Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   GVU Trojaner Windows 7 64 Bit (https://www.trojaner-board.de/142714-gvu-trojaner-windows-7-64-bit.html)

Lou Schalter 08.10.2013 17:10

GVU Trojaner Windows 7 64 Bit
 
Hallo liebe Community,

habe mir bereits einige der artverwandten Fälle angesehen und mich nun dazu entschlossen euch um eure fachkundige Hilfe zu bitten. Es handelt sich um den Computer eines guten Freundes von mir.

Kleinere Probleme kriege ich in der Regel auch selbst beseitigt. Allerdings musste ich feststellen, dass bei ihm noch einiges mehr im Argen lag bzw. liegt.

(In erster Linie bin ich aber schon hier wegen dem GVU-Trojaner. Der abgesicherte Modus mit Netzwerktreibern geht nicht, hatte ich gestern Abend schon kurz ausprobiert. Aber ich glaube er kann sich noch mit einem anderen Benutzer anmelden.)

Java war nicht auf dem aktuellen Stand, er besucht offenbar teils recht "ominöse" Websites, verwendet bislang sonst auch gerne nicht aktuelle Software, ... .

Konnte ihn nun tatsächlich von dem Sinn und Zweck des Leitfadens "Das sichere Windows System" von Paule (weiß nicht ob ich den Link hier posten darf) überzeugen. Der Gute hat mir versprochen in Zukunft mit Bedacht zu surfen und den Anschnallgurt anzulegen.

Fahre später direkt zu ihm und werde versuchen die Log-Files zu posten, Frage vorab:

Farbar's Recovery Scan Tool
oder
OTLPENet.exe von OldTimer ?

Bereits im Voraus vielen Dank für eure Hilfe,
Lou Schalter

Edit: Bitte entschuldigt, hatte die Punkte überlesen:

Ich habe Windows Vista, 7 oder 8
Erzeuge ein FRST-Logfile nach dieser Anleitung: Scan mit Farbar Recovery Scan Tool

Ich habe Windows XP
Erzeuge ein Logfile, das du mit OTLpe erstellt hast: Scan mit Otlpe

=> Werde mit FRST ein Logfile erstellen und gleich hier posten.

aharonov 08.10.2013 18:25

Hi,

Zitat:

=> Werde mit FRST ein Logfile erstellen und gleich hier posten.
Genau.
Sobald das Log da ist, kann ich den Rechner entsperren.

Lou Schalter 08.10.2013 21:42

Wenn ich im Abgesicherten Modus (sowohl Netzwerktreiber als auch Eingabeaufforderung) starten will bleibt es bei WINDOWS\system32\drivers\CLASSPNP.sys hängen und danach fährt sich der Rechner automatisch wieder selbst herunter.

Bei der Auswahl von "Computer reparieren" in den erweiterten Startoptionen kommt der Fehler:

Status 0xc000000e
Info: Fehler bei der Startauswahl. Zugriff auf ein erforderliches Gerät nicht möglich.

Hm. Da ist guter Rat teuer.

Habe jetzt alles Moegliche versucht, mit OTLPE hatte ich schliesslich Erfolg.
Hoffe das ist o.k. Mit FRST ging garnichts, da bin ich einfach nicht weiter gekommen.

Hier die Logs.

Extras.txt

OTL Logfile:
Code:

OTL Extras logfile created on: 10/8/2013 11:17:52 PM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 87.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS
Drive F: | 273.20 Gb Total Space | 17.62 Gb Free Space | 6.45% Space Free | Partition Type: NTFS
Drive G: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- E:\Windows\System32\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- E:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 File not found
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding
"{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64)
"{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding
"{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64)
"{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\*****_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"JNLP" = JNLP
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
< End of report >

--- --- ---

OLT.txt

OTL Logfile:

Code:

OTL logfile created on: 10/8/2013 11:17:52 PM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 87.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS
Drive F: | 273.20 Gb Total Space | 17.62 Gb Free Space | 6.45% Space Free | Partition Type: NTFS
Drive G: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2011/11/09 23:11:32 | 000,204,288 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2008/01/19 04:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2008/01/19 04:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\appmgmts.dll -- (AppMgmt)
SRV - [2011/08/06 01:14:15 | 000,411,432 | ---- | M] (Valve Corporation) [Disabled] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/11/20 23:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand] -- F:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2010/06/23 19:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto] -- E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh)
SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/08 16:55:54 | 000,075,064 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2009/07/13 21:41:53 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand] -- F:\Windows\System32\qwave.dll -- (QWAVE)
SRV - [2008/07/27 14:03:13 | 000,069,632 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2006/12/27 19:00:00 | 000,356,352 | ---- | M] (AVM Berlin) [Auto] -- E:\Program Files (x86)\avmwlanstick\WLanNetService.exe -- (AVM WLAN Connection Service)
SRV - [2006/10/18 10:26:16 | 000,285,216 | ---- | M] (Acronis) [Auto] -- E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011/11/09 23:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/11/09 22:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/12/07 14:19:02 | 000,187,912 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\MAudioFastTrack.sys -- (MAUSBFASTTRACK)
DRV:64bit: - [2009/07/14 10:36:28 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/04/21 13:08:10 | 000,012,800 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand] -- E:\Windows\System32\drivers\danew.sys -- (danewFltr)
DRV:64bit: - [2007/02/16 10:36:21 | 000,629,536 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2007/02/16 10:36:20 | 000,198,944 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2006/12/27 19:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- E:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB)
DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2005/03/28 20:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
 
========== Standard Registry (All) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\Administrator_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 62 77 37 8F B3 C3 CE 01  [binary data]
IE - HKU\Administrator_ON_F\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\Administrator_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\*****_ON_F\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 AC 4D D3 F3 F7 CC 01  [binary data]
IE - HKU\*****_ON_F\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\*****_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\LocalService_ON_F\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
 
IE - HKU\NetworkService_ON_F\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:  File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0:  File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.4:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.7:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.40.2:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
[2012/02/01 20:14:46 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/18 11:49:07 | 000,000,000 | ---D | M] (Skype Click to Call) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/06/20 17:02:25 | 000,000,000 | ---D | M] (Adobe Flash) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82e4700b-58f2-4aa0-8949-964b59155c87}
[2011/12/20 21:09:49 | 000,000,000 | ---D | M] (Default) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/11 12:08:03 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/02/12 16:56:10 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2010/02/15 16:52:08 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/06/28 12:11:23 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/27 14:00:28 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/12/20 21:09:48 | 000,025,560 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2011/12/20 21:09:48 | 000,140,760 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2007/04/10 12:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- E:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2010/09/14 23:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/20 21:09:48 | 000,067,032 | ---- | M] (mozilla.org) -- E:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2011/06/06 06:55:30 | 000,183,696 | ---- | M] (Adobe Systems Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2010/06/28 12:02:52 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2010/06/28 12:02:52 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2011/03/12 16:14:17 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011/03/12 16:14:17 | 000,002,344 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011/03/12 16:14:17 | 000,002,371 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2011/03/12 16:14:17 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011/03/12 16:14:17 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011/03/12 16:14:17 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
[2011/05/15 21:20:36 | 000,000,849 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
 
O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} -  File not found
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} -  File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} -  File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  File not found
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (af0.Adblock.BHO) - {90EFF544-3981-4d46-85C9-C0361D0931D6} - E:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} -  File not found
O2 - BHO: (no name) - {C4415769-1588-4AD6-9624-B2E69DB78D1A} - Reg Error: Value error. File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} -  File not found
O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} -  File not found
O3 - HKU\Administrator_ON_F\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} -  File not found
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [IAAnotif]  File not found
O4:64bit: - HKLM..\Run: [Launch LCore]  File not found
O4:64bit: - HKLM..\Run: [M-Audio Taskbar Icon] E:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
O4:64bit: - HKLM..\Run: [MSC]  File not found
O4:64bit: - HKLM..\Run: [SoundMAX]  File not found
O4 - HKLM..\Run: [DeathAdder] E:\Program Files (x86)\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [DigidesignMMERefresh] E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid Technology, Inc..)
O4 - HKLM..\Run: [SoundMAXPnP] E:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VirtualCloneDrive]  File not found
O4 - HKLM..\Run: [vmware-tray]  File not found
O4 - HKU\*****_ON_F..\Run: [Google Update]  File not found
O4 - HKU\*****_ON_F..\Run: [SpybotSD TeaTimer]  File not found
O4 - HKU\LocalService_ON_F..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_F..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_F..\RunOnce: [mctadmin]  File not found
O4 - HKU\NetworkService_ON_F..\RunOnce: [mctadmin]  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\Administrator_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\*****_ON_F\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} -  File not found
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} -  File not found
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -  File not found
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -  File not found
O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} -  File not found
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} -  File not found
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -  File not found
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -  File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -  File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] -  File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000016 -  File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] -  File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 -  File not found
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - .DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15:64bit: - .DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15:64bit: - .DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15:64bit: - .DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15:64bit: - *****_ON_F\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15:64bit: - *****_ON_F\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15:64bit: - *****_ON_F\..Trusted Domains: soe.com ([]* in Trusted sites)
O15:64bit: - *****_ON_F\..Trusted Domains: sony.com ([]* in Trusted sites)
O15:64bit: - *****_ON_F\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15:64bit: - *****_ON_F\..Trusted Ranges: Range1 ([https] in Trusted sites)
O15:64bit: - LocalService_ON_F\..Trusted Domains: clonewarsadventures.com ([]* in )
O15:64bit: - LocalService_ON_F\..Trusted Domains: freerealms.com ([]* in )
O15:64bit: - LocalService_ON_F\..Trusted Domains: soe.com ([]* in )
O15:64bit: - LocalService_ON_F\..Trusted Domains: sony.com ([]* in )
O15:64bit: - NetworkService_ON_F\..Trusted Domains: clonewarsadventures.com ([]* in )
O15:64bit: - NetworkService_ON_F\..Trusted Domains: freerealms.com ([]* in )
O15:64bit: - NetworkService_ON_F\..Trusted Domains: soe.com ([]* in )
O15:64bit: - NetworkService_ON_F\..Trusted Domains: sony.com ([]* in )
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - E:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} -  File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - E:\Windows\System32\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - E:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - E:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - E:\Windows\System32\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - E:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - E:\Windows\System32\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) -  File not found
O30:64bit: - LSA: Security Packages - (livessp) -  File not found
O30 - LSA: Security Packages - (kerberos) - E:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - E:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - E:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - E:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) -  File not found
O30 - LSA: Security Packages - (livessp) -  File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/10/08 23:11:50 | 000,000,000 | -HSD | C] -- E:\RECYCLER
[2013/10/08 14:35:33 | 001,954,124 | ---- | C] (Farbar) -- F:\Users\Administrator\Desktop\FRST64.exe
[2013/10/07 19:47:21 | 004,095,448 | ---- | C] (BrightFort LLC                                              ) -- F:\Users\Administrator\Desktop\spywareblastersetup50.exe
[2013/10/07 19:43:00 | 001,032,220 | ---- | C] (Thisisu) -- F:\Users\Administrator\Desktop\JRT.exe
[2013/09/26 16:21:33 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Steam
[3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ]
[1 E:\*.tmp files -> E:\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013/10/08 13:57:58 | 001,954,124 | ---- | M] (Farbar) -- F:\Users\Administrator\Desktop\FRST64.exe
[2013/10/07 19:47:21 | 004,095,448 | ---- | M] (BrightFort LLC                                              ) -- F:\Users\Administrator\Desktop\spywareblastersetup50.exe
[2013/10/07 19:43:07 | 001,032,220 | ---- | M] (Thisisu) -- F:\Users\Administrator\Desktop\JRT.exe
[2013/10/07 19:24:22 | 001,045,226 | ---- | M] () -- F:\Users\Administrator\Desktop\adwcleaner.exe
[3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ]
[1 E:\*.tmp files -> E:\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013/10/07 19:24:02 | 001,045,226 | ---- | C] () -- F:\Users\Administrator\Desktop\adwcleaner.exe
[2012/01/09 17:01:06 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin
[2012/01/04 18:06:52 | 000,217,088 | ---- | C] () -- E:\Windows\SysWow64\qtmlClient.dll
[2011/11/09 17:39:44 | 000,059,904 | ---- | C] () -- E:\Windows\SysWow64\OpenVideo.dll
[2011/11/09 17:39:32 | 000,054,784 | ---- | C] () -- E:\Windows\SysWow64\OVDecode.dll
[2011/10/14 19:54:52 | 000,321,856 | ---- | C] () -- E:\Windows\SysWow64\nvStreaming.exe
[2011/10/08 23:37:34 | 000,000,732 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps64.dat
[2011/09/12 19:06:16 | 000,003,917 | ---- | C] () -- E:\Windows\SysWow64\atipblag.dat
[2011/04/09 12:55:28 | 000,179,261 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat
[2010/12/22 18:05:26 | 000,001,356 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps.dat
[2010/11/27 13:56:32 | 000,000,120 | ---- | C] () -- E:\Users\*****\AppData\default.pls
[2010/06/06 14:15:17 | 000,122,992 | -H-- | C] () -- E:\Windows\SysWow64\mlfcache.dat
[2010/03/08 16:55:54 | 002,434,856 | ---- | C] () -- E:\Windows\SysWow64\pbsvc_bc2.exe
[2010/02/05 10:34:43 | 000,000,093 | ---- | C] () -- E:\Users\*****\AppData\Local\fusioncache.dat
[2009/12/09 20:29:02 | 000,052,736 | ---- | C] () -- E:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/22 21:00:42 | 000,000,000 | ---- | C] () -- E:\Windows\SysWow64\Access.dat
[2009/11/08 12:37:00 | 000,044,544 | ---- | C] () -- E:\Windows\SysWow64\Gif89.dll
[2009/09/27 09:13:48 | 000,000,033 | ---- | C] () -- E:\Windows\Multimedia manager.INI
[2009/01/23 18:40:27 | 000,000,056 | -H-- | C] () -- E:\Windows\SysWow64\ezsidmv.dat
[2009/01/01 12:00:39 | 000,043,520 | ---- | C] () -- E:\Windows\SysWow64\CmdLineExt03.dll
[2008/11/27 19:29:00 | 000,096,801 | ---- | C] () -- E:\Windows\War3Unin.dat
[2008/08/25 15:34:16 | 000,000,466 | RHS- | C] () -- E:\ProgramData\ntuser.pol
[2008/08/12 16:17:52 | 000,003,308 | ---- | C] () -- E:\Windows\bthservsdp.dat
[2008/08/08 15:57:05 | 000,106,605 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchema.bin
[2008/08/08 15:57:05 | 000,018,904 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/07/29 12:02:05 | 000,000,000 | ---- | C] () -- E:\ProgramData\LauncherAccess.dt
[2008/07/29 12:00:03 | 000,005,632 | ---- | C] () -- E:\Windows\SysWow64\drivers\StarOpen.sys
[2008/04/22 17:46:56 | 000,368,640 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll
[2008/04/22 17:46:42 | 000,060,124 | ---- | C] () -- E:\Windows\SysWow64\tcpmon.ini
[2008/02/18 16:26:18 | 000,001,167 | ---- | C] () -- E:\Windows\mozver.dat
[2008/02/14 13:32:04 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat
[2008/02/12 15:46:22 | 000,214,864 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.exe
[2008/02/12 15:46:21 | 000,669,184 | ---- | C] () -- E:\Windows\SysWow64\pbsvc.exe
[2008/02/12 15:46:21 | 000,075,064 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrA.exe
[2008/02/11 15:22:15 | 000,000,069 | ---- | C] () -- E:\Windows\NeroDigital.ini
[2007/05/19 09:22:17 | 001,499,938 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI
[2006/11/02 11:35:48 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2006/11/02 11:00:58 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll
[2006/11/02 08:37:14 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
 
========== LOP Check ==========
 
[2008/02/12 08:04:51 | 000,000,000 | ---D | M] -- E:\ProgramData\Acronis
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2011/02/03 14:59:54 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2011/11/18 11:48:32 | 000,000,000 | ---D | M] -- E:\ProgramData\Easybits GO
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2011/05/23 07:23:38 | 000,000,000 | ---D | M] -- E:\ProgramData\HighAndes
[2012/01/04 19:05:27 | 000,000,000 | ---D | M] -- E:\ProgramData\PACE Anti-Piracy
[2011/09/23 11:31:20 | 000,000,000 | ---D | M] -- E:\ProgramData\Panasonic
[2012/02/02 19:24:32 | 000,000,000 | ---D | M] -- E:\ProgramData\PMB Files
[2010/03/15 16:13:37 | 000,000,000 | ---D | M] -- E:\ProgramData\Samsung
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2010/02/15 11:14:21 | 000,000,000 | ---D | M] -- E:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}
[2010/06/28 11:47:55 | 000,000,000 | ---D | M] -- E:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/02/02 20:09:36 | 000,032,606 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
[2012/02/02 20:05:00 | 000,000,420 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{67EDA5FC-0019-45FD-BD8F-60FFCB19790F}.job
[2012/02/02 20:07:06 | 000,000,454 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{FF4DA3C5-B76D-406A-8828-716AE39A637B}.job
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 128 bytes -> E:\Windows:nlsPreferences
@Alternate Data Stream - 1264 bytes -> E:\ProgramData\Microsoft:SQasxH89fAhVdXZTo4rQsa1lB8
@Alternate Data Stream - 1257 bytes -> E:\ProgramData\Microsoft:mF4IF8xPxZPwwlfGMSTyMdmOB
@Alternate Data Stream - 1241 bytes -> E:\ProgramData\Microsoft:DsK0QpZjrH4Bu7uFCcUC3mv2JNM
@Alternate Data Stream - 1237 bytes -> E:\ProgramData\Microsoft:BzN69YMHrh8PpgVkajVTf
@Alternate Data Stream - 1126 bytes -> E:\Program Files (x86)\Common Files\System:8pBA6f4chx8LvxmXGoa
@Alternate Data Stream - 1075 bytes -> E:\Users\*****\AppData\Local:Gy1L44sVjSHClQdReyzsUh8
< End of report >

--- --- ---

aharonov 08.10.2013 22:12

Hallo,

und du bist dir sicher, dass hier Malware das Problem ist? (Hat man den GVU-Sperrschirm gesehen?)
In diesem Log kann ich keine Spur davon erkennen..

Lou Schalter 08.10.2013 22:19

Hallo Leo,

der Form halber zunaechst einmal vielen Dank! Finde das toll, dass du mir bei der Sache weiter hilfst.

Ja, ich bin mir sehr sicher. Sobald ich mich unter dem Benutzer anmelde kommt der Sperrschirm. Soll ich mal so starten und dir eine Hardcopy davon einstellen?

Mit FRST habe ich es nicht hin bekommen, siehe obig beschriebene Fehlermeldung.
Dann habe ich es mit OTLPE versucht. Ging zunaechst auch nicht, dann habe ich mir eine Start-CD damit erstellt und es hin bekommen.

Sitze gerade am betroffenen Computer und nutze den InternetExplorer der Benutzeroberflaeche von der gebooteten CD.

Soll ich mal bei den Scans ueberall auf ALL einstellen?

Die Windows-Installation ist hier ein wenig merkwuerdig gestaltet ... es ist ein Raid, aber das System ist auf der Platte F so wie es aussieht.

Edit

Er hat gestern Abend offenbar noch diverse AntiMalware-Software installiert und mit einem dieser Programme drueber gebuegelt meint er gerade. Also vom Administrator-Benutzerkonto aus. Da kann man sich nach wie vor anmelden. Zudem hat er gestern Abend noch 30 Windows-Updates gestartet, welche es noch heruntergeladen hatte bevor der Rechner aus gegangen ist. Vorhin hat es mir beim Booten die ganze Zeit angezeigt, dass etwas beim Windows-Update schief gelaufen sei, es wuerde rueckgaengig gemacht werden, hernach konnte ich mich ganz normal als Admin anmelden. Habe dann mal unter dem Admin-Kondo prophylaktisch die Windows-Updates fuer den Moment wieder komplett rausgenommen, diese duerften uns jetzt gerade kaum weiterhelfen.

Edit 2

Auf der Festplatte E sitzt auch noch ein Betriebtssystem, vielleicht hat es sich ja dort versteckt ... ?

Hier die OLT.txt

OTL Logfile:
Code:

OTL logfile created on: 10/9/2013 12:26:53 AM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
64bit-Windows Vista (TM) Ultimate Service Pack 1 (Version = 6.0.6001) - Type = System
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 83.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS
Drive F: | 273.20 Gb Total Space | 17.62 Gb Free Space | 6.45% Space Free | Partition Type: NTFS
Drive G: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2011/11/09 23:11:32 | 000,204,288 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2008/05/01 20:49:54 | 000,160,272 | ---- | M] (Logitech, Inc.) [Auto] -- E:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2008/01/19 04:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2008/01/19 04:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\appmgmts.dll -- (AppMgmt)
SRV - [2011/10/15 04:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/10/14 19:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto] -- E:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/08/06 01:14:15 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/06/23 19:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto] -- E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh)
SRV - [2010/06/17 17:50:00 | 003,890,920 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand] -- E:\Windows\SysWow64\GameMon.des -- (npggsvc)
SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/08 16:55:54 | 000,075,064 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2009/07/21 09:34:28 | 000,185,089 | ---- | M] (Avira GmbH) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009/06/07 07:20:20 | 000,061,440 | ---- | M] (Nalpeiron Ltd.) [Auto] -- E:\Windows\SysWOW64\NlsSrv32.exe -- (nlsX86cc)
SRV - [2009/05/13 11:48:18 | 000,108,289 | ---- | M] (Avira GmbH) [Auto] -- E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008/07/27 14:03:13 | 000,069,632 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2006/12/27 19:00:00 | 000,356,352 | ---- | M] (AVM Berlin) [Auto] -- E:\Program Files (x86)\avmwlanstick\WLanNetService.exe -- (AVM WLAN Connection Service)
SRV - [2006/10/18 10:26:16 | 000,285,216 | ---- | M] (Acronis) [Auto] -- E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011/11/09 23:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2011/11/09 23:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/11/09 22:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/10/17 13:40:40 | 000,090,128 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand] -- E:\Windows\System32\drivers\AtihdLH6.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/08/02 12:38:56 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011/02/03 15:00:31 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System] -- E:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2010/12/07 14:19:02 | 000,187,912 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\MAudioFastTrack.sys -- (MAUSBFASTTRACK)
DRV:64bit: - [2010/06/13 20:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand] -- E:\Windows\System32\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010/04/26 22:25:14 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ss_mdm.sys -- (ss_mdm)
DRV:64bit: - [2010/04/26 22:25:14 | 000,127,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV:64bit: - [2010/04/26 22:25:14 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV:64bit: - [2010/03/18 21:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- E:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/12/07 16:32:51 | 000,074,880 | ---- | M] (Avira GmbH) [File_System | Auto] -- E:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2009/09/30 10:32:44 | 000,120,336 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009/09/09 14:25:14 | 000,871,408 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- E:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009/09/09 13:17:41 | 000,033,344 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2009/07/14 10:36:28 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/04/21 13:08:10 | 000,012,800 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand] -- E:\Windows\System32\drivers\danew.sys -- (danewFltr)
DRV:64bit: - [2008/02/28 21:17:08 | 000,041,488 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2008/02/28 21:17:00 | 000,112,144 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LMouKE.Sys -- (LMouKE)
DRV:64bit: - [2008/02/28 21:16:52 | 000,057,360 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2008/02/28 21:16:44 | 000,054,800 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2008/02/28 21:16:28 | 000,113,680 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\L8042mou.Sys -- (L8042mou)
DRV:64bit: - [2008/01/19 02:47:12 | 000,046,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\WpdUsb.sys -- (WpdUsb)
DRV:64bit: - [2008/01/19 02:34:08 | 000,048,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\avc.sys -- (Avc)
DRV:64bit: - [2008/01/19 02:34:06 | 000,058,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\61883.sys -- (61883)
DRV:64bit: - [2008/01/19 02:34:04 | 000,061,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\msdv.sys -- (MSDV)
DRV:64bit: - [2007/02/16 10:36:21 | 000,629,536 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2007/02/16 10:36:21 | 000,065,312 | ---- | M] (Acronis) [File_System | Auto] -- E:\Windows\System32\drivers\tifsfilt.sys -- (tifsfilter)
DRV:64bit: - [2007/02/16 10:36:20 | 000,198,944 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2007/01/12 12:43:40 | 000,037,552 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\frmupgr.sys -- (DFUBTUSB)
DRV:64bit: - [2006/12/27 19:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- E:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB)
DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2005/03/28 20:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2010/06/13 20:32:54 | 000,016,448 | ---- | M] (Teruten Inc) [File_System | On_Demand] -- E:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2006/07/24 10:05:00 | 000,005,632 | ---- | M] () [File_System | System] -- E:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen)
DRV - [2005/01/04 05:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand] -- E:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\*****_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\*****_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\*****_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
IE - HKU\Lisa_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
 
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de/"
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"
FF - prefs.js..keyword.URL: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"
 
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=: 
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\*****\Music\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: E:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WPF,version=3.5: E:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision: E:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming: E:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/11 21:28:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/12/20 21:09:49 | 000,000,000 | ---D | M]
 
[2010/06/01 15:33:19 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Extensions
[2010/06/05 22:12:15 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\7bq2ynvd.default\extensions
[2009/11/19 07:39:36 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\7bq2ynvd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/05 22:12:15 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\7bq2ynvd.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2009/11/19 07:39:36 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\7bq2ynvd.default\extensions\staged-xpis
[2012/02/01 20:14:46 | 000,000,000 | ---D | M] (No name found) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\9mi91wdq.default\extensions
[2011/04/18 07:52:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\9mi91wdq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/05 22:12:15 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\9mi91wdq.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/04/18 07:52:28 | 000,000,000 | ---D | M] (Fast Video Download (with SearchMenu)) -- E:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\9mi91wdq.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2012/02/01 20:14:46 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/18 11:49:07 | 000,000,000 | ---D | M] (Skype Click to Call) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/06/20 17:02:25 | 000,000,000 | ---D | M] (Adobe Flash) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82e4700b-58f2-4aa0-8949-964b59155c87}
[2010/06/28 12:11:23 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/27 14:00:28 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) -- E:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{3112CA9C-DE6D-4884-A869-9855DE68056C}
File not found (No name found) -- E:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{B13721C7-F507-4982-B2E5-502A71474FED}
[2010/09/14 23:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/12 16:14:17 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011/03/12 16:14:17 | 000,002,344 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011/03/12 16:14:17 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011/03/12 16:14:17 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011/03/12 16:14:17 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Adobe Flash) - {82E4700B-58F2-4AA0-8949-964B59155C87} - E:\Users\*****\AppData\Roaming\AdobeFlash\IE\AdobeFlash.dll (Adobe Systems, Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [Bluetooth Connection Assistant]  File not found
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] E:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] E:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] E:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] E:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [M-Audio Taskbar Icon] E:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
O4:64bit: - HKLM..\Run: [Windows Defender] E:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AcronisTimounterMonitor] E:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [APSDaemon] E:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [AVMWlanClient] E:\Program Files (x86)\avmwlanstick\wlangui.exe (AVM Berlin)
O4 - HKLM..\Run: [DeathAdder] E:\Program Files (x86)\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [DigidesignMMERefresh] E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid Technology, Inc..)
O4 - HKLM..\Run: [DivXUpdate] E:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NPSStartup]  File not found
O4 - HKLM..\Run: [StartCCC] E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] E:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKU\*****_ON_E..\Run: [AutoStartNPSAgent] D:\Anwendungen\NewPCStudio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\*****_ON_E..\Run: [avupdate]  File not found
O4 - HKU\*****_ON_E..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] E:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\*****_ON_E..\Run: [DAEMON Tools Lite] D:\Anwendungen\Daemon\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\Lisa_ON_E..\Run: [WindowsWelcomeCenter] E:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\LocalService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_E..\Run: [WindowsWelcomeCenter] E:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\NetworkService_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_E..\Run: [WindowsWelcomeCenter] E:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\UpdatusUser_ON_E..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\UpdatusUser_ON_E..\Run: [WindowsWelcomeCenter] E:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\Lisa_ON_E..\RunOnce: [FlashPlayerUpdate] E:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\*****_ON_E\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00  [binary data]
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - E:\Users\*****\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - E:\Users\*****\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} -  File not found
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} -  File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - E:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - E:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.254
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - E:\Windows\System32\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: D:\#Sicherung\200SATA\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: D:\#Sicherung\200SATA\Internet Explorer Wallpaper.bmp
O30:64bit: - LSA: Authentication Packages - (relog_ap) - E:\Windows\System32\relog_ap.dll (Acronis)
O30 - LSA: Authentication Packages - (relog_ap) - E:\Windows\SysWow64\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{325ed12e-aac4-11de-9084-00040ec6ee83}\Shell\AutoRun\command - "" = K:\installer.exe
O33 - MountPoints2\{325ed12e-aac4-11de-9084-00040ec6ee83}\Shell\verb\command - "" = K:\installer.exe
O33 - MountPoints2\{399d00a2-2fc5-11e0-a0cd-001a922d4236}\Shell - "" = AutoRun
O33 - MountPoints2\{399d00a2-2fc5-11e0-a0cd-001a922d4236}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{399d00a9-2fc5-11e0-a0cd-001a922d4236}\Shell - "" = AutoRun
O33 - MountPoints2\{399d00a9-2fc5-11e0-a0cd-001a922d4236}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\{c86c8c10-d80a-11dc-9404-00040ec6ee83}\Shell\AutoRun\command - "" = E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
O33 - MountPoints2\{fbb62ea3-9d70-11de-a731-00040ec6ee83}\Shell - "" = AutoRun
O33 - MountPoints2\{fbb62ea3-9d70-11de-a731-00040ec6ee83}\Shell\AutoRun\command - "" = I:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/10/08 23:11:50 | 000,000,000 | -HSD | C] -- E:\RECYCLER
[2013/09/26 16:21:33 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Steam
[3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ]
[1 E:\*.tmp files -> E:\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ]
[1 E:\*.tmp files -> E:\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/01/09 17:01:06 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin
[2012/01/04 18:06:52 | 000,217,088 | ---- | C] () -- E:\Windows\SysWow64\qtmlClient.dll
[2011/11/09 17:39:44 | 000,059,904 | ---- | C] () -- E:\Windows\SysWow64\OpenVideo.dll
[2011/11/09 17:39:32 | 000,054,784 | ---- | C] () -- E:\Windows\SysWow64\OVDecode.dll
[2011/10/14 19:54:52 | 000,321,856 | ---- | C] () -- E:\Windows\SysWow64\nvStreaming.exe
[2011/10/08 23:37:34 | 000,000,732 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps64.dat
[2011/09/12 19:06:16 | 000,003,917 | ---- | C] () -- E:\Windows\SysWow64\atipblag.dat
[2011/04/09 12:55:28 | 000,179,261 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat
[2010/12/22 18:05:26 | 000,001,356 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps.dat
[2010/11/27 13:56:32 | 000,000,120 | ---- | C] () -- E:\Users\*****\AppData\default.pls
[2010/06/06 14:15:17 | 000,122,992 | -H-- | C] () -- E:\Windows\SysWow64\mlfcache.dat
[2010/03/08 16:55:54 | 002,434,856 | ---- | C] () -- E:\Windows\SysWow64\pbsvc_bc2.exe
[2010/02/05 10:34:43 | 000,000,093 | ---- | C] () -- E:\Users\*****\AppData\Local\fusioncache.dat
[2009/12/09 20:29:02 | 000,052,736 | ---- | C] () -- E:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/22 21:00:42 | 000,000,000 | ---- | C] () -- E:\Windows\SysWow64\Access.dat
[2009/11/08 12:37:00 | 000,044,544 | ---- | C] () -- E:\Windows\SysWow64\Gif89.dll
[2009/09/27 09:13:48 | 000,000,033 | ---- | C] () -- E:\Windows\Multimedia manager.INI
[2009/01/23 18:40:27 | 000,000,056 | -H-- | C] () -- E:\Windows\SysWow64\ezsidmv.dat
[2009/01/01 12:00:39 | 000,043,520 | ---- | C] () -- E:\Windows\SysWow64\CmdLineExt03.dll
[2008/11/27 19:29:00 | 000,096,801 | ---- | C] () -- E:\Windows\War3Unin.dat
[2008/08/25 15:34:16 | 000,000,466 | RHS- | C] () -- E:\ProgramData\ntuser.pol
[2008/08/12 16:17:52 | 000,003,308 | ---- | C] () -- E:\Windows\bthservsdp.dat
[2008/08/08 15:57:05 | 000,106,605 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchema.bin
[2008/08/08 15:57:05 | 000,018,904 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/07/29 12:02:05 | 000,000,000 | ---- | C] () -- E:\ProgramData\LauncherAccess.dt
[2008/07/29 12:00:03 | 000,005,632 | ---- | C] () -- E:\Windows\SysWow64\drivers\StarOpen.sys
[2008/04/22 17:46:56 | 000,368,640 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll
[2008/04/22 17:46:42 | 000,060,124 | ---- | C] () -- E:\Windows\SysWow64\tcpmon.ini
[2008/02/18 16:26:18 | 000,001,167 | ---- | C] () -- E:\Windows\mozver.dat
[2008/02/14 13:32:04 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat
[2008/02/12 15:46:22 | 000,214,864 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.exe
[2008/02/12 15:46:21 | 000,669,184 | ---- | C] () -- E:\Windows\SysWow64\pbsvc.exe
[2008/02/12 15:46:21 | 000,075,064 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrA.exe
[2008/02/11 15:22:15 | 000,000,069 | ---- | C] () -- E:\Windows\NeroDigital.ini
[2007/05/19 09:22:17 | 001,499,938 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI
[2006/11/02 11:35:48 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2006/11/02 11:00:58 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll
[2006/11/02 08:37:14 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
 
========== LOP Check ==========
 
[2008/02/12 08:04:51 | 000,000,000 | ---D | M] -- E:\ProgramData\Acronis
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2011/02/03 14:59:54 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2011/11/18 11:48:32 | 000,000,000 | ---D | M] -- E:\ProgramData\Easybits GO
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2011/05/23 07:23:38 | 000,000,000 | ---D | M] -- E:\ProgramData\HighAndes
[2012/01/04 19:05:27 | 000,000,000 | ---D | M] -- E:\ProgramData\PACE Anti-Piracy
[2011/09/23 11:31:20 | 000,000,000 | ---D | M] -- E:\ProgramData\Panasonic
[2012/02/02 19:24:32 | 000,000,000 | ---D | M] -- E:\ProgramData\PMB Files
[2010/03/15 16:13:37 | 000,000,000 | ---D | M] -- E:\ProgramData\Samsung
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2010/02/15 11:14:21 | 000,000,000 | ---D | M] -- E:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}
[2010/06/28 11:47:55 | 000,000,000 | ---D | M] -- E:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/02/02 20:09:36 | 000,032,606 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
[2012/02/02 20:05:00 | 000,000,420 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{67EDA5FC-0019-45FD-BD8F-60FFCB19790F}.job
[2012/02/02 20:07:06 | 000,000,454 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{FF4DA3C5-B76D-406A-8828-716AE39A637B}.job
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 128 bytes -> E:\Windows:nlsPreferences
@Alternate Data Stream - 1264 bytes -> E:\ProgramData\Microsoft:SQasxH89fAhVdXZTo4rQsa1lB8
@Alternate Data Stream - 1257 bytes -> E:\ProgramData\Microsoft:mF4IF8xPxZPwwlfGMSTyMdmOB
@Alternate Data Stream - 1241 bytes -> E:\ProgramData\Microsoft:DsK0QpZjrH4Bu7uFCcUC3mv2JNM
@Alternate Data Stream - 1237 bytes -> E:\ProgramData\Microsoft:BzN69YMHrh8PpgVkajVTf
@Alternate Data Stream - 1126 bytes -> E:\Program Files (x86)\Common Files\System:8pBA6f4chx8LvxmXGoa
@Alternate Data Stream - 1075 bytes -> E:\Users\*****\AppData\Local:Gy1L44sVjSHClQdReyzsUh8
< End of report >

--- --- ---

[/CODE]

aharonov 08.10.2013 22:38

Hallo,

Zitat:

Also vom Administrator-Benutzerkonto aus. Da kann man sich nach wie vor anmelden.
Ach so, dann müssen wir nicht von der Boot-CD scannen.
Gehe bitte in diesen Admin-Account und mach dort einen FRST-Scan wie folgt:


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Lou Schalter 09.10.2013 00:10

Das hatte ich vorhin bereits probiert. Da hatte es dann als es bei SCHEDLGU.txt war erstmal gehangen, danach kam die Fehlermeldung

Line 11324 File G{backslash}FRST64.exe

Error in expression

EDIT

Bin gerade als Administrator angemeldet, habe mit FRST64 gescannt, hier die (leere) Logdatei:

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013
Ran by Administrator at 2013-10-09 00:49:59
Running from C:\Users\Administrator\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

Es kam wieder die Fehlermeldung:

AutoIt Error

Line 11324 (File "C:\Users\Administrator\Desktop\FRST64.exe"):

Error: Error in Expression

Und vorher, während dem Scannen hat sich Microsoft Security Essentials gemeldet und angezeigt:

Von Security Essentials wurden unbekannte Elemente auf dem PC gefunden. (...)
Dateipfad: C:\ProgramData\4wcl7hv.plz

EDIT 2

Hier noch der Log von Gmer (auch auf dem Admin-Konto ausgeführt)

Code:

GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-10-09 01:28:18
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk2\DR2 -> \Device\Scsi\mv64xx1Port1Path0Target0Lun0 MARVELL_ rev.1.01 273,31GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\pwtoapod.sys


---- User code sections - GMER 2.1 ----

.text  C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe[2756] C:\Windows\BDTSupport.dll!GetInformation + 7                                                                                  0000000010001047 18 bytes [10, 33, C4, 89, 44, 24, 1C, ...]
.text  C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe[2756] C:\Windows\BDTSupport.dll!GetInformation + 26                                                                                000000001000105a 10 bytes [10, 8D, 4C, 24, 10, C7, 44, ...]
.text  ...                                                                                                                                                                                                * 11
.text  C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe[2756] C:\Windows\BDTSupport.dll!getSubProductCode + 6                                                                              00000000100010d6 3 bytes [A1, 94, D0]
.text  C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe[2756] C:\Windows\BDTSupport.dll!getSubProductCode + 10                                                                              00000000100010da 8 bytes [10, 33, C4, 89, 84, 24, 20, ...]
.text  C:\Windows\system32\hasplms.exe[2836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                      0000000076fb1465 2 bytes [FB, 76]
.text  C:\Windows\system32\hasplms.exe[2836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                    0000000076fb14bb 2 bytes [FB, 76]
.text  ...                                                                                                                                                                                                * 2
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322                                                                                                            0000000072dc1a22 2 bytes [DC, 72]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496                                                                                                            0000000072dc1ad0 2 bytes [DC, 72]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552                                                                                                            0000000072dc1b08 2 bytes [DC, 72]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730                                                                                                            0000000072dc1bba 2 bytes [DC, 72]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762                                                                                                            0000000072dc1bda 2 bytes [DC, 72]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                                                    0000000076fb1465 2 bytes [FB, 76]
.text  C:\Windows\SysWOW64\PnkBstrA.exe[2932] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                                                    0000000076fb14bb 2 bytes [FB, 76]
.text  ...                                                                                                                                                                                                * 2
.text  C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                                    0000000076fb1465 2 bytes [FB, 76]
.text  C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                                    0000000076fb14bb 2 bytes [FB, 76]
.text  ...                                                                                                                                                                                                * 2
.text  C:\Program Files\Internet Explorer\iexplore.exe[4192] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect                                                                              000007fefd8d4ed0 9 bytes [68, 78, 03, FE, 02, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4192] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW  000007fefbc65c54 7 bytes [68, 08, 03, FE, 02, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4192] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet  000007fefbc65c64 9 bytes [68, 40, 03, FE, 02, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4192] C:\Windows\system32\comdlg32.dll!PageSetupDlgW                                                                                              000007fefee617a0 9 bytes [68, B0, 03, FE, 02, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_A                                                                                          0000000076e1f578 7 bytes JMP 0000000103340570
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_W                                                                                          0000000076e2b0cc 7 bytes JMP 00000001033405a8
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\kernel32.dll!CreateThread                                                                                                0000000076cf6580 9 bytes JMP 00000001033404c8
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\ole32.dll!OleLoadFromStream                                                                                              000007fefdaa75f0 7 bytes [68, E0, 05, 34, 03, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!VariantClear                                                                                                000007fefd871180 10 bytes [68, C0, 06, 34, 03, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!SysFreeString                                                                                              000007fefd871320 7 bytes [68, 50, 06, 34, 03, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen                                                                                      000007fefd874450 6 bytes [68, 18, 06, 34, 03, C3]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!VariantChangeType                                                                                          000007fefd876720 10 bytes [68, 88, 06, 34, 03, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect                                                                              000007fefd8d4ed0 9 bytes [68, 78, 03, 34, 03, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW  000007fefbc65c54 7 bytes [68, 08, 03, 34, 03, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet  000007fefbc65c64 9 bytes [68, 40, 03, 34, 03, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[4884] C:\Windows\system32\comdlg32.dll!PageSetupDlgW                                                                                              000007fefee617a0 9 bytes [68, B0, 03, 34, 03, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_A                                                                                          0000000076e1f578 7 bytes JMP 0000000102ff0570
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_W                                                                                          0000000076e2b0cc 7 bytes JMP 0000000102ff05a8
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\kernel32.dll!CreateThread                                                                                                0000000076cf6580 9 bytes JMP 0000000102ff04c8
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\ole32.dll!OleLoadFromStream                                                                                              000007fefdaa75f0 7 bytes [68, E0, 05, FF, 02, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!VariantClear                                                                                                000007fefd871180 10 bytes [68, C0, 06, FF, 02, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!SysFreeString                                                                                              000007fefd871320 7 bytes [68, 50, 06, FF, 02, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen                                                                                      000007fefd874450 6 bytes [68, 18, 06, FF, 02, C3]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!VariantChangeType                                                                                          000007fefd876720 10 bytes [68, 88, 06, FF, 02, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect                                                                              000007fefd8d4ed0 9 bytes [68, 78, 03, FF, 02, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW  000007fefbc65c54 7 bytes [68, 08, 03, FF, 02, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet  000007fefbc65c64 9 bytes [68, 40, 03, FF, 02, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[8792] C:\Windows\system32\comdlg32.dll!PageSetupDlgW                                                                                              000007fefee617a0 9 bytes [68, B0, 03, FF, 02, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_A                                                                                          0000000076e1f578 7 bytes JMP 0000000100bd0570
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\SYSTEM32\ntdll.dll!NtdllDefWindowProc_W                                                                                          0000000076e2b0cc 7 bytes JMP 0000000100bd05a8
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\kernel32.dll!CreateThread                                                                                                0000000076cf6580 9 bytes JMP 0000000100bd04c8
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\ole32.dll!OleLoadFromStream                                                                                              000007fefdaa75f0 7 bytes [68, E0, 05, BD, 00, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!VariantClear                                                                                                000007fefd871180 10 bytes [68, C0, 06, BD, 00, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!SysFreeString                                                                                              000007fefd871320 7 bytes [68, 50, 06, BD, 00, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen                                                                                      000007fefd874450 6 bytes [68, 18, 06, BD, 00, C3]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!VariantChangeType                                                                                          000007fefd876720 10 bytes [68, 88, 06, BD, 00, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\OLEAUT32.dll!OleCreatePropertyFrameIndirect                                                                              000007fefd8d4ed0 9 bytes [68, 78, 03, BD, 00, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheetW  000007fefbc65c54 7 bytes [68, 08, 03, BD, 00, C3, CC]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll!PropertySheet  000007fefbc65c64 9 bytes [68, 40, 03, BD, 00, C3, CC, ...]
.text  C:\Program Files\Internet Explorer\iexplore.exe[7792] C:\Windows\system32\comdlg32.dll!PageSetupDlgW                                                                                              000007fefee617a0 9 bytes [68, B0, 03, BD, 00, C3, CC, ...]

