriöse Verbindugen auf



Kontrollscans mit (1) MBAM, (2) ESET und (3) SecurityCheck bitte:


1. Schritt: MBAM

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




2. Schritt: ESET

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




3. Schritt: SecurityCheck

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.
__________________
"Die Wahrheit ist normalerweise nur eine Entschuldigung für einen Mangel an Fantasie." (Elim Garak)

Das Trojaner-Board unterstützen
Warum Linux besser als Windows ist!

Antwort

Themen zu Firefox baut unseriöse Verbindugen auf
aufbau, firefox, gefährlich, gen, kurzem, link, meldung, monitor, resource, sofort, ublock, verbindungen, virus, website, windows, wissen



Ähnliche Themen: Firefox baut unseriöse Verbindugen auf


  1. PC baut Seiten langsam auf
    Log-Analyse und Auswertung - 24.09.2016 (27)
  2. In Chrome werden Links umgeleitet, unseriöse Werbung erscheint
    Log-Analyse und Auswertung - 13.05.2015 (23)
  3. Chrome öffnet sich selbst, bzw. unseriöse Seiten
    Log-Analyse und Auswertung - 17.04.2015 (9)
  4. Googel öffnet ungefragt unseriöse Seiten.
    Plagegeister aller Art und deren Bekämpfung - 16.08.2014 (17)
  5. Wurde weitergeleitet auf unseriöse Seite!
    Plagegeister aller Art und deren Bekämpfung - 20.01.2014 (28)
  6. Win8: Virus blendet unseriöse Werbebanner in Googleseite ein
    Log-Analyse und Auswertung - 04.09.2013 (14)
  7. System baut Verbindung auf
    Log-Analyse und Auswertung - 11.05.2011 (3)
  8. Umleitung auf diverse unseriöse Seiten sowie seltsame Suchmaschinen
    Plagegeister aller Art und deren Bekämpfung - 25.04.2011 (91)
  9. Sicherheitsexpertin baut Android-Botnetz
    Nachrichten - 25.01.2011 (0)
  10. Firefox - Google öffnet unseriöse Suchmaschinen
    Log-Analyse und Auswertung - 13.09.2010 (16)
  11. HILFE! Trojaner gefangen! Google Weiterleitung auf unseriöse Seiten -
    Plagegeister aller Art und deren Bekämpfung - 20.12.2009 (4)
  12. PC langsamer und Google leitet auf diverse unseriöse Seiten weiter
    Plagegeister aller Art und deren Bekämpfung - 17.12.2009 (5)
  13. iexplore.exe baut tunnel auf
    Plagegeister aller Art und deren Bekämpfung - 26.05.2009 (0)
  14. Vista: IE/Firefox baut keine Seite auf obwohl Internetverbindung steht!
    Log-Analyse und Auswertung - 18.03.2009 (5)
  15. IE öffnet alle 15 min unseriöse Security Seite
    Log-Analyse und Auswertung - 24.07.2008 (1)
  16. IE baut dauernd ne Seite auf !!
    Plagegeister aller Art und deren Bekämpfung - 09.10.2006 (3)
  17. Wie baut man Trojaner???????
    Log-Analyse und Auswertung - 29.04.2005 (2)

Zum Thema Firefox baut unseriöse Verbindugen auf - Hallo erstmal! Ich habe mal vor kurzem im sog. "Resourcenmonitor" von Windows geschaut wohin u.a. firefox seine Verbindungen aufbaut. Da habe ich gesehen, dass eine Verbindung zu hxxp://waw02s05-in-f4.e100.net aufgeabut wird. - Firefox baut unseriöse Verbindugen auf...
Archiv
Du betrachtest: Firefox baut unseriöse Verbindugen auf auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.