---- Threads - GMER 2.1 ----

Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:5052]                                                                                                                            0000000075df7587
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:3020]                                                                                                                            000000006db50cb3
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:4144]                                                                                                                            0000000077032e65
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:3004]                                                                                                                            0000000077033e85
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4768:10040]                                                                                                                            0000000077033e85

---- EOF - GMER 2.1 ----

EDIT 3

Es ist spaet, frage mich gerade wo diese ominoese Partition G auf einmal herkommt ... jedenfalls ist hier auch ein Betriebssystem installiert. Hier die Logfiles.

OTL.txt

Code:

OTL logfile created on: 10/9/2013 2:58:46 AM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS
Drive F: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive G: | 273.20 Gb Total Space | 17.53 Gb Free Space | 6.42% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - [2011/11/09 23:11:32 | 000,204,288 | ---- | M] (AMD) [Auto] -- E:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2008/01/19 04:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2008/01/19 04:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\appmgmts.dll -- (AppMgmt)
SRV - [2011/08/06 01:14:15 | 000,411,432 | ---- | M] (Valve Corporation) [Disabled] -- E:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/06/06 06:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/11/20 23:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand] -- G:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2010/06/23 19:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto] -- E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh)
SRV - [2010/03/18 07:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/08 16:55:54 | 000,075,064 | ---- | M] () [Auto] -- E:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2009/07/13 21:41:53 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand] -- G:\Windows\System32\qwave.dll -- (QWAVE)
SRV - [2008/07/27 14:03:13 | 000,069,632 | ---- | M] (Microsoft Corporation) [Disabled] -- E:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2006/12/27 19:00:00 | 000,356,352 | ---- | M] (AVM Berlin) [Auto] -- E:\Program Files (x86)\avmwlanstick\WLanNetService.exe -- (AVM WLAN Connection Service)
SRV - [2006/10/18 10:26:16 | 000,285,216 | ---- | M] (Acronis) [Auto] -- E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2011/11/09 23:45:30 | 010,567,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/11/09 22:12:44 | 000,325,632 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/12/07 14:19:02 | 000,187,912 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\MAudioFastTrack.sys -- (MAUSBFASTTRACK)
DRV:64bit: - [2009/07/14 10:36:28 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/04/21 13:08:10 | 000,012,800 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand] -- E:\Windows\System32\drivers\danew.sys -- (danewFltr)
DRV:64bit: - [2007/02/16 10:36:21 | 000,629,536 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2007/02/16 10:36:20 | 000,198,944 | ---- | M] (Acronis) [Kernel | Boot] -- E:\Windows\System32\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2006/12/27 19:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand] -- E:\Windows\System32\drivers\fwlanusb.sys -- (FWLANUSB)
DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- E:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2005/03/28 20:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand] -- E:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
 
========== Standard Registry (All) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157
IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\Administrator_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 62 77 37 8F B3 C3 CE 01  [binary data]
IE - HKU\Administrator_ON_G\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\Administrator_ON_G\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\*****_ON_G\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 AC 4D D3 F3 F7 CC 01  [binary data]
IE - HKU\*****_ON_G\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\*****_ON_G\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\LocalService_ON_G\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
 
IE - HKU\NetworkService_ON_G\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - E:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer:  File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0:  File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.4:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.7:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.40.2:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.0:  File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: E:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
[2012/02/01 20:14:46 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/18 11:49:07 | 000,000,000 | ---D | M] (Skype Click to Call) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/06/20 17:02:25 | 000,000,000 | ---D | M] (Adobe Flash) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{82e4700b-58f2-4aa0-8949-964b59155c87}
[2011/12/20 21:09:49 | 000,000,000 | ---D | M] (Default) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/11 12:08:03 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/02/12 16:56:10 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2010/02/15 16:52:08 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/06/28 12:11:23 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/27 14:00:28 | 000,000,000 | ---D | M] (Java Console) -- E:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/12/20 21:09:48 | 000,025,560 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2011/12/20 21:09:48 | 000,140,760 | ---- | M] (Mozilla Foundation) -- E:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2007/04/10 12:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- E:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2010/09/14 23:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/20 21:09:48 | 000,067,032 | ---- | M] (mozilla.org) -- E:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2011/06/06 06:55:30 | 000,183,696 | ---- | M] (Adobe Systems Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2010/06/28 12:02:52 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2010/06/28 12:02:52 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2010/06/28 12:02:53 | 000,159,744 | ---- | M] (Apple Inc.) -- E:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2011/03/12 16:14:17 | 000,001,392 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011/03/12 16:14:17 | 000,002,344 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011/03/12 16:14:17 | 000,002,371 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2011/03/12 16:14:17 | 000,006,805 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011/03/12 16:14:17 | 000,001,178 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2011/03/12 16:14:17 | 000,001,105 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
[2011/05/15 21:20:36 | 000,000,849 | ---- | M] () -- E:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
 
O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} -  File not found
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} -  File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} -  File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  File not found
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (af0.Adblock.BHO) - {90EFF544-3981-4d46-85C9-C0361D0931D6} - E:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} -  File not found
O2 - BHO: (no name) - {C4415769-1588-4AD6-9624-B2E69DB78D1A} - Reg Error: Value error. File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} -  File not found
O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} -  File not found
O3 - HKU\Administrator_ON_G\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} -  File not found
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] E:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [IAAnotif]  File not found
O4:64bit: - HKLM..\Run: [Launch LCore]  File not found
O4:64bit: - HKLM..\Run: [M-Audio Taskbar Icon] E:\Windows\System32\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
O4:64bit: - HKLM..\Run: [MSC]  File not found
O4:64bit: - HKLM..\Run: [SoundMAX]  File not found
O4 - HKLM..\Run: [DeathAdder] E:\Program Files (x86)\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [DigidesignMMERefresh] E:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid Technology, Inc..)
O4 - HKLM..\Run: [SoundMAXPnP] E:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VirtualCloneDrive]  File not found
O4 - HKLM..\Run: [vmware-tray]  File not found
O4 - HKU\*****_ON_G..\Run: [Google Update]  File not found
O4 - HKU\*****_ON_G..\Run: [SpybotSD TeaTimer]  File not found
O4 - HKU\LocalService_ON_G..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_G..\Run: [Sidebar] E:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_G..\RunOnce: [mctadmin]  File not found
O4 - HKU\NetworkService_ON_G..\RunOnce: [mctadmin]  File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\Administrator_ON_G\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\*****_ON_G\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} -  File not found
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} -  File not found
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -  File not found
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -  File not found
O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} -  File not found
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} -  File not found
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -  File not found
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -  File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -  File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] -  File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 -  File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000016 -  File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - E:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - E:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - E:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] -  File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - E:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 -  File not found
O13:64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - .DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15:64bit: - .DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15:64bit: - .DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15:64bit: - .DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15:64bit: - *****_ON_G\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15:64bit: - *****_ON_G\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15:64bit: - *****_ON_G\..Trusted Domains: soe.com ([]* in Trusted sites)
O15:64bit: - *****_ON_G\..Trusted Domains: sony.com ([]* in Trusted sites)
O15:64bit: - *****_ON_G\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15:64bit: - *****_ON_G\..Trusted Ranges: Range1 ([https] in Trusted sites)
O15:64bit: - LocalService_ON_G\..Trusted Domains: clonewarsadventures.com ([]* in )
O15:64bit: - LocalService_ON_G\..Trusted Domains: freerealms.com ([]* in )
O15:64bit: - LocalService_ON_G\..Trusted Domains: soe.com ([]* in )
O15:64bit: - LocalService_ON_G\..Trusted Domains: sony.com ([]* in )
O15:64bit: - NetworkService_ON_G\..Trusted Domains: clonewarsadventures.com ([]* in )
O15:64bit: - NetworkService_ON_G\..Trusted Domains: freerealms.com ([]* in )
O15:64bit: - NetworkService_ON_G\..Trusted Domains: soe.com ([]* in )
O15:64bit: - NetworkService_ON_G\..Trusted Domains: sony.com ([]* in )
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - E:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - E:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - E:\Windows\System32\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - E:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - E:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - E:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} -  File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - E:\Windows\System32\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - E:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - E:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - E:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - E:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - E:\Windows\System32\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - E:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - E:\Windows\System32\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) -  File not found
O30:64bit: - LSA: Security Packages - (livessp) -  File not found
O30 - LSA: Security Packages - (kerberos) - E:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - E:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - E:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - E:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - E:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) -  File not found
O30 - LSA: Security Packages - (livessp) -  File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/10/08 23:11:50 | 000,000,000 | -HSD | C] -- E:\RECYCLER
[2013/09/26 16:21:33 | 000,000,000 | ---D | C] -- E:\Program Files (x86)\Steam
[3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ]
[1 E:\*.tmp files -> E:\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[3 E:\Windows\SysWow64\*.tmp files -> E:\Windows\SysWow64\*.tmp -> ]
[1 E:\*.tmp files -> E:\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/01/09 17:01:06 | 000,000,000 | ---- | C] () -- E:\Windows\ativpsrm.bin
[2012/01/04 18:06:52 | 000,217,088 | ---- | C] () -- E:\Windows\SysWow64\qtmlClient.dll
[2011/11/09 17:39:44 | 000,059,904 | ---- | C] () -- E:\Windows\SysWow64\OpenVideo.dll
[2011/11/09 17:39:32 | 000,054,784 | ---- | C] () -- E:\Windows\SysWow64\OVDecode.dll
[2011/10/14 19:54:52 | 000,321,856 | ---- | C] () -- E:\Windows\SysWow64\nvStreaming.exe
[2011/10/08 23:37:34 | 000,000,732 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps64.dat
[2011/09/12 19:06:16 | 000,003,917 | ---- | C] () -- E:\Windows\SysWow64\atipblag.dat
[2011/04/09 12:55:28 | 000,179,261 | ---- | C] () -- E:\Windows\SysWow64\xlive.dll.cat
[2010/12/22 18:05:26 | 000,001,356 | ---- | C] () -- E:\Users\*****\AppData\Local\d3d9caps.dat
[2010/11/27 13:56:32 | 000,000,120 | ---- | C] () -- E:\Users\*****\AppData\default.pls
[2010/06/06 14:15:17 | 000,122,992 | -H-- | C] () -- E:\Windows\SysWow64\mlfcache.dat
[2010/03/08 16:55:54 | 002,434,856 | ---- | C] () -- E:\Windows\SysWow64\pbsvc_bc2.exe
[2010/02/05 10:34:43 | 000,000,093 | ---- | C] () -- E:\Users\*****\AppData\Local\fusioncache.dat
[2009/12/09 20:29:02 | 000,052,736 | ---- | C] () -- E:\Users\*****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/22 21:00:42 | 000,000,000 | ---- | C] () -- E:\Windows\SysWow64\Access.dat
[2009/11/08 12:37:00 | 000,044,544 | ---- | C] () -- E:\Windows\SysWow64\Gif89.dll
[2009/09/27 09:13:48 | 000,000,033 | ---- | C] () -- E:\Windows\Multimedia manager.INI
[2009/01/23 18:40:27 | 000,000,056 | -H-- | C] () -- E:\Windows\SysWow64\ezsidmv.dat
[2009/01/01 12:00:39 | 000,043,520 | ---- | C] () -- E:\Windows\SysWow64\CmdLineExt03.dll
[2008/11/27 19:29:00 | 000,096,801 | ---- | C] () -- E:\Windows\War3Unin.dat
[2008/08/25 15:34:16 | 000,000,466 | RHS- | C] () -- E:\ProgramData\ntuser.pol
[2008/08/12 16:17:52 | 000,003,308 | ---- | C] () -- E:\Windows\bthservsdp.dat
[2008/08/08 15:57:05 | 000,106,605 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchema.bin
[2008/08/08 15:57:05 | 000,018,904 | ---- | C] () -- E:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/07/29 12:02:05 | 000,000,000 | ---- | C] () -- E:\ProgramData\LauncherAccess.dt
[2008/07/29 12:00:03 | 000,005,632 | ---- | C] () -- E:\Windows\SysWow64\drivers\StarOpen.sys
[2008/04/22 17:46:56 | 000,368,640 | ---- | C] () -- E:\Windows\SysWow64\msjetoledb40.dll
[2008/04/22 17:46:42 | 000,060,124 | ---- | C] () -- E:\Windows\SysWow64\tcpmon.ini
[2008/02/18 16:26:18 | 000,001,167 | ---- | C] () -- E:\Windows\mozver.dat
[2008/02/14 13:32:04 | 000,000,000 | ---- | C] () -- E:\Windows\nsreg.dat
[2008/02/12 15:46:22 | 000,214,864 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrB.exe
[2008/02/12 15:46:21 | 000,669,184 | ---- | C] () -- E:\Windows\SysWow64\pbsvc.exe
[2008/02/12 15:46:21 | 000,075,064 | ---- | C] () -- E:\Windows\SysWow64\PnkBstrA.exe
[2008/02/11 15:22:15 | 000,000,069 | ---- | C] () -- E:\Windows\NeroDigital.ini
[2007/05/19 09:22:17 | 001,499,938 | ---- | C] () -- E:\Windows\SysWow64\PerfStringBackup.INI
[2006/11/02 11:35:48 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2006/11/02 11:00:58 | 000,197,632 | ---- | C] () -- E:\Windows\SysWow64\ir32_32.dll
[2006/11/02 08:37:14 | 000,215,943 | ---- | C] () -- E:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | ---- | C] () -- E:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | ---- | C] () -- E:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
 
========== LOP Check ==========
 
[2008/02/12 08:04:51 | 000,000,000 | ---D | M] -- E:\ProgramData\Acronis
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2011/02/03 14:59:54 | 000,000,000 | ---D | M] -- E:\ProgramData\DAEMON Tools Lite
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2011/11/18 11:48:32 | 000,000,000 | ---D | M] -- E:\ProgramData\Easybits GO
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2011/05/23 07:23:38 | 000,000,000 | ---D | M] -- E:\ProgramData\HighAndes
[2012/01/04 19:05:27 | 000,000,000 | ---D | M] -- E:\ProgramData\PACE Anti-Piracy
[2011/09/23 11:31:20 | 000,000,000 | ---D | M] -- E:\ProgramData\Panasonic
[2012/02/02 19:24:32 | 000,000,000 | ---D | M] -- E:\ProgramData\PMB Files
[2010/03/15 16:13:37 | 000,000,000 | ---D | M] -- E:\ProgramData\Samsung
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2006/11/02 11:41:02 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2007/02/16 04:35:14 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2010/02/15 11:14:21 | 000,000,000 | ---D | M] -- E:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}
[2010/06/28 11:47:55 | 000,000,000 | ---D | M] -- E:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/02/02 20:09:36 | 000,032,606 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
[2012/02/02 20:05:00 | 000,000,420 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{67EDA5FC-0019-45FD-BD8F-60FFCB19790F}.job
[2012/02/02 20:07:06 | 000,000,454 | -H-- | M] () -- E:\Windows\Tasks\User_Feed_Synchronization-{FF4DA3C5-B76D-406A-8828-716AE39A637B}.job
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 128 bytes -> E:\Windows:nlsPreferences
@Alternate Data Stream - 1264 bytes -> E:\ProgramData\Microsoft:SQasxH89fAhVdXZTo4rQsa1lB8
@Alternate Data Stream - 1257 bytes -> E:\ProgramData\Microsoft:mF4IF8xPxZPwwlfGMSTyMdmOB
@Alternate Data Stream - 1241 bytes -> E:\ProgramData\Microsoft:DsK0QpZjrH4Bu7uFCcUC3mv2JNM
@Alternate Data Stream - 1237 bytes -> E:\ProgramData\Microsoft:BzN69YMHrh8PpgVkajVTf
@Alternate Data Stream - 1126 bytes -> E:\Program Files (x86)\Common Files\System:8pBA6f4chx8LvxmXGoa
@Alternate Data Stream - 1075 bytes -> E:\Users\*****\AppData\Local:Gy1L44sVjSHClQdReyzsUh8
< End of report >

Extras.txt

Code:

OTL Extras logfile created on: 10/9/2013 2:58:46 AM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files (x86)
Drive C: | 110.00 Mb Total Space | 85.88 Mb Free Space | 78.07% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 6.35 Gb Free Space | 1.36% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 313.54 Gb Free Space | 67.32% Space Free | Partition Type: NTFS
Drive F: | 7.26 Gb Total Space | 7.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive G: | 273.20 Gb Total Space | 17.53 Gb Free Space | 6.42% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- E:\Windows\System32\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- E:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 File not found
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding
"{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64)
"{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding
"{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64)
"{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\*****_ON_G\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"JNLP" = JNLP
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
< End of report >

Zwischenfrage: Ist das richtig, dass hier beim OTLPE bei Use No-Company-Name WhiteList bislang immer ein Haekchen gesetzt war? In eurer Anleitung existiert dieses Feld garnicht. Im Tutorial ist die Version 3.1.30.3, ich nutze gerade Version 3.1.48.0.

aharonov 09.10.2013 08:57

Hallo,

Zitat:

Von Security Essentials wurden unbekannte Elemente auf dem PC gefunden. (...)
Dateipfad: C:\ProgramData\4wcl7hv.plz
Das gehört eindeutig zum GVU-Sperrschirm.

Wenn FRST nicht läuft, dann versuch bitte, im Admin-Account mit OTL (nicht OTLpe..) zu scannen wie folgt:


Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
  • Doppelklick auf die OTL.exe.
  • Unter Extra Registry, wähle bitte Use SafeList.
  • Setze den Haken bei Scan all Users.
  • Klicke nun auf Run Scan.
  • Wenn der Scan beendet ist, werden 2 Logfiles (OTL.txt und Extras.txt) erstellt.
  • Poste den Inhalt dieser Logfiles hier in den Thread.

Lou Schalter 09.10.2013 18:52

Hi Leo,

hier die Logs von OTL:
(danke fürs nochmalige Erwähnen: "nicht OTLpe", sonst hätt' ich letzteres genommen)

Code:

OTL logfile created on: 09.10.2013 19:42:01 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Administrator\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
11,99 Gb Total Physical Memory | 10,13 Gb Available Physical Memory | 84,47% Memory free
23,98 Gb Paging File | 21,81 Gb Available in Paging File | 90,95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 273,20 Gb Total Space | 17,66 Gb Free Space | 6,46% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 313,53 Gb Free Space | 67,32% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 6,35 Gb Free Space | 1,36% Space Free | Partition Type: NTFS
Drive G: | 7,26 Gb Total Space | 7,26 Gb Free Space | 99,99% Space Free | Partition Type: FAT32
 
Computer Name: *****-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - File not found --
PRC - [2013.10.09 19:41:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\OTL.exe
PRC - [2013.09.15 19:53:00 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012.03.03 01:17:18 | 003,246,040 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.12.07 22:11:56 | 000,659,224 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech Gaming Software\Applets\LCDMedia.exe
PRC - [2011.04.14 11:48:32 | 001,758,208 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
PRC - [2011.03.29 16:33:08 | 000,598,312 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.03.26 00:42:04 | 000,129,648 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
PRC - [2011.03.25 23:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2011.03.21 11:06:08 | 000,248,320 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
PRC - [2010.12.11 20:17:48 | 000,358,944 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2010.10.22 03:00:00 | 000,376,832 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
PRC - [2010.06.24 01:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) -- C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
PRC - [2010.04.27 14:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
PRC - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2010.01.22 01:21:02 | 000,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2009.06.04 20:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009.05.18 14:29:16 | 003,866,624 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe
PRC - [2007.12.19 11:58:24 | 000,163,840 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.04.14 11:48:32 | 001,758,208 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
MOD - [2011.03.21 11:06:08 | 000,248,320 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
MOD - [2010.04.27 14:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2013.03.29 03:34:18 | 000,241,152 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012.06.28 10:53:00 | 004,941,768 | ---- | M] (SafeNet Inc.) [Auto | Running] -- C:\Windows\SysNative\hasplms.exe -- (hasplms)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009.06.05 18:42:04 | 000,111,616 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters)
SRV - [2013.10.08 00:48:41 | 000,060,512 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\ProgramData\vh7lcw4.pzz -- (Winmgmt)
SRV - [2013.09.19 23:45:28 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.09.15 19:53:00 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013.01.27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013.01.27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.03 01:17:18 | 003,246,040 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.03.29 16:33:08 | 000,598,312 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.03.26 00:42:16 | 000,334,448 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2011.03.26 00:42:00 | 000,404,080 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2011.03.26 00:41:50 | 000,113,264 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2011.03.25 23:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2011.03.16 11:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.12.11 20:18:12 | 001,064,584 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2010.10.22 03:00:00 | 000,376,832 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service)
SRV - [2010.08.19 14:57:14 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe -- (ufad-ws60)
SRV - [2010.06.24 01:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto | Running] -- C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.01.22 01:21:02 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2010.01.18 14:14:24 | 001,141,712 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2010.01.09 22:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.12.09 15:23:34 | 000,365,280 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.06.04 20:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013.03.29 04:35:02 | 011,658,752 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013.03.29 03:09:44 | 000,581,120 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013.02.14 13:41:10 | 000,096,768 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2013.01.20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012.11.07 09:49:58 | 000,025,600 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rzdaendpt.sys -- (rzdaendpt)
DRV:64bit: - [2012.11.07 09:49:54 | 000,023,040 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rzvkeyboard.sys -- (rzvkeyboard)
DRV:64bit: - [2012.11.07 09:49:46 | 000,113,664 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd)
DRV:64bit: - [2012.06.28 10:51:36 | 000,139,592 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aksfridge.sys -- (aksfridge)
DRV:64bit: - [2012.03.03 01:17:20 | 000,285,280 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2012.03.03 01:17:16 | 001,263,200 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm273.sys -- (tdrpman273)
DRV:64bit: - [2012.03.03 01:17:14 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2012.03.03 01:17:10 | 000,277,088 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.22 16:14:54 | 000,078,208 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aksdf.sys -- (aksdf)
DRV:64bit: - [2011.09.28 17:31:30 | 000,321,536 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hardlock.sys -- (hardlock)
DRV:64bit: - [2011.03.26 00:43:06 | 000,068,720 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2011.03.26 00:43:04 | 000,081,008 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2011.03.26 00:41:18 | 000,031,856 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2011.03.26 00:41:08 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2011.03.25 23:27:36 | 000,038,512 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2011.03.25 21:04:58 | 000,045,104 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2011.03.25 21:04:58 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.01.15 18:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010.12.17 00:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010.12.07 20:19:02 | 000,187,912 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MAudioFastTrack.sys -- (MAUSBFASTTRACK)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.10.22 03:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fwlanusb.sys -- (FWLANUSB)
DRV:64bit: - [2010.10.22 03:00:00 | 000,014,120 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avmeject.sys -- (avmeject)
DRV:64bit: - [2010.10.01 01:16:34 | 000,013,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VKbms.sys -- (VKbms)
DRV:64bit: - [2010.03.23 17:37:34 | 000,012,032 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\danew.sys -- (danewFltr)
DRV:64bit: - [2009.12.23 12:36:04 | 000,105,592 | ---- | M] (PACE Anti-Piracy, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Tpkd.sys -- (Tpkd)
DRV:64bit: - [2009.11.24 03:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009.11.24 03:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009.09.23 16:10:04 | 000,218,056 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PCTCore64.sys -- (PCTCore)
DRV:64bit: - [2009.09.16 16:26:18 | 000,331,816 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv64xx.sys -- (mv64xx)
DRV:64bit: - [2009.08.10 16:25:32 | 000,047,104 | ---- | M] (Cypress Semiconductor) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CYUSB.sys -- (CYUSB)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.05 18:42:04 | 000,475,136 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2009.06.04 19:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.03.02 00:05:32 | 000,187,392 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2005.03.29 02:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2010.08.19 14:56:38 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 62 77 37 8F B3 C3 CE 01  [binary data]
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.4: C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.7: C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.40.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
[2012.08.05 15:23:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
 
O1 HOSTS File: ([2012.07.03 21:20:32 | 000,001,401 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O1 - Hosts: 68.168.222.227 www.google-analytics.com.
O1 - Hosts: 68.168.222.227 ad-emea.doubleclick.net.
O1 - Hosts: 68.168.222.227 www.statcounter.com.
O1 - Hosts: 108.163.215.51 www.google-analytics.com.
O1 - Hosts: 108.163.215.51 ad-emea.doubleclick.net.
O1 - Hosts: 108.163.215.51 www.statcounter.com.
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Reg Error: Value error.) - {C4415769-1588-4AD6-9624-B2E69DB78D1A} - Reg Error: Value error. File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKU\S-1-5-21-1037283242-4171337582-128212150-500\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [M-Audio Taskbar Icon] C:\Windows\SysNative\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [SoundMAX] C:\Program Files (x86)\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid Technology, Inc..)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vmware-tray] C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000014 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000016 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{11598DD2-21FD-4F1A-8609-82672B95369C}: DhcpNameServer = 192.168.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6BD4187B-1E1C-4C45-B0AC-7C258A9EEF84}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BCE4204A-550C-44D7-BA0F-60B49CD5C464}: DhcpNameServer = 192.168.10.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.10.09 05:11:50 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013.10.08 20:31:48 | 000,000,000 | ---D | C] -- C:\FRST
[2013.10.08 02:03:07 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2013.10.08 02:02:10 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.10.08 02:02:10 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.10.08 02:02:09 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.10.08 02:02:09 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.10.08 02:02:08 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.10.08 02:02:08 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.10.08 02:02:07 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.10.08 02:02:07 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.10.08 02:02:07 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.10.08 02:02:06 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.10.08 02:02:06 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.10.08 02:02:06 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.10.08 02:02:05 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.10.08 02:02:05 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.10.08 02:02:05 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.10.08 01:52:51 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2013.10.08 01:51:02 | 001,472,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013.10.08 01:51:02 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2013.10.08 01:51:01 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2013.10.08 01:50:57 | 000,155,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ataport.sys
[2013.10.08 01:50:56 | 003,968,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013.10.08 01:50:55 | 005,550,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013.10.08 01:50:55 | 003,913,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013.10.08 01:50:55 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2013.10.08 01:50:55 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2013.10.08 01:50:55 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2013.10.08 01:50:55 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2013.10.08 01:50:55 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013.10.08 01:50:55 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2013.10.08 01:50:55 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2013.10.08 01:50:54 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2013.10.08 01:50:54 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2013.10.08 01:50:54 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2013.10.08 01:50:54 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2013.10.08 01:50:54 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2013.10.08 01:50:54 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013.10.08 01:50:54 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013.10.08 01:50:54 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013.10.08 01:50:54 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2013.10.08 01:50:54 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013.10.08 01:50:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013.10.08 01:50:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013.10.08 01:50:53 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2013.10.08 01:50:53 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2013.10.08 01:50:53 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2013.10.08 01:50:53 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2013.10.08 01:50:53 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013.10.08 01:50:53 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013.10.08 01:50:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013.10.08 01:50:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013.10.08 01:50:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013.10.08 01:50:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013.10.08 01:50:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013.10.08 01:50:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013.10.08 01:50:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013.10.08 01:50:53 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2013.10.08 01:50:48 | 001,888,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2013.10.08 01:50:48 | 001,620,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2013.10.08 01:50:47 | 001,217,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2013.10.08 01:50:43 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll
[2013.10.08 01:47:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2013.10.08 01:47:48 | 000,129,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSSTDFMT.DLL
[2013.10.08 01:47:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
[2013.10.08 01:47:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpywareBlaster
[2013.10.08 01:40:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2013.10.08 01:40:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013.10.08 01:40:09 | 000,868,264 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013.10.08 01:40:09 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.10.08 01:39:58 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.10.08 01:39:58 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013.10.08 01:39:58 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.10.08 01:39:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013.10.08 01:39:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013.10.08 01:24:27 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.10.08 01:18:50 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Macromedia
[2013.10.08 01:18:43 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Adobe
[2013.10.08 01:18:39 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\Threat Expert
[2013.10.08 01:15:44 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\ATI
[2013.10.08 01:15:44 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\ATI
[2013.10.08 01:15:43 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Razer
[2013.10.08 01:15:42 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\Logitech
[2013.10.08 01:15:36 | 000,000,000 | R--D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013.10.08 01:15:36 | 000,000,000 | R--D | C] -- C:\Users\Administrator\Searches
[2013.10.08 01:15:36 | 000,000,000 | R--D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013.10.08 01:15:26 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Identities
[2013.10.08 01:15:23 | 000,000,000 | R--D | C] -- C:\Users\Administrator\Contacts
[2013.10.08 01:02:37 | 000,000,000 | ---D | C] -- C:\ProgramData\VMware
[2013.10.08 00:48:36 | 000,060,512 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\vh7lcw4.pzz
 
========== Files - Modified Within 30 Days ==========
 
[2013.10.09 21:38:23 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.10.09 21:38:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.10.09 21:38:07 | 1066,737,662 | -HS- | M] () -- C:\hiberfil.sys
[2013.10.09 21:36:09 | 001,313,301 | ---- | M] () -- C:\ProgramData\vh7lcw4.pff
[2013.10.09 21:36:03 | 000,000,000 | ---- | M] () -- C:\ProgramData\vh7lcw4.ctrl
[2013.10.09 19:45:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.10.09 01:31:00 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000UA.job
[2013.10.09 01:31:00 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000Core.job
[2013.10.09 01:04:04 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.10.09 00:54:46 | 000,026,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.10.09 00:54:46 | 000,026,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.10.08 20:15:30 | 000,427,632 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.10.08 01:56:57 | 001,680,578 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.10.08 01:56:57 | 000,713,640 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.10.08 01:56:57 | 000,666,652 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.10.08 01:56:57 | 000,155,258 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.10.08 01:56:57 | 000,127,308 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.10.08 01:47:48 | 000,001,085 | ---- | M] () -- C:\Users\Public\Desktop\SpywareBlaster.lnk
[2013.10.08 01:39:54 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.10.08 01:39:53 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.10.08 01:39:53 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.10.08 01:39:52 | 000,868,264 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013.10.08 01:39:52 | 000,790,440 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013.10.08 01:39:52 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013.10.08 00:48:41 | 000,060,512 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\vh7lcw4.pzz
[2013.10.08 00:48:32 | 000,180,224 | ---- | M] () -- C:\ProgramData\4wcl7hv.plz
[2013.09.19 23:45:28 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.09.19 23:45:28 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.09.19 23:45:06 | 003,723,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013.09.15 19:53:00 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.09.15 19:52:42 | 000,281,392 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.09.15 19:52:42 | 000,281,392 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
 
========== Files Created - No Company Name ==========
 
[2013.10.08 01:47:48 | 000,001,085 | ---- | C] () -- C:\Users\Public\Desktop\SpywareBlaster.lnk
[2013.10.08 01:15:38 | 000,001,445 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.10.08 00:57:49 | 001,313,301 | ---- | C] () -- C:\ProgramData\vh7lcw4.pff
[2013.10.08 00:48:35 | 000,000,000 | ---- | C] () -- C:\ProgramData\vh7lcw4.ctrl
[2013.10.08 00:48:32 | 000,180,224 | ---- | C] () -- C:\ProgramData\4wcl7hv.plz
[2013.08.20 19:53:55 | 003,123,272 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2013.07.20 21:59:20 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2013.05.05 02:46:01 | 000,000,099 | ---- | C] () -- C:\Windows\wininit.ini
[2013.03.29 04:13:14 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.03.29 04:13:12 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.03.22 00:29:49 | 000,281,392 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.03.22 00:29:39 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.12.28 02:40:49 | 000,002,889 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.js
[2012.12.28 02:40:47 | 095,023,320 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012.11.27 01:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.10.23 01:54:10 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2012.10.23 00:45:31 | 000,076,351 | ---- | C] () -- C:\ProgramData\kuksclqtviclkhm
[2012.10.18 13:33:10 | 000,038,520 | ---- | C] () -- C:\Windows\SysWow64\RGBAcodec.dll
[2012.04.06 03:29:34 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.04.06 03:29:34 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.03.03 23:07:54 | 000,217,088 | ---- | C] () -- C:\Windows\SysWow64\qtmlClient.dll
[2012.03.02 00:19:41 | 001,685,884 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.03.02 00:10:30 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 1337 bytes -> C:\ProgramData\Microsoft:mxdZjYwDRUU9SQXpYjdCMYzUP
@Alternate Data Stream - 1283 bytes -> C:\ProgramData\Microsoft:ZdNaBsvHQikjGLGKCWNicw
@Alternate Data Stream - 1264 bytes -> C:\ProgramData\Microsoft:pkHZHlxYL9cCCjokyYftwajtsX
@Alternate Data Stream - 1217 bytes -> C:\Program Files (x86)\Common Files\microsoft shared:gnhzvPLd0sUBaw8pJEsRfHqpr
@Alternate Data Stream - 1206 bytes -> C:\Program Files (x86)\Common Files\System:PrIFGv3bUMI5Igbq0nbXopSpyk
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 1088 bytes -> C:\ProgramData\Microsoft:UQ5sVDzEmldjh7UWHKV2QyxI

< End of report >

Code:

OTL Extras logfile created on: 09.10.2013 19:42:01 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Administrator\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
11,99 Gb Total Physical Memory | 10,13 Gb Available Physical Memory | 84,47% Memory free
23,98 Gb Paging File | 21,81 Gb Available in Paging File | 90,95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 273,20 Gb Total Space | 17,66 Gb Free Space | 6,46% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 313,53 Gb Free Space | 67,32% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 6,35 Gb Free Space | 1,36% Space Free | Partition Type: NTFS
Drive G: | 7,26 Gb Total Space | 7,26 Gb Free Space | 99,99% Space Free | Partition Type: FAT32
 
Computer Name: *****-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{041BCE83-F0B9-42D1-98BE-DDB265046063}" = lport=80 | protocol=6 | dir=in | name=war thunder |
"{0805053A-2D43-46DB-B6E8-C95866660227}" = lport=443 | protocol=6 | dir=in | name=war thunder |
"{0EC80031-90A4-47C4-9AF6-50E38B75A54B}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{0F0D9157-BC97-4A28-9567-A415DE507C11}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{17C41F29-DD98-478C-A980-412CA94CA2C0}" = lport=6881 | protocol=6 | dir=in | name=war thunder |
"{1B3A2FEC-0698-4C0D-BB3D-22CAAF787117}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{21463FB6-1085-48F8-9205-48761E89DDBE}" = lport=20443 | protocol=6 | dir=in | name=war thunder |
"{2815342B-CB9F-4B0F-8C16-0836C3C21267}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2F9DF250-BCED-43F5-9F69-4722BA5895EC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{30E90380-F1DF-4901-A56C-2D139EC694D1}" = lport=33333 | protocol=6 | dir=in | name=war thunder |
"{365C43FD-1ED3-4691-BD37-225EC7E54053}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3B7B4058-3EA7-4774-A62E-1B0F20D50C6F}" = lport=27022 | protocol=6 | dir=in | name=war thunder |
"{4955C946-9F15-469B-8B89-DE4CF9D748DE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{53B88C47-6B5D-4469-AD9F-1717E374E805}" = lport=6881 | protocol=6 | dir=in | name=war thunder |
"{5AE90831-8968-482E-815E-B62FA82CA4DC}" = lport=58450 | protocol=6 | dir=in | name=pando media booster |
"{5C3E00E0-90A5-4860-97E9-01BD041CFB1F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5C9FD667-CA31-4590-8763-62C0D354001D}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{610A475D-04CE-41DC-9DB9-21DD0C4380B6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6306A43C-7079-4C06-A5FC-BDBC8E7845E8}" = lport=58450 | protocol=17 | dir=in | name=pando media booster |
"{66F3C3EC-F97B-4AB9-A52F-DE90A0FF84D2}" = lport=27022 | protocol=6 | dir=in | name=war thunder |
"{69D713A9-FEDC-4863-9FDF-A9DA627ABDF6}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{6C21A427-567D-4834-8C34-0FA68FA01E65}" = lport=33333 | protocol=6 | dir=in | name=war thunder |
"{6E91E018-6D08-4F28-B83A-F97215F2BDCA}" = lport=7850 | protocol=6 | dir=in | name=war thunder |
"{6E9FF070-27A5-4C7E-B7E5-5A26D15317D1}" = lport=8090 | protocol=6 | dir=in | name=war thunder |
"{72181C67-C0E7-4502-91B3-014CDB4FE2CA}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{838C401F-6CA0-4185-BC51-CD883082FCB5}" = lport=3478 | protocol=17 | dir=in | name=war thunder |
"{96C3713B-196C-418E-AE7C-CB84EFC9C457}" = lport=443 | protocol=6 | dir=in | name=war thunder |
"{9A0C4E94-4384-475F-84FF-583F564C38DC}" = lport=20010 | protocol=17 | dir=in | name=war thunder |
"{A05CAD94-3CE1-4AEA-AA0C-1A7A0E0BCFCB}" = lport=7850 | protocol=6 | dir=in | name=war thunder |
"{AAF928B3-6249-4ADA-96E3-5E8B463C7318}" = lport=20010 | protocol=17 | dir=in | name=war thunder |
"{ABDE700B-565F-4D3E-81EE-FED88D82F7DE}" = lport=80 | protocol=6 | dir=in | name=war thunder |
"{C8650C6D-76E7-4EFC-8344-63995A1077C6}" = lport=20443 | protocol=6 | dir=in | name=war thunder |
"{D3FAACCA-4B0B-4E1D-AE9F-18E53669AA38}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{D995391C-FB24-4D35-94B5-E6CCBB9713AB}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D9E68CE7-5CDC-4C5B-B415-80D0BBC033C5}" = lport=3478 | protocol=17 | dir=in | name=war thunder |
"{DA058CD9-40ED-43BA-A059-20E7F3CF68DA}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DB460ABC-21A0-4747-B0B8-5BFB3041AB75}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E8825B2F-13A2-4046-86B5-6A30668ECD85}" = lport=58450 | protocol=17 | dir=in | name=pando media booster |
"{EB2F7BA6-18A1-46DF-AC0D-B7DA18BA583B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F1462203-C1F7-4687-A23C-85BA2914B8EB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F1A05989-01CE-4803-80E3-37887A65FB09}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F8B62395-FFB8-4EDC-8C26-5364811074EC}" = lport=8090 | protocol=6 | dir=in | name=war thunder |
"{FA0C5556-BFA4-43A2-B3D6-DBFD37ED810F}" = lport=58450 | protocol=6 | dir=in | name=pando media booster |
"{FBEEF205-9E30-4CF0-99CE-AC321FB70BAD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01BD868C-FD52-4933-B88A-C8417DFE13BD}" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\aces.exe |
"{0275CBC9-B9BB-40D6-B2CB-059DA4F2CC7F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe |
"{031CD01C-3FB8-4A03-82B4-1B49CC5B9D85}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{049DAD6C-F750-415B-8CAF-D38814DA0F87}" = protocol=6 | dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{0513EA52-9DC4-4FB7-82D5-33AD118AFD13}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe |
"{05C72326-50DE-43C5-9CBE-29726CFE721E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{08070037-EE8D-4D55-A57B-97EAE4D4C3F8}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{0F8E0939-6F0E-43BC-A7D9-303BE8F2BB7E}" = protocol=6 | dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{113419EF-5D14-469B-AE21-CF469CB0E222}" = protocol=17 | dir=in | app=c:\program files (x86)\lightworks\lightworks.exe |
"{12917B2D-C70C-4961-9784-C9B51F489016}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3mp.exe |
"{16808560-D3CC-4BAD-8BE6-2AD598DBE107}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{1A5F6987-38B6-46D4-84DF-0C396DC3AF92}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1ADABC35-509D-429B-8CB9-69F9599C2ED0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{1B89B5D8-057C-4B2A-B2BA-CC9FFEFC3813}" = protocol=6 | dir=in | app=e:\spiele\starcraft ii\starcraft ii public test.exe |
"{1EDBC7DB-4604-49C8-8E98-FA3330750C00}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{21F34AFA-67E9-4D68-9A08-3ECD20CD353C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\aoeonline.exe |
"{2278786D-13E6-4E1F-9CAE-5946B7F92382}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{23AE1166-4F85-48E0-8835-AE3B1832A7DF}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
"{26957A25-D5B8-4D50-B427-B5E901DF06CF}" = protocol=17 | dir=in | app=e:\spiele\starcraft ii\starcraft ii.exe |
"{2828F2F1-FF4B-435A-9C1A-A43A61E22CEF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{2C0938F1-97BA-4CEE-9F1E-A4CF9D6EFA24}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war thunder\launcher.exe |
"{2ED26C03-0F60-4DB8-838C-B05D6942A7E1}" = dir=in | app=c:\windows\system32\hasplms.exe |
"{3090C7B3-06AE-416C-BF48-E08C473D38B0}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\assassinscreed3.exe |
"{336FE4D9-B5C5-433B-ACA2-48FE99F38072}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |
"{34322A03-4144-4FCF-B157-C748FEFDE7F3}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{385C7191-8E30-4D59-B368-BB5C1BEF498B}" = protocol=6 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"{43B288F5-130B-406E-A447-F17F79D32344}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{45D18C22-76C0-4176-9671-C58D88BD8F18}" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe |
"{4A88F78F-4876-4AFE-BD47-B77DEC2296F4}" = protocol=17 | dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{4CBE7146-A7E6-47CE-A1A8-B5540A3F7B51}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{4ED9F4EC-2ED8-4948-A690-740B1CC70F77}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4F09FA49-E30A-4F12-A22A-4A364DF84DE9}" = protocol=6 | dir=in | app=e:\spiele\starcraft ii\starcraft ii.exe |
"{517D58F3-7967-4A20-A21A-93DE266419AA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{51C99D30-A920-4286-B8EA-EF769339FECE}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{533B6B7F-079E-4255-BFE6-9C8895A6127E}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{562C9129-D4C2-4F77-A8D4-AE0CA62D89A1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\war thunder\launcher.exe |
"{58BB5F4C-509B-43AA-86B9-D9B224ACCA37}" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe |
"{609AACF0-4FF7-463B-9A09-55349F6F6FD6}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{627F33BA-D876-4266-8710-F86180498D0D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6350022A-7BFF-4B72-B05D-627DE0424078}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{63855988-6EC1-45DA-AAE2-66172D85BB65}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{63FFD871-9CBD-4D11-B688-872CE95B2172}" = protocol=17 | dir=in | app=c:\users\*****\appdata\local\temp\gw2.exe |
"{64B1F469-0617-41DA-B24A-C3ACF668D1A4}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\simcity\simcity\simcity.exe |
"{685E88BB-7A53-48C4-8533-E58BD32A470B}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{6B6DB0F4-33DE-4421-BE5F-A53B82945762}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6BEA41D0-7BAA-4B8D-9521-98ED5C07BEE9}" = protocol=6 | dir=in | app=c:\users\*****\appdata\local\temp\gw2.exe |
"{6C4DADBF-00D2-42C0-86DE-31A9F09853C8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{6D770FB3-9FCE-42E6-A7F6-07A812A221D6}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
"{6F708AA9-F12C-48DA-AB81-91D7E8DD3BE4}" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe |
"{717652E7-E9D8-4E28-BD0B-BD588A355D69}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\simcity\simcity\simcity.exe |
"{72C0C221-D09E-4E7C-8971-F624C329F2FC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{7343813F-51F7-45D7-A98E-8130638C9293}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{73C7AA5E-6C07-4BEB-BE46-3EF4525E1ED6}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{76BA101E-437A-4207-BC67-2A631856840C}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{7A5BD92E-60E8-4520-8AA3-22897019673C}" = protocol=17 | dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{7BA40122-01DA-4B85-A646-745159EECEA4}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe |
"{7C592E07-DB00-41F3-B551-9F1E32119350}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe |
"{814DF18C-641E-4F1E-9882-8071B5EB3EC4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{824F6E93-7DDA-4E50-A736-E940D34E4DC8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{85B9F90F-214D-4CED-801C-0F840483CE06}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{8A0A3ED0-F350-47C2-A937-C7A20B80DF6F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8BF32488-7DEE-44F9-8932-ACEDE15F92E6}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{8EFB36D1-6693-41A5-8CE0-056D27DE3655}" = protocol=17 | dir=in | app=e:\spiele\spiele\codemasters\der herr der ringe online\lotroclient.exe |
"{993BDBF9-A5A7-4302-82CE-5D661DB643A8}" = protocol=6 | dir=out | app=system |
"{9A7E9D20-B845-451C-815C-350B4C098E02}" = protocol=6 | dir=in | app=c:\program files (x86)\lightworks\lightworks.exe |
"{A2D30372-E6E7-4904-9DBB-479436C9429E}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\ac3mp.exe |
"{A33DE1A7-7E99-4034-A971-CB38223E8D17}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{A3C8F432-459F-4CC2-BE53-93C50D170876}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\company of heroes\reliccoh.exe |
"{A8F9240A-862F-4C84-92D6-0E5FC3BDE145}" = protocol=6 | dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{AACC15C5-0AC0-47C8-8016-9A674473C726}" = protocol=6 | dir=in | app=c:\program files (x86)\lightworks\ntcardvt.exe |
"{ABFF51FE-6B79-42D1-9B08-A751B800ABAA}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{ACEBA7E2-7200-44B1-920C-B2D0CE527800}" = protocol=17 | dir=in | app=e:\spiele\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"{AFD4055D-F339-414C-BB98-E0D1FA32A14D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{B2800A25-F1F6-4283-B0C2-8465D531105D}" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe |
"{B61DC346-C285-40D4-98BA-2045B6AEB7AB}" = protocol=17 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"{B62DE640-DF77-4BB3-982E-F50D044A4FBE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war ii - retribution\dow2.exe |
"{B65C42C8-1112-4D6E-B1E1-717D303883C9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{B6AC4BA6-CA25-414B-B9F2-A4F73BB2A11B}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{B972066D-7D0C-4850-8884-DBBCE549C225}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{BB1899E8-109E-4659-9A63-A1D6382EA45C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{BB45FFF7-47B0-4784-86EF-DBEE8FAD0376}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"{BCCEC534-81AF-4A8E-A43C-39B7227E373F}" = protocol=6 | dir=in | app=e:\spiele\spiele\codemasters\der herr der ringe online\lotroclient.exe |
"{BF0A0A04-B9F7-4E9C-AD0F-EBA278CD6633}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{BFB338AC-DAC6-4126-A911-49812FC824E9}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{BFE19329-87FC-4ED1-ACED-36663644AEB8}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{C0F3A06C-820D-483B-ADE2-EC6D5393A180}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{C23EC837-13D8-49EE-B9A4-CE7A4CBA51EE}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{C3E6226C-5ADA-4AA6-AA96-6158FBE622C8}" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe |
"{C4495D5B-EE5B-4481-8335-7A963D1E7924}" = protocol=17 | dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{C6CCC671-4726-4472-A5ED-76116B5BE22F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war ii - retribution\dow2.exe |
"{C71F4C5E-35A1-4B01-B759-5C46E6150102}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C783DB10-C5A0-4831-ACB8-0A19E4E91CFF}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{CAC30814-02A9-4CD3-BE40-B4CFF458BDD2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{CC3ECC34-D6EB-4084-B62C-34D7704C679A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{CDD89E04-545E-4727-9300-5FDC44B397DA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |
"{CE5602DF-7B9F-40BE-B2A4-EDA5EC5ADEBE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{CF75015E-0144-4023-923C-06F46C04CBCC}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{D09D215C-46C1-4F01-B338-ED6AAF2BBB5C}" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\aces.exe |
"{D3F88BFE-7A6D-48B4-A3F6-542B7779CA64}" = protocol=17 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{D5788B80-9F9A-40AD-8AF4-FFCB7AF9046C}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\company of heroes\reliccoh.exe |
"{DD7B4AB7-F33E-4999-B372-377ECADDE39E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DD96DCD5-A4A8-46DF-BF93-1F74871162D4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe |
"{DDFB45FF-8963-4491-9C53-CFB9927CAEB2}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{E4A5EC19-BD79-453F-90C3-522EB18FE925}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E56B7801-1C2E-4A58-930D-7A98EA4A221A}" = protocol=17 | dir=in | app=c:\program files (x86)\lightworks\ntcardvt.exe |
"{E9921D88-D850-436A-A819-94F9989F2080}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EDB12D78-262B-4031-8CB6-3DE923853FBA}" = protocol=6 | dir=in | app=c:\program files (x86)\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{F11D0917-2FAA-44D2-A4C3-0CCD38DADECD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\aoeonline.exe |
"{F12251A2-9809-4851-92EC-668D3D394601}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iii\assassinscreed3.exe |
"{F3415043-5083-4638-A372-146D50E4B1F8}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{F40F5E1C-8B56-4DE7-A7DF-7C2B30A1E022}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{F5EE74CE-2E58-41C4-82B7-17DF64A2F074}" = protocol=6 | dir=in | app=e:\spiele\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"{FB0C2BA0-FE50-4750-9E24-E71E8AEF954E}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FC9C145A-A02D-426E-84BC-E66E0DA3733D}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FCC736DC-1ED3-4BFC-A248-096608C2E0CE}" = protocol=17 | dir=in | app=e:\spiele\starcraft ii\starcraft ii public test.exe |
"{FCD5E02C-834D-4ACF-9B6F-02E8DDD27F7D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{FE9A56DC-1D68-420D-84E0-B6C07A00B448}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe |
"{FEB7362F-9909-4C1B-8841-7448E736BB01}" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\launcher.exe |
"TCP Query User{0277EAEB-C7DA-4306-B961-EB9BD1007115}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{06D130BD-7E7A-41E1-8A9C-565650BA6C2E}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"TCP Query User{139EF40A-EDBA-48A6-9F24-1A4FBB95012C}C:\users\*****\appdata\local\microsoft\windows\temporary internet files\content.ie5\7jrjab1y\diablo-iii-setup-dede.exe" = protocol=6 | dir=in | app=c:\users\*****\appdata\local\microsoft\windows\temporary internet files\content.ie5\7jrjab1y\diablo-iii-setup-dede.exe |
"TCP Query User{2FBDD666-3D9C-47A1-B4E1-B953E0EFD5CA}C:\program files (x86)\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"TCP Query User{3209600D-473D-4F8D-B37D-94E94C5F619F}C:\program files (x86)\war thunder\aces.exe" = protocol=6 | dir=in | app=c:\program files (x86)\war thunder\aces.exe |
"TCP Query User{3E28EB28-1E84-4FE4-8C79-9E8ABBB1A90F}E:\spiele\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=6 | dir=in | app=e:\spiele\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"TCP Query User{8091DD60-F51C-4B73-867C-0EBA126ECFF5}C:\users\*****\appdata\roaming\paabyw\yxeno.exe" = protocol=6 | dir=in | app=c:\users\*****\appdata\roaming\paabyw\yxeno.exe |
"TCP Query User{8374D1FF-91B9-4A66-8970-AC1B87B2BF5F}C:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe |
"TCP Query User{A14AC6B5-838E-46DA-9C72-A28EDD9137A0}C:\users\*****\appdata\roaming\rybe\pays.exe" = protocol=6 | dir=in | app=c:\users\*****\appdata\roaming\rybe\pays.exe |
"TCP Query User{A741BADC-D60A-4462-BBCB-6B250AB57B45}C:\program files (x86)\marvell\raid\apache2\bin\httpd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\marvell\raid\apache2\bin\httpd.exe |
"TCP Query User{A8AF028F-6634-4CAC-8A2A-638A99DF4D73}D:\program files (x86)\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe" = protocol=6 | dir=in | app=d:\program files (x86)\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe |
"TCP Query User{C78436BC-8D98-463D-A144-2EBDEBEDCEFA}E:\spiele\spiele\codemasters\der herr der ringe online\lotroclient.exe" = protocol=6 | dir=in | app=e:\spiele\spiele\codemasters\der herr der ringe online\lotroclient.exe |
"TCP Query User{D1032DF4-5673-428D-9C77-D45EBD65216D}C:\users\*****\appdata\local\temp\gw2.exe" = protocol=6 | dir=in | app=c:\users\*****\appdata\local\temp\gw2.exe |
"TCP Query User{FDF857FF-268E-41F6-9647-29278D088F37}C:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"UDP Query User{1779D395-10B6-44F5-8002-1BD1E854FE1A}C:\program files (x86)\war thunder\aces.exe" = protocol=17 | dir=in | app=c:\program files (x86)\war thunder\aces.exe |
"UDP Query User{4C008A4B-2271-4208-817E-23CD14707C16}C:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe |
"UDP Query User{84B6DCBD-1008-41F1-B58E-47547DCC3245}C:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"UDP Query User{88D1FC30-1D23-4F90-AA3B-22EE2A2BD08E}C:\users\*****\appdata\local\microsoft\windows\temporary internet files\content.ie5\7jrjab1y\diablo-iii-setup-dede.exe" = protocol=17 | dir=in | app=c:\users\*****\appdata\local\microsoft\windows\temporary internet files\content.ie5\7jrjab1y\diablo-iii-setup-dede.exe |
"UDP Query User{8E3F20B3-91B4-4E6A-8EFB-B9B33647F10D}C:\users\*****\appdata\local\temp\gw2.exe" = protocol=17 | dir=in | app=c:\users\*****\appdata\local\temp\gw2.exe |
"UDP Query User{A72B61F8-1873-4695-89F4-4EFBA1514353}C:\users\*****\appdata\roaming\rybe\pays.exe" = protocol=17 | dir=in | app=c:\users\*****\appdata\roaming\rybe\pays.exe |
"UDP Query User{A860AB25-5E62-4881-AA33-AB62630A233E}E:\spiele\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=17 | dir=in | app=e:\spiele\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe |
"UDP Query User{A8FC0A65-4EA9-41E5-AC53-3D4FCAC93336}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{AC261C5A-1244-4B32-B519-F3FB731AF317}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
"UDP Query User{B3DE29B2-E2EA-4367-8176-8EC66BCE62B2}C:\program files (x86)\marvell\raid\apache2\bin\httpd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\marvell\raid\apache2\bin\httpd.exe |
"UDP Query User{B47A89E3-6E80-4A7A-89C5-88842902AD4E}C:\program files (x86)\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"UDP Query User{D560999C-09BF-4943-98E2-DB9D6AFE8356}E:\spiele\spiele\codemasters\der herr der ringe online\lotroclient.exe" = protocol=17 | dir=in | app=e:\spiele\spiele\codemasters\der herr der ringe online\lotroclient.exe |
"UDP Query User{E6B865E6-9FA3-4412-B57B-6A9E6F903E4A}D:\program files (x86)\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe" = protocol=17 | dir=in | app=d:\program files (x86)\steam\steamapps\common\dc universe online\unreal3\binaries\win32\dcgame.exe |
"UDP Query User{F065CDF5-A64E-4BE4-BBC7-416D2BBBC73D}C:\users\*****\appdata\roaming\paabyw\yxeno.exe" = protocol=17 | dir=in | app=c:\users\*****\appdata\roaming\paabyw\yxeno.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding
"{02382870-19C7-3ACD-BBAE-F6E3760947DC}" = Microsoft .NET Framework 4 Extended DEU Language Pack
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1280E900-35DA-4E08-A700-B79A5B2B8532}" = Microsoft Antimalware Service DE-DE Language Pack
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding
"{57580625-C673-7FEA-8791-E84B7AAF5069}" = ccc-utility64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91A8C38A-0239-11E0-9658-189EDFD72085}" = M-Audio FastTrack Driver 6.0.6 (x64)
"{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DE-DE Language Pack
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended DEU Language Pack" = Microsoft .NET Framework 4 Extended DEU Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{02FCAA8F-59D3-4198-822E-135C61EE4F0B}" = NeroKwikMedia Help (CHM)
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{0F7A6FD0-87F5-FB5D-973C-CF604DE1BC6B}" = CCC Help Polish
"{13464292-6666-B2DB-1B0C-A3FE14DAD1F9}" = CCC Help Dutch
"{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
"{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
"{1A9BE3D6-4D53-2C9D-B77D-562D85936B91}" = CCC Help Norwegian
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{210DFA65-F805-1A2B-4F83-8E27279AE385}" = Catalyst Control Center Graphics Previews Common
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
"{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 40
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{29822CAD-C76A-0BEE-55F5-AAA524DA814F}" = CCC Help Greek
"{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
"{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{338CD56F-1CDC-CF32-33F6-DED2DF92284E}" = CCC Help French
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{371F27A1-9502-4762-AE97-1C1938B21055}" = Avid Pro Tools SE 8.0.3
"{3A1293DF-7D09-BB0F-9576-EC47EE4A9362}" = CCC Help Italian
"{46458556-5C46-79A9-A6FF-81DF1F8B2729}" = CCC Help Hungarian
"{47416F0B-6589-591E-C6F8-4235D2230B14}" = Catalyst Control Center InstallProxy
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
"{519D68B8-A768-4CDC-E4C9-B115D49CED93}" = CCC Help Norwegian
"{51D383BC-D988-8C1E-FAA1-BC5260A32A87}" = CCC Help Polish
"{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{52C7650B-B2A0-4682-BDBE-CDEFE0522F4F}" = PC VGA Camer@
"{5508128A-2C7B-46B5-81F9-58E8E8115F0B}" = AdblockIE
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{58CB9A9A-1EFB-4EA8-B50C-3097E754AC21}" = High-Definition Video Playback
"{5A883D2B-D279-0D01-6E62-B810AFD8CC62}" = Catalyst Control Center InstallProxy
"{625FC7D1-656D-1BEC-F86F-3EACAFDAA8FE}" = CCC Help English
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
"{67A4760F-9804-CCF6-C319-27840ED77924}" = CCC Help Korean
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis*True*Image*Home
"{6BE5E4A9-D88B-532D-26E6-883C32BF098A}" = CCC Help Thai
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6E0D26C1-4265-1D02-4D19-D0A8F6A463F8}" = Catalyst Control Center
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7351EEF8-9D6C-5F46-5A19-F2C7456CE132}" = CCC Help German
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79361740-EAE3-11E2-9911-B8AC6F98CCE3}" = Google Earth Plug-in
"{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DD62206-7B6C-E32E-BD11-B49B3B089D16}" = CCC Help Danish
"{7F172E34-4107-8964-6AEA-5051FFD265FF}" = CCC Help Portuguese
"{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
"{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89D05F35-933A-89C0-B935-C92BEE4229BD}" = CCC Help French
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010
"{90140000-0016-0407-0000-0000000FF1CE}_Office14.STANDARDR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010
"{90140000-0018-0407-0000-0000000FF1CE}_Office14.STANDARDR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010
"{90140000-0019-0407-0000-0000000FF1CE}_Office14.STANDARDR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010
"{90140000-001A-0407-0000-0000000FF1CE}_Office14.STANDARDR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010
"{90140000-001B-0407-0000-0000000FF1CE}_Office14.STANDARDR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-0000-0000000FF1CE}_Office14.STANDARDR_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.STANDARDR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.STANDARDR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010
"{90140000-001F-0410-0000-0000000FF1CE}_Office14.STANDARDR_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.STANDARDR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0407-1000-0000000FF1CE}_Office14.STANDARDR_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010
"{90140000-002C-0407-0000-0000000FF1CE}_Office14.STANDARDR_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010
"{90140000-006E-0407-0000-0000000FF1CE}_Office14.STANDARDR_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010
"{90140000-00A1-0407-0000-0000000FF1CE}_Office14.STANDARDR_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2010
"{91140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARDR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{959E4378-CCA1-E4E4-2425-793DA92E8D95}" = CCC Help Czech
"{96BB3C67-4EB4-9757-E0C2-C0D2FE9053B1}" = CCC Help Turkish
"{9739158D-EDED-D628-9865-1460B5A7FAE3}" = CCC Help Portuguese
"{974F4B73-2017-E174-9070-3F58F01B341F}" = CCC Help Danish
"{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
"{9809124C-0C4C-2367-7889-1E16D8EF1AAF}" = CCC Help Chinese Standard
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98E20A18-3C29-86FA-50B4-918C2B34A082}" = CCC Help Hungarian
"{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}" = Assassin's Creed(R) III v1.06
"{9E2E5EB3-DC6E-9277-E9DB-13175E7DDA39}" = CCC Help Dutch
"{A2S166A0-F031-4E27-A057-C69733219434}_is1" = TERA
"{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}" = VMware Workstation
"{A6E1EE9D-01DD-82FD-BDBC-193BCEF9FD5C}" = CCC Help Greek
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AAACC0A5-4382-04D0-C75E-0669C7B949B6}" = CCC Help Japanese
"{AB13F192-49FC-A065-F15C-746B10CC43C8}" = CCC Help Japanese
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Deutsch
"{ACEF4078-9B86-2455-E18D-34D52D37D9D5}" = CCC Help Chinese Standard
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AE548812-D611-608D-61C6-7E40F28573A2}" = CCC Help Russian
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B8010864-15F8-613B-20EF-AC35B14B3E0D}" = CCC Help Russian
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
"{BC63AEF9-1367-9F7C-5926-52E56450EDCD}" = CCC Help Spanish
"{C1342411-5A98-DE8A-5629-D0C518E1C280}" = CCC Help Finnish
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C1E2D27F-B363-588E-8859-9EF7F4EBF418}" = CCC Help Chinese Traditional
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D08B4177-5160-6B66-8934-2F9012134D61}" = CCC Help Thai
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D34A6029-FB1A-9EA8-A938-5393F82A3A00}" = CCC Help Korean
"{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
"{D76AC809-CCC1-6198-4970-A63FA5CF7DCB}" = CCC Help Swedish
"{DA675EE2-4C04-9699-0EE2-7EF9FE7AB870}" = CCC Help German
"{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
"{E06F7C95-4D68-63D9-2231-AA5F8E186FCB}" = CCC Help English
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E21A8F3C-1ACB-46B1-CE72-E9CF09549DED}" = Catalyst Control Center Localization All
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E2F52AC2-B925-C18F-E1AE-42FBD46ECAC7}" = CCC Help Czech
"{E3A09D13-4D40-3CF8-7D32-8BD55F8D1533}" = CCC Help Spanish
"{E649AC39-69C0-C6FE-0A54-4752DB5D1FD2}" = Catalyst Control Center Graphics Previews Common
"{E9463114-898C-7C2A-2C47-E9ABC63F5D43}" = CCC Help Finnish
"{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}" = Lightworks
"{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
"{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}" = Razer DeathAdder(TM) Mouse
"{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1" = War Thunder Launcher 1.0.1.199
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F2C35491-9323-3AE7-6023-6B4128045153}" = CCC Help Swedish
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}" = SimCity™
"{FC66A32F-1A57-AC5C-4F12-DAC2F4CB77A0}" = CCC Help Chinese Traditional
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"{FF10AC4D-3349-99DA-3E58-5197CEA1D833}" = CCC Help Italian
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"{FFEC93FF-C162-C0C3-B5E7-01214B0E5F2D}" = CCC Help Turkish
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVMWLANCLI" = AVM FRITZ!WLAN
"Battlelog Web Plugins" = Battlelog Web Plugins
"Browser Defender_is1" = Browser Defender 2.0.6.15
"Company of Heroes" = Company of Heroes
"Diablo III" = Diablo III
"ESN Sonar-0.70.4" = ESN Sonar
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.12.0.128
"Guild Wars 2" = Guild Wars 2
"Host OpenAL (ADI)" = Host OpenAL (ADI)
"InstallShield_{52C7650B-B2A0-4682-BDBE-CDEFE0522F4F}" = PC VGA Camer@
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.9.5 (Basic)
"mv61xxDriver" = marvell 61xx
"Office14.STANDARDR" = Microsoft Office Standard 2010
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"Security Task Manager" = Security Task Manager 1.8d
"Spyware Doctor" = Spyware Doctor 7.0
"SpywareBlaster_is1" = SpywareBlaster 5.0
"StarCraft II" = StarCraft II
"Steam App 105430" = Age of Empires Online
"Steam App 20570" = Warhammer® 40,000™: Dawn of War® II - Chaos Rising™
"Steam App 236390" = War Thunder
"Steam App 24200" = DC Universe Online
"Steam App 49520" = Borderlands 2
"Steam App 55150" = Warhammer 40,000 Space Marine
"Steam App 56400" = Warhammer® 40,000™: Dawn of War® II – Retribution™
"Steam App 570" = Dota 2
"Uplay" = Uplay
"uTorrent" = µTorrent
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 2.0.0
"VMware_Workstation" = VMware Workstation
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 24.06.2013 04:28:27 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 25.06.2013 21:48:14 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 26.06.2013 13:46:54 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 27.06.2013 16:05:45 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 28.06.2013 17:24:29 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 29.06.2013 18:14:23 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 30.06.2013 07:34:56 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 01.07.2013 14:36:42 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 02.07.2013 13:32:08 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 02.07.2013 22:25:09 | Computer Name = *****-PC | Source = WinMgmt | ID = 10
Description =
 
[ System Events ]
Error - 09.10.2013 13:44:10 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:44:40 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:45:10 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:45:40 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:46:10 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:46:40 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:47:10 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:47:40 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:48:10 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
Error - 09.10.2013 13:48:40 | Computer Name = *****-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "Windows-Verwaltungsinstrumentation" wurde mit folgendem
 Fehler beendet:  %%127
 
 
< End of report >

Info: Habe erst während des Scans festgestellt, dass Security Essentials noch aktiv war. Hätte ich das besser ausgeschaltet / soll ichs nochmal mit deaktiviertem SE scannen?

aharonov 09.10.2013 20:46

Ok, das passt. Dann im Admin-Konto weiter wie folgt:


Schritt 1

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.




Schritt 2

Starte bitte die OTL.exe.
  • Setze den Haken bei Scan all Users.
  • Drücke auf den Quick Scan Button.
  • Poste den Inhalt von OTL.txt hier in den Thread.

Lou Schalter 10.10.2013 07:32

Hi Leo,

hier die Logfiles:

Code:

ComboFix 13-10-09.01 - Administrator 10.10.2013  7:54.1.8 - x64
ausgeführt von:: c:\users\Administrator\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\4wcl7hv.plz
c:\programdata\dsgsdgdsgdsgw.pad
c:\programdata\vh7lcw4.pzz
c:\users\*****\3730873.exe
c:\users\*****\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\*****\npwmsdrm.dll
c:\windows\npwmsdrm.dll
D:\install.exe
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-09-10 bis 2013-10-10  ))))))))))))))))))))))))))))))
.
.
2013-10-10 06:00 . 2013-10-10 06:00        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-10-10 06:00 . 2013-10-10 06:00        --------        d-----w-        c:\users\*****\AppData\Local\temp
2013-10-08 22:57 . 2013-09-05 05:32        9694160        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A3B20919-56B4-444B-A0D3-C65A7F9B6497}\mpengine.dll
2013-10-08 18:31 . 2013-10-08 18:31        --------        d-----w-        C:\FRST
2013-10-08 00:03 . 2013-10-08 00:05        --------        d-----w-        c:\windows\system32\MRT
2013-10-07 23:52 . 2013-10-07 23:52        --------        d-sh--w-        c:\windows\SysWow64\%APPDATA%
2013-10-07 23:51 . 2013-07-19 01:58        2048        ----a-w-        c:\windows\system32\tzres.dll
2013-10-07 23:51 . 2013-07-19 01:41        2048        ----a-w-        c:\windows\SysWow64\tzres.dll
2013-10-07 23:51 . 2013-07-09 05:52        224256        ----a-w-        c:\windows\system32\wintrust.dll
2013-10-07 23:51 . 2013-07-09 05:46        1472512        ----a-w-        c:\windows\system32\crypt32.dll
2013-10-07 23:51 . 2013-07-09 04:52        175104        ----a-w-        c:\windows\SysWow64\wintrust.dll
2013-10-07 23:51 . 2013-07-09 04:46        1166848        ----a-w-        c:\windows\SysWow64\crypt32.dll
2013-10-07 23:51 . 2013-07-09 05:46        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2013-10-07 23:51 . 2013-07-09 05:46        139776        ----a-w-        c:\windows\system32\cryptnet.dll
2013-10-07 23:51 . 2013-07-09 04:46        140288        ----a-w-        c:\windows\SysWow64\cryptsvc.dll
2013-10-07 23:51 . 2013-07-09 04:46        103936        ----a-w-        c:\windows\SysWow64\cryptnet.dll
2013-10-07 23:47 . 2013-10-07 23:47        --------        d-----w-        c:\programdata\Licenses
2013-10-07 23:47 . 2009-03-24 10:52        129872        ----a-w-        c:\windows\SysWow64\MSSTDFMT.DLL
2013-10-07 23:47 . 2013-10-07 23:49        --------        d-----w-        c:\program files (x86)\SpywareBlaster
2013-10-07 23:40 . 2013-10-07 23:40        --------        d-----w-        c:\programdata\Oracle
2013-10-07 23:40 . 2013-10-07 23:40        --------        d-----w-        c:\program files (x86)\Common Files\Java
2013-10-07 23:40 . 2013-10-07 23:39        868264        ----a-w-        c:\windows\SysWow64\npDeployJava1.dll
2013-10-07 23:39 . 2013-10-07 23:39        96168        ----a-w-        c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-07 23:39 . 2013-10-07 23:39        --------        d-----w-        c:\program files (x86)\Java
2013-10-07 23:24 . 2013-10-07 23:25        --------        d-----w-        C:\AdwCleaner
2013-10-07 23:18 . 2013-10-07 23:18        --------        d-----w-        c:\users\Administrator\AppData\Local\Threat Expert
2013-10-07 23:15 . 2013-10-07 23:15        --------        d-----w-        c:\users\Administrator\AppData\Roaming\ATI
2013-10-07 23:15 . 2013-10-07 23:15        --------        d-----w-        c:\users\Administrator\AppData\Local\ATI
2013-10-07 23:15 . 2013-10-07 23:15        --------        d-----w-        c:\users\Administrator\AppData\Roaming\Razer
2013-10-07 23:15 . 2013-10-07 23:15        --------        d-----w-        c:\users\Administrator\AppData\Local\Logitech
2013-10-07 23:02 . 2013-10-10 06:02        --------        d-----w-        c:\programdata\VMware
2013-10-07 20:25 . 2013-09-05 05:32        9694160        ----a-w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-09-29 11:43 . 2013-09-29 12:04        --------        d-----w-        c:\users\*****\AppData\Local\SCE
2013-09-10 18:17 . 2013-09-10 18:19        --------        d-----w-        c:\users\*****\AppData\Roaming\PACE Anti-Piracy
2013-09-10 18:17 . 2013-09-10 18:17        --------        d-----w-        c:\users\*****\AppData\Local\PACE Anti-Piracy
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-10 05:45 . 2012-11-12 11:57        692616        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-10-10 05:45 . 2012-03-01 21:23        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-10 05:45 . 2012-11-12 12:45        17813896        ----a-w-        c:\windows\SysWow64\FlashPlayerInstaller.exe
2013-10-07 23:39 . 2012-03-04 16:42        790440        ----a-w-        c:\windows\SysWow64\deployJava1.dll
2013-09-15 17:53 . 2013-03-21 22:29        76888        ----a-w-        c:\windows\SysWow64\PnkBstrA.exe
2013-09-15 17:52 . 2013-03-22 21:58        281392        ----a-w-        c:\windows\SysWow64\PnkBstrB.xtr
2013-09-15 17:52 . 2013-03-21 22:29        281392        ----a-w-        c:\windows\SysWow64\PnkBstrB.exe
2013-09-06 21:37 . 2013-09-06 21:37        965008        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D63563FB-9D56-4649-8722-020D83192E35}\gapaengine.dll
2013-09-01 15:08 . 2012-03-01 21:15        79143768        ----a-w-        c:\windows\system32\MRT.exe
2013-08-22 20:33 . 2012-06-13 06:11        941720        ------w-        c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-08-20 17:54 . 2013-03-21 22:29        189248        ----a-w-        c:\windows\SysWow64\PnkBstrB.ex0
2013-08-20 09:16 . 2013-08-20 17:53        3123272        ----a-w-        c:\windows\SysWow64\pbsvc.exe
2013-08-02 01:48 . 2013-10-07 23:50        44032        ----a-w-        c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-06-05 1310720]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"vmware-tray"="c:\program files (x86)\VMware\VMware Workstation\vmware-tray.exe" [2011-03-25 129648]
"DigidesignMMERefresh"="c:\program files (x86)\Digidesign\Drivers\MMERefresh.exe" [2010-06-23 77824]
"DeathAdder"="c:\program files (x86)\Razer\DeathAdder\razerhid.exe" [2011-03-21 248320]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-28 642656]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
vh7lcw4.lnk - c:\windows\System32\rundll32.exe c:\progra~3\4wcl7hv.plz,GL300 [2009-7-14 45568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 ajlvsasx;ajlvsasx;c:\windows\system32\drivers\ajlvsasx.sys;c:\windows\SYSNATIVE\drivers\ajlvsasx.sys [x]
R1 crtjnuyc;crtjnuyc;c:\windows\system32\drivers\crtjnuyc.sys;c:\windows\SYSNATIVE\drivers\crtjnuyc.sys [x]
R1 eaarkkjg;eaarkkjg;c:\windows\system32\drivers\eaarkkjg.sys;c:\windows\SYSNATIVE\drivers\eaarkkjg.sys [x]
R1 ktmujbzd;ktmujbzd;c:\windows\system32\drivers\ktmujbzd.sys;c:\windows\SYSNATIVE\drivers\ktmujbzd.sys [x]
R1 ptqllcii;ptqllcii;c:\windows\system32\drivers\ptqllcii.sys;c:\windows\SYSNATIVE\drivers\ptqllcii.sys [x]
R1 rlffuili;rlffuili;c:\windows\system32\drivers\rlffuili.sys;c:\windows\SYSNATIVE\drivers\rlffuili.sys [x]
R1 rmtofanc;rmtofanc;c:\windows\system32\drivers\rmtofanc.sys;c:\windows\SYSNATIVE\drivers\rmtofanc.sys [x]
R1 ubqgdokm;ubqgdokm;c:\windows\system32\drivers\ubqgdokm.sys;c:\windows\SYSNATIVE\drivers\ubqgdokm.sys [x]
R1 varehocl;varehocl;c:\windows\system32\drivers\varehocl.sys;c:\windows\SYSNATIVE\drivers\varehocl.sys [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys;c:\windows\SYSNATIVE\drivers\avmeject.sys [x]
R3 CYUSB;Cypress Generic USB Driver;c:\windows\system32\Drivers\CYUSB.sys;c:\windows\SYSNATIVE\Drivers\CYUSB.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys;c:\windows\SYSNATIVE\DRIVERS\fwlanusb.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 rzdaendpt;Razer DeathAdder end point;c:\windows\system32\DRIVERS\rzdaendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzdaendpt.sys [x]
R3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys;c:\windows\SYSNATIVE\DRIVERS\rzvkeyboard.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R4 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\Spyware Doctor\pctsAuxs.exe;c:\program files (x86)\Spyware Doctor\pctsAuxs.exe [x]
S0 mv64xx;mv64xx;c:\windows\system32\DRIVERS\mv64xx.sys;c:\windows\SYSNATIVE\DRIVERS\mv64xx.sys [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys;c:\windows\SYSNATIVE\drivers\PCTCore64.sys [x]
S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys;c:\windows\SYSNATIVE\DRIVERS\tdrpm273.sys [x]
S2 afcdpsrv;Acronis Nonstop Backup-Dienst;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x]
S2 aksdf;aksdf;c:\windows\system32\drivers\aksdf.sys;c:\windows\SYSNATIVE\drivers\aksdf.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe;c:\program files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe [x]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
S2 hasplms;Sentinel Local License Manager;c:\windows\system32\hasplms.exe  -run;c:\windows\SYSNATIVE\hasplms.exe  -run [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys;c:\windows\SYSNATIVE\drivers\vmci.sys [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [x]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys;c:\windows\SYSNATIVE\drivers\danew.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MAUSBFASTTRACK;Service for M-Audio FastTrack;c:\windows\system32\DRIVERS\MAudioFastTrack.sys;c:\windows\SYSNATIVE\DRIVERS\MAudioFastTrack.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x]
S3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys;c:\windows\SYSNATIVE\DRIVERS\VKbms.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-10-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-12 05:45]
.
2013-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-21 15:25]
.
2013-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-07-21 15:25]
.
2013-10-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000Core.job
- c:\users\*****\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-05 15:30]
.
2013-10-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000UA.job
- c:\users\*****\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-05 15:30]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-04 186904]
"Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-12-11 358944]
"M-Audio Taskbar Icon"="c:\windows\system32\M-AudioTaskBarIcon.exe" [2010-12-07 798728]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-12-07 5889816]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
LSP: c:\program files (x86)\VMware\VMware Workstation\vsocklib.dll
TCP: DhcpNameServer = 192.168.2.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{C4415769-1588-4AD6-9624-B2E69DB78D1A} - (no file)
BHO-{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-VMware_Workstation - c:\programdata\VMware\VMware Workstation\Uninstaller\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1037283242-4171337582-128212150-500\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{472734EA-242A-422B-ADF8-83D1E48CC825}"=hex:51,66,7a,6c,4c,1d,3b,1b,fa,2b,35,
  5d,1a,75,4c,0c,b3,f7,c3,91,e0,ce,8a,38
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,3b,1b,0c,17,cd,
  02,9d,b9,e4,0c,bb,99,ba,17,88,6c,ff,de
"{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}"=hex:51,66,7a,6c,4c,1d,3b,1b,0b,22,1d,
  30,39,58,93,01,ac,7d,20,dc,ca,22,16,fa
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,3b,1b,72,66,62,
  49,44,3e,34,63,38,4b,60,2d,7d,00,0a,52
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,3b,1b,ab,88,06,
  6c,c0,87,4b,08,a8,e4,94,9a,f5,9b,6f,5e
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,3b,1b,74,cb,22,
  8a,32,1d,d8,04,90,c3,11,24,72,4a,21,db
"{90EFF544-3981-4D46-85C9-C0361D0931D6}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,ea,fd,
  8a,b1,68,21,03,9b,c6,80,76,19,4b,73,cb
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,3b,1b,25,b7,e1,
  ae,11,5f,3e,07,a4,2d,02,f3,04,cc,40,e2
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,3b,1b,54,1f,da,
  c1,75,f5,3c,0d,a2,7b,dc,65,c5,87,ca,b4
"{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}"=hex:51,66,7a,6c,4c,1d,3b,1b,59,34,81,
  f4,f0,84,7e,03,bd,d5,8e,48,4d,67,cf,fb
.
[HKEY_USERS\S-1-5-21-1037283242-4171337582-128212150-500\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (Administrator)
"Timestamp"=hex:35,17,e3,eb,78,c4,ce,01
.
[HKEY_USERS\S-1-5-21-1037283242-4171337582-128212150-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b8,2b,ad,d6,53,b4,4d,4f,80,97,e5,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b8,2b,ad,d6,53,b4,4d,4f,80,97,e5,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\avmwlanstick\WlanNetService.exe
c:\windows\system32\hasplms.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\VMware\VMware Workstation\vmware-authd.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
c:\program files (x86)\Razer\DeathAdder\razertra.exe
c:\program files (x86)\Razer\DeathAdder\razerofa.exe
c:\program files (x86)\Razer\DeathAdder\vdDaemon.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-10-10  08:13:37 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-10-10 06:13
.
Vor Suchlauf: 11 Verzeichnis(se), 18.532.544.512 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 20.958.351.360 Bytes frei
.
- - End Of File - - F5F1E32134A5E803033A6649432EE4E3
87D88FA4D3EFD4431866EA91949644BF

Code:

OTL logfile created on: 10.10.2013 08:17:03 - Run 2
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\Administrator\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
11,99 Gb Total Physical Memory | 10,01 Gb Available Physical Memory | 83,48% Memory free
23,98 Gb Paging File | 21,87 Gb Available in Paging File | 91,18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 273,20 Gb Total Space | 19,62 Gb Free Space | 7,18% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 313,55 Gb Free Space | 67,32% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 6,35 Gb Free Space | 1,36% Space Free | Partition Type: NTFS
Drive G: | 7,26 Gb Total Space | 7,26 Gb Free Space | 99,99% Space Free | Partition Type: FAT32
 
Computer Name: *****-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - File not found --
PRC - [2013.10.09 19:41:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Desktop\OTL.exe
PRC - [2013.09.15 19:53:00 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012.03.03 01:17:18 | 003,246,040 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.04.14 11:48:32 | 001,758,208 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
PRC - [2011.03.29 16:33:08 | 000,598,312 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011.03.26 00:42:04 | 000,129,648 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
PRC - [2011.03.26 00:41:50 | 000,113,264 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
PRC - [2011.03.25 23:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2011.03.21 11:06:08 | 000,248,320 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
PRC - [2010.12.11 20:17:48 | 000,358,944 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2010.10.22 03:00:00 | 000,376,832 | ---- | M] (AVM Berlin) -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
PRC - [2010.06.24 01:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) -- C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
PRC - [2010.04.27 14:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
PRC - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2010.01.22 01:21:02 | 000,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2009.06.04 20:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009.06.04 20:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2009.01.26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007.12.19 11:58:24 | 000,163,840 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2011.04.14 11:48:32 | 001,758,208 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
MOD - [2011.03.21 11:06:08 | 000,248,320 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
MOD - [2010.04.27 14:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2013.03.29 03:34:18 | 000,241,152 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012.06.28 10:53:00 | 004,941,768 | ---- | M] (SafeNet Inc.) [Auto | Running] -- C:\Windows\SysNative\hasplms.exe -- (hasplms)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009.06.05 18:42:04 | 000,111,616 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters)
SRV - [2013.10.10 07:45:37 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.09.15 19:53:00 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013.01.27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013.01.27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.03.03 01:17:18 | 003,246,040 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.03.29 16:33:08 | 000,598,312 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.03.26 00:42:16 | 000,334,448 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2011.03.26 00:42:00 | 000,404,080 | ---- | M] (VMware, Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2011.03.26 00:41:50 | 000,113,264 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2011.03.25 23:27:40 | 000,539,248 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2011.03.16 11:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.12.11 20:18:12 | 001,064,584 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2010.10.22 03:00:00 | 000,376,832 | ---- | M] (AVM Berlin) [Auto | Running] -- C:\Program Files (x86)\avmwlanstick\WlanNetService.exe -- (AVM WLAN Connection Service)
SRV - [2010.08.19 14:57:14 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe -- (ufad-ws60)
SRV - [2010.06.24 01:40:36 | 000,077,824 | ---- | M] (Avid Technology, Inc..) [Auto | Running] -- C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe -- (DigiRefresh)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.01.22 01:21:02 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2010.01.18 14:14:24 | 001,141,712 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2010.01.09 22:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.12.09 15:23:34 | 000,365,280 | ---- | M] (PC Tools) [Disabled | Stopped] -- C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2009.08.18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.06.04 20:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013.03.29 04:35:02 | 011,658,752 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013.03.29 03:09:44 | 000,581,120 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013.02.14 13:41:10 | 000,096,768 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2013.01.20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012.11.07 09:49:58 | 000,025,600 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rzdaendpt.sys -- (rzdaendpt)
DRV:64bit: - [2012.11.07 09:49:54 | 000,023,040 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rzvkeyboard.sys -- (rzvkeyboard)
DRV:64bit: - [2012.11.07 09:49:46 | 000,113,664 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd)
DRV:64bit: - [2012.06.28 10:51:36 | 000,139,592 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aksfridge.sys -- (aksfridge)
DRV:64bit: - [2012.03.03 01:17:20 | 000,285,280 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2012.03.03 01:17:16 | 001,263,200 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm273.sys -- (tdrpman273)
DRV:64bit: - [2012.03.03 01:17:14 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2012.03.03 01:17:10 | 000,277,088 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.11.22 16:14:54 | 000,078,208 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aksdf.sys -- (aksdf)
DRV:64bit: - [2011.09.28 17:31:30 | 000,321,536 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hardlock.sys -- (hardlock)
DRV:64bit: - [2011.03.26 00:43:06 | 000,068,720 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2011.03.26 00:43:04 | 000,081,008 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2011.03.26 00:41:18 | 000,031,856 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2011.03.26 00:41:08 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2011.03.25 23:27:36 | 000,038,512 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2011.03.25 21:04:58 | 000,045,104 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2011.03.25 21:04:58 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.01.15 18:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2010.12.17 00:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010.12.07 20:19:02 | 000,187,912 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MAudioFastTrack.sys -- (MAUSBFASTTRACK)
DRV:64bit: - [2010.11.21 05:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 05:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.10.22 03:00:00 | 000,460,800 | ---- | M] (AVM GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fwlanusb.sys -- (FWLANUSB)
DRV:64bit: - [2010.10.22 03:00:00 | 000,014,120 | ---- | M] (AVM Berlin) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avmeject.sys -- (avmeject)
DRV:64bit: - [2010.10.01 01:16:34 | 000,013,312 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VKbms.sys -- (VKbms)
DRV:64bit: - [2010.03.23 17:37:34 | 000,012,032 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\danew.sys -- (danewFltr)
DRV:64bit: - [2009.12.23 12:36:04 | 000,105,592 | ---- | M] (PACE Anti-Piracy, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Tpkd.sys -- (Tpkd)
DRV:64bit: - [2009.11.24 03:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009.11.24 03:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009.09.23 16:10:04 | 000,218,056 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PCTCore64.sys -- (PCTCore)
DRV:64bit: - [2009.09.16 16:26:18 | 000,331,816 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv64xx.sys -- (mv64xx)
DRV:64bit: - [2009.08.10 16:25:32 | 000,047,104 | ---- | M] (Cypress Semiconductor) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CYUSB.sys -- (CYUSB)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.06.05 18:42:04 | 000,475,136 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2009.06.04 19:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.03.02 00:05:32 | 000,187,392 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2005.03.29 02:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2010.08.19 14:56:38 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 23 21 02 80 C5 CE 01  [binary data]
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1037283242-4171337582-128212150-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.4: C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.7: C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.40.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
[2012.08.05 15:23:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
 
O1 HOSTS File: ([2013.10.10 08:08:06 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Reg Error: Value error.) - {C4415769-1588-4AD6-9624-B2E69DB78D1A} - Reg Error: Value error. File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKU\S-1-5-21-1037283242-4171337582-128212150-500\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [M-Audio Taskbar Icon] C:\Windows\SysNative\M-AudioTaskBarIcon.exe (Avid Technology, Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe (Avid Technology, Inc..)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vmware-tray] C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1037283242-4171337582-128212150-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1037283242-4171337582-128212150-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000014 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000016 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{11598DD2-21FD-4F1A-8609-82672B95369C}: DhcpNameServer = 192.168.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6BD4187B-1E1C-4C45-B0AC-7C258A9EEF84}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BCE4204A-550C-44D7-BA0F-60B49CD5C464}: DhcpNameServer = 192.168.10.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.10.10 08:08:09 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2013.10.10 07:51:22 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013.10.10 07:51:22 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013.10.10 07:51:22 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.10.10 07:50:19 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.10.10 07:49:12 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.10.08 20:31:48 | 000,000,000 | ---D | C] -- C:\FRST
[2013.10.08 02:03:07 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2013.10.08 01:52:51 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2013.10.08 01:47:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2013.10.08 01:47:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
[2013.10.08 01:47:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpywareBlaster
[2013.10.08 01:40:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2013.10.08 01:40:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013.10.08 01:39:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013.10.08 01:39:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013.10.08 01:24:27 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.10.08 01:18:50 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Macromedia
[2013.10.08 01:18:43 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Adobe
[2013.10.08 01:18:39 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\Threat Expert
[2013.10.08 01:15:44 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\ATI
[2013.10.08 01:15:44 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\ATI
[2013.10.08 01:15:43 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Razer
[2013.10.08 01:15:42 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\Logitech
[2013.10.08 01:15:36 | 000,000,000 | R--D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013.10.08 01:15:36 | 000,000,000 | R--D | C] -- C:\Users\Administrator\Searches
[2013.10.08 01:15:36 | 000,000,000 | R--D | C] -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013.10.08 01:15:26 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Identities
[2013.10.08 01:15:23 | 000,000,000 | R--D | C] -- C:\Users\Administrator\Contacts
[2013.10.08 01:02:37 | 000,000,000 | ---D | C] -- C:\ProgramData\VMware
 
========== Files - Modified Within 30 Days ==========
 
[2013.10.10 08:17:46 | 000,026,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.10.10 08:17:46 | 000,026,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.10.10 08:09:40 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.10.10 08:08:06 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.10.10 08:08:03 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.10.10 08:06:50 | 001,659,522 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.10.10 08:06:50 | 000,713,640 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.10.10 08:06:50 | 000,666,652 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.10.10 08:06:50 | 000,155,258 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.10.10 08:06:50 | 000,127,308 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.10.10 08:02:38 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.10.10 08:02:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.10.10 08:02:29 | 1066,737,662 | -HS- | M] () -- C:\hiberfil.sys
[2013.10.09 21:36:09 | 001,313,301 | ---- | M] () -- C:\ProgramData\vh7lcw4.pff
[2013.10.09 21:36:03 | 000,000,000 | ---- | M] () -- C:\ProgramData\vh7lcw4.ctrl
[2013.10.09 21:31:00 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000UA.job
[2013.10.09 01:31:00 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000Core.job
[2013.10.08 20:15:30 | 000,427,632 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.10.08 01:47:48 | 000,001,085 | ---- | M] () -- C:\Users\Public\Desktop\SpywareBlaster.lnk
[2013.09.15 19:53:00 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.09.15 19:52:42 | 000,281,392 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2013.09.15 19:52:42 | 000,281,392 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
 
========== Files Created - No Company Name ==========
 
[2013.10.10 07:51:22 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013.10.10 07:51:22 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013.10.10 07:51:22 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013.10.10 07:51:22 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013.10.10 07:51:22 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013.10.08 01:47:48 | 000,001,085 | ---- | C] () -- C:\Users\Public\Desktop\SpywareBlaster.lnk
[2013.10.08 01:15:38 | 000,001,445 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013.10.08 00:57:49 | 001,313,301 | ---- | C] () -- C:\ProgramData\vh7lcw4.pff
[2013.10.08 00:48:35 | 000,000,000 | ---- | C] () -- C:\ProgramData\vh7lcw4.ctrl
[2013.08.20 19:53:55 | 003,123,272 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2013.07.20 21:59:20 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2013.05.05 02:46:01 | 000,000,099 | ---- | C] () -- C:\Windows\wininit.ini
[2013.03.29 04:13:14 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.03.29 04:13:12 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.03.22 00:29:49 | 000,281,392 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.03.22 00:29:39 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012.11.27 01:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.10.23 01:54:10 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2012.10.23 00:45:31 | 000,076,351 | ---- | C] () -- C:\ProgramData\kuksclqtviclkhm
[2012.10.18 13:33:10 | 000,038,520 | ---- | C] () -- C:\Windows\SysWow64\RGBAcodec.dll
[2012.04.06 03:29:34 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.04.06 03:29:34 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.03.03 23:07:54 | 000,217,088 | ---- | C] () -- C:\Windows\SysWow64\qtmlClient.dll
[2012.03.02 00:19:41 | 001,685,884 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.03.02 00:10:30 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.10.08 01:15:43 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Razer
[2013.06.16 23:43:52 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\.minecraft
[2012.03.03 01:32:34 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Acronis
[2013.09.10 20:42:40 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Digidesign
[2013.02.17 16:34:29 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\DVDVideoSoft
[2012.03.04 00:51:27 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LolClient
[2012.06.14 14:31:52 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\LolClient2
[2013.08.01 00:21:08 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Origin
[2013.09.10 20:19:25 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\PACE Anti-Piracy
[2012.03.03 23:11:50 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\Razer
[2013.10.08 00:28:44 | 000,000,000 | ---D | M] -- C:\Users\*****\AppData\Roaming\TS3Client
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 1337 bytes -> C:\ProgramData\Microsoft:mxdZjYwDRUU9SQXpYjdCMYzUP
@Alternate Data Stream - 1283 bytes -> C:\ProgramData\Microsoft:ZdNaBsvHQikjGLGKCWNicw
@Alternate Data Stream - 1264 bytes -> C:\ProgramData\Microsoft:pkHZHlxYL9cCCjokyYftwajtsX
@Alternate Data Stream - 1217 bytes -> C:\Program Files (x86)\Common Files\microsoft shared:gnhzvPLd0sUBaw8pJEsRfHqpr
@Alternate Data Stream - 1206 bytes -> C:\Program Files (x86)\Common Files\System:PrIFGv3bUMI5Igbq0nbXopSpyk
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 1088 bytes -> C:\ProgramData\Microsoft:UQ5sVDzEmldjh7UWHKV2QyxI

< End of report >

Und hier mal die bei "Erkanntes Element" in Microsoft Security Essentials aufgeführten letzten Positionen (hatte SE ausgeschaltet, dabei waren mir die Einträge aufgefallen. Steht bestimmt auch irgendwo in den Logs, aber schaden kanns ja nicht ^^):

Code:

09.10. Trojan:JS/Reveton.A
08.10. Trojan:Win32/Reveton.V
08.10. Trojan:Win32/Reveton.V (Eintrag doppelt)
06.10. Exploit:Java/CVE-2013-2465

und bei "unter Quarantäne gestellte Elemente":

09.10.13 Trojan:JS/Reveton.A
08.10.13 Trojan:Win32/Reveton.V
05.05.13 Trojan:Win32/Urausy.C
21.03.13 PWS:Win32/Zbot
18.03.13 Exploit:Win64/Anogre.gen!A
26.02.13 Exploit:Win64/Anogre.gen!A
23.02.13 Exploit:Win64/Anogre.gen!A
18.01.13 Exploit:Win64/Anogre.gen!A
06.01.13 Trojan:Win32/Meredrop
28.12.12 Trojan:Win32/Reveton!Ink (jeweils unterschiedliche Uhrzeiten)
28.12.12 Trojan:Win32/Reveton!Ink
28.12.12 Trojan:Win32/Reveton!Ink
28.12.12 Trojan:Win32/Reveton!Ink
28.12.12 Trojan:Win32/Reveton!Ink


aharonov 10.10.2013 09:36

Hi,

ich seh da einen Hinweis im Log, dass auch noch ein Bootkit (schätzungsweise Wistler; ein Befall des MBR = Masterbootsektors) vorliegt... Dem müssen wir danach auch unbedingt noch nachgehen.
Aber zuerst zum Sperrbildschirm: Mach bitte folgenden OTL-Fix im Admin-Konto. Kannst du danach den Rechner wieder normal in das betroffene Benutzerkonto starten, ohne dass dir irgendwas den Weg versperrt?


  • Starte bitte die OTL.exe.
  • Kopiere nun den folgenden Inhalt aus der Codebox in die http://larusso.trojaner-board.de/Images/otlfix.jpg Textbox.
    Wichtig: Falls du deinen Benutzernamen im Log unkenntlich gemacht hast (z.B. durch *****), dann mach das hier im Skript wieder rückgängig.
Code:

:OTL
[2013.10.09 21:36:09 | 001,313,301 | ---- | M] () -- C:\ProgramData\vh7lcw4.pff
[2013.10.09 21:36:03 | 000,000,000 | ---- | M] () -- C:\ProgramData\vh7lcw4.ctrl
[2012.10.23 00:45:31 | 000,076,351 | ---- | C] () -- C:\ProgramData\kuksclqtviclkhm
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 1337 bytes -> C:\ProgramData\Microsoft:mxdZjYwDRUU9SQXpYjdCMYzUP
@Alternate Data Stream - 1283 bytes -> C:\ProgramData\Microsoft:ZdNaBsvHQikjGLGKCWNicw
@Alternate Data Stream - 1264 bytes -> C:\ProgramData\Microsoft:pkHZHlxYL9cCCjokyYftwajtsX
@Alternate Data Stream - 1217 bytes -> C:\Program Files (x86)\Common Files\microsoft shared:gnhzvPLd0sUBaw8pJEsRfHqpr
@Alternate Data Stream - 1206 bytes -> C:\Program Files (x86)\Common Files\System:PrIFGv3bUMI5Igbq0nbXopSpyk
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 1088 bytes -> C:\ProgramData\Microsoft:UQ5sVDzEmldjh7UWHKV2QyxI

:files
c:\users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vh7lcw4.lnk

:commands
[emptytemp]

  • Schliesse nun bitte alle anderen Programme.
  • Klicke jetzt auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Diesen bitte zulassen.
  • Nach dem Neustart findest du ein Textdokument auf deinem Desktop.
    (Auch zu finden unter C:\_OTL\MovedFiles\<date_time>.log)
  • Kopiere nun dessen Inhalt hier in deinen Thread.

Lou Schalter 10.10.2013 19:21

Hier der Log vom OTL Fix:

Code:

All processes killed
========== OTL ==========
C:\ProgramData\vh7lcw4.pff moved successfully.
C:\ProgramData\vh7lcw4.ctrl moved successfully.
C:\ProgramData\kuksclqtviclkhm moved successfully.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
ADS C:\ProgramData\Microsoft:mxdZjYwDRUU9SQXpYjdCMYzUP deleted successfully.
ADS C:\ProgramData\Microsoft:ZdNaBsvHQikjGLGKCWNicw deleted successfully.
ADS C:\ProgramData\Microsoft:pkHZHlxYL9cCCjokyYftwajtsX deleted successfully.
ADS C:\Program Files (x86)\Common Files\microsoft shared:gnhzvPLd0sUBaw8pJEsRfHqpr deleted successfully.
ADS C:\Program Files (x86)\Common Files\System:PrIFGv3bUMI5Igbq0nbXopSpyk deleted successfully.
ADS C:\ProgramData\TEMP:5C321E34 deleted successfully.
ADS C:\ProgramData\TEMP:A8ADE5D8 deleted successfully.
ADS C:\ProgramData\Microsoft:UQ5sVDzEmldjh7UWHKV2QyxI deleted successfully.
========== FILES ==========
c:\users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vh7lcw4.lnk moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 18806 bytes
->Temporary Internet Files folder emptied: 225863737 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 1783 bytes
 
User: All Users
 
User: *****
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1392778 bytes
->Java cache emptied: 2455154 bytes
->Google Chrome cache emptied: 225237102 bytes
->Flash cache emptied: 10983 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8410484 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67765 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 442,00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 10102013_201521

Files\Folders moved on Reboot...
C:\Users\Administrator\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C50ECY5D\142714-gvu-trojaner-windows-7-64-bit-2[1].htm moved successfully.
C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2476.log moved successfully.
File move failed. C:\Windows\temp\TmpFile1 scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

EDIT:

Jawoll, bin jetzt wieder unter dem normalen Benutzer angemeldet. :)

aharonov 10.10.2013 20:13

Ok, dann ab jetzt im betroffenen Konto weitermachen:


Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Lou Schalter 10.10.2013 20:17

Er frägt mich ob ich von Version 2.8.13.0 auf Version 3.0.0.12 updaten will. Denke das dürfte nix schaden, ich update mal.

aharonov 10.10.2013 20:18

Ja lass ihn updaten. :)

Lou Schalter 10.10.2013 20:25

Da gibts bei "Additional options" ein Feld mehr als in der Anleitung.

Also neben

-Verify file digital signatures
-Detect TDLFS file system

ist da noch

-Use KSN to scan objects (ist serienmäßig ein Häkchen gesetzt)

Soll ich das auch lassen?

aharonov 10.10.2013 20:56

Ja lass den Haken dort stehen und starte den Scan.

Lou Schalter 10.10.2013 21:00

Super, danke. Wollte nichts falsch machen, da hab' ich lieber mal auf deine Antwort gewartet bevor ich was klicke :D.

Hier die Logdatei:

Code:

21:20:34.0181 0x1234  TDSS rootkit removing tool 3.0.0.12 Oct  9 2013 14:59:22
21:20:34.0467 0x1234  ============================================================
21:20:34.0467 0x1234  Current date / time: 2013/10/10 21:20:34.0467
21:20:34.0467 0x1234  SystemInfo:
21:20:34.0467 0x1234 
21:20:34.0467 0x1234  OS Version: 6.1.7601 ServicePack: 1.0
21:20:34.0467 0x1234  Product type: Workstation
21:20:34.0467 0x1234  ComputerName: *****-PC
21:20:34.0468 0x1234  UserName: *****
21:20:34.0468 0x1234  Windows directory: C:\Windows
21:20:34.0468 0x1234  System windows directory: C:\Windows
21:20:34.0468 0x1234  Running under WOW64
21:20:34.0468 0x1234  Processor architecture: Intel x64
21:20:34.0468 0x1234  Number of processors: 8
21:20:34.0468 0x1234  Page size: 0x1000
21:20:34.0468 0x1234  Boot type: Normal boot
21:20:34.0468 0x1234  ============================================================
21:20:35.0518 0x1234  System UUID: {438E91DF-0BCC-791E-3945-FA16759C1496}
21:20:35.0838 0x1234  Drive \Device\Harddisk2\DR2 - Size: 0x4453C00000 (273.31 Gb), SectorSize: 0x200, Cylinders: 0x8B5E, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000048
21:20:35.0857 0x1234  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:20:35.0858 0x1234  Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:20:35.0866 0x1234  Drive \Device\Harddisk3\DR3 - Size: 0x1D1A00000 (7.28 Gb), SectorSize: 0x200, Cylinders: 0x3B5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:20:35.0869 0x1234  ============================================================
21:20:35.0869 0x1234  \Device\Harddisk2\DR2:
21:20:35.0869 0x1234  MBR partitions:
21:20:35.0869 0x1234  \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x37000
21:20:35.0869 0x1234  \Device\Harddisk2\DR2\Partition2: MBR, Type 0x7, StartLBA 0x37800, BlocksNum 0x22266800
21:20:35.0869 0x1234  \Device\Harddisk0\DR0:
21:20:35.0869 0x1234  MBR partitions:
21:20:35.0869 0x1234  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
21:20:35.0869 0x1234  \Device\Harddisk1\DR1:
21:20:35.0870 0x1234  MBR partitions:
21:20:35.0870 0x1234  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
21:20:35.0870 0x1234  \Device\Harddisk3\DR3:
21:20:35.0871 0x1234  MBR partitions:
21:20:35.0871 0x1234  \Device\Harddisk3\DR3\Partition1: MBR, Type 0xB, StartLBA 0xB88, BlocksNum 0xE8C478
21:20:35.0871 0x1234  ============================================================
21:20:35.0890 0x1234  C: <-> \Device\Harddisk2\DR2\Partition2
21:20:35.0921 0x1234  E: <-> \Device\Harddisk0\DR0\Partition1
21:20:35.0939 0x1234  D: <-> \Device\Harddisk1\DR1\Partition1
21:20:35.0939 0x1234  ============================================================
21:20:35.0939 0x1234  Initialize success
21:20:35.0939 0x1234  ============================================================
21:57:09.0819 0x0968  ============================================================
21:57:09.0819 0x0968  Scan started
21:57:09.0819 0x0968  Mode: Manual; SigCheck; TDLFS;
21:57:09.0819 0x0968  ============================================================
21:57:09.0819 0x0968  KSN ping started
21:57:12.0572 0x0968  KSN ping finished: true
21:57:12.0984 0x0968  ================ Scan system memory ========================
21:57:12.0984 0x0968  System memory - ok
21:57:12.0985 0x0968  ================ Scan services =============================
21:57:13.0108 0x0968  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
21:57:13.0163 0x0968  1394ohci - ok
21:57:13.0181 0x0968  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
21:57:13.0202 0x0968  ACPI - ok
21:57:13.0214 0x0968  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
21:57:13.0237 0x0968  AcpiPmi - ok
21:57:13.0300 0x0968  [ 1FE7229F34038D1ABE837688EC0EF15B, BEDCCCC47285DC7B8D43A6F8B69347E53E4165E30C684503D6A8FDAE191D0ABF ] AcrSch2Svc      C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
21:57:13.0335 0x0968  AcrSch2Svc - ok
21:57:13.0362 0x0968  [ 1C090E86AFD15231377AD37436C3C719, 7C8C679ADB7AF0A965508012C4F3F2FA68D0BFE0E04941B94693D94DB0931B53 ] ADIHdAudAddService C:\Windows\system32\drivers\ADIHdAud.sys
21:57:13.0395 0x0968  ADIHdAudAddService - ok
21:57:13.0429 0x0968  [ 62B7936F9036DD6ED36E6A7EFA805DC0, C58EA1B46CB3595386C9217A7785F2A436916FB1E0BDC0E4BE484292C55AA455 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:57:13.0437 0x0968  AdobeARMservice - ok
21:57:13.0512 0x0968  [ A283108E14F3970432C21AF4C0CB1BCE, 1D3219EF916D54232838870EDE557296AACB714B456ED0AAE0DE3CE3822F4643 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:57:13.0528 0x0968  AdobeFlashPlayerUpdateSvc - ok
21:57:13.0556 0x0968  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
21:57:13.0579 0x0968  adp94xx - ok
21:57:13.0597 0x0968  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci        C:\Windows\system32\drivers\adpahci.sys
21:57:13.0616 0x0968  adpahci - ok
21:57:13.0628 0x0968  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
21:57:13.0641 0x0968  adpu320 - ok
21:57:13.0653 0x0968  [ 3BDB13C79CC8C06E2F8182595903ED69, 9E00D6649E862DE6812718B091C350E05A2C5C4D28DE8E05E3DD1F789A04EE96 ] AEADIFilters    C:\Windows\system32\AEADISRV.EXE
21:57:13.0676 0x0968  AEADIFilters - ok
21:57:13.0690 0x0968  [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
21:57:13.0723 0x0968  AeLookupSvc - ok
21:57:13.0744 0x0968  [ AE1FCE2CD1E99BEA89183BA8CD320872, 96F14BCA0C2479F39A5027A71922907D0F35CAD8E9A5037674DF7995BBDB2B51 ] afcdp          C:\Windows\system32\DRIVERS\afcdp.sys
21:57:13.0762 0x0968  afcdp - ok
21:57:13.0846 0x0968  [ AF44F7E027037628F1FAC3C13CDE73E6, 56A95EBF2241C275FD401487C5F0E86859F8637D8B1BD01B7157EE9BC22B1907 ] afcdpsrv        C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
21:57:13.0936 0x0968  afcdpsrv - ok
21:57:13.0972 0x0968  [ 1C7857B62DE5994A75B054A9FD4C3825, 83F963D7E636532B1AD30B1E727EC429317CA540F6EB3BB268FCC0B163B67767 ] AFD            C:\Windows\system32\drivers\afd.sys
21:57:14.0001 0x0968  AFD - ok
21:57:14.0009 0x0968  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\drivers\agp440.sys
21:57:14.0021 0x0968  agp440 - ok
21:57:14.0039 0x0968  ajlvsasx - ok
21:57:14.0052 0x0968  [ 44F360B65C37A42EB5B71C2E5179FDD5, A7E65515FEE1698C96F647111F5C7D009C5FAC9A1F62D027802861A699AF1F93 ] aksdf          C:\Windows\system32\drivers\aksdf.sys
21:57:14.0077 0x0968  aksdf - ok
21:57:14.0119 0x0968  [ BC61697103C9EFC3DBA83777CEA8E76B, 15F55C9E4ACB695A5A9BEF52D69AFE9D8D50F8307B81349FB4300368B52493D3 ] aksfridge      C:\Windows\system32\drivers\aksfridge.sys
21:57:14.0131 0x0968  aksfridge - ok
21:57:14.0148 0x0968  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG            C:\Windows\System32\alg.exe
21:57:14.0172 0x0968  ALG - ok
21:57:14.0193 0x0968  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
21:57:14.0203 0x0968  aliide - ok
21:57:14.0229 0x0968  [ 310F86335B0505DDC6D2DD48E66EF06B, 936273CA046B3AE0944E6C1557CECB2A0C61D034977BBB9FACBE062617CF3A2C ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
21:57:14.0260 0x0968  AMD External Events Utility - ok
21:57:14.0275 0x0968  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
21:57:14.0285 0x0968  amdide - ok
21:57:14.0301 0x0968  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
21:57:14.0325 0x0968  AmdK8 - ok
21:57:14.0586 0x0968  [ 79CC9BE187E3144E1B58A54B842475E7, 89DD3177B5CE649AC0093603CE13FBFD93AC24F8E16C52672549110141106F4A ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
21:57:14.0941 0x0968  amdkmdag - ok
21:57:14.0975 0x0968  [ 07561D3B7FD99F6E186C49C2D0628E38, D2D72EB45EAD29A3099C040E99A4F1F4902D3BDC0466800C63ECD33343DC1224 ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
21:57:15.0020 0x0968  amdkmdap - ok
21:57:15.0033 0x0968  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
21:57:15.0051 0x0968  AmdPPM - ok
21:57:15.0074 0x0968  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
21:57:15.0086 0x0968  amdsata - ok
21:57:15.0100 0x0968  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
21:57:15.0115 0x0968  amdsbs - ok
21:57:15.0123 0x0968  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata        C:\Windows\system32\drivers\amdxata.sys
21:57:15.0132 0x0968  amdxata - ok
21:57:15.0149 0x0968  [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644ED2E50CF9BB491A ] AppID          C:\Windows\system32\drivers\appid.sys
21:57:15.0182 0x0968  AppID - ok
21:57:15.0191 0x0968  [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
21:57:15.0228 0x0968  AppIDSvc - ok
21:57:15.0239 0x0968  [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo        C:\Windows\System32\appinfo.dll
21:57:15.0259 0x0968  Appinfo - ok
21:57:15.0268 0x0968  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt        C:\Windows\System32\appmgmts.dll
21:57:15.0289 0x0968  AppMgmt - ok
21:57:15.0297 0x0968  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc            C:\Windows\system32\drivers\arc.sys
21:57:15.0308 0x0968  arc - ok
21:57:15.0316 0x0968  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\drivers\arcsas.sys
21:57:15.0328 0x0968  arcsas - ok
21:57:15.0369 0x0968  aspnet_state - ok
21:57:15.0383 0x0968  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
21:57:15.0416 0x0968  AsyncMac - ok
21:57:15.0439 0x0968  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi          C:\Windows\system32\drivers\atapi.sys
21:57:15.0449 0x0968  atapi - ok
21:57:15.0473 0x0968  [ ED3A041014FBBFDC23D6C04F9C7A5D79, A039D8F4C0EA2101898A253E13DFED5FA8500C412ACC47835415E27C9BD068FF ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
21:57:15.0496 0x0968  AtiHDAudioService - ok
21:57:15.0523 0x0968  [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:57:15.0577 0x0968  AudioEndpointBuilder - ok
21:57:15.0594 0x0968  [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
21:57:15.0635 0x0968  AudioSrv - ok
21:57:15.0669 0x0968  [ C6F4C466B654C1BE98AF31418BB5AC30, 62AA4456F8E22A6E508EB44DE4309615057117AAF923C13BBED15AA39630E76B ] AVM WLAN Connection Service C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
21:57:15.0690 0x0968  AVM WLAN Connection Service - detected UnsignedFile.Multi.Generic ( 1 )
21:57:18.0107 0x0968  Detect skipped due to KSN trusted
21:57:18.0107 0x0968  AVM WLAN Connection Service - ok
21:57:18.0123 0x0968  [ 1DC2F715792CF33428AD7993ACBD224D, 129FBD517E016914CD61C35894C0B9B2074E680F1EB21201597E5C13CAF4529F ] avmeject        C:\Windows\system32\drivers\avmeject.sys
21:57:18.0133 0x0968  avmeject - ok
21:57:18.0148 0x0968  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\Windows\System32\AxInstSV.dll
21:57:18.0172 0x0968  AxInstSV - ok
21:57:18.0190 0x0968  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv        C:\Windows\system32\drivers\bxvbda.sys
21:57:18.0220 0x0968  b06bdrv - ok
21:57:18.0233 0x0968  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
21:57:18.0261 0x0968  b57nd60a - ok
21:57:18.0270 0x0968  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
21:57:18.0285 0x0968  BDESVC - ok
21:57:18.0289 0x0968  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
21:57:18.0322 0x0968  Beep - ok
21:57:18.0352 0x0968  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE            C:\Windows\System32\bfe.dll
21:57:18.0400 0x0968  BFE - ok
21:57:18.0426 0x0968  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\system32\qmgr.dll
21:57:18.0479 0x0968  BITS - ok
21:57:18.0487 0x0968  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
21:57:18.0506 0x0968  blbdrive - ok
21:57:18.0520 0x0968  [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
21:57:18.0539 0x0968  bowser - ok
21:57:18.0546 0x0968  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
21:57:18.0564 0x0968  BrFiltLo - ok
21:57:18.0571 0x0968  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
21:57:18.0584 0x0968  BrFiltUp - ok
21:57:18.0595 0x0968  [ 5C2F352A4E961D72518261257AAE204B, 9EE1001E1D46A414A7A86FE1DBBE232203E26F54D9EF43ED31ED8EACD4D09853 ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
21:57:18.0625 0x0968  BridgeMP - ok
21:57:18.0640 0x0968  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser        C:\Windows\System32\browser.dll
21:57:18.0659 0x0968  Browser - ok
21:57:18.0703 0x0968  [ 21FA3E51618FF8E2F4B29964ABC5884F, AB6E5ACEBC426354C7CD7D297D8D2CA086755F0E410320CA15B989E8963ECC78 ] Browser Defender Update Service C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
21:57:18.0713 0x0968  Browser Defender Update Service - ok
21:57:18.0725 0x0968  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
21:57:18.0755 0x0968  Brserid - ok
21:57:18.0761 0x0968  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
21:57:18.0780 0x0968  BrSerWdm - ok
21:57:18.0787 0x0968  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
21:57:18.0809 0x0968  BrUsbMdm - ok
21:57:18.0816 0x0968  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
21:57:18.0834 0x0968  BrUsbSer - ok
21:57:18.0843 0x0968  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
21:57:18.0863 0x0968  BTHMODEM - ok
21:57:18.0874 0x0968  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv        C:\Windows\system32\bthserv.dll
21:57:18.0903 0x0968  bthserv - ok
21:57:18.0913 0x0968  catchme - ok
21:57:18.0932 0x0968  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
21:57:18.0973 0x0968  cdfs - ok
21:57:18.0983 0x0968  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
21:57:19.0000 0x0968  cdrom - ok
21:57:19.0009 0x0968  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc    C:\Windows\System32\certprop.dll
21:57:19.0047 0x0968  CertPropSvc - ok
21:57:19.0055 0x0968  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\drivers\circlass.sys
21:57:19.0073 0x0968  circlass - ok
21:57:19.0091 0x0968  [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS            C:\Windows\system32\CLFS.sys
21:57:19.0112 0x0968  CLFS - ok
21:57:19.0135 0x0968  [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:57:19.0145 0x0968  clr_optimization_v2.0.50727_32 - ok
21:57:19.0180 0x0968  [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:57:19.0190 0x0968  clr_optimization_v2.0.50727_64 - ok
21:57:19.0245 0x0968  [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:57:19.0256 0x0968  clr_optimization_v4.0.30319_32 - ok
21:57:19.0305 0x0968  [ C6F9AF94DCD58122A4D7E89DB6BED29D, CB0E5AE60EC76323585FB86D89E8DB7ADB5EDF6EA3D0B27E9ECE75B8CAA8BFDE ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:57:19.0318 0x0968  clr_optimization_v4.0.30319_64 - ok
21:57:19.0345 0x0968  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
21:57:19.0380 0x0968  CmBatt - ok
21:57:19.0390 0x0968  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
21:57:19.0401 0x0968  cmdide - ok
21:57:19.0422 0x0968  [ 9AC4F97C2D3E93367E2148EA940CD2CD, 530E089E5CF868AECDB2B5548EBE76E0CA98FC74A72897292AB2485734402E3B ] CNG            C:\Windows\system32\Drivers\cng.sys
21:57:19.0456 0x0968  CNG - ok
21:57:19.0463 0x0968  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
21:57:19.0473 0x0968  Compbatt - ok
21:57:19.0481 0x0968  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
21:57:19.0503 0x0968  CompositeBus - ok
21:57:19.0506 0x0968  COMSysApp - ok
21:57:19.0517 0x0968  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
21:57:19.0531 0x0968  crcdisk - ok
21:57:19.0538 0x0968  crtjnuyc - ok
21:57:19.0560 0x0968  [ 6B400F211BEE880A37A1ED0368776BF4, 2F27C6FA96A1C8CBDA467846DA57E63949A7EA37DB094B13397DDD30114295BD ] CryptSvc        C:\Windows\system32\cryptsvc.dll
21:57:19.0584 0x0968  CryptSvc - ok
21:57:19.0602 0x0968  [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC            C:\Windows\system32\drivers\csc.sys
21:57:19.0634 0x0968  CSC - ok
21:57:19.0657 0x0968  [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService      C:\Windows\System32\cscsvc.dll
21:57:19.0695 0x0968  CscService - ok
21:57:19.0713 0x0968  [ 8EC96B753727B380089D66D4AB5869DF, F8E36B68EED9680291610C83E7DF16A04D278E3E7BC807CF8A870D01C4E5A95E ] CYUSB          C:\Windows\system32\Drivers\CYUSB.sys
21:57:19.0728 0x0968  CYUSB - ok
21:57:19.0742 0x0968  [ 003626F7CA17C204F16CD5047AF0703A, BA9063D77A60AF1107A1A6B3C1DD6F1EF3D9DCE7616BAC67DF13AEDD67B683F3 ] danewFltr      C:\Windows\system32\drivers\danew.sys
21:57:19.0757 0x0968  danewFltr - ok
21:57:19.0778 0x0968  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch      C:\Windows\system32\rpcss.dll
21:57:19.0826 0x0968  DcomLaunch - ok
21:57:19.0842 0x0968  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc      C:\Windows\System32\defragsvc.dll
21:57:19.0878 0x0968  defragsvc - ok
21:57:19.0890 0x0968  [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
21:57:19.0925 0x0968  DfsC - ok
21:57:19.0941 0x0968  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
21:57:19.0970 0x0968  Dhcp - ok
21:57:19.0981 0x0968  DigiRefresh - ok
21:57:19.0989 0x0968  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
21:57:20.0022 0x0968  discache - ok
21:57:20.0034 0x0968  [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk            C:\Windows\system32\drivers\disk.sys
21:57:20.0045 0x0968  Disk - ok
21:57:20.0055 0x0968  [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc          C:\Windows\system32\drivers\dmvsc.sys
21:57:20.0074 0x0968  dmvsc - ok
21:57:20.0087 0x0968  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
21:57:20.0109 0x0968  Dnscache - ok
21:57:20.0122 0x0968  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc        C:\Windows\System32\dot3svc.dll
21:57:20.0158 0x0968  dot3svc - ok
21:57:20.0173 0x0968  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS            C:\Windows\system32\dps.dll
21:57:20.0209 0x0968  DPS - ok
21:57:20.0217 0x0968  [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
21:57:20.0230 0x0968  drmkaud - ok
21:57:20.0265 0x0968  [ AF2E16242AA723F68F461B6EAE2EAD3D, 3973633C6D231DB8D92DE310D3A0836C64639B9A20C6C56385FB218A707C1BC3 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
21:57:20.0292 0x0968  DXGKrnl - ok
21:57:20.0296 0x0968  eaarkkjg - ok
21:57:20.0314 0x0968  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost        C:\Windows\System32\eapsvc.dll
21:57:20.0345 0x0968  EapHost - ok
21:57:20.0424 0x0968  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv          C:\Windows\system32\drivers\evbda.sys
21:57:20.0530 0x0968  ebdrv - ok
21:57:20.0542 0x0968  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] EFS            C:\Windows\System32\lsass.exe
21:57:20.0559 0x0968  EFS - ok
21:57:20.0599 0x0968  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
21:57:20.0635 0x0968  ehRecvr - ok
21:57:20.0648 0x0968  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched        C:\Windows\ehome\ehsched.exe
21:57:20.0668 0x0968  ehSched - ok
21:57:20.0693 0x0968  [ A05FC7ECA0966EBB70E4D17B855A853B, 16A0C8138A3BBD8BE2658261131F9777940CFB1431018A10710E5C1A88AB70EA ] ElbyCDIO        C:\Windows\system32\Drivers\ElbyCDIO.sys
21:57:20.0703 0x0968  ElbyCDIO - ok
21:57:20.0721 0x0968  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
21:57:20.0747 0x0968  elxstor - ok
21:57:20.0756 0x0968  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
21:57:20.0771 0x0968  ErrDev - ok
21:57:20.0796 0x0968  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem    C:\Windows\system32\es.dll
21:57:20.0837 0x0968  EventSystem - ok
21:57:20.0848 0x0968  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat          C:\Windows\system32\drivers\exfat.sys
21:57:20.0880 0x0968  exfat - ok
21:57:20.0893 0x0968  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
21:57:20.0935 0x0968  fastfat - ok
21:57:20.0956 0x0968  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax            C:\Windows\system32\fxssvc.exe
21:57:20.0992 0x0968  Fax - ok
21:57:20.0999 0x0968  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc            C:\Windows\system32\drivers\fdc.sys
21:57:21.0014 0x0968  fdc - ok
21:57:21.0022 0x0968  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost        C:\Windows\system32\fdPHost.dll
21:57:21.0055 0x0968  fdPHost - ok
21:57:21.0065 0x0968  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
21:57:21.0098 0x0968  FDResPub - ok
21:57:21.0105 0x0968  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
21:57:21.0116 0x0968  FileInfo - ok
21:57:21.0123 0x0968  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
21:57:21.0156 0x0968  Filetrace - ok
21:57:21.0161 0x0968  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
21:57:21.0173 0x0968  flpydisk - ok
21:57:21.0190 0x0968  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
21:57:21.0208 0x0968  FltMgr - ok
21:57:21.0243 0x0968  [ 5C4CB4086FB83115B153E47ADD961A0C, 0C3AB7D04BEB3A8FDE00B0C86E6FE064B1CEBB3E4DE1A29CD27830806FA300B3 ] FontCache      C:\Windows\system32\FntCache.dll
21:57:21.0296 0x0968  FontCache - ok
21:57:21.0324 0x0968  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:57:21.0334 0x0968  FontCache3.0.0.0 - ok
21:57:21.0345 0x0968  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
21:57:21.0357 0x0968  FsDepends - ok
21:57:21.0367 0x0968  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
21:57:21.0378 0x0968  Fs_Rec - ok
21:57:21.0390 0x0968  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
21:57:21.0408 0x0968  fvevol - ok
21:57:21.0428 0x0968  [ 444534CBA693DD23C1CC589681E01656, DF8ED7FFA66E0A88EBB58A491A177D8CEB35B08B0911D7A1F4B8865755DC27CE ] FWLANUSB        C:\Windows\system32\DRIVERS\fwlanusb.sys
21:57:21.0453 0x0968  FWLANUSB - ok
21:57:21.0461 0x0968  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
21:57:21.0473 0x0968  gagp30kx - ok
21:57:21.0495 0x0968  [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc          C:\Windows\System32\gpsvc.dll
21:57:21.0545 0x0968  gpsvc - ok
21:57:21.0587 0x0968  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:57:21.0597 0x0968  gupdate - ok
21:57:21.0612 0x0968  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:57:21.0621 0x0968  gupdatem - ok
21:57:21.0657 0x0968  [ D619BA1712B83D14149850E758B835AD, AD18807EC4DA6FA8C6846C1A0D914071FD59BD3273AFC103E5F2A7141F18C5F4 ] hardlock        C:\Windows\system32\drivers\hardlock.sys
21:57:21.0684 0x0968  hardlock - ok
21:57:21.0690 0x0968  hasplms - ok
21:57:21.0707 0x0968  [ D5FA01185A7D5A65724FD87B34E53F5B, 4951DC34E0E0EA598C3599B619D5DEEF527D0B5D2C2C6392469865C6420B31C0 ] hcmon          C:\Windows\system32\drivers\hcmon.sys
21:57:21.0716 0x0968  hcmon - ok
21:57:21.0724 0x0968  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
21:57:21.0742 0x0968  hcw85cir - ok
21:57:21.0762 0x0968  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:57:21.0794 0x0968  HdAudAddService - ok
21:57:21.0805 0x0968  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
21:57:21.0827 0x0968  HDAudBus - ok
21:57:21.0835 0x0968  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt        C:\Windows\system32\drivers\HidBatt.sys
21:57:21.0851 0x0968  HidBatt - ok
21:57:21.0862 0x0968  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
21:57:21.0882 0x0968  HidBth - ok
21:57:21.0895 0x0968  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr          C:\Windows\system32\drivers\hidir.sys
21:57:21.0910 0x0968  HidIr - ok
21:57:21.0918 0x0968  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv        C:\Windows\System32\hidserv.dll
21:57:21.0952 0x0968  hidserv - ok
21:57:21.0962 0x0968  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
21:57:21.0975 0x0968  HidUsb - ok
21:57:21.0986 0x0968  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
21:57:22.0020 0x0968  hkmsvc - ok
21:57:22.0040 0x0968  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:57:22.0064 0x0968  HomeGroupListener - ok
21:57:22.0077 0x0968  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:57:22.0099 0x0968  HomeGroupProvider - ok
21:57:22.0108 0x0968  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
21:57:22.0119 0x0968  HpSAMD - ok
21:57:22.0145 0x0968  [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
21:57:22.0201 0x0968  HTTP - ok
21:57:22.0209 0x0968  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
21:57:22.0218 0x0968  hwpolicy - ok
21:57:22.0229 0x0968  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
21:57:22.0243 0x0968  i8042prt - ok
21:57:22.0283 0x0968  [ 7548066DF68A8A1A56B043359F915F37, 6225DDE554E45858374CBD284A85A00F773089A667C08492187A637232B8BD9A ] IAANTMON        C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
21:57:22.0300 0x0968  IAANTMON - ok
21:57:22.0321 0x0968  [ 1D004CB1DA6323B1F55CAEF7F94B61D9, 8FFFB429BA46938724BBB87AB9B3EC77EA17C4B893BABDBDD38309F02963D405 ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
21:57:22.0337 0x0968  iaStor - ok
21:57:22.0356 0x0968  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
21:57:22.0378 0x0968  iaStorV - ok
21:57:22.0419 0x0968  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209AFC22A34D2BE99 ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:57:22.0449 0x0968  idsvc - ok
21:57:22.0460 0x0968  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
21:57:22.0471 0x0968  iirsp - ok
21:57:22.0498 0x0968  [ FCD84C381E0140AF901E58D48882D26B, 76955FFC230C801E8ED890E32076075F04CD6E5EC79E594FDE6D23797A36B406 ] IKEEXT          C:\Windows\System32\ikeext.dll
21:57:22.0552 0x0968  IKEEXT - ok
21:57:22.0567 0x0968  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
21:57:22.0577 0x0968  intelide - ok
21:57:22.0590 0x0968  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
21:57:22.0608 0x0968  intelppm - ok
21:57:22.0617 0x0968  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
21:57:22.0650 0x0968  IPBusEnum - ok
21:57:22.0660 0x0968  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:57:22.0689 0x0968  IpFilterDriver - ok
21:57:22.0711 0x0968  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
21:57:22.0745 0x0968  iphlpsvc - ok
21:57:22.0754 0x0968  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
21:57:22.0774 0x0968  IPMIDRV - ok
21:57:22.0783 0x0968  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
21:57:22.0831 0x0968  IPNAT - ok
21:57:22.0838 0x0968  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
21:57:22.0859 0x0968  IRENUM - ok
21:57:22.0867 0x0968  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
21:57:22.0877 0x0968  isapnp - ok
21:57:22.0895 0x0968  [ D931D7309DEB2317035B07C9F9E6B0BD, 13AD84172ED8C6153F8A98499C01733B74E48464CE07D099508E38D409913ED3 ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
21:57:22.0913 0x0968  iScsiPrt - ok
21:57:22.0924 0x0968  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
21:57:22.0934 0x0968  kbdclass - ok
21:57:22.0946 0x0968  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
21:57:22.0964 0x0968  kbdhid - ok
21:57:22.0971 0x0968  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] KeyIso          C:\Windows\system32\lsass.exe
21:57:22.0984 0x0968  KeyIso - ok
21:57:22.0994 0x0968  [ 97A7070AEA4C058B6418519E869A63B4, 15345C2D6CA159BD498002974A0BD21CAB611124D85E3320248B47652AEF23C8 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
21:57:23.0006 0x0968  KSecDD - ok
21:57:23.0019 0x0968  [ 26C43A7C2862447EC59DEDA188D1DA07, 5363BF87E650FE2010ACA9417D6920FF4ED752256FF47732882E9B2BA1ED154B ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
21:57:23.0032 0x0968  KSecPkg - ok
21:57:23.0043 0x0968  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
21:57:23.0077 0x0968  ksthunk - ok
21:57:23.0095 0x0968  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm          C:\Windows\system32\msdtckrm.dll
21:57:23.0135 0x0968  KtmRm - ok
21:57:23.0148 0x0968  ktmujbzd - ok
21:57:23.0167 0x0968  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\Windows\System32\srvsvc.dll
21:57:23.0206 0x0968  LanmanServer - ok
21:57:23.0219 0x0968  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:57:23.0255 0x0968  LanmanWorkstation - ok
21:57:23.0279 0x0968  [ FA529FB35694C24BF98A9EF67C1CD9D0, 7B3C587C38CF13D514140F0A55E58997D6071D1DEFD97E274E3F490660AC6075 ] LGBusEnum      C:\Windows\system32\drivers\LGBusEnum.sys
21:57:23.0288 0x0968  LGBusEnum - ok
21:57:23.0311 0x0968  [ 94B29CE153765E768F004FB3440BE2B0, E74C01CEBDA589CDDE35CBCBAA18700E3742DD3B48A90DB3630992467FFC5024 ] LGVirHid        C:\Windows\system32\drivers\LGVirHid.sys
21:57:23.0318 0x0968  LGVirHid - ok
21:57:23.0327 0x0968  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
21:57:23.0356 0x0968  lltdio - ok
21:57:23.0373 0x0968  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
21:57:23.0415 0x0968  lltdsvc - ok
21:57:23.0423 0x0968  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts        C:\Windows\System32\lmhsvc.dll
21:57:23.0455 0x0968  lmhosts - ok
21:57:23.0469 0x0968  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
21:57:23.0482 0x0968  LSI_FC - ok
21:57:23.0494 0x0968  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
21:57:23.0506 0x0968  LSI_SAS - ok
21:57:23.0515 0x0968  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
21:57:23.0526 0x0968  LSI_SAS2 - ok
21:57:23.0535 0x0968  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
21:57:23.0547 0x0968  LSI_SCSI - ok
21:57:23.0556 0x0968  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv          C:\Windows\system32\drivers\luafv.sys
21:57:23.0591 0x0968  luafv - ok
21:57:23.0617 0x0968  [ E2C6A3F80C1979B911408C17E3893371, 56FD7B743303BDC751C031372D7242C5CD25DAF927942D2D90F71033E7DE625C ] MAUSBFASTTRACK  C:\Windows\system32\DRIVERS\MAudioFastTrack.sys
21:57:23.0628 0x0968  MAUSBFASTTRACK - ok
21:57:23.0642 0x0968  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
21:57:23.0661 0x0968  Mcx2Svc - ok
21:57:23.0668 0x0968  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas        C:\Windows\system32\drivers\megasas.sys
21:57:23.0679 0x0968  megasas - ok
21:57:23.0689 0x0968  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
21:57:23.0707 0x0968  MegaSR - ok
21:57:23.0722 0x0968  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS          C:\Windows\system32\mmcss.dll
21:57:23.0758 0x0968  MMCSS - ok
21:57:23.0764 0x0968  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem          C:\Windows\system32\drivers\modem.sys
21:57:23.0794 0x0968  Modem - ok
21:57:23.0808 0x0968  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
21:57:23.0827 0x0968  monitor - ok
21:57:23.0836 0x0968  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
21:57:23.0846 0x0968  mouclass - ok
21:57:23.0855 0x0968  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
21:57:23.0871 0x0968  mouhid - ok
21:57:23.0881 0x0968  [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
21:57:23.0893 0x0968  mountmgr - ok
21:57:23.0910 0x0968  [ F8A10560B35C66F9DE212F03DAD5BFA7, 3ADCBC309A55494326EE8D152F92DFD11E1F97C897C8019BAB547E75D735FE92 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
21:57:23.0927 0x0968  MpFilter - ok
21:57:23.0935 0x0968  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
21:57:23.0948 0x0968  mpio - ok
21:57:23.0960 0x0968  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
21:57:23.0990 0x0968  mpsdrv - ok
21:57:24.0017 0x0968  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\Windows\system32\mpssvc.dll
21:57:24.0066 0x0968  MpsSvc - ok
21:57:24.0077 0x0968  [ DC722758B8261E1ABAFD31A3C0A66380, 88BBE073E2CCD1DAB4656DDC53D5161E8A91D035ADAC1465D0CEBA86F1BB6D9A ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
21:57:24.0096 0x0968  MRxDAV - ok
21:57:24.0109 0x0968  [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
21:57:24.0125 0x0968  mrxsmb - ok
21:57:24.0141 0x0968  [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:57:24.0160 0x0968  mrxsmb10 - ok
21:57:24.0173 0x0968  [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:57:24.0187 0x0968  mrxsmb20 - ok
21:57:24.0194 0x0968  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
21:57:24.0204 0x0968  msahci - ok
21:57:24.0214 0x0968  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
21:57:24.0227 0x0968  msdsm - ok
21:57:24.0238 0x0968  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC          C:\Windows\System32\msdtc.exe
21:57:24.0254 0x0968  MSDTC - ok
21:57:24.0262 0x0968  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
21:57:24.0296 0x0968  Msfs - ok
21:57:24.0305 0x0968  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
21:57:24.0337 0x0968  mshidkmdf - ok
21:57:24.0345 0x0968  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
21:57:24.0355 0x0968  msisadrv - ok
21:57:24.0380 0x0968  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
21:57:24.0422 0x0968  MSiSCSI - ok
21:57:24.0425 0x0968  msiserver - ok
21:57:24.0438 0x0968  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
21:57:24.0475 0x0968  MSKSSRV - ok
21:57:24.0506 0x0968  [ E07DEC52FF801841BA9B6878A60304FB, A57A999F411559EA97C830C9FE0234578E2E98EDAF72F9949891F901B83B22A4 ] MsMpSvc        C:\Program Files\Microsoft Security Client\MsMpEng.exe
21:57:24.0518 0x0968  MsMpSvc - ok
21:57:24.0528 0x0968  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
21:57:24.0559 0x0968  MSPCLOCK - ok
21:57:24.0572 0x0968  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
21:57:24.0603 0x0968  MSPQM - ok
21:57:24.0617 0x0968  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
21:57:24.0639 0x0968  MsRPC - ok
21:57:24.0648 0x0968  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
21:57:24.0658 0x0968  mssmbios - ok
21:57:24.0667 0x0968  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
21:57:24.0698 0x0968  MSTEE - ok
21:57:24.0705 0x0968  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
21:57:24.0722 0x0968  MTConfig - ok
21:57:24.0735 0x0968  [ 03B7145C889603537E9FFEABB1AD1089, B3CD93B893D4A2370CBF382366C6F596372857F8711EF6FFF83BFE2B449F424E ] MTsensor        C:\Windows\system32\DRIVERS\ASACPI.sys
21:57:24.0751 0x0968  MTsensor - ok
21:57:24.0760 0x0968  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup            C:\Windows\system32\Drivers\mup.sys
21:57:24.0770 0x0968  Mup - ok
21:57:24.0789 0x0968  [ 1CA758BC0DEAF35D21ECAACC30427527, DAC9839E2602365C9B867C602A739450CF7F2C5F65A6539F310B55F9D3C8447E ] mv64xx          C:\Windows\system32\DRIVERS\mv64xx.sys
21:57:24.0803 0x0968  mv64xx - ok
21:57:24.0822 0x0968  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
21:57:24.0870 0x0968  napagent - ok
21:57:24.0887 0x0968  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
21:57:24.0917 0x0968  NativeWifiP - ok
21:57:24.0958 0x0968  [ 13AA2130F2A104DD775EAD0F0EE5417B, EBA07599FC2D10750CE6372EA6BA94EDDAFFF732223A1135F1971B958A6B57A2 ] NAUpdate        C:\Program Files (x86)\Nero\Update\NASvc.exe
21:57:24.0984 0x0968  NAUpdate - ok
21:57:25.0051 0x0968  [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS            C:\Windows\system32\drivers\ndis.sys
21:57:25.0093 0x0968  NDIS - ok
21:57:25.0108 0x0968  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
21:57:25.0143 0x0968  NdisCap - ok
21:57:25.0152 0x0968  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
21:57:25.0180 0x0968  NdisTapi - ok
21:57:25.0189 0x0968  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
21:57:25.0219 0x0968  Ndisuio - ok
21:57:25.0230 0x0968  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
21:57:25.0266 0x0968  NdisWan - ok
21:57:25.0275 0x0968  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
21:57:25.0303 0x0968  NDProxy - ok
21:57:25.0312 0x0968  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
21:57:25.0344 0x0968  NetBIOS - ok
21:57:25.0352 0x0968  [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
21:57:25.0386 0x0968  NetBT - ok
21:57:25.0393 0x0968  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] Netlogon        C:\Windows\system32\lsass.exe
21:57:25.0404 0x0968  Netlogon - ok
21:57:25.0422 0x0968  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
21:57:25.0467 0x0968  Netman - ok
21:57:25.0482 0x0968  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:57:25.0493 0x0968  NetMsmqActivator - ok
21:57:25.0498 0x0968  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:57:25.0507 0x0968  NetPipeActivator - ok
21:57:25.0530 0x0968  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
21:57:25.0574 0x0968  netprofm - ok
21:57:25.0584 0x0968  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:57:25.0594 0x0968  NetTcpActivator - ok
21:57:25.0598 0x0968  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:57:25.0608 0x0968  NetTcpPortSharing - ok
21:57:25.0614 0x0968  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
21:57:25.0625 0x0968  nfrd960 - ok
21:57:25.0648 0x0968  [ 162100E0BC8377710F9D170631921C03, B4FC4F6BCCA5A61EC86F9D10F4FE284E9393CE4599CE64BC8360202F0108B499 ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
21:57:25.0662 0x0968  NisDrv - ok
21:57:25.0683 0x0968  [ C6E15F2F95F9C0A6098D43510B604E52, 7B621846EC4DD066657536755455ADB016207A45D49FC5E5F1D50EAD2CCB6B13 ] NisSrv          C:\Program Files\Microsoft Security Client\NisSrv.exe
21:57:25.0707 0x0968  NisSrv - ok
21:57:25.0718 0x0968  [ 8AD77806D336673F270DB31645267293, E23F324913554A23CD043DD27D4305AF62F48C0561A0FC7B7811E55B74B1BE79 ] NlaSvc          C:\Windows\System32\nlasvc.dll
21:57:25.0744 0x0968  NlaSvc - ok
21:57:25.0751 0x0968  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
21:57:25.0781 0x0968  Npfs - ok
21:57:25.0790 0x0968  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi            C:\Windows\system32\nsisvc.dll
21:57:25.0822 0x0968  nsi - ok
21:57:25.0830 0x0968  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
21:57:25.0862 0x0968  nsiproxy - ok
21:57:25.0909 0x0968  [ B98F8C6E31CD07B2E6F71F7F648E38C0, 2FEA100B80680FBBF644CB6763738804155DF1E94A6542CAE2B2786D770D554E ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
21:57:25.0960 0x0968  Ntfs - ok
21:57:25.0967 0x0968  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
21:57:25.0999 0x0968  Null - ok
21:57:26.0014 0x0968  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
21:57:26.0027 0x0968  nvraid - ok
21:57:26.0045 0x0968  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
21:57:26.0058 0x0968  nvstor - ok
21:57:26.0068 0x0968  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
21:57:26.0081 0x0968  nv_agp - ok
21:57:26.0089 0x0968  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
21:57:26.0110 0x0968  ohci1394 - ok
21:57:26.0145 0x0968  [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:57:26.0156 0x0968  ose - ok
21:57:26.0282 0x0968  [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
21:57:26.0417 0x0968  osppsvc - ok
21:57:26.0446 0x0968  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
21:57:26.0473 0x0968  p2pimsvc - ok
21:57:26.0491 0x0968  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
21:57:26.0514 0x0968  p2psvc - ok
21:57:26.0523 0x0968  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport        C:\Windows\system32\drivers\parport.sys
21:57:26.0540 0x0968  Parport - ok
21:57:26.0551 0x0968  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
21:57:26.0563 0x0968  partmgr - ok
21:57:26.0577 0x0968  [ 3AEAA8B561E63452C655DC0584922257, 04C072969B58657602EB0C21CEDF24FCEE14E61B90A0F758F93925EF2C9FC32D ] PcaSvc          C:\Windows\System32\pcasvc.dll
21:57:26.0601 0x0968  PcaSvc - ok
21:57:26.0612 0x0968  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci            C:\Windows\system32\drivers\pci.sys
21:57:26.0626 0x0968  pci - ok
21:57:26.0636 0x0968  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
21:57:26.0646 0x0968  pciide - ok
21:57:26.0656 0x0968  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
21:57:26.0672 0x0968  pcmcia - ok
21:57:26.0687 0x0968  [ 3A68080572B81577791A7B19BB880DA9, 9F64FAB46BF6B5AB46EF77A7077295587F4A6C4851D5EB04D9EC8ECC4C7C67D1 ] PCTCore        C:\Windows\system32\drivers\PCTCore64.sys
21:57:26.0701 0x0968  PCTCore - ok
21:57:26.0708 0x0968  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw            C:\Windows\system32\drivers\pcw.sys
21:57:26.0719 0x0968  pcw - ok
21:57:26.0738 0x0968  [ 68769C3356B3BE5D1C732C97B9A80D6E, FB2D61145980A2899D1B7729184C54070315B0E63C9A22400A76CCD39E00029C ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
21:57:26.0791 0x0968  PEAUTH - ok
21:57:26.0828 0x0968  [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc    C:\Windows\system32\peerdistsvc.dll
21:57:26.0882 0x0968  PeerDistSvc - ok
21:57:26.0933 0x0968  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
21:57:26.0953 0x0968  PerfHost - ok
21:57:26.0996 0x0968  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla            C:\Windows\system32\pla.dll
21:57:27.0067 0x0968  pla - ok
21:57:27.0088 0x0968  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
21:57:27.0114 0x0968  PlugPlay - ok
21:57:27.0134 0x0968  PnkBstrA - ok
21:57:27.0146 0x0968  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
21:57:27.0163 0x0968  PNRPAutoReg - ok
21:57:27.0174 0x0968  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
21:57:27.0192 0x0968  PNRPsvc - ok
21:57:27.0212 0x0968  [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
21:57:27.0259 0x0968  PolicyAgent - ok
21:57:27.0275 0x0968  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power          C:\Windows\system32\umpo.dll
21:57:27.0309 0x0968  Power - ok
21:57:27.0322 0x0968  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
21:57:27.0356 0x0968  PptpMiniport - ok
21:57:27.0366 0x0968  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor      C:\Windows\system32\drivers\processr.sys
21:57:27.0383 0x0968  Processor - ok
21:57:27.0403 0x0968  [ 53E83F1F6CF9D62F32801CF66D8352A8, 1225FED810BE8E0729EEAE5B340035CCBB9BACD3EF247834400F9B72D05ACE48 ] ProfSvc        C:\Windows\system32\profsvc.dll
21:57:27.0426 0x0968  ProfSvc - ok
21:57:27.0432 0x0968  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] ProtectedStorage C:\Windows\system32\lsass.exe
21:57:27.0443 0x0968  ProtectedStorage - ok
21:57:27.0458 0x0968  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
21:57:27.0494 0x0968  Psched - ok
21:57:27.0497 0x0968  ptqllcii - ok
21:57:27.0538 0x0968  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
21:57:27.0587 0x0968  ql2300 - ok
21:57:27.0602 0x0968  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
21:57:27.0614 0x0968  ql40xx - ok
21:57:27.0631 0x0968  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE          C:\Windows\system32\qwave.dll
21:57:27.0654 0x0968  QWAVE - ok
21:57:27.0661 0x0968  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
21:57:27.0682 0x0968  QWAVEdrv - ok
21:57:27.0688 0x0968  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
21:57:27.0715 0x0968  RasAcd - ok
21:57:27.0732 0x0968  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
21:57:27.0761 0x0968  RasAgileVpn - ok
21:57:27.0772 0x0968  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto        C:\Windows\System32\rasauto.dll
21:57:27.0805 0x0968  RasAuto - ok
21:57:27.0815 0x0968  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
21:57:27.0849 0x0968  Rasl2tp - ok
21:57:27.0866 0x0968  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
21:57:27.0905 0x0968  RasMan - ok
21:57:27.0919 0x0968  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
21:57:27.0952 0x0968  RasPppoe - ok
21:57:27.0960 0x0968  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
21:57:27.0997 0x0968  RasSstp - ok
21:57:28.0013 0x0968  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
21:57:28.0062 0x0968  rdbss - ok
21:57:28.0070 0x0968  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
21:57:28.0089 0x0968  rdpbus - ok
21:57:28.0095 0x0968  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
21:57:28.0125 0x0968  RDPCDD - ok
21:57:28.0136 0x0968  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR          C:\Windows\system32\drivers\rdpdr.sys
21:57:28.0152 0x0968  RDPDR - ok
21:57:28.0163 0x0968  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
21:57:28.0194 0x0968  RDPENCDD - ok
21:57:28.0202 0x0968  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
21:57:28.0236 0x0968  RDPREFMP - ok
21:57:28.0251 0x0968  [ E61608AA35E98999AF9AAEEEA6114B0A, F754CDE89DC96786D2A3C4D19EE2AEF1008E634E4DE3C0CBF927436DE90C04A6 ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
21:57:28.0276 0x0968  RDPWD - ok
21:57:28.0288 0x0968  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
21:57:28.0303 0x0968  rdyboost - ok
21:57:28.0311 0x0968  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
21:57:28.0348 0x0968  RemoteAccess - ok
21:57:28.0362 0x0968  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
21:57:28.0399 0x0968  RemoteRegistry - ok
21:57:28.0401 0x0968  rlffuili - ok
21:57:28.0409 0x0968  rmtofanc - ok
21:57:28.0425 0x0968  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
21:57:28.0463 0x0968  RpcEptMapper - ok
21:57:28.0471 0x0968  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
21:57:28.0491 0x0968  RpcLocator - ok
21:57:28.0513 0x0968  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs          C:\Windows\system32\rpcss.dll
21:57:28.0554 0x0968  RpcSs - ok
21:57:28.0567 0x0968  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
21:57:28.0598 0x0968  rspndr - ok
21:57:28.0626 0x0968  [ ABCB5A38A0D85BDF69B7877E1AD1EED5, 44DF1A92E8FA53677A04C46088B0AD49F1F6A090820BE550A514C4FBFD91444D ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
21:57:28.0648 0x0968  RTL8167 - ok
21:57:28.0661 0x0968  [ AE4FDA46C0A644DC9FB2545BDF4CB496, 35C911D94B887E64395EC3F493971E5D36176A3632D2F9FB7B4D5A886E9464F1 ] rzdaendpt      C:\Windows\system32\DRIVERS\rzdaendpt.sys
21:57:28.0678 0x0968  rzdaendpt - ok
21:57:28.0695 0x0968  [ D28AB8D41CA4633EA69F2897F0B45565, B8FF66583530787419D04EEA75A49B61FB184523E652C720B1EF1F1695864F0A ] rzudd          C:\Windows\system32\DRIVERS\rzudd.sys
21:57:28.0715 0x0968  rzudd - ok
21:57:28.0738 0x0968  [ 4CE040A51CFA6614F46419CB5F5B7BB6, 91DD7B91287800E96EF0DB9DD69B3315629BFA690592C2D0A3E596386A84CD95 ] rzvkeyboard    C:\Windows\system32\DRIVERS\rzvkeyboard.sys
21:57:28.0753 0x0968  rzvkeyboard - ok
21:57:28.0758 0x0968  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap          C:\Windows\system32\drivers\vms3cap.sys
21:57:28.0773 0x0968  s3cap - ok
21:57:28.0776 0x0968  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] SamSs          C:\Windows\system32\lsass.exe
21:57:28.0789 0x0968  SamSs - ok
21:57:28.0798 0x0968  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
21:57:28.0811 0x0968  sbp2port - ok
21:57:28.0874 0x0968  [ 794D4B48DFB6E999537C7C3947863463, 93DA8AA20D6B02A3360E7F56150F126E75266E9372E6409D42B89DA588EF49C3 ] SBSDWSCService  C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
21:57:28.0912 0x0968  SBSDWSCService - ok
21:57:28.0925 0x0968  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
21:57:28.0961 0x0968  SCardSvr - ok
21:57:28.0968 0x0968  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
21:57:29.0001 0x0968  scfilter - ok
21:57:29.0033 0x0968  [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule        C:\Windows\system32\schedsvc.dll
21:57:29.0096 0x0968  Schedule - ok
21:57:29.0106 0x0968  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc    C:\Windows\System32\certprop.dll
21:57:29.0134 0x0968  SCPolicySvc - ok
21:57:29.0164 0x0968  [ EE088B31F5EB673A62E7E0D09B0007B0, 686B697F554E02ACADD5E44F707EF1E7DD87539FF8156F4FF67533E5D26BC160 ] sdAuxService    C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe
21:57:29.0184 0x0968  sdAuxService - ok
21:57:29.0222 0x0968  [ 747FFE0A5A34C349A363BE97C632B7C4, 7AC092581CCED5080DA8ED3B7243B0DC99B648493ACDE7EB02461DB0DDB1C0B0 ] sdCoreService  C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe
21:57:29.0259 0x0968  sdCoreService - ok
21:57:29.0277 0x0968  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
21:57:29.0293 0x0968  SDRSVC - ok
21:57:29.0304 0x0968  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
21:57:29.0338 0x0968  secdrv - ok
21:57:29.0350 0x0968  [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon        C:\Windows\system32\seclogon.dll
21:57:29.0380 0x0968  seclogon - ok
21:57:29.0388 0x0968  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\system32\sens.dll
21:57:29.0422 0x0968  SENS - ok
21:57:29.0427 0x0968  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
21:57:29.0440 0x0968  SensrSvc - ok
21:57:29.0448 0x0968  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum        C:\Windows\system32\drivers\serenum.sys
21:57:29.0466 0x0968  Serenum - ok
21:57:29.0479 0x0968  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\drivers\serial.sys
21:57:29.0499 0x0968  Serial - ok
21:57:29.0515 0x0968  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\drivers\sermouse.sys
21:57:29.0534 0x0968  sermouse - ok
21:57:29.0547 0x0968  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
21:57:29.0584 0x0968  SessionEnv - ok
21:57:29.0591 0x0968  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
21:57:29.0604 0x0968  sffdisk - ok
21:57:29.0607 0x0968  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
21:57:29.0624 0x0968  sffp_mmc - ok
21:57:29.0629 0x0968  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
21:57:29.0646 0x0968  sffp_sd - ok
21:57:29.0653 0x0968  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
21:57:29.0670 0x0968  sfloppy - ok
21:57:29.0707 0x0968  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
21:57:29.0750 0x0968  SharedAccess - ok
21:57:29.0769 0x0968  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:57:29.0814 0x0968  ShellHWDetection - ok
21:57:29.0823 0x0968  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
21:57:29.0834 0x0968  SiSRaid2 - ok
21:57:29.0843 0x0968  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
21:57:29.0854 0x0968  SiSRaid4 - ok
21:57:29.0873 0x0968  [ F07AF60B152221472FBDB2FECEC4896D, A18FDCE8462A48429E249C44F0E49F844F2E3A4B5215349DE104F34D935EF983 ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
21:57:29.0884 0x0968  SkypeUpdate - ok
21:57:29.0895 0x0968  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
21:57:29.0931 0x0968  Smb - ok
21:57:29.0956 0x0968  [ B2C19AE46C5A109679B4FB38058DF05A, 93DD4D356650C51348795653286E6C627FF5F7071F2787DF7C50B75A3120E308 ] snapman        C:\Windows\system32\DRIVERS\snapman.sys
21:57:29.0974 0x0968  snapman - ok
21:57:29.0987 0x0968  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
21:57:30.0007 0x0968  SNMPTRAP - ok
21:57:30.0013 0x0968  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr          C:\Windows\system32\drivers\spldr.sys
21:57:30.0023 0x0968  spldr - ok
21:57:30.0044 0x0968  [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler        C:\Windows\System32\spoolsv.exe
21:57:30.0074 0x0968  Spooler - ok
21:57:30.0155 0x0968  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
21:57:30.0285 0x0968  sppsvc - ok
21:57:30.0297 0x0968  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
21:57:30.0328 0x0968  sppuinotify - ok
21:57:30.0347 0x0968  [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv            C:\Windows\system32\DRIVERS\srv.sys
21:57:30.0378 0x0968  srv - ok
21:57:30.0393 0x0968  [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
21:57:30.0425 0x0968  srv2 - ok
21:57:30.0438 0x0968  [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
21:57:30.0455 0x0968  srvnet - ok
21:57:30.0465 0x0968  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
21:57:30.0500 0x0968  SSDPSRV - ok
21:57:30.0507 0x0968  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc        C:\Windows\system32\sstpsvc.dll
21:57:30.0539 0x0968  SstpSvc - ok
21:57:30.0562 0x0968  Steam Client Service - ok
21:57:30.0567 0x0968  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
21:57:30.0577 0x0968  stexstor - ok
21:57:30.0601 0x0968  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\Windows\System32\wiaservc.dll
21:57:30.0640 0x0968  stisvc - ok
21:57:30.0653 0x0968  [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt        C:\Windows\system32\drivers\vmstorfl.sys
21:57:30.0662 0x0968  storflt - ok
21:57:30.0668 0x0968  [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc        C:\Windows\system32\storsvc.dll
21:57:30.0683 0x0968  StorSvc - ok
21:57:30.0694 0x0968  [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc        C:\Windows\system32\drivers\storvsc.sys
21:57:30.0705 0x0968  storvsc - ok
21:57:30.0710 0x0968  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
21:57:30.0720 0x0968  swenum - ok
21:57:30.0737 0x0968  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv          C:\Windows\System32\swprv.dll
21:57:30.0782 0x0968  swprv - ok
21:57:30.0823 0x0968  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain        C:\Windows\system32\sysmain.dll
21:57:30.0897 0x0968  SysMain - ok
21:57:30.0907 0x0968  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:57:30.0929 0x0968  TabletInputService - ok
21:57:30.0939 0x0968  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv        C:\Windows\System32\tapisrv.dll
21:57:30.0981 0x0968  TapiSrv - ok
21:57:30.0990 0x0968  [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS            C:\Windows\System32\tbssvc.dll
21:57:31.0024 0x0968  TBS - ok
21:57:31.0075 0x0968  [ DB74544B75566C974815E79A62433F29, 035EBF70FDA28CF2B6C1FD7EE0ED703DB4B647064B5DBA6E258878A19B1BCCA4 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
21:57:31.0136 0x0968  Tcpip - ok
21:57:31.0206 0x0968  [ DB74544B75566C974815E79A62433F29, 035EBF70FDA28CF2B6C1FD7EE0ED703DB4B647064B5DBA6E258878A19B1BCCA4 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
21:57:31.0250 0x0968  TCPIP6 - ok
21:57:31.0270 0x0968  [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
21:57:31.0282 0x0968  tcpipreg - ok
21:57:31.0292 0x0968  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
21:57:31.0306 0x0968  TDPIPE - ok
21:57:31.0344 0x0968  [ 99527D49EE0A96FC25537C61B270A372, 519E23F86EC86349F92C4A88DBD19C097AEE0A6E152776B32B45D293ED14946B ] tdrpman273      C:\Windows\system32\DRIVERS\tdrpm273.sys
21:57:31.0383 0x0968  tdrpman273 - ok
21:57:31.0393 0x0968  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
21:57:31.0408 0x0968  TDTCP - ok
21:57:31.0421 0x0968  [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719C48B08FAFA9661 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
21:57:31.0452 0x0968  tdx - ok
21:57:31.0460 0x0968  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
21:57:31.0471 0x0968  TermDD - ok
21:57:31.0492 0x0968  [ 2E648163254233755035B46DD7B89123, 6FA0D07CE18A3A69D82EE49D875F141E39406E92C34EAC76AC4EB052E6EBCBCD ] TermService    C:\Windows\System32\termsrv.dll
21:57:31.0549 0x0968  TermService - ok
21:57:31.0556 0x0968  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
21:57:31.0574 0x0968  Themes - ok
21:57:31.0585 0x0968  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER    C:\Windows\system32\mmcss.dll
21:57:31.0615 0x0968  THREADORDER - ok
21:57:31.0647 0x0968  [ 2C1CAF5563548A15515EAB07D2A069C6, 863405BAC725C7DC6CC86613365A099A2370781018996DD3E74981565AD0DDF5 ] timounter      C:\Windows\system32\DRIVERS\timntr.sys
21:57:31.0680 0x0968  timounter - ok
21:57:31.0695 0x0968  [ C676B0F52F2B6483AFB88F79CABB011E, 8F10C7C91B47F87C3E29785BDACA49831857849F688C34A1F097C9D6593003AA ] Tpkd            C:\Windows\system32\drivers\Tpkd.sys
21:57:31.0706 0x0968  Tpkd - ok
21:57:31.0722 0x0968  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
21:57:31.0759 0x0968  TrkWks - ok
21:57:31.0778 0x0968  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:57:31.0809 0x0968  TrustedInstaller - ok
21:57:31.0820 0x0968  [ 4CE278FC9671BA81A138D70823FCAA09, CBE501436696E32A3701B9F377B823AC36647B6626595F76CC63E2396AD7D300 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
21:57:31.0837 0x0968  tssecsrv - ok
21:57:31.0848 0x0968  [ D11C783E3EF9A3C52C0EBE83CC5000E9, A136C355D4C8945729163D15801364A614E23217B15F9313C85BA45BB71A74EB ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
21:57:31.0868 0x0968  TsUsbFlt - ok
21:57:31.0875 0x0968  [ 9CC2CCAE8A84820EAECB886D477CBCB8, 50D8AA2D7477A6618A0C31BB4D1C4887B457865FB1105E2E7B984EEFA337B804 ] TsUsbGD        C:\Windows\system32\drivers\TsUsbGD.sys
21:57:31.0891 0x0968  TsUsbGD - ok
21:57:31.0903 0x0968  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
21:57:31.0938 0x0968  tunnel - ok
21:57:31.0946 0x0968  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
21:57:31.0957 0x0968  uagp35 - ok
21:57:31.0959 0x0968  ubqgdokm - ok
21:57:31.0975 0x0968  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
21:57:32.0017 0x0968  udfs - ok
21:57:32.0054 0x0968  [ 215462AE7E6A897D675E84DD1E3B3B56, 7F45E77F971E9AC3E1402663EF5F6A2D496F9BB758C8E50D2D329E834E20B7D8 ] ufad-ws60      C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe
21:57:32.0067 0x0968  ufad-ws60 - ok
21:57:32.0074 0x0968  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect      C:\Windows\system32\UI0Detect.exe
21:57:32.0093 0x0968  UI0Detect - ok
21:57:32.0110 0x0968  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
21:57:32.0121 0x0968  uliagpkx - ok
21:57:32.0133 0x0968  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
21:57:32.0150 0x0968  umbus - ok
21:57:32.0163 0x0968  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\drivers\umpass.sys
21:57:32.0178 0x0968  UmPass - ok
21:57:32.0188 0x0968  [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService    C:\Windows\System32\umrdp.dll
21:57:32.0212 0x0968  UmRdpService - ok
21:57:32.0226 0x0968  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
21:57:32.0269 0x0968  upnphost - ok
21:57:32.0287 0x0968  [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A, DE1CDDEEF2285CC8387E88ACB13C000576DC8819DF6DC648C988068B5C83BB15 ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
21:57:32.0310 0x0968  usbaudio - ok
21:57:32.0324 0x0968  [ 6F1A3157A1C89435352CEB543CDB359C, 325B46220779C5FE3B6F19FF794474837FAB9675D9C98ACB68CCE47B1CFE5F12 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
21:57:32.0339 0x0968  usbccgp - ok
21:57:32.0357 0x0968  [ AF0892A803FDDA7492F595368E3B68E7, F263346DEB4D742EB436CF578F187AC8521D84CED52E98475E6198EC52244F07 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
21:57:32.0374 0x0968  usbcir - ok
21:57:32.0392 0x0968  [ C025055FE7B87701EB042095DF1A2D7B, D7B34B6C2C5BD3C8141895AC21BB637EA5E3C4F7A85EEF4C4C36E6BB2045A3D9 ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
21:57:32.0407 0x0968  usbehci - ok
21:57:32.0425 0x0968  [ 287C6C9410B111B68B52CA298F7B8C24, 98900C08FE662A00DF8B37837B2BEBF9ACB7989C387AF36B2109B05A4F462D4E ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
21:57:32.0449 0x0968  usbhub - ok
21:57:32.0457 0x0968  [ 9840FC418B4CBD632D3D0A667A725C31, 776D86A032DCA2842EF7AADB35473193CA80547223EFAA7F110F296C377077B0 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
21:57:32.0473 0x0968  usbohci - ok
21:57:32.0481 0x0968  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\drivers\usbprint.sys
21:57:32.0498 0x0968  usbprint - ok
21:57:32.0509 0x0968  [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:57:32.0527 0x0968  USBSTOR - ok
21:57:32.0540 0x0968  [ 62069A34518BCF9C1FD9E74B3F6DB7CD, C58E21424718729324B285BEE1C96551540FCC3FD650B2D10895EBA48D981E25 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
21:57:32.0559 0x0968  usbuhci - ok
21:57:32.0565 0x0968  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms          C:\Windows\System32\uxsms.dll
21:57:32.0600 0x0968  UxSms - ok
21:57:32.0611 0x0968  varehocl - ok
21:57:32.0618 0x0968  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] VaultSvc        C:\Windows\system32\lsass.exe
21:57:32.0630 0x0968  VaultSvc - ok
21:57:32.0639 0x0968  [ FD911873C0BB6945FA38C16E9A2B58F9, EF8C833321449A6E8B671890F2EBC82ABC276B890D274AADDB626D763EE98964 ] VClone          C:\Windows\system32\DRIVERS\VClone.sys
21:57:32.0654 0x0968  VClone - ok
21:57:32.0666 0x0968  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
21:57:32.0676 0x0968  vdrvroot - ok
21:57:32.0693 0x0968  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds            C:\Windows\System32\vds.exe
21:57:32.0743 0x0968  vds - ok
21:57:32.0754 0x0968  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
21:57:32.0768 0x0968  vga - ok
21:57:32.0774 0x0968  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave        C:\Windows\System32\drivers\vga.sys
21:57:32.0807 0x0968  VgaSave - ok
21:57:32.0817 0x0968  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
21:57:32.0835 0x0968  vhdmp - ok
21:57:32.0846 0x0968  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\drivers\viaide.sys
21:57:32.0856 0x0968  viaide - ok
21:57:32.0870 0x0968  [ 3B59BB6D10CF969DBE4DB93D9EAD7FB4, 8BD4648AAD460F276C79AF81D1479E781E62D292F3318D39B53703403E57E52F ] VKbms          C:\Windows\system32\DRIVERS\VKbms.sys
21:57:32.0885 0x0968  VKbms - ok
21:57:32.0904 0x0968  [ 7AC6239C65DADE55DEFD573B98616C3F, 39EC745BFA38C70DA80DC121CB24C12ED9AF9AFDCFE38FCD853CFA53D6E538A8 ] VMAuthdService  C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
21:57:32.0914 0x0968  VMAuthdService - ok
21:57:32.0924 0x0968  [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus          C:\Windows\system32\drivers\vmbus.sys
21:57:32.0938 0x0968  vmbus - ok
21:57:32.0946 0x0968  [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
21:57:32.0962 0x0968  VMBusHID - ok
21:57:32.0974 0x0968  [ 312AEC23A85424543AF898A59209B479, 7423643ACA900824CCC44B6347AD81E027A9C2A42C12C7F7FD9B89F3D5B5F654 ] vmci            C:\Windows\system32\drivers\vmci.sys
21:57:32.0983 0x0968  vmci - ok
21:57:33.0002 0x0968  [ FFC30CAEEB2FC5FEE8568CFF74EDEAED, 56DA6F766906A160C326AAA901E0B50E5CA8B054BDE1B95DD6EA14BBB5286E65 ] vmkbd          C:\Windows\system32\drivers\VMkbd.sys
21:57:33.0010 0x0968  vmkbd - ok
21:57:33.0022 0x0968  [ 9D54F1339E78C95BF3D9939EBCB66378, 99E29225443049B35E633BB7E709AC89B555F6A1EC5FAE075825A74F088FDC9A ] VMnetAdapter    C:\Windows\system32\DRIVERS\vmnetadapter.sys
21:57:33.0029 0x0968  VMnetAdapter - ok
21:57:33.0043 0x0968  [ FB54EF3AA613D2832FD3812E7CB2FC75, 2D638EFE2E457C4F9B50AF49C7A0B0DA82A98FF10049C2E5DABE32B7E0BA2B23 ] VMnetBridge    C:\Windows\system32\DRIVERS\vmnetbridge.sys
21:57:33.0051 0x0968  VMnetBridge - ok
21:57:33.0057 0x0968  VMnetDHCP - ok
21:57:33.0066 0x0968  [ 56D547BFC3F1619FA82EC9EF5D24E802, D82DDC1E15F87E3E5809991CEFD81CE24BC8C9249108F36F7B854CEDBDB56FFC ] VMnetuserif    C:\Windows\system32\drivers\vmnetuserif.sys
21:57:33.0075 0x0968  VMnetuserif - ok
21:57:33.0115 0x0968  [ 19368F7C4DC6EF444B826249FC8A0E30, 6F26729EA0BD651FCCC8657BF7C40174AC06926373B467BC3BD3ED352421D2FA ] VMUSBArbService C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
21:57:33.0137 0x0968  VMUSBArbService - ok
21:57:33.0142 0x0968  VMware NAT Service - ok
21:57:33.0161 0x0968  [ 62CD5A87FDE14701506D4E0DD8F13D2E, C449E52039BAF7B262BEE4D1389239B196965A0A08E002441CE56B89EF6688E8 ] vmx86          C:\Windows\system32\drivers\vmx86.sys
21:57:33.0171 0x0968  vmx86 - ok
21:57:33.0181 0x0968  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
21:57:33.0192 0x0968  volmgr - ok
21:57:33.0206 0x0968  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
21:57:33.0223 0x0968  volmgrx - ok
21:57:33.0234 0x0968  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap        C:\Windows\system32\drivers\volsnap.sys
21:57:33.0251 0x0968  volsnap - ok
21:57:33.0261 0x0968  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
21:57:33.0275 0x0968  vsmraid - ok
21:57:33.0313 0x0968  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS            C:\Windows\system32\vssvc.exe
21:57:33.0390 0x0968  VSS - ok
21:57:33.0407 0x0968  [ E61C910E2DDF4797C1B1F9239636E894, BEC555AB66BD0D33BBC9ABFF7F3955F7D0821383549C8BAC1944B63A85F897E8 ] vstor2-ws60    C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys
21:57:33.0415 0x0968  vstor2-ws60 - ok
21:57:33.0423 0x0968  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
21:57:33.0438 0x0968  vwifibus - ok
21:57:33.0453 0x0968  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time        C:\Windows\system32\w32time.dll
21:57:33.0496 0x0968  W32Time - ok
21:57:33.0507 0x0968  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
21:57:33.0522 0x0968  WacomPen - ok
21:57:33.0533 0x0968  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
21:57:33.0568 0x0968  WANARP - ok
21:57:33.0573 0x0968  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
21:57:33.0602 0x0968  Wanarpv6 - ok
21:57:33.0642 0x0968  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\Windows\system32\wbengine.exe
21:57:33.0702 0x0968  wbengine - ok
21:57:33.0714 0x0968  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
21:57:33.0736 0x0968  WbioSrvc - ok
21:57:33.0750 0x0968  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
21:57:33.0784 0x0968  wcncsvc - ok
21:57:33.0792 0x0968  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:57:33.0810 0x0968  WcsPlugInService - ok
21:57:33.0820 0x0968  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\drivers\wd.sys
21:57:33.0830 0x0968  Wd - ok
21:57:33.0856 0x0968  [ 442783E2CB0DA19873B7A63833FF4CB4, 09254970265476214F3187CC22A4F9C7C2769D419600E83FBE302C3A103E527F ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
21:57:33.0890 0x0968  Wdf01000 - ok
21:57:33.0898 0x0968  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost  C:\Windows\system32\wdi.dll
21:57:33.0923 0x0968  WdiServiceHost - ok
21:57:33.0927 0x0968  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost  C:\Windows\system32\wdi.dll
21:57:33.0945 0x0968  WdiSystemHost - ok
21:57:33.0957 0x0968  [ 3DB6D04E1C64272F8B14EB8BC4616280, 9138642B1C19F895D4ECFD930160C80FBF15813CE63BBF4C899842C300FD3026 ] WebClient      C:\Windows\System32\webclnt.dll
21:57:33.0986 0x0968  WebClient - ok
21:57:33.0998 0x0968  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\Windows\system32\wecsvc.dll
21:57:34.0044 0x0968  Wecsvc - ok
21:57:34.0052 0x0968  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
21:57:34.0085 0x0968  wercplsupport - ok
21:57:34.0097 0x0968  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
21:57:34.0130 0x0968  WerSvc - ok
21:57:34.0143 0x0968  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
21:57:34.0173 0x0968  WfpLwf - ok
21:57:34.0178 0x0968  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
21:57:34.0189 0x0968  WIMMount - ok
21:57:34.0195 0x0968  WinDefend - ok
21:57:34.0202 0x0968  WinHttpAutoProxySvc - ok
21:57:34.0233 0x0968  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
21:57:34.0267 0x0968  Winmgmt - ok
21:57:34.0313 0x0968  [ BCB1310604AA415C4508708975B3931E, 9D943F086D454345153A0DD426B4432532A44FD87950386B186E1CAD2AC70565 ] WinRM          C:\Windows\system32\WsmSvc.dll
21:57:34.0396 0x0968  WinRM - ok
21:57:34.0428 0x0968  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
21:57:34.0447 0x0968  WinUsb - ok
21:57:34.0468 0x0968  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc        C:\Windows\System32\wlansvc.dll
21:57:34.0512 0x0968  Wlansvc - ok
21:57:34.0596 0x0968  [ 98F138897EF4246381D197CB81846D62, A9FA88475AFBB8883297708608EC7C1AC29F229C3299A84D557172604813A18C ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:57:34.0662 0x0968  wlidsvc - ok
21:57:34.0677 0x0968  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
21:57:34.0693 0x0968  WmiAcpi - ok
21:57:34.0711 0x0968  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
21:57:34.0732 0x0968  wmiApSrv - ok
21:57:34.0747 0x0968  WMPNetworkSvc - ok
21:57:34.0759 0x0968  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
21:57:34.0771 0x0968  WPCSvc - ok
21:57:34.0779 0x0968  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
21:57:34.0795 0x0968  WPDBusEnum - ok
21:57:34.0802 0x0968  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
21:57:34.0831 0x0968  ws2ifsl - ok
21:57:34.0840 0x0968  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\system32\wscsvc.dll
21:57:34.0862 0x0968  wscsvc - ok
21:57:34.0864 0x0968  WSearch - ok
21:57:34.0932 0x0968  [ D9EF901DCA379CFE914E9FA13B73B4C4, 3BE9693B7B2AFEE23D72AF5DA211379724D752F0EC18ACB7D3DE3DDFC5AE0004 ] wuauserv        C:\Windows\system32\wuaueng.dll
21:57:35.0007 0x0968  wuauserv - ok
21:57:35.0033 0x0968  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
21:57:35.0054 0x0968  WudfPf - ok
21:57:35.0076 0x0968  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
21:57:35.0106 0x0968  WUDFRd - ok
21:57:35.0119 0x0968  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
21:57:35.0138 0x0968  wudfsvc - ok
21:57:35.0153 0x0968  [ FE90B750AB808FB9DD8FBB428B5FF83B, 3F8F592EC813BE292D305A87C5BA852F8BC3D7CE610612D9871F209A17326AA8 ] WwanSvc        C:\Windows\System32\wwansvc.dll
21:57:35.0177 0x0968  WwanSvc - ok
21:57:35.0196 0x0968  ================ Scan global ===============================
21:57:35.0208 0x0968  [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll
21:57:35.0224 0x0968  [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll
21:57:35.0236 0x0968  [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll
21:57:35.0250 0x0968  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
21:57:35.0266 0x0968  [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe
21:57:35.0277 0x0968  [ Global ] - ok
21:57:35.0278 0x0968  ================ Scan MBR ==================================
21:57:35.0281 0x0968  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2
21:57:35.0411 0x0968  \Device\Harddisk2\DR2 - ok
21:57:35.0430 0x0968  [ 87D88FA4D3EFD4431866EA91949644BF ] \Device\Harddisk0\DR0
21:57:35.0432 0x0968  \Device\Harddisk0\DR0 - detected Rootkit.Boot.Wistler.a ( 0 )
21:57:35.0432 0x0968  \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - infected
21:57:38.0050 0x0968  [ 87D88FA4D3EFD4431866EA91949644BF ] \Device\Harddisk1\DR1
21:57:38.0068 0x0968  \Device\Harddisk1\DR1 - detected Rootkit.Boot.Wistler.a ( 0 )
21:57:38.0068 0x0968  \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - infected
21:57:40.0682 0x0968  [ DDAE9D649DB12F6AFF24483F2C298989 ] \Device\Harddisk3\DR3
21:57:41.0680 0x0968  \Device\Harddisk3\DR3 - ok
21:57:41.0681 0x0968  ================ Scan VBR ==================================
21:57:41.0688 0x0968  [ 648FC44956DAA6F6D2A8D210255768CC ] \Device\Harddisk2\DR2\Partition1
21:57:41.0689 0x0968  \Device\Harddisk2\DR2\Partition1 - ok
21:57:41.0693 0x0968  [ EE9BD2983364C91FDF0753BA7BC6215D ] \Device\Harddisk2\DR2\Partition2
21:57:41.0695 0x0968  \Device\Harddisk2\DR2\Partition2 - ok
21:57:41.0697 0x0968  [ 3541107D5B9039B36E7DAD4CDEDD327F ] \Device\Harddisk0\DR0\Partition1
21:57:41.0699 0x0968  \Device\Harddisk0\DR0\Partition1 - ok
21:57:41.0711 0x0968  [ A59F8BF144837A8162BE68CC117745D5 ] \Device\Harddisk1\DR1\Partition1
21:57:41.0714 0x0968  \Device\Harddisk1\DR1\Partition1 - ok
21:57:41.0724 0x0968  [ 4B1FF6B5531814D37FB80B561FA4672E ] \Device\Harddisk3\DR3\Partition1
21:57:41.0726 0x0968  \Device\Harddisk3\DR3\Partition1 - ok
21:57:41.0735 0x0968  AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.2.223.0 ), 0x60000 ( disabled : updated )
21:57:41.0778 0x0968  Win FW state via NFP2: enabled
21:57:44.0280 0x0968  ============================================================
21:57:44.0280 0x0968  Scan finished
21:57:44.0280 0x0968  ============================================================
21:57:44.0286 0x142c  Detected object count: 2
21:57:44.0286 0x142c  Actual detected object count: 2
21:58:03.0872 0x142c  \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - skipped by user
21:58:03.0872 0x142c  \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - User select action: Skip
21:58:03.0873 0x142c  \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - skipped by user
21:58:03.0873 0x142c  \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - User select action: Skip

EDIT:

Der Kandidat erhält im Übrigen 100 Punkte! Hast nen Volltreffer gelandet mit deiner Vermutung. Er hat tatsächlich Wistler drauf. Habe natürlich fein artig geskipped (:

aharonov 10.10.2013 21:06

Zitat:

Habe natürlich fein artig geskipped (:
Aber jetzt darfst du ihn löschen. :kloppen:


Schritt 1

Starte bitte TDSSkiller.exe.
Vista und Win7 User mit Rechtsklick "als Administrator ausführen".
  • Drücke auf Start Scan.
    Mache während des Scans nichts am Rechner!
  • Gehe sicher, dass bei Rootkit.Boot.Wistler.a die Option Cure (default) angehakt ist.
  • Drücke Continue --> Reboot.
  • TDSSKiller wird ein Logfile auf deinem Systemlaufwerk speichern (C:\TDSSKiller.<version_date_time>log.txt).
  • Poste bitte den Inhalt dieses Logfiles in deinen Thread.



Schritt 2

Bringst du jetzt FRST zum Laufen, oder klappt das immer noch nicht?
Lade dazu bitte eine Version von FRST herunter:


Downloade dir bitte Farbar Recovery Scan Tool 64-Bit und speichere es auf den Desktop.
  • Starte die FRST64.exe.
  • Setze den Haken bei Addition.txt und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden zwei Logfiles FRST.txt und Addition.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieser beiden Logfiles bitte hier in deinen Thread.

Lou Schalter 10.10.2013 21:11

Cure (default) war angehakt, habe auf Continue geklickt, jetzt kommt ein Fenster:

Warning

Can't cure MBR. Write standard boot code?

If you have installed custom bootloader (eg Acronis, Grub, Lilo), you will need to reinstall them after the treatment.

EDIT:

Wenn ich jetzt wüsste für was das Akronym "MBR" steht könnte ich auch selbst schlussfolgern ob "Yes" oder "No" zu klicken ist ... hmmm. Also ganz sicher steht es weder für "durch Menstruationskrämpfe bedingte Rückenbeschwerden", noch für "Mercedes Benz Rückrufaktion" ... http://www.trojaner-board.de/images/smilies/kloppen.gif

EDIT 2:

Hier eine Hardcopy von der Meldung:
http://s7.directupload.net/images/131010/snadihwg.jpg

aharonov 10.10.2013 21:47

Zitat:

Wenn ich jetzt wüsste für was das Akronym "MBR" steht könnte ich auch selbst schlussfolgern ob "Yes" oder "No" zu klicken ist
Es steht für Master Boot Record (deutsch: Masterbootsektor); siehe z.B. hier.
Es bleibt keine Alternative, als "Yes" zu drücken und den bösartigen Code durch einen Standard-Windows-MBR zu überschreiben.

Lou Schalter 10.10.2013 21:48

O.k. Habe ich geklickt. Reboote jetzt. BRB.

aharonov 10.10.2013 21:49

Ok. Ich verabschiede mich für heute und bin morgen wieder da.
Poste dann noch das neue Log des TDSSKillers und versuche einen FRST-Scan wie beschrieben.

Lou Schalter 10.10.2013 21:53

Hier der TDSS-Log:

Code:

22:08:47.0783 0x1780  TDSS rootkit removing tool 3.0.0.12 Oct  9 2013 14:59:22
22:08:48.0077 0x1780  ============================================================
22:08:48.0078 0x1780  Current date / time: 2013/10/10 22:08:48.0077
22:08:48.0078 0x1780  SystemInfo:
22:08:48.0078 0x1780 
22:08:48.0078 0x1780  OS Version: 6.1.7601 ServicePack: 1.0
22:08:48.0078 0x1780  Product type: Workstation
22:08:48.0078 0x1780  ComputerName: *****-PC
22:08:48.0078 0x1780  UserName: *****
22:08:48.0078 0x1780  Windows directory: C:\Windows
22:08:48.0078 0x1780  System windows directory: C:\Windows
22:08:48.0078 0x1780  Running under WOW64
22:08:48.0078 0x1780  Processor architecture: Intel x64
22:08:48.0078 0x1780  Number of processors: 8
22:08:48.0078 0x1780  Page size: 0x1000
22:08:48.0078 0x1780  Boot type: Normal boot
22:08:48.0078 0x1780  ============================================================
22:08:48.0912 0x1780  System UUID: {438E91DF-0BCC-791E-3945-FA16759C1496}
22:08:49.0207 0x1780  Drive \Device\Harddisk2\DR2 - Size: 0x4453C00000 (273.31 Gb), SectorSize: 0x200, Cylinders: 0x8B5E, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000048
22:08:49.0225 0x1780  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:08:49.0226 0x1780  Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:08:49.0235 0x1780  Drive \Device\Harddisk3\DR3 - Size: 0x1D1A00000 (7.28 Gb), SectorSize: 0x200, Cylinders: 0x3B5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
22:08:49.0238 0x1780  ============================================================
22:08:49.0238 0x1780  \Device\Harddisk2\DR2:
22:08:49.0238 0x1780  MBR partitions:
22:08:49.0238 0x1780  \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x37000
22:08:49.0238 0x1780  \Device\Harddisk2\DR2\Partition2: MBR, Type 0x7, StartLBA 0x37800, BlocksNum 0x22266800
22:08:49.0238 0x1780  \Device\Harddisk0\DR0:
22:08:49.0242 0x1780  MBR partitions:
22:08:49.0242 0x1780  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
22:08:49.0242 0x1780  \Device\Harddisk1\DR1:
22:08:49.0242 0x1780  MBR partitions:
22:08:49.0242 0x1780  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
22:08:49.0242 0x1780  \Device\Harddisk3\DR3:
22:08:49.0244 0x1780  MBR partitions:
22:08:49.0244 0x1780  \Device\Harddisk3\DR3\Partition1: MBR, Type 0xB, StartLBA 0xB88, BlocksNum 0xE8C478
22:08:49.0244 0x1780  ============================================================
22:08:49.0246 0x1780  C: <-> \Device\Harddisk2\DR2\Partition2
22:08:49.0273 0x1780  E: <-> \Device\Harddisk0\DR0\Partition1
22:08:49.0293 0x1780  D: <-> \Device\Harddisk1\DR1\Partition1
22:08:49.0293 0x1780  ============================================================
22:08:49.0294 0x1780  Initialize success
22:08:49.0294 0x1780  ============================================================
22:09:13.0690 0x15d0  ============================================================
22:09:13.0690 0x15d0  Scan started
22:09:13.0690 0x15d0  Mode: Manual; SigCheck; TDLFS;
22:09:13.0690 0x15d0  ============================================================
22:09:13.0690 0x15d0  KSN ping started
22:09:16.0088 0x15d0  KSN ping finished: true
22:09:16.0270 0x15d0  ================ Scan system memory ========================
22:09:16.0270 0x15d0  System memory - ok
22:09:16.0270 0x15d0  ================ Scan services =============================
22:09:16.0381 0x15d0  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
22:09:16.0420 0x15d0  1394ohci - ok
22:09:16.0438 0x15d0  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
22:09:16.0454 0x15d0  ACPI - ok
22:09:16.0463 0x15d0  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
22:09:16.0477 0x15d0  AcpiPmi - ok
22:09:16.0549 0x15d0  [ 1FE7229F34038D1ABE837688EC0EF15B, BEDCCCC47285DC7B8D43A6F8B69347E53E4165E30C684503D6A8FDAE191D0ABF ] AcrSch2Svc      C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
22:09:16.0576 0x15d0  AcrSch2Svc - ok
22:09:16.0602 0x15d0  [ 1C090E86AFD15231377AD37436C3C719, 7C8C679ADB7AF0A965508012C4F3F2FA68D0BFE0E04941B94693D94DB0931B53 ] ADIHdAudAddService C:\Windows\system32\drivers\ADIHdAud.sys
22:09:16.0623 0x15d0  ADIHdAudAddService - ok
22:09:16.0661 0x15d0  [ 62B7936F9036DD6ED36E6A7EFA805DC0, C58EA1B46CB3595386C9217A7785F2A436916FB1E0BDC0E4BE484292C55AA455 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:09:16.0668 0x15d0  AdobeARMservice - ok
22:09:16.0747 0x15d0  [ A283108E14F3970432C21AF4C0CB1BCE, 1D3219EF916D54232838870EDE557296AACB714B456ED0AAE0DE3CE3822F4643 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:09:16.0761 0x15d0  AdobeFlashPlayerUpdateSvc - ok
22:09:16.0781 0x15d0  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
22:09:16.0801 0x15d0  adp94xx - ok
22:09:16.0819 0x15d0  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci        C:\Windows\system32\drivers\adpahci.sys
22:09:16.0835 0x15d0  adpahci - ok
22:09:16.0845 0x15d0  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
22:09:16.0857 0x15d0  adpu320 - ok
22:09:16.0867 0x15d0  [ 3BDB13C79CC8C06E2F8182595903ED69, 9E00D6649E862DE6812718B091C350E05A2C5C4D28DE8E05E3DD1F789A04EE96 ] AEADIFilters    C:\Windows\system32\AEADISRV.EXE
22:09:16.0879 0x15d0  AEADIFilters - ok
22:09:16.0890 0x15d0  [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
22:09:16.0919 0x15d0  AeLookupSvc - ok
22:09:16.0942 0x15d0  [ AE1FCE2CD1E99BEA89183BA8CD320872, 96F14BCA0C2479F39A5027A71922907D0F35CAD8E9A5037674DF7995BBDB2B51 ] afcdp          C:\Windows\system32\DRIVERS\afcdp.sys
22:09:16.0957 0x15d0  afcdp - ok
22:09:17.0038 0x15d0  [ AF44F7E027037628F1FAC3C13CDE73E6, 56A95EBF2241C275FD401487C5F0E86859F8637D8B1BD01B7157EE9BC22B1907 ] afcdpsrv        C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
22:09:17.0105 0x15d0  afcdpsrv - ok
22:09:17.0134 0x15d0  [ 1C7857B62DE5994A75B054A9FD4C3825, 83F963D7E636532B1AD30B1E727EC429317CA540F6EB3BB268FCC0B163B67767 ] AFD            C:\Windows\system32\drivers\afd.sys
22:09:17.0155 0x15d0  AFD - ok
22:09:17.0165 0x15d0  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\drivers\agp440.sys
22:09:17.0175 0x15d0  agp440 - ok
22:09:17.0192 0x15d0  ajlvsasx - ok
22:09:17.0205 0x15d0  [ 44F360B65C37A42EB5B71C2E5179FDD5, A7E65515FEE1698C96F647111F5C7D009C5FAC9A1F62D027802861A699AF1F93 ] aksdf          C:\Windows\system32\drivers\aksdf.sys
22:09:17.0217 0x15d0  aksdf - ok
22:09:17.0250 0x15d0  [ BC61697103C9EFC3DBA83777CEA8E76B, 15F55C9E4ACB695A5A9BEF52D69AFE9D8D50F8307B81349FB4300368B52493D3 ] aksfridge      C:\Windows\system32\drivers\aksfridge.sys
22:09:17.0261 0x15d0  aksfridge - ok
22:09:17.0280 0x15d0  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG            C:\Windows\System32\alg.exe
22:09:17.0293 0x15d0  ALG - ok
22:09:17.0306 0x15d0  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
22:09:17.0315 0x15d0  aliide - ok
22:09:17.0338 0x15d0  [ 310F86335B0505DDC6D2DD48E66EF06B, 936273CA046B3AE0944E6C1557CECB2A0C61D034977BBB9FACBE062617CF3A2C ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
22:09:17.0360 0x15d0  AMD External Events Utility - ok
22:09:17.0372 0x15d0  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
22:09:17.0382 0x15d0  amdide - ok
22:09:17.0401 0x15d0  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
22:09:17.0414 0x15d0  AmdK8 - ok
22:09:17.0682 0x15d0  [ 79CC9BE187E3144E1B58A54B842475E7, 89DD3177B5CE649AC0093603CE13FBFD93AC24F8E16C52672549110141106F4A ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
22:09:17.0953 0x15d0  amdkmdag - ok
22:09:17.0992 0x15d0  [ 07561D3B7FD99F6E186C49C2D0628E38, D2D72EB45EAD29A3099C040E99A4F1F4902D3BDC0466800C63ECD33343DC1224 ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
22:09:18.0021 0x15d0  amdkmdap - ok
22:09:18.0041 0x15d0  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
22:09:18.0053 0x15d0  AmdPPM - ok
22:09:18.0068 0x15d0  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
22:09:18.0080 0x15d0  amdsata - ok
22:09:18.0097 0x15d0  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
22:09:18.0109 0x15d0  amdsbs - ok
22:09:18.0116 0x15d0  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata        C:\Windows\system32\drivers\amdxata.sys
22:09:18.0125 0x15d0  amdxata - ok
22:09:18.0134 0x15d0  [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644ED2E50CF9BB491A ] AppID          C:\Windows\system32\drivers\appid.sys
22:09:18.0162 0x15d0  AppID - ok
22:09:18.0169 0x15d0  [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
22:09:18.0197 0x15d0  AppIDSvc - ok
22:09:18.0208 0x15d0  [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo        C:\Windows\System32\appinfo.dll
22:09:18.0221 0x15d0  Appinfo - ok
22:09:18.0229 0x15d0  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt        C:\Windows\System32\appmgmts.dll
22:09:18.0244 0x15d0  AppMgmt - ok
22:09:18.0252 0x15d0  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc            C:\Windows\system32\drivers\arc.sys
22:09:18.0263 0x15d0  arc - ok
22:09:18.0272 0x15d0  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\drivers\arcsas.sys
22:09:18.0283 0x15d0  arcsas - ok
22:09:18.0326 0x15d0  aspnet_state - ok
22:09:18.0342 0x15d0  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
22:09:18.0370 0x15d0  AsyncMac - ok
22:09:18.0384 0x15d0  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi          C:\Windows\system32\drivers\atapi.sys
22:09:18.0394 0x15d0  atapi - ok
22:09:18.0418 0x15d0  [ ED3A041014FBBFDC23D6C04F9C7A5D79, A039D8F4C0EA2101898A253E13DFED5FA8500C412ACC47835415E27C9BD068FF ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
22:09:18.0430 0x15d0  AtiHDAudioService - ok
22:09:18.0456 0x15d0  [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:09:18.0497 0x15d0  AudioEndpointBuilder - ok
22:09:18.0517 0x15d0  [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
22:09:18.0557 0x15d0  AudioSrv - ok
22:09:18.0589 0x15d0  [ C6F4C466B654C1BE98AF31418BB5AC30, 62AA4456F8E22A6E508EB44DE4309615057117AAF923C13BBED15AA39630E76B ] AVM WLAN Connection Service C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
22:09:18.0601 0x15d0  AVM WLAN Connection Service - detected UnsignedFile.Multi.Generic ( 1 )
22:09:21.0012 0x15d0  Detect skipped due to KSN trusted
22:09:21.0012 0x15d0  AVM WLAN Connection Service - ok
22:09:21.0029 0x15d0  [ 1DC2F715792CF33428AD7993ACBD224D, 129FBD517E016914CD61C35894C0B9B2074E680F1EB21201597E5C13CAF4529F ] avmeject        C:\Windows\system32\drivers\avmeject.sys
22:09:21.0038 0x15d0  avmeject - ok
22:09:21.0052 0x15d0  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\Windows\System32\AxInstSV.dll
22:09:21.0069 0x15d0  AxInstSV - ok
22:09:21.0087 0x15d0  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv        C:\Windows\system32\drivers\bxvbda.sys
22:09:21.0108 0x15d0  b06bdrv - ok
22:09:21.0146 0x15d0  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
22:09:21.0163 0x15d0  b57nd60a - ok
22:09:21.0175 0x15d0  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
22:09:21.0188 0x15d0  BDESVC - ok
22:09:21.0193 0x15d0  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
22:09:21.0221 0x15d0  Beep - ok
22:09:21.0259 0x15d0  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE            C:\Windows\System32\bfe.dll
22:09:21.0301 0x15d0  BFE - ok
22:09:21.0329 0x15d0  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\system32\qmgr.dll
22:09:21.0375 0x15d0  BITS - ok
22:09:21.0384 0x15d0  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
22:09:21.0396 0x15d0  blbdrive - ok
22:09:21.0406 0x15d0  [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
22:09:21.0419 0x15d0  bowser - ok
22:09:21.0426 0x15d0  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
22:09:21.0440 0x15d0  BrFiltLo - ok
22:09:21.0443 0x15d0  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
22:09:21.0456 0x15d0  BrFiltUp - ok
22:09:21.0477 0x15d0  [ 5C2F352A4E961D72518261257AAE204B, 9EE1001E1D46A414A7A86FE1DBBE232203E26F54D9EF43ED31ED8EACD4D09853 ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
22:09:21.0507 0x15d0  BridgeMP - ok
22:09:21.0521 0x15d0  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser        C:\Windows\System32\browser.dll
22:09:21.0535 0x15d0  Browser - ok
22:09:21.0584 0x15d0  [ 21FA3E51618FF8E2F4B29964ABC5884F, AB6E5ACEBC426354C7CD7D297D8D2CA086755F0E410320CA15B989E8963ECC78 ] Browser Defender Update Service C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
22:09:21.0593 0x15d0  Browser Defender Update Service - ok
22:09:21.0606 0x15d0  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
22:09:21.0624 0x15d0  Brserid - ok
22:09:21.0635 0x15d0  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
22:09:21.0649 0x15d0  BrSerWdm - ok
22:09:21.0653 0x15d0  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
22:09:21.0667 0x15d0  BrUsbMdm - ok
22:09:21.0675 0x15d0  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
22:09:21.0686 0x15d0  BrUsbSer - ok
22:09:21.0708 0x15d0  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
22:09:21.0722 0x15d0  BTHMODEM - ok
22:09:21.0734 0x15d0  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv        C:\Windows\system32\bthserv.dll
22:09:21.0763 0x15d0  bthserv - ok
22:09:21.0771 0x15d0  catchme - ok
22:09:21.0781 0x15d0  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
22:09:21.0810 0x15d0  cdfs - ok
22:09:21.0820 0x15d0  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
22:09:21.0834 0x15d0  cdrom - ok
22:09:21.0848 0x15d0  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc    C:\Windows\System32\certprop.dll
22:09:21.0876 0x15d0  CertPropSvc - ok
22:09:21.0885 0x15d0  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\drivers\circlass.sys
22:09:21.0899 0x15d0  circlass - ok
22:09:21.0919 0x15d0  [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS            C:\Windows\system32\CLFS.sys
22:09:21.0935 0x15d0  CLFS - ok
22:09:21.0949 0x15d0  [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:09:21.0958 0x15d0  clr_optimization_v2.0.50727_32 - ok
22:09:21.0999 0x15d0  [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:09:22.0008 0x15d0  clr_optimization_v2.0.50727_64 - ok
22:09:22.0075 0x15d0  [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:09:22.0085 0x15d0  clr_optimization_v4.0.30319_32 - ok
22:09:22.0119 0x15d0  [ C6F9AF94DCD58122A4D7E89DB6BED29D, CB0E5AE60EC76323585FB86D89E8DB7ADB5EDF6EA3D0B27E9ECE75B8CAA8BFDE ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:09:22.0129 0x15d0  clr_optimization_v4.0.30319_64 - ok
22:09:22.0137 0x15d0  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
22:09:22.0150 0x15d0  CmBatt - ok
22:09:22.0159 0x15d0  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
22:09:22.0169 0x15d0  cmdide - ok
22:09:22.0188 0x15d0  [ 9AC4F97C2D3E93367E2148EA940CD2CD, 530E089E5CF868AECDB2B5548EBE76E0CA98FC74A72897292AB2485734402E3B ] CNG            C:\Windows\system32\Drivers\cng.sys
22:09:22.0210 0x15d0  CNG - ok
22:09:22.0217 0x15d0  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
22:09:22.0227 0x15d0  Compbatt - ok
22:09:22.0239 0x15d0  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
22:09:22.0253 0x15d0  CompositeBus - ok
22:09:22.0262 0x15d0  COMSysApp - ok
22:09:22.0286 0x15d0  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
22:09:22.0295 0x15d0  crcdisk - ok
22:09:22.0329 0x15d0  crtjnuyc - ok
22:09:22.0349 0x15d0  [ 6B400F211BEE880A37A1ED0368776BF4, 2F27C6FA96A1C8CBDA467846DA57E63949A7EA37DB094B13397DDD30114295BD ] CryptSvc        C:\Windows\system32\cryptsvc.dll
22:09:22.0365 0x15d0  CryptSvc - ok
22:09:22.0383 0x15d0  [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC            C:\Windows\system32\drivers\csc.sys
22:09:22.0405 0x15d0  CSC - ok
22:09:22.0430 0x15d0  [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService      C:\Windows\System32\cscsvc.dll
22:09:22.0456 0x15d0  CscService - ok
22:09:22.0471 0x15d0  [ 8EC96B753727B380089D66D4AB5869DF, F8E36B68EED9680291610C83E7DF16A04D278E3E7BC807CF8A870D01C4E5A95E ] CYUSB          C:\Windows\system32\Drivers\CYUSB.sys
22:09:22.0482 0x15d0  CYUSB - ok
22:09:22.0498 0x15d0  [ 003626F7CA17C204F16CD5047AF0703A, BA9063D77A60AF1107A1A6B3C1DD6F1EF3D9DCE7616BAC67DF13AEDD67B683F3 ] danewFltr      C:\Windows\system32\drivers\danew.sys
22:09:22.0508 0x15d0  danewFltr - ok
22:09:22.0530 0x15d0  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch      C:\Windows\system32\rpcss.dll
22:09:22.0570 0x15d0  DcomLaunch - ok
22:09:22.0583 0x15d0  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc      C:\Windows\System32\defragsvc.dll
22:09:22.0617 0x15d0  defragsvc - ok
22:09:22.0630 0x15d0  [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
22:09:22.0659 0x15d0  DfsC - ok
22:09:22.0679 0x15d0  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
22:09:22.0697 0x15d0  Dhcp - ok
22:09:22.0714 0x15d0  DigiRefresh - ok
22:09:22.0719 0x15d0  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
22:09:22.0747 0x15d0  discache - ok
22:09:22.0754 0x15d0  [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk            C:\Windows\system32\drivers\disk.sys
22:09:22.0764 0x15d0  Disk - ok
22:09:22.0771 0x15d0  [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc          C:\Windows\system32\drivers\dmvsc.sys
22:09:22.0783 0x15d0  dmvsc - ok
22:09:22.0801 0x15d0  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
22:09:22.0816 0x15d0  Dnscache - ok
22:09:22.0824 0x15d0  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc        C:\Windows\System32\dot3svc.dll
22:09:22.0856 0x15d0  dot3svc - ok
22:09:22.0869 0x15d0  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS            C:\Windows\system32\dps.dll
22:09:22.0899 0x15d0  DPS - ok
22:09:22.0909 0x15d0  [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
22:09:22.0922 0x15d0  drmkaud - ok
22:09:22.0956 0x15d0  [ AF2E16242AA723F68F461B6EAE2EAD3D, 3973633C6D231DB8D92DE310D3A0836C64639B9A20C6C56385FB218A707C1BC3 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
22:09:22.0984 0x15d0  DXGKrnl - ok
22:09:22.0996 0x15d0  eaarkkjg - ok
22:09:23.0010 0x15d0  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost        C:\Windows\System32\eapsvc.dll
22:09:23.0040 0x15d0  EapHost - ok
22:09:23.0118 0x15d0  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv          C:\Windows\system32\drivers\evbda.sys
22:09:23.0202 0x15d0  ebdrv - ok
22:09:23.0221 0x15d0  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] EFS            C:\Windows\System32\lsass.exe
22:09:23.0234 0x15d0  EFS - ok
22:09:23.0274 0x15d0  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
22:09:23.0300 0x15d0  ehRecvr - ok
22:09:23.0313 0x15d0  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched        C:\Windows\ehome\ehsched.exe
22:09:23.0327 0x15d0  ehSched - ok
22:09:23.0350 0x15d0  [ A05FC7ECA0966EBB70E4D17B855A853B, 16A0C8138A3BBD8BE2658261131F9777940CFB1431018A10710E5C1A88AB70EA ] ElbyCDIO        C:\Windows\system32\Drivers\ElbyCDIO.sys
22:09:23.0359 0x15d0  ElbyCDIO - ok
22:09:23.0376 0x15d0  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
22:09:23.0395 0x15d0  elxstor - ok
22:09:23.0402 0x15d0  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
22:09:23.0414 0x15d0  ErrDev - ok
22:09:23.0436 0x15d0  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem    C:\Windows\system32\es.dll
22:09:23.0472 0x15d0  EventSystem - ok
22:09:23.0484 0x15d0  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat          C:\Windows\system32\drivers\exfat.sys
22:09:23.0515 0x15d0  exfat - ok
22:09:23.0529 0x15d0  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
22:09:23.0561 0x15d0  fastfat - ok
22:09:23.0584 0x15d0  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax            C:\Windows\system32\fxssvc.exe
22:09:23.0610 0x15d0  Fax - ok
22:09:23.0619 0x15d0  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc            C:\Windows\system32\drivers\fdc.sys
22:09:23.0630 0x15d0  fdc - ok
22:09:23.0640 0x15d0  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost        C:\Windows\system32\fdPHost.dll
22:09:23.0668 0x15d0  fdPHost - ok
22:09:23.0680 0x15d0  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
22:09:23.0710 0x15d0  FDResPub - ok
22:09:23.0717 0x15d0  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
22:09:23.0728 0x15d0  FileInfo - ok
22:09:23.0735 0x15d0  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
22:09:23.0763 0x15d0  Filetrace - ok
22:09:23.0769 0x15d0  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
22:09:23.0781 0x15d0  flpydisk - ok
22:09:23.0794 0x15d0  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
22:09:23.0808 0x15d0  FltMgr - ok
22:09:23.0841 0x15d0  [ 5C4CB4086FB83115B153E47ADD961A0C, 0C3AB7D04BEB3A8FDE00B0C86E6FE064B1CEBB3E4DE1A29CD27830806FA300B3 ] FontCache      C:\Windows\system32\FntCache.dll
22:09:23.0877 0x15d0  FontCache - ok
22:09:23.0900 0x15d0  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:09:23.0907 0x15d0  FontCache3.0.0.0 - ok
22:09:23.0919 0x15d0  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
22:09:23.0928 0x15d0  FsDepends - ok
22:09:23.0939 0x15d0  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
22:09:23.0948 0x15d0  Fs_Rec - ok
22:09:23.0967 0x15d0  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
22:09:23.0983 0x15d0  fvevol - ok
22:09:24.0001 0x15d0  [ 444534CBA693DD23C1CC589681E01656, DF8ED7FFA66E0A88EBB58A491A177D8CEB35B08B0911D7A1F4B8865755DC27CE ] FWLANUSB        C:\Windows\system32\DRIVERS\fwlanusb.sys
22:09:24.0020 0x15d0  FWLANUSB - ok
22:09:24.0028 0x15d0  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
22:09:24.0038 0x15d0  gagp30kx - ok
22:09:24.0062 0x15d0  [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc          C:\Windows\System32\gpsvc.dll
22:09:24.0106 0x15d0  gpsvc - ok
22:09:24.0147 0x15d0  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:09:24.0156 0x15d0  gupdate - ok
22:09:24.0172 0x15d0  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:09:24.0181 0x15d0  gupdatem - ok
22:09:24.0217 0x15d0  [ D619BA1712B83D14149850E758B835AD, AD18807EC4DA6FA8C6846C1A0D914071FD59BD3273AFC103E5F2A7141F18C5F4 ] hardlock        C:\Windows\system32\drivers\hardlock.sys
22:09:24.0233 0x15d0  hardlock - ok
22:09:24.0241 0x15d0  hasplms - ok
22:09:24.0266 0x15d0  [ D5FA01185A7D5A65724FD87B34E53F5B, 4951DC34E0E0EA598C3599B619D5DEEF527D0B5D2C2C6392469865C6420B31C0 ] hcmon          C:\Windows\system32\drivers\hcmon.sys
22:09:24.0274 0x15d0  hcmon - ok
22:09:24.0283 0x15d0  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
22:09:24.0295 0x15d0  hcw85cir - ok
22:09:24.0318 0x15d0  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:09:24.0339 0x15d0  HdAudAddService - ok
22:09:24.0362 0x15d0  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
22:09:24.0377 0x15d0  HDAudBus - ok
22:09:24.0383 0x15d0  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt        C:\Windows\system32\drivers\HidBatt.sys
22:09:24.0395 0x15d0  HidBatt - ok
22:09:24.0406 0x15d0  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
22:09:24.0421 0x15d0  HidBth - ok
22:09:24.0432 0x15d0  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr          C:\Windows\system32\drivers\hidir.sys
22:09:24.0447 0x15d0  HidIr - ok
22:09:24.0454 0x15d0  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv        C:\Windows\System32\hidserv.dll
22:09:24.0483 0x15d0  hidserv - ok
22:09:24.0493 0x15d0  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
22:09:24.0505 0x15d0  HidUsb - ok
22:09:24.0514 0x15d0  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
22:09:24.0544 0x15d0  hkmsvc - ok
22:09:24.0560 0x15d0  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:09:24.0577 0x15d0  HomeGroupListener - ok
22:09:24.0589 0x15d0  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:09:24.0604 0x15d0  HomeGroupProvider - ok
22:09:24.0612 0x15d0  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
22:09:24.0622 0x15d0  HpSAMD - ok
22:09:24.0648 0x15d0  [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
22:09:24.0691 0x15d0  HTTP - ok
22:09:24.0696 0x15d0  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
22:09:24.0705 0x15d0  hwpolicy - ok
22:09:24.0724 0x15d0  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
22:09:24.0737 0x15d0  i8042prt - ok
22:09:24.0778 0x15d0  [ 7548066DF68A8A1A56B043359F915F37, 6225DDE554E45858374CBD284A85A00F773089A667C08492187A637232B8BD9A ] IAANTMON        C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
22:09:24.0792 0x15d0  IAANTMON - ok
22:09:24.0813 0x15d0  [ 1D004CB1DA6323B1F55CAEF7F94B61D9, 8FFFB429BA46938724BBB87AB9B3EC77EA17C4B893BABDBDD38309F02963D405 ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
22:09:24.0828 0x15d0  iaStor - ok
22:09:24.0845 0x15d0  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
22:09:24.0862 0x15d0  iaStorV - ok
22:09:24.0902 0x15d0  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209AFC22A34D2BE99 ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:09:24.0925 0x15d0  idsvc - ok
22:09:24.0936 0x15d0  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
22:09:24.0945 0x15d0  iirsp - ok
22:09:24.0970 0x15d0  [ FCD84C381E0140AF901E58D48882D26B, 76955FFC230C801E8ED890E32076075F04CD6E5EC79E594FDE6D23797A36B406 ] IKEEXT          C:\Windows\System32\ikeext.dll
22:09:25.0015 0x15d0  IKEEXT - ok
22:09:25.0027 0x15d0  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
22:09:25.0036 0x15d0  intelide - ok
22:09:25.0055 0x15d0  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
22:09:25.0068 0x15d0  intelppm - ok
22:09:25.0076 0x15d0  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
22:09:25.0107 0x15d0  IPBusEnum - ok
22:09:25.0120 0x15d0  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:09:25.0148 0x15d0  IpFilterDriver - ok
22:09:25.0171 0x15d0  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
22:09:25.0194 0x15d0  iphlpsvc - ok
22:09:25.0206 0x15d0  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
22:09:25.0219 0x15d0  IPMIDRV - ok
22:09:25.0230 0x15d0  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
22:09:25.0259 0x15d0  IPNAT - ok
22:09:25.0270 0x15d0  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
22:09:25.0284 0x15d0  IRENUM - ok
22:09:25.0291 0x15d0  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
22:09:25.0300 0x15d0  isapnp - ok
22:09:25.0314 0x15d0  [ D931D7309DEB2317035B07C9F9E6B0BD, 13AD84172ED8C6153F8A98499C01733B74E48464CE07D099508E38D409913ED3 ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
22:09:25.0328 0x15d0  iScsiPrt - ok
22:09:25.0336 0x15d0  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
22:09:25.0345 0x15d0  kbdclass - ok
22:09:25.0357 0x15d0  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
22:09:25.0369 0x15d0  kbdhid - ok
22:09:25.0375 0x15d0  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] KeyIso          C:\Windows\system32\lsass.exe
22:09:25.0387 0x15d0  KeyIso - ok
22:09:25.0398 0x15d0  [ 97A7070AEA4C058B6418519E869A63B4, 15345C2D6CA159BD498002974A0BD21CAB611124D85E3320248B47652AEF23C8 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
22:09:25.0408 0x15d0  KSecDD - ok
22:09:25.0423 0x15d0  [ 26C43A7C2862447EC59DEDA188D1DA07, 5363BF87E650FE2010ACA9417D6920FF4ED752256FF47732882E9B2BA1ED154B ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
22:09:25.0435 0x15d0  KSecPkg - ok
22:09:25.0443 0x15d0  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
22:09:25.0470 0x15d0  ksthunk - ok
22:09:25.0485 0x15d0  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm          C:\Windows\system32\msdtckrm.dll
22:09:25.0522 0x15d0  KtmRm - ok
22:09:25.0532 0x15d0  ktmujbzd - ok
22:09:25.0547 0x15d0  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\Windows\System32\srvsvc.dll
22:09:25.0580 0x15d0  LanmanServer - ok
22:09:25.0595 0x15d0  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:09:25.0626 0x15d0  LanmanWorkstation - ok
22:09:25.0652 0x15d0  [ FA529FB35694C24BF98A9EF67C1CD9D0, 7B3C587C38CF13D514140F0A55E58997D6071D1DEFD97E274E3F490660AC6075 ] LGBusEnum      C:\Windows\system32\drivers\LGBusEnum.sys
22:09:25.0660 0x15d0  LGBusEnum - ok
22:09:25.0679 0x15d0  [ 94B29CE153765E768F004FB3440BE2B0, E74C01CEBDA589CDDE35CBCBAA18700E3742DD3B48A90DB3630992467FFC5024 ] LGVirHid        C:\Windows\system32\drivers\LGVirHid.sys
22:09:25.0688 0x15d0  LGVirHid - ok
22:09:25.0708 0x15d0  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
22:09:25.0736 0x15d0  lltdio - ok
22:09:25.0754 0x15d0  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
22:09:25.0788 0x15d0  lltdsvc - ok
22:09:25.0791 0x15d0  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts        C:\Windows\System32\lmhsvc.dll
22:09:25.0819 0x15d0  lmhosts - ok
22:09:25.0834 0x15d0  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
22:09:25.0846 0x15d0  LSI_FC - ok
22:09:25.0855 0x15d0  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
22:09:25.0866 0x15d0  LSI_SAS - ok
22:09:25.0873 0x15d0  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
22:09:25.0883 0x15d0  LSI_SAS2 - ok
22:09:25.0892 0x15d0  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
22:09:25.0903 0x15d0  LSI_SCSI - ok
22:09:25.0910 0x15d0  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv          C:\Windows\system32\drivers\luafv.sys
22:09:25.0941 0x15d0  luafv - ok
22:09:25.0966 0x15d0  [ E2C6A3F80C1979B911408C17E3893371, 56FD7B743303BDC751C031372D7242C5CD25DAF927942D2D90F71033E7DE625C ] MAUSBFASTTRACK  C:\Windows\system32\DRIVERS\MAudioFastTrack.sys
22:09:25.0977 0x15d0  MAUSBFASTTRACK - ok
22:09:25.0987 0x15d0  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
22:09:26.0000 0x15d0  Mcx2Svc - ok
22:09:26.0009 0x15d0  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas        C:\Windows\system32\drivers\megasas.sys
22:09:26.0019 0x15d0  megasas - ok
22:09:26.0030 0x15d0  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
22:09:26.0044 0x15d0  MegaSR - ok
22:09:26.0055 0x15d0  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS          C:\Windows\system32\mmcss.dll
22:09:26.0084 0x15d0  MMCSS - ok
22:09:26.0091 0x15d0  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem          C:\Windows\system32\drivers\modem.sys
22:09:26.0119 0x15d0  Modem - ok
22:09:26.0133 0x15d0  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
22:09:26.0147 0x15d0  monitor - ok
22:09:26.0156 0x15d0  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
22:09:26.0166 0x15d0  mouclass - ok
22:09:26.0176 0x15d0  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
22:09:26.0187 0x15d0  mouhid - ok
22:09:26.0196 0x15d0  [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
22:09:26.0207 0x15d0  mountmgr - ok
22:09:26.0226 0x15d0  [ F8A10560B35C66F9DE212F03DAD5BFA7, 3ADCBC309A55494326EE8D152F92DFD11E1F97C897C8019BAB547E75D735FE92 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
22:09:26.0242 0x15d0  MpFilter - ok
22:09:26.0251 0x15d0  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
22:09:26.0263 0x15d0  mpio - ok
22:09:26.0287 0x15d0  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
22:09:26.0317 0x15d0  mpsdrv - ok
22:09:26.0345 0x15d0  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\Windows\system32\mpssvc.dll
22:09:26.0390 0x15d0  MpsSvc - ok
22:09:26.0402 0x15d0  [ DC722758B8261E1ABAFD31A3C0A66380, 88BBE073E2CCD1DAB4656DDC53D5161E8A91D035ADAC1465D0CEBA86F1BB6D9A ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
22:09:26.0420 0x15d0  MRxDAV - ok
22:09:26.0433 0x15d0  [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
22:09:26.0447 0x15d0  mrxsmb - ok
22:09:26.0461 0x15d0  [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:09:26.0477 0x15d0  mrxsmb10 - ok
22:09:26.0489 0x15d0  [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:09:26.0503 0x15d0  mrxsmb20 - ok
22:09:26.0515 0x15d0  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
22:09:26.0524 0x15d0  msahci - ok
22:09:26.0535 0x15d0  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
22:09:26.0546 0x15d0  msdsm - ok
22:09:26.0558 0x15d0  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC          C:\Windows\System32\msdtc.exe
22:09:26.0573 0x15d0  MSDTC - ok
22:09:26.0583 0x15d0  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
22:09:26.0611 0x15d0  Msfs - ok
22:09:26.0618 0x15d0  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
22:09:26.0645 0x15d0  mshidkmdf - ok
22:09:26.0652 0x15d0  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
22:09:26.0662 0x15d0  msisadrv - ok
22:09:26.0675 0x15d0  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
22:09:26.0707 0x15d0  MSiSCSI - ok
22:09:26.0709 0x15d0  msiserver - ok
22:09:26.0726 0x15d0  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
22:09:26.0753 0x15d0  MSKSSRV - ok
22:09:26.0791 0x15d0  [ E07DEC52FF801841BA9B6878A60304FB, A57A999F411559EA97C830C9FE0234578E2E98EDAF72F9949891F901B83B22A4 ] MsMpSvc        C:\Program Files\Microsoft Security Client\MsMpEng.exe
22:09:26.0802 0x15d0  MsMpSvc - ok
22:09:26.0812 0x15d0  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
22:09:26.0841 0x15d0  MSPCLOCK - ok
22:09:26.0850 0x15d0  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
22:09:26.0878 0x15d0  MSPQM - ok
22:09:26.0891 0x15d0  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
22:09:26.0907 0x15d0  MsRPC - ok
22:09:26.0918 0x15d0  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
22:09:26.0927 0x15d0  mssmbios - ok
22:09:26.0935 0x15d0  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
22:09:26.0962 0x15d0  MSTEE - ok
22:09:26.0970 0x15d0  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
22:09:26.0982 0x15d0  MTConfig - ok
22:09:26.0993 0x15d0  [ 03B7145C889603537E9FFEABB1AD1089, B3CD93B893D4A2370CBF382366C6F596372857F8711EF6FFF83BFE2B449F424E ] MTsensor        C:\Windows\system32\DRIVERS\ASACPI.sys
22:09:27.0002 0x15d0  MTsensor - ok
22:09:27.0010 0x15d0  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup            C:\Windows\system32\Drivers\mup.sys
22:09:27.0021 0x15d0  Mup - ok
22:09:27.0038 0x15d0  [ 1CA758BC0DEAF35D21ECAACC30427527, DAC9839E2602365C9B867C602A739450CF7F2C5F65A6539F310B55F9D3C8447E ] mv64xx          C:\Windows\system32\DRIVERS\mv64xx.sys
22:09:27.0052 0x15d0  mv64xx - ok
22:09:27.0071 0x15d0  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
22:09:27.0108 0x15d0  napagent - ok
22:09:27.0126 0x15d0  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
22:09:27.0147 0x15d0  NativeWifiP - ok
22:09:27.0189 0x15d0  [ 13AA2130F2A104DD775EAD0F0EE5417B, EBA07599FC2D10750CE6372EA6BA94EDDAFFF732223A1135F1971B958A6B57A2 ] NAUpdate        C:\Program Files (x86)\Nero\Update\NASvc.exe
22:09:27.0207 0x15d0  NAUpdate - ok
22:09:27.0236 0x15d0  [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS            C:\Windows\system32\drivers\ndis.sys
22:09:27.0262 0x15d0  NDIS - ok
22:09:27.0275 0x15d0  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
22:09:27.0303 0x15d0  NdisCap - ok
22:09:27.0311 0x15d0  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
22:09:27.0339 0x15d0  NdisTapi - ok
22:09:27.0368 0x15d0  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
22:09:27.0396 0x15d0  Ndisuio - ok
22:09:27.0408 0x15d0  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
22:09:27.0437 0x15d0  NdisWan - ok
22:09:27.0445 0x15d0  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
22:09:27.0472 0x15d0  NDProxy - ok
22:09:27.0479 0x15d0  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
22:09:27.0507 0x15d0  NetBIOS - ok
22:09:27.0515 0x15d0  [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
22:09:27.0547 0x15d0  NetBT - ok
22:09:27.0555 0x15d0  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] Netlogon        C:\Windows\system32\lsass.exe
22:09:27.0567 0x15d0  Netlogon - ok
22:09:27.0584 0x15d0  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
22:09:27.0620 0x15d0  Netman - ok
22:09:27.0635 0x15d0  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:09:27.0645 0x15d0  NetMsmqActivator - ok
22:09:27.0649 0x15d0  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:09:27.0659 0x15d0  NetPipeActivator - ok
22:09:27.0676 0x15d0  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
22:09:27.0714 0x15d0  netprofm - ok
22:09:27.0724 0x15d0  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:09:27.0733 0x15d0  NetTcpActivator - ok
22:09:27.0738 0x15d0  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
22:09:27.0747 0x15d0  NetTcpPortSharing - ok
22:09:27.0760 0x15d0  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
22:09:27.0770 0x15d0  nfrd960 - ok
22:09:27.0792 0x15d0  [ 162100E0BC8377710F9D170631921C03, B4FC4F6BCCA5A61EC86F9D10F4FE284E9393CE4599CE64BC8360202F0108B499 ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
22:09:27.0805 0x15d0  NisDrv - ok
22:09:27.0826 0x15d0  [ C6E15F2F95F9C0A6098D43510B604E52, 7B621846EC4DD066657536755455ADB016207A45D49FC5E5F1D50EAD2CCB6B13 ] NisSrv          C:\Program Files\Microsoft Security Client\NisSrv.exe
22:09:27.0844 0x15d0  NisSrv - ok
22:09:27.0857 0x15d0  [ 8AD77806D336673F270DB31645267293, E23F324913554A23CD043DD27D4305AF62F48C0561A0FC7B7811E55B74B1BE79 ] NlaSvc          C:\Windows\System32\nlasvc.dll
22:09:27.0875 0x15d0  NlaSvc - ok
22:09:27.0881 0x15d0  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
22:09:27.0910 0x15d0  Npfs - ok
22:09:27.0923 0x15d0  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi            C:\Windows\system32\nsisvc.dll
22:09:27.0951 0x15d0  nsi - ok
22:09:27.0963 0x15d0  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
22:09:27.0993 0x15d0  nsiproxy - ok
22:09:28.0040 0x15d0  [ B98F8C6E31CD07B2E6F71F7F648E38C0, 2FEA100B80680FBBF644CB6763738804155DF1E94A6542CAE2B2786D770D554E ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
22:09:28.0082 0x15d0  Ntfs - ok
22:09:28.0089 0x15d0  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
22:09:28.0118 0x15d0  Null - ok
22:09:28.0128 0x15d0  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
22:09:28.0140 0x15d0  nvraid - ok
22:09:28.0153 0x15d0  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
22:09:28.0165 0x15d0  nvstor - ok
22:09:28.0173 0x15d0  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
22:09:28.0185 0x15d0  nv_agp - ok
22:09:28.0192 0x15d0  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
22:09:28.0204 0x15d0  ohci1394 - ok
22:09:28.0235 0x15d0  [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:09:28.0245 0x15d0  ose - ok
22:09:28.0377 0x15d0  [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
22:09:28.0481 0x15d0  osppsvc - ok
22:09:28.0508 0x15d0  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
22:09:28.0527 0x15d0  p2pimsvc - ok
22:09:28.0544 0x15d0  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
22:09:28.0565 0x15d0  p2psvc - ok
22:09:28.0574 0x15d0  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport        C:\Windows\system32\drivers\parport.sys
22:09:28.0587 0x15d0  Parport - ok
22:09:28.0599 0x15d0  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
22:09:28.0610 0x15d0  partmgr - ok
22:09:28.0624 0x15d0  [ 3AEAA8B561E63452C655DC0584922257, 04C072969B58657602EB0C21CEDF24FCEE14E61B90A0F758F93925EF2C9FC32D ] PcaSvc          C:\Windows\System32\pcasvc.dll
22:09:28.0644 0x15d0  PcaSvc - ok
22:09:28.0652 0x15d0  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci            C:\Windows\system32\drivers\pci.sys
22:09:28.0664 0x15d0  pci - ok
22:09:28.0671 0x15d0  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
22:09:28.0681 0x15d0  pciide - ok
22:09:28.0692 0x15d0  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
22:09:28.0705 0x15d0  pcmcia - ok
22:09:28.0725 0x15d0  [ 3A68080572B81577791A7B19BB880DA9, 9F64FAB46BF6B5AB46EF77A7077295587F4A6C4851D5EB04D9EC8ECC4C7C67D1 ] PCTCore        C:\Windows\system32\drivers\PCTCore64.sys
22:09:28.0737 0x15d0  PCTCore - ok
22:09:28.0744 0x15d0  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw            C:\Windows\system32\drivers\pcw.sys
22:09:28.0754 0x15d0  pcw - ok
22:09:28.0773 0x15d0  [ 68769C3356B3BE5D1C732C97B9A80D6E, FB2D61145980A2899D1B7729184C54070315B0E63C9A22400A76CCD39E00029C ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
22:09:28.0814 0x15d0  PEAUTH - ok
22:09:28.0851 0x15d0  [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc    C:\Windows\system32\peerdistsvc.dll
22:09:28.0891 0x15d0  PeerDistSvc - ok
22:09:28.0945 0x15d0  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
22:09:28.0958 0x15d0  PerfHost - ok
22:09:28.0999 0x15d0  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla            C:\Windows\system32\pla.dll
22:09:29.0056 0x15d0  pla - ok
22:09:29.0084 0x15d0  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
22:09:29.0104 0x15d0  PlugPlay - ok
22:09:29.0120 0x15d0  PnkBstrA - ok
22:09:29.0129 0x15d0  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
22:09:29.0140 0x15d0  PNRPAutoReg - ok
22:09:29.0153 0x15d0  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
22:09:29.0171 0x15d0  PNRPsvc - ok
22:09:29.0191 0x15d0  [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
22:09:29.0228 0x15d0  PolicyAgent - ok
22:09:29.0246 0x15d0  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power          C:\Windows\system32\umpo.dll
22:09:29.0278 0x15d0  Power - ok
22:09:29.0289 0x15d0  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
22:09:29.0317 0x15d0  PptpMiniport - ok
22:09:29.0325 0x15d0  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor      C:\Windows\system32\drivers\processr.sys
22:09:29.0337 0x15d0  Processor - ok
22:09:29.0354 0x15d0  [ 53E83F1F6CF9D62F32801CF66D8352A8, 1225FED810BE8E0729EEAE5B340035CCBB9BACD3EF247834400F9B72D05ACE48 ] ProfSvc        C:\Windows\system32\profsvc.dll
22:09:29.0370 0x15d0  ProfSvc - ok
22:09:29.0375 0x15d0  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] ProtectedStorage C:\Windows\system32\lsass.exe
22:09:29.0386 0x15d0  ProtectedStorage - ok
22:09:29.0402 0x15d0  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
22:09:29.0431 0x15d0  Psched - ok
22:09:29.0433 0x15d0  ptqllcii - ok
22:09:29.0471 0x15d0  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
22:09:29.0509 0x15d0  ql2300 - ok
22:09:29.0519 0x15d0  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
22:09:29.0531 0x15d0  ql40xx - ok
22:09:29.0547 0x15d0  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE          C:\Windows\system32\qwave.dll
22:09:29.0567 0x15d0  QWAVE - ok
22:09:29.0572 0x15d0  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
22:09:29.0588 0x15d0  QWAVEdrv - ok
22:09:29.0595 0x15d0  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
22:09:29.0622 0x15d0  RasAcd - ok
22:09:29.0640 0x15d0  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
22:09:29.0668 0x15d0  RasAgileVpn - ok
22:09:29.0683 0x15d0  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto        C:\Windows\System32\rasauto.dll
22:09:29.0713 0x15d0  RasAuto - ok
22:09:29.0726 0x15d0  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
22:09:29.0756 0x15d0  Rasl2tp - ok
22:09:29.0773 0x15d0  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
22:09:29.0808 0x15d0  RasMan - ok
22:09:29.0826 0x15d0  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
22:09:29.0855 0x15d0  RasPppoe - ok
22:09:29.0861 0x15d0  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
22:09:29.0890 0x15d0  RasSstp - ok
22:09:29.0904 0x15d0  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
22:09:29.0936 0x15d0  rdbss - ok
22:09:29.0945 0x15d0  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
22:09:29.0958 0x15d0  rdpbus - ok
22:09:29.0982 0x15d0  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
22:09:30.0009 0x15d0  RDPCDD - ok
22:09:30.0022 0x15d0  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR          C:\Windows\system32\drivers\rdpdr.sys
22:09:30.0036 0x15d0  RDPDR - ok
22:09:30.0042 0x15d0  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
22:09:30.0069 0x15d0  RDPENCDD - ok
22:09:30.0082 0x15d0  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
22:09:30.0110 0x15d0  RDPREFMP - ok
22:09:30.0126 0x15d0  [ E61608AA35E98999AF9AAEEEA6114B0A, F754CDE89DC96786D2A3C4D19EE2AEF1008E634E4DE3C0CBF927436DE90C04A6 ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
22:09:30.0142 0x15d0  RDPWD - ok
22:09:30.0155 0x15d0  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
22:09:30.0168 0x15d0  rdyboost - ok
22:09:30.0179 0x15d0  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
22:09:30.0209 0x15d0  RemoteAccess - ok
22:09:30.0221 0x15d0  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
22:09:30.0252 0x15d0  RemoteRegistry - ok
22:09:30.0255 0x15d0  rlffuili - ok
22:09:30.0260 0x15d0  rmtofanc - ok
22:09:30.0271 0x15d0  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
22:09:30.0301 0x15d0  RpcEptMapper - ok
22:09:30.0310 0x15d0  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
22:09:30.0322 0x15d0  RpcLocator - ok
22:09:30.0344 0x15d0  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs          C:\Windows\system32\rpcss.dll
22:09:30.0382 0x15d0  RpcSs - ok
22:09:30.0391 0x15d0  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
22:09:30.0419 0x15d0  rspndr - ok
22:09:30.0449 0x15d0  [ ABCB5A38A0D85BDF69B7877E1AD1EED5, 44DF1A92E8FA53677A04C46088B0AD49F1F6A090820BE550A514C4FBFD91444D ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
22:09:30.0469 0x15d0  RTL8167 - ok
22:09:30.0485 0x15d0  [ AE4FDA46C0A644DC9FB2545BDF4CB496, 35C911D94B887E64395EC3F493971E5D36176A3632D2F9FB7B4D5A886E9464F1 ] rzdaendpt      C:\Windows\system32\DRIVERS\rzdaendpt.sys
22:09:30.0496 0x15d0  rzdaendpt - ok
22:09:30.0518 0x15d0  [ D28AB8D41CA4633EA69F2897F0B45565, B8FF66583530787419D04EEA75A49B61FB184523E652C720B1EF1F1695864F0A ] rzudd          C:\Windows\system32\DRIVERS\rzudd.sys
22:09:30.0532 0x15d0  rzudd - ok
22:09:30.0557 0x15d0  [ 4CE040A51CFA6614F46419CB5F5B7BB6, 91DD7B91287800E96EF0DB9DD69B3315629BFA690592C2D0A3E596386A84CD95 ] rzvkeyboard    C:\Windows\system32\DRIVERS\rzvkeyboard.sys
22:09:30.0569 0x15d0  rzvkeyboard - ok
22:09:30.0577 0x15d0  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap          C:\Windows\system32\drivers\vms3cap.sys
22:09:30.0588 0x15d0  s3cap - ok
22:09:30.0591 0x15d0  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] SamSs          C:\Windows\system32\lsass.exe
22:09:30.0602 0x15d0  SamSs - ok
22:09:30.0613 0x15d0  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
22:09:30.0623 0x15d0  sbp2port - ok
22:09:30.0686 0x15d0  [ 794D4B48DFB6E999537C7C3947863463, 93DA8AA20D6B02A3360E7F56150F126E75266E9372E6409D42B89DA588EF49C3 ] SBSDWSCService  C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
22:09:30.0715 0x15d0  SBSDWSCService - ok
22:09:30.0727 0x15d0  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
22:09:30.0759 0x15d0  SCardSvr - ok
22:09:30.0766 0x15d0  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
22:09:30.0793 0x15d0  scfilter - ok
22:09:30.0827 0x15d0  [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule        C:\Windows\system32\schedsvc.dll
22:09:30.0878 0x15d0  Schedule - ok
22:09:30.0888 0x15d0  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc    C:\Windows\System32\certprop.dll
22:09:30.0916 0x15d0  SCPolicySvc - ok
22:09:30.0947 0x15d0  [ EE088B31F5EB673A62E7E0D09B0007B0, 686B697F554E02ACADD5E44F707EF1E7DD87539FF8156F4FF67533E5D26BC160 ] sdAuxService    C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe
22:09:30.0962 0x15d0  sdAuxService - ok
22:09:30.0996 0x15d0  [ 747FFE0A5A34C349A363BE97C632B7C4, 7AC092581CCED5080DA8ED3B7243B0DC99B648493ACDE7EB02461DB0DDB1C0B0 ] sdCoreService  C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe
22:09:31.0024 0x15d0  sdCoreService - ok
22:09:31.0043 0x15d0  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
22:09:31.0058 0x15d0  SDRSVC - ok
22:09:31.0075 0x15d0  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
22:09:31.0102 0x15d0  secdrv - ok
22:09:31.0112 0x15d0  [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon        C:\Windows\system32\seclogon.dll
22:09:31.0140 0x15d0  seclogon - ok
22:09:31.0148 0x15d0  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\system32\sens.dll
22:09:31.0177 0x15d0  SENS - ok
22:09:31.0181 0x15d0  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
22:09:31.0194 0x15d0  SensrSvc - ok
22:09:31.0202 0x15d0  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum        C:\Windows\system32\drivers\serenum.sys
22:09:31.0214 0x15d0  Serenum - ok
22:09:31.0223 0x15d0  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\drivers\serial.sys
22:09:31.0235 0x15d0  Serial - ok
22:09:31.0242 0x15d0  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\drivers\sermouse.sys
22:09:31.0254 0x15d0  sermouse - ok
22:09:31.0266 0x15d0  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
22:09:31.0295 0x15d0  SessionEnv - ok
22:09:31.0301 0x15d0  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
22:09:31.0314 0x15d0  sffdisk - ok
22:09:31.0317 0x15d0  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
22:09:31.0330 0x15d0  sffp_mmc - ok
22:09:31.0335 0x15d0  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
22:09:31.0348 0x15d0  sffp_sd - ok
22:09:31.0356 0x15d0  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
22:09:31.0367 0x15d0  sfloppy - ok
22:09:31.0411 0x15d0  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
22:09:31.0447 0x15d0  SharedAccess - ok
22:09:31.0465 0x15d0  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:09:31.0500 0x15d0  ShellHWDetection - ok
22:09:31.0506 0x15d0  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
22:09:31.0516 0x15d0  SiSRaid2 - ok
22:09:31.0525 0x15d0  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
22:09:31.0535 0x15d0  SiSRaid4 - ok
22:09:31.0560 0x15d0  [ F07AF60B152221472FBDB2FECEC4896D, A18FDCE8462A48429E249C44F0E49F844F2E3A4B5215349DE104F34D935EF983 ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
22:09:31.0570 0x15d0  SkypeUpdate - ok
22:09:31.0582 0x15d0  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
22:09:31.0611 0x15d0  Smb - ok
22:09:31.0628 0x15d0  [ B2C19AE46C5A109679B4FB38058DF05A, 93DD4D356650C51348795653286E6C627FF5F7071F2787DF7C50B75A3120E308 ] snapman        C:\Windows\system32\DRIVERS\snapman.sys
22:09:31.0641 0x15d0  snapman - ok
22:09:31.0653 0x15d0  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
22:09:31.0665 0x15d0  SNMPTRAP - ok
22:09:31.0668 0x15d0  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr          C:\Windows\system32\drivers\spldr.sys
22:09:31.0678 0x15d0  spldr - ok
22:09:31.0698 0x15d0  [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler        C:\Windows\System32\spoolsv.exe
22:09:31.0722 0x15d0  Spooler - ok
22:09:31.0804 0x15d0  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
22:09:31.0909 0x15d0  sppsvc - ok
22:09:31.0918 0x15d0  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
22:09:31.0948 0x15d0  sppuinotify - ok
22:09:31.0968 0x15d0  [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv            C:\Windows\system32\DRIVERS\srv.sys
22:09:31.0989 0x15d0  srv - ok
22:09:32.0001 0x15d0  [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
22:09:32.0020 0x15d0  srv2 - ok
22:09:32.0034 0x15d0  [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
22:09:32.0047 0x15d0  srvnet - ok
22:09:32.0057 0x15d0  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
22:09:32.0089 0x15d0  SSDPSRV - ok
22:09:32.0098 0x15d0  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc        C:\Windows\system32\sstpsvc.dll
22:09:32.0128 0x15d0  SstpSvc - ok
22:09:32.0147 0x15d0  Steam Client Service - ok
22:09:32.0154 0x15d0  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
22:09:32.0164 0x15d0  stexstor - ok
22:09:32.0182 0x15d0  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\Windows\System32\wiaservc.dll
22:09:32.0211 0x15d0  stisvc - ok
22:09:32.0222 0x15d0  [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt        C:\Windows\system32\drivers\vmstorfl.sys
22:09:32.0232 0x15d0  storflt - ok
22:09:32.0237 0x15d0  [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc        C:\Windows\system32\storsvc.dll
22:09:32.0249 0x15d0  StorSvc - ok
22:09:32.0258 0x15d0  [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc        C:\Windows\system32\drivers\storvsc.sys
22:09:32.0267 0x15d0  storvsc - ok
22:09:32.0272 0x15d0  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
22:09:32.0281 0x15d0  swenum - ok
22:09:32.0297 0x15d0  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv          C:\Windows\System32\swprv.dll
22:09:32.0336 0x15d0  swprv - ok
22:09:32.0380 0x15d0  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain        C:\Windows\system32\sysmain.dll
22:09:32.0432 0x15d0  SysMain - ok
22:09:32.0442 0x15d0  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:09:32.0459 0x15d0  TabletInputService - ok
22:09:32.0473 0x15d0  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv        C:\Windows\System32\tapisrv.dll
22:09:32.0506 0x15d0  TapiSrv - ok
22:09:32.0514 0x15d0  [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS            C:\Windows\System32\tbssvc.dll
22:09:32.0544 0x15d0  TBS - ok
22:09:32.0595 0x15d0  [ DB74544B75566C974815E79A62433F29, 035EBF70FDA28CF2B6C1FD7EE0ED703DB4B647064B5DBA6E258878A19B1BCCA4 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
22:09:32.0640 0x15d0  Tcpip - ok
22:09:32.0701 0x15d0  [ DB74544B75566C974815E79A62433F29, 035EBF70FDA28CF2B6C1FD7EE0ED703DB4B647064B5DBA6E258878A19B1BCCA4 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
22:09:32.0746 0x15d0  TCPIP6 - ok
22:09:32.0770 0x15d0  [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
22:09:32.0781 0x15d0  tcpipreg - ok
22:09:32.0788 0x15d0  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
22:09:32.0799 0x15d0  TDPIPE - ok
22:09:32.0835 0x15d0  [ 99527D49EE0A96FC25537C61B270A372, 519E23F86EC86349F92C4A88DBD19C097AEE0A6E152776B32B45D293ED14946B ] tdrpman273      C:\Windows\system32\DRIVERS\tdrpm273.sys
22:09:32.0866 0x15d0  tdrpman273 - ok
22:09:32.0881 0x15d0  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
22:09:32.0892 0x15d0  TDTCP - ok
22:09:32.0904 0x15d0  [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719C48B08FAFA9661 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
22:09:32.0932 0x15d0  tdx - ok
22:09:32.0945 0x15d0  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
22:09:32.0955 0x15d0  TermDD - ok
22:09:32.0982 0x15d0  [ 2E648163254233755035B46DD7B89123, 6FA0D07CE18A3A69D82EE49D875F141E39406E92C34EAC76AC4EB052E6EBCBCD ] TermService    C:\Windows\System32\termsrv.dll
22:09:33.0024 0x15d0  TermService - ok
22:09:33.0030 0x15d0  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
22:09:33.0046 0x15d0  Themes - ok
22:09:33.0056 0x15d0  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER    C:\Windows\system32\mmcss.dll
22:09:33.0085 0x15d0  THREADORDER - ok
22:09:33.0116 0x15d0  [ 2C1CAF5563548A15515EAB07D2A069C6, 863405BAC725C7DC6CC86613365A099A2370781018996DD3E74981565AD0DDF5 ] timounter      C:\Windows\system32\DRIVERS\timntr.sys
22:09:33.0141 0x15d0  timounter - ok
22:09:33.0154 0x15d0  [ C676B0F52F2B6483AFB88F79CABB011E, 8F10C7C91B47F87C3E29785BDACA49831857849F688C34A1F097C9D6593003AA ] Tpkd            C:\Windows\system32\drivers\Tpkd.sys
22:09:33.0163 0x15d0  Tpkd - ok
22:09:33.0178 0x15d0  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
22:09:33.0209 0x15d0  TrkWks - ok
22:09:33.0228 0x15d0  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:09:33.0258 0x15d0  TrustedInstaller - ok
22:09:33.0272 0x15d0  [ 4CE278FC9671BA81A138D70823FCAA09, CBE501436696E32A3701B9F377B823AC36647B6626595F76CC63E2396AD7D300 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
22:09:33.0283 0x15d0  tssecsrv - ok
22:09:33.0296 0x15d0  [ D11C783E3EF9A3C52C0EBE83CC5000E9, A136C355D4C8945729163D15801364A614E23217B15F9313C85BA45BB71A74EB ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
22:09:33.0307 0x15d0  TsUsbFlt - ok
22:09:33.0317 0x15d0  [ 9CC2CCAE8A84820EAECB886D477CBCB8, 50D8AA2D7477A6618A0C31BB4D1C4887B457865FB1105E2E7B984EEFA337B804 ] TsUsbGD        C:\Windows\system32\drivers\TsUsbGD.sys
22:09:33.0328 0x15d0  TsUsbGD - ok
22:09:33.0340 0x15d0  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
22:09:33.0369 0x15d0  tunnel - ok
22:09:33.0379 0x15d0  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
22:09:33.0389 0x15d0  uagp35 - ok
22:09:33.0391 0x15d0  ubqgdokm - ok
22:09:33.0406 0x15d0  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
22:09:33.0440 0x15d0  udfs - ok
22:09:33.0478 0x15d0  [ 215462AE7E6A897D675E84DD1E3B3B56, 7F45E77F971E9AC3E1402663EF5F6A2D496F9BB758C8E50D2D329E834E20B7D8 ] ufad-ws60      C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe
22:09:33.0490 0x15d0  ufad-ws60 - ok
22:09:33.0497 0x15d0  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect      C:\Windows\system32\UI0Detect.exe
22:09:33.0509 0x15d0  UI0Detect - ok
22:09:33.0520 0x15d0  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
22:09:33.0531 0x15d0  uliagpkx - ok
22:09:33.0539 0x15d0  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
22:09:33.0551 0x15d0  umbus - ok
22:09:33.0560 0x15d0  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\drivers\umpass.sys
22:09:33.0571 0x15d0  UmPass - ok
22:09:33.0581 0x15d0  [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService    C:\Windows\System32\umrdp.dll
22:09:33.0597 0x15d0  UmRdpService - ok
22:09:33.0611 0x15d0  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
22:09:33.0647 0x15d0  upnphost - ok
22:09:33.0664 0x15d0  [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A, DE1CDDEEF2285CC8387E88ACB13C000576DC8819DF6DC648C988068B5C83BB15 ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
22:09:33.0679 0x15d0  usbaudio - ok
22:09:33.0696 0x15d0  [ 6F1A3157A1C89435352CEB543CDB359C, 325B46220779C5FE3B6F19FF794474837FAB9675D9C98ACB68CCE47B1CFE5F12 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
22:09:33.0709 0x15d0  usbccgp - ok
22:09:33.0722 0x15d0  [ AF0892A803FDDA7492F595368E3B68E7, F263346DEB4D742EB436CF578F187AC8521D84CED52E98475E6198EC52244F07 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
22:09:33.0738 0x15d0  usbcir - ok
22:09:33.0748 0x15d0  [ C025055FE7B87701EB042095DF1A2D7B, D7B34B6C2C5BD3C8141895AC21BB637EA5E3C4F7A85EEF4C4C36E6BB2045A3D9 ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
22:09:33.0760 0x15d0  usbehci - ok
22:09:33.0778 0x15d0  [ 287C6C9410B111B68B52CA298F7B8C24, 98900C08FE662A00DF8B37837B2BEBF9ACB7989C387AF36B2109B05A4F462D4E ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
22:09:33.0796 0x15d0  usbhub - ok
22:09:33.0803 0x15d0  [ 9840FC418B4CBD632D3D0A667A725C31, 776D86A032DCA2842EF7AADB35473193CA80547223EFAA7F110F296C377077B0 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
22:09:33.0815 0x15d0  usbohci - ok
22:09:33.0822 0x15d0  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\drivers\usbprint.sys
22:09:33.0835 0x15d0  usbprint - ok
22:09:33.0843 0x15d0  [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:09:33.0856 0x15d0  USBSTOR - ok
22:09:33.0869 0x15d0  [ 62069A34518BCF9C1FD9E74B3F6DB7CD, C58E21424718729324B285BEE1C96551540FCC3FD650B2D10895EBA48D981E25 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
22:09:33.0880 0x15d0  usbuhci - ok
22:09:33.0886 0x15d0  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms          C:\Windows\System32\uxsms.dll
22:09:33.0915 0x15d0  UxSms - ok
22:09:33.0925 0x15d0  varehocl - ok
22:09:33.0931 0x15d0  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] VaultSvc        C:\Windows\system32\lsass.exe
22:09:33.0943 0x15d0  VaultSvc - ok
22:09:33.0956 0x15d0  [ FD911873C0BB6945FA38C16E9A2B58F9, EF8C833321449A6E8B671890F2EBC82ABC276B890D274AADDB626D763EE98964 ] VClone          C:\Windows\system32\DRIVERS\VClone.sys
22:09:33.0966 0x15d0  VClone - ok
22:09:33.0975 0x15d0  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
22:09:33.0984 0x15d0  vdrvroot - ok
22:09:34.0002 0x15d0  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds            C:\Windows\System32\vds.exe
22:09:34.0041 0x15d0  vds - ok
22:09:34.0055 0x15d0  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
22:09:34.0068 0x15d0  vga - ok
22:09:34.0075 0x15d0  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave        C:\Windows\System32\drivers\vga.sys
22:09:34.0103 0x15d0  VgaSave - ok
22:09:34.0115 0x15d0  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
22:09:34.0128 0x15d0  vhdmp - ok
22:09:34.0139 0x15d0  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\drivers\viaide.sys
22:09:34.0149 0x15d0  viaide - ok
22:09:34.0166 0x15d0  [ 3B59BB6D10CF969DBE4DB93D9EAD7FB4, 8BD4648AAD460F276C79AF81D1479E781E62D292F3318D39B53703403E57E52F ] VKbms          C:\Windows\system32\DRIVERS\VKbms.sys
22:09:34.0177 0x15d0  VKbms - ok
22:09:34.0197 0x15d0  [ 7AC6239C65DADE55DEFD573B98616C3F, 39EC745BFA38C70DA80DC121CB24C12ED9AF9AFDCFE38FCD853CFA53D6E538A8 ] VMAuthdService  C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
22:09:34.0207 0x15d0  VMAuthdService - ok
22:09:34.0216 0x15d0  [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus          C:\Windows\system32\drivers\vmbus.sys
22:09:34.0229 0x15d0  vmbus - ok
22:09:34.0237 0x15d0  [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
22:09:34.0248 0x15d0  VMBusHID - ok
22:09:34.0263 0x15d0  [ 312AEC23A85424543AF898A59209B479, 7423643ACA900824CCC44B6347AD81E027A9C2A42C12C7F7FD9B89F3D5B5F654 ] vmci            C:\Windows\system32\drivers\vmci.sys
22:09:34.0272 0x15d0  vmci - ok
22:09:34.0291 0x15d0  [ FFC30CAEEB2FC5FEE8568CFF74EDEAED, 56DA6F766906A160C326AAA901E0B50E5CA8B054BDE1B95DD6EA14BBB5286E65 ] vmkbd          C:\Windows\system32\drivers\VMkbd.sys
22:09:34.0299 0x15d0  vmkbd - ok
22:09:34.0311 0x15d0  [ 9D54F1339E78C95BF3D9939EBCB66378, 99E29225443049B35E633BB7E709AC89B555F6A1EC5FAE075825A74F088FDC9A ] VMnetAdapter    C:\Windows\system32\DRIVERS\vmnetadapter.sys
22:09:34.0319 0x15d0  VMnetAdapter - ok
22:09:34.0332 0x15d0  [ FB54EF3AA613D2832FD3812E7CB2FC75, 2D638EFE2E457C4F9B50AF49C7A0B0DA82A98FF10049C2E5DABE32B7E0BA2B23 ] VMnetBridge    C:\Windows\system32\DRIVERS\vmnetbridge.sys
22:09:34.0340 0x15d0  VMnetBridge - ok
22:09:34.0346 0x15d0  VMnetDHCP - ok
22:09:34.0356 0x15d0  [ 56D547BFC3F1619FA82EC9EF5D24E802, D82DDC1E15F87E3E5809991CEFD81CE24BC8C9249108F36F7B854CEDBDB56FFC ] VMnetuserif    C:\Windows\system32\drivers\vmnetuserif.sys
22:09:34.0364 0x15d0  VMnetuserif - ok
22:09:34.0391 0x15d0  [ 19368F7C4DC6EF444B826249FC8A0E30, 6F26729EA0BD651FCCC8657BF7C40174AC06926373B467BC3BD3ED352421D2FA ] VMUSBArbService C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
22:09:34.0409 0x15d0  VMUSBArbService - ok
22:09:34.0413 0x15d0  VMware NAT Service - ok
22:09:34.0430 0x15d0  [ 62CD5A87FDE14701506D4E0DD8F13D2E, C449E52039BAF7B262BEE4D1389239B196965A0A08E002441CE56B89EF6688E8 ] vmx86          C:\Windows\system32\drivers\vmx86.sys
22:09:34.0439 0x15d0  vmx86 - ok
22:09:34.0450 0x15d0  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
22:09:34.0460 0x15d0  volmgr - ok
22:09:34.0474 0x15d0  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
22:09:34.0506 0x15d0  volmgrx - ok
22:09:34.0527 0x15d0  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap        C:\Windows\system32\drivers\volsnap.sys
22:09:34.0543 0x15d0  volsnap - ok
22:09:34.0554 0x15d0  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
22:09:34.0566 0x15d0  vsmraid - ok
22:09:34.0606 0x15d0  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS            C:\Windows\system32\vssvc.exe
22:09:34.0669 0x15d0  VSS - ok
22:09:34.0687 0x15d0  [ E61C910E2DDF4797C1B1F9239636E894, BEC555AB66BD0D33BBC9ABFF7F3955F7D0821383549C8BAC1944B63A85F897E8 ] vstor2-ws60    C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys
22:09:34.0696 0x15d0  vstor2-ws60 - ok
22:09:34.0704 0x15d0  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
22:09:34.0719 0x15d0  vwifibus - ok
22:09:34.0738 0x15d0  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time        C:\Windows\system32\w32time.dll
22:09:34.0775 0x15d0  W32Time - ok
22:09:34.0784 0x15d0  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
22:09:34.0795 0x15d0  WacomPen - ok
22:09:34.0802 0x15d0  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
22:09:34.0830 0x15d0  WANARP - ok
22:09:34.0834 0x15d0  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
22:09:34.0862 0x15d0  Wanarpv6 - ok
22:09:34.0901 0x15d0  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\Windows\system32\wbengine.exe
22:09:34.0945 0x15d0  wbengine - ok
22:09:34.0957 0x15d0  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
22:09:34.0977 0x15d0  WbioSrvc - ok
22:09:34.0991 0x15d0  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
22:09:35.0015 0x15d0  wcncsvc - ok
22:09:35.0023 0x15d0  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:09:35.0035 0x15d0  WcsPlugInService - ok
22:09:35.0041 0x15d0  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\drivers\wd.sys
22:09:35.0050 0x15d0  Wd - ok
22:09:35.0077 0x15d0  [ 442783E2CB0DA19873B7A63833FF4CB4, 09254970265476214F3187CC22A4F9C7C2769D419600E83FBE302C3A103E527F ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
22:09:35.0102 0x15d0  Wdf01000 - ok
22:09:35.0115 0x15d0  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost  C:\Windows\system32\wdi.dll
22:09:35.0133 0x15d0  WdiServiceHost - ok
22:09:35.0136 0x15d0  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost  C:\Windows\system32\wdi.dll
22:09:35.0153 0x15d0  WdiSystemHost - ok
22:09:35.0166 0x15d0  [ 3DB6D04E1C64272F8B14EB8BC4616280, 9138642B1C19F895D4ECFD930160C80FBF15813CE63BBF4C899842C300FD3026 ] WebClient      C:\Windows\System32\webclnt.dll
22:09:35.0187 0x15d0  WebClient - ok
22:09:35.0198 0x15d0  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\Windows\system32\wecsvc.dll
22:09:35.0231 0x15d0  Wecsvc - ok
22:09:35.0240 0x15d0  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
22:09:35.0271 0x15d0  wercplsupport - ok
22:09:35.0282 0x15d0  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
22:09:35.0313 0x15d0  WerSvc - ok
22:09:35.0320 0x15d0  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
22:09:35.0349 0x15d0  WfpLwf - ok
22:09:35.0355 0x15d0  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
22:09:35.0365 0x15d0  WIMMount - ok
22:09:35.0372 0x15d0  WinDefend - ok
22:09:35.0379 0x15d0  WinHttpAutoProxySvc - ok
22:09:35.0413 0x15d0  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
22:09:35.0447 0x15d0  Winmgmt - ok
22:09:35.0495 0x15d0  [ BCB1310604AA415C4508708975B3931E, 9D943F086D454345153A0DD426B4432532A44FD87950386B186E1CAD2AC70565 ] WinRM          C:\Windows\system32\WsmSvc.dll
22:09:35.0566 0x15d0  WinRM - ok
22:09:35.0601 0x15d0  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
22:09:35.0616 0x15d0  WinUsb - ok
22:09:35.0637 0x15d0  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc        C:\Windows\System32\wlansvc.dll
22:09:35.0672 0x15d0  Wlansvc - ok
22:09:35.0761 0x15d0  [ 98F138897EF4246381D197CB81846D62, A9FA88475AFBB8883297708608EC7C1AC29F229C3299A84D557172604813A18C ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:09:35.0810 0x15d0  wlidsvc - ok
22:09:35.0822 0x15d0  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
22:09:35.0834 0x15d0  WmiAcpi - ok
22:09:35.0849 0x15d0  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
22:09:35.0865 0x15d0  wmiApSrv - ok
22:09:35.0880 0x15d0  WMPNetworkSvc - ok
22:09:35.0896 0x15d0  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
22:09:35.0908 0x15d0  WPCSvc - ok
22:09:35.0918 0x15d0  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
22:09:35.0935 0x15d0  WPDBusEnum - ok
22:09:35.0943 0x15d0  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
22:09:35.0971 0x15d0  ws2ifsl - ok
22:09:35.0978 0x15d0  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\system32\wscsvc.dll
22:09:35.0996 0x15d0  wscsvc - ok
22:09:35.0998 0x15d0  WSearch - ok
22:09:36.0061 0x15d0  [ D9EF901DCA379CFE914E9FA13B73B4C4, 3BE9693B7B2AFEE23D72AF5DA211379724D752F0EC18ACB7D3DE3DDFC5AE0004 ] wuauserv        C:\Windows\system32\wuaueng.dll
22:09:36.0116 0x15d0  wuauserv - ok
22:09:36.0133 0x15d0  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
22:09:36.0146 0x15d0  WudfPf - ok
22:09:36.0162 0x15d0  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
22:09:36.0177 0x15d0  WUDFRd - ok
22:09:36.0189 0x15d0  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
22:09:36.0202 0x15d0  wudfsvc - ok
22:09:36.0217 0x15d0  [ FE90B750AB808FB9DD8FBB428B5FF83B, 3F8F592EC813BE292D305A87C5BA852F8BC3D7CE610612D9871F209A17326AA8 ] WwanSvc        C:\Windows\System32\wwansvc.dll
22:09:36.0235 0x15d0  WwanSvc - ok
22:09:36.0254 0x15d0  ================ Scan global ===============================
22:09:36.0269 0x15d0  [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll
22:09:36.0283 0x15d0  [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll
22:09:36.0294 0x15d0  [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll
22:09:36.0308 0x15d0  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
22:09:36.0319 0x15d0  [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe
22:09:36.0326 0x15d0  [ Global ] - ok
22:09:36.0326 0x15d0  ================ Scan MBR ==================================
22:09:36.0331 0x15d0  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2
22:09:36.0748 0x15d0  \Device\Harddisk2\DR2 - ok
22:09:36.0771 0x15d0  [ 87D88FA4D3EFD4431866EA91949644BF ] \Device\Harddisk0\DR0
22:09:36.0773 0x15d0  \Device\Harddisk0\DR0 - detected Rootkit.Boot.Wistler.a ( 0 )
22:09:36.0773 0x15d0  \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - infected
22:09:39.0407 0x15d0  [ 87D88FA4D3EFD4431866EA91949644BF ] \Device\Harddisk1\DR1
22:09:39.0429 0x15d0  \Device\Harddisk1\DR1 - detected Rootkit.Boot.Wistler.a ( 0 )
22:09:39.0429 0x15d0  \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - infected
22:09:42.0030 0x15d0  [ DDAE9D649DB12F6AFF24483F2C298989 ] \Device\Harddisk3\DR3
22:09:43.0027 0x15d0  \Device\Harddisk3\DR3 - ok
22:09:43.0028 0x15d0  ================ Scan VBR ==================================
22:09:43.0040 0x15d0  [ 648FC44956DAA6F6D2A8D210255768CC ] \Device\Harddisk2\DR2\Partition1
22:09:43.0042 0x15d0  \Device\Harddisk2\DR2\Partition1 - ok
22:09:43.0046 0x15d0  [ EE9BD2983364C91FDF0753BA7BC6215D ] \Device\Harddisk2\DR2\Partition2
22:09:43.0048 0x15d0  \Device\Harddisk2\DR2\Partition2 - ok
22:09:43.0050 0x15d0  [ 3541107D5B9039B36E7DAD4CDEDD327F ] \Device\Harddisk0\DR0\Partition1
22:09:43.0051 0x15d0  \Device\Harddisk0\DR0\Partition1 - ok
22:09:43.0054 0x15d0  [ A59F8BF144837A8162BE68CC117745D5 ] \Device\Harddisk1\DR1\Partition1
22:09:43.0056 0x15d0  \Device\Harddisk1\DR1\Partition1 - ok
22:09:43.0066 0x15d0  [ 911F9106D691F1862BE6E8DEF08C586E ] \Device\Harddisk3\DR3\Partition1
22:09:43.0068 0x15d0  \Device\Harddisk3\DR3\Partition1 - ok
22:09:43.0073 0x15d0  AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.2.223.0 ), 0x60000 ( disabled : updated )
22:09:43.0077 0x15d0  Win FW state via NFP2: enabled
22:09:48.0582 0x15d0  ============================================================
22:09:48.0582 0x15d0  Scan finished
22:09:48.0582 0x15d0  ============================================================
22:09:48.0587 0x1a70  Detected object count: 2
22:09:48.0587 0x1a70  Actual detected object count: 2
22:10:02.0997 0x1a70  \Device\Harddisk0\DR0\# - copied to quarantine
22:10:02.0997 0x1a70  \Device\Harddisk0\DR0 - copied to quarantine
22:10:02.0998 0x1a70  \Device\Harddisk0\DR0 - processing error
22:47:31.0950 0x1a70  \Device\Harddisk0\DR0 - will be restored on reboot
22:47:31.0950 0x1a70  \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - User select action: Cure Restore
22:47:31.0990 0x1a70  \Device\Harddisk1\DR1\# - copied to quarantine
22:47:31.0990 0x1a70  \Device\Harddisk1\DR1 - copied to quarantine
22:47:33.0453 0x1a70  \Device\Harddisk1\DR1 - processing error
22:47:38.0565 0x1a70  \Device\Harddisk1\DR1 - will be restored on reboot
22:47:38.0565 0x1a70  \Device\Harddisk1\DR1 ( Rootkit.Boot.Wistler.a ) - User select action: Cure Restore
22:48:11.0961 0x0ef0  Deinitialize success

FRST-Versuch ist am Laufen

Lou Schalter 10.10.2013 23:19

Hat geklappt. Hier die Logs:


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by ***** (administrator) on *****-PC on 10-10-2013 22:54:30
Running from C:\Users\*****\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Andrea Electronics Corporation) C:\Windows\system32\AEADISRV.EXE
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
(Threat Expert Ltd.) C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
(Avid Technology, Inc..) C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
(SafeNet Inc.) C:\Windows\system32\hasplms.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Kaspersky Lab ZAO) C:\Users\*****\AppData\Local\temp\{5FE98B5E-EA8F-4487-AFA3-D1EA5ADCA351}.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Avid Technology, Inc.) C:\Windows\System32\M-AudioTaskBarIcon.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
() C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Razer Inc.) C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
() C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPop3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [358944 2010-12-11] (Acronis)
HKLM\...\Run: [M-Audio Taskbar Icon] - C:\Windows\system32\M-AudioTaskBarIcon.exe [798728 2010-12-07] (Avid Technology, Inc.)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [5889816 2011-12-07] (Logitech Inc.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKCU\...\Run: [Google Update] - C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-21] (Google Inc.)
MountPoints2: {3aaca747-f6ae-11e2-81cf-005056c00008} - G:\Startme.exe
MountPoints2: {7561e1d3-6444-11e1-9b58-00040ecc87e4} - H:\SETUP.EXE
MountPoints2: {f27fbd11-63df-11e1-a2c1-e0cb4e3e42d0} - E:\pushinst.exe
HKLM-x32\...\Run: [SoundMAXPnP] - C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1310720 2009-06-05] (Analog Devices, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [vmware-tray] - C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [129648 2011-03-26] (VMware, Inc.)
HKLM-x32\...\Run: [DigidesignMMERefresh] - C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe [77824 2010-06-24] (Avid Technology, Inc..)
HKLM-x32\...\Run: [DeathAdder] - C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe [248320 2011-03-21] ()
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x70AC4DD3F3F7CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109727&tt=010812_nich_3112_8&babsrc=SP_ss&mntrId=9e1017a8000000000000e0cb4e3e3e0f
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109727&tt=010812_nich_3112_8&babsrc=SP_ss&mntrId=9e1017a8000000000000e0cb4e3e3e0f
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: PC Tools Browser Guard BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: af0.Adblock.BHO - {90EFF544-3981-4d46-85C9-C0361D0931D6} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: No Name - {C4415769-1588-4AD6-9624-B2E69DB78D1A} -  No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -  No File
Toolbar: HKLM-x32 - PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [321464] (PC Tools Research Pty Ltd.)
Winsock: Catalog9 02 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [321464] (PC Tools Research Pty Ltd.)
Winsock: Catalog9 03 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [321464] (PC Tools Research Pty Ltd.)
Winsock: Catalog9 14 C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll [346736] (VMware, Inc.)
Winsock: Catalog9 15 C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll [346736] (VMware, Inc.)
Winsock: Catalog9 16 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [321464] (PC Tools Research Pty Ltd.)
Winsock: Catalog9-x64 01 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [233912] (PC Tools Research Pty Ltd.)
Winsock: Catalog9-x64 02 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [233912] (PC Tools Research Pty Ltd.)
Winsock: Catalog9-x64 03 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [233912] (PC Tools Research Pty Ltd.)
Winsock: Catalog9-x64 14 C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll [446576] (VMware, Inc.)
Winsock: Catalog9-x64 15 C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll [446576] (VMware, Inc.)
Winsock: Catalog9-x64 16 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [233912] (PC Tools Research Pty Ltd.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_1
CHR Extension: (Chrome In-App Payments service) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

==================== Services (Whitelisted) =================

R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2009-06-05] (Andrea Electronics Corporation)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
R2 Browser Defender Update Service; C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe [112592 2010-01-22] (Threat Expert Ltd.)
R2 DigiRefresh; C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe [77824 2010-06-24] (Avid Technology, Inc..)
R2 hasplms; C:\Windows\system32\hasplms.exe [4941768 2012-06-28] (SafeNet Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-09-15] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 sdAuxService; C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe [365280 2009-12-09] (PC Tools)
S4 sdCoreService; C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe [1141712 2010-01-18] (PC Tools)
S3 ufad-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe [191024 2010-08-19] (VMware, Inc.)
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]

==================== Drivers (Whitelisted) ====================

S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin)
S3 CYUSB; C:\Windows\System32\Drivers\CYUSB.sys [47104 2009-08-10] (Cypress Semiconductor)
S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [321536 2011-09-28] (SafeNet Inc.)
R3 MAUSBFASTTRACK; C:\Windows\System32\DRIVERS\MAudioFastTrack.sys [187912 2010-12-07] (Avid Technology, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R0 mv64xx; C:\Windows\System32\DRIVERS\mv64xx.sys [331816 2009-09-16] (Marvell Semiconductor, Inc.)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
R0 PCTCore; C:\Windows\System32\drivers\PCTCore64.sys [218056 2009-09-23] (PC Tools)
S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [25600 2012-11-07] (Razer USA Ltd)
S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [23040 2012-11-07] (Razer USA Ltd)
R2 vstor2-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.)
R2 vstor2-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.)
S1 ajlvsasx; \??\C:\Windows\system32\drivers\ajlvsasx.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S1 crtjnuyc; \??\C:\Windows\system32\drivers\crtjnuyc.sys [x]
S1 eaarkkjg; \??\C:\Windows\system32\drivers\eaarkkjg.sys [x]
S1 ktmujbzd; \??\C:\Windows\system32\drivers\ktmujbzd.sys [x]
S1 ptqllcii; \??\C:\Windows\system32\drivers\ptqllcii.sys [x]
S1 rlffuili; \??\C:\Windows\system32\drivers\rlffuili.sys [x]
S1 rmtofanc; \??\C:\Windows\system32\drivers\rmtofanc.sys [x]
S1 ubqgdokm; \??\C:\Windows\system32\drivers\ubqgdokm.sys [x]
S1 varehocl; \??\C:\Windows\system32\drivers\varehocl.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-10 22:53 - 2013-10-10 22:54 - 01954124 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-10-10 22:10 - 2013-10-10 22:10 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-10-10 21:20 - 2013-10-10 22:08 - 00000000 ____D C:\Users\*****\Desktop\tdsskiller
2013-10-10 21:17 - 2013-10-10 21:19 - 04101172 _____ C:\Users\*****\Desktop\tdsskiller.zip
2013-10-10 21:13 - 2013-10-10 21:20 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\*****\Desktop\TDSSKiller.exe
2013-10-10 20:15 - 2013-10-10 20:15 - 00000000 ____D C:\_OTL
2013-10-10 20:13 - 2013-10-10 20:14 - 00001183 _____ C:\Users\Administrator\Desktop\OTL FIX.txt
2013-10-10 08:22 - 2013-10-10 08:22 - 00092158 _____ C:\Users\Administrator\Desktop\OTL.Txt
2013-10-10 08:13 - 2013-10-10 08:13 - 00023010 _____ C:\ComboFix.txt
2013-10-10 07:51 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-10 07:51 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-10 07:51 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-10 07:50 - 2013-10-10 08:13 - 00000000 ____D C:\Qoobox
2013-10-10 07:49 - 2013-10-10 08:10 - 00000000 ____D C:\Windows\erdnt
2013-10-10 07:47 - 2013-10-10 07:47 - 05131844 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFix.exe
2013-10-09 19:41 - 2013-10-09 19:41 - 00602112 _____ (OldTimer Tools) C:\Users\Administrator\Desktop\OTL.exe
2013-10-09 01:28 - 2013-10-09 01:31 - 00016321 _____ C:\Users\Administrator\Desktop\Gmer.txt
2013-10-09 01:22 - 2013-10-09 01:22 - 00377856 _____ C:\Users\Administrator\Desktop\gmer_2.1.19163.exe
2013-10-09 01:20 - 2013-10-09 01:21 - 00000320 _____ C:\Users\Administrator\Desktop\Addition.txt
2013-10-09 01:18 - 2013-10-09 01:19 - 01954124 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe
2013-10-08 20:40 - 2013-10-08 20:46 - 00010918 _____ C:\Windows\IE10_main.log
2013-10-08 20:31 - 2013-10-08 20:31 - 00000000 ____D C:\FRST
2013-10-08 02:03 - 2013-10-08 02:05 - 00000000 ____D C:\Windows\system32\MRT
2013-10-08 02:02 - 2013-07-31 16:17 - 17833472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-08 02:02 - 2013-07-31 15:42 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-08 02:02 - 2013-07-31 15:29 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-08 02:02 - 2013-07-31 15:20 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-08 02:02 - 2013-07-31 15:19 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-08 02:02 - 2013-07-31 15:18 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-10-08 02:02 - 2013-07-31 15:17 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-08 02:02 - 2013-07-31 15:16 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-08 02:02 - 2013-07-31 15:14 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-10-08 02:02 - 2013-07-31 15:13 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-08 02:02 - 2013-07-31 15:13 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-10-08 02:02 - 2013-07-31 15:11 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-08 02:02 - 2013-07-31 15:11 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-08 02:02 - 2013-07-31 15:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-08 02:02 - 2013-07-31 15:08 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-08 02:02 - 2013-07-31 15:05 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-08 02:02 - 2013-07-31 12:30 - 12335104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-08 02:02 - 2013-07-31 12:05 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-08 02:02 - 2013-07-31 12:00 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-08 02:02 - 2013-07-31 11:53 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-08 02:02 - 2013-07-31 11:52 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-10-08 02:02 - 2013-07-31 11:52 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-08 02:02 - 2013-07-31 11:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-10-08 02:02 - 2013-07-31 11:49 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-08 02:02 - 2013-07-31 11:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-08 02:02 - 2013-07-31 11:48 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-10-08 02:02 - 2013-07-31 11:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-10-08 02:02 - 2013-07-31 11:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-08 02:02 - 2013-07-31 11:46 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-08 02:02 - 2013-07-31 11:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-08 02:02 - 2013-07-31 11:45 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-10-08 02:02 - 2013-07-31 11:42 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-08 01:52 - 2013-10-08 01:52 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2013-10-08 01:51 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-10-08 01:51 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-10-08 01:51 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-10-08 01:51 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-10-08 01:51 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-10-08 01:51 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-10-08 01:51 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-10-08 01:51 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-10-08 01:51 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-10-08 01:51 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-10-08 01:50 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-08 01:50 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-10-08 01:50 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-08 01:50 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-08 01:50 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-10-08 01:50 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-08 01:50 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-10-08 01:50 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-10-08 01:50 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-10-08 01:50 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-10-08 01:50 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-08 01:50 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-08 01:50 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-08 01:50 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-10-08 01:50 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-10-08 01:50 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-10-08 01:50 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-10-08 01:50 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-08 01:50 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-08 01:50 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-08 01:50 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-08 01:50 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-10-08 01:50 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-10-08 01:50 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-10-08 01:50 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-10-08 01:50 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-10-08 01:50 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-10-08 01:50 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-10-08 01:50 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-10-08 01:50 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-10-08 01:50 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-08 01:50 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-10-08 01:47 - 2013-10-08 01:49 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2013-10-08 01:47 - 2013-10-08 01:47 - 04095448 _____ (BrightFort LLC                                              ) C:\Users\Administrator\Desktop\spywareblastersetup50.exe
2013-10-08 01:47 - 2013-10-08 01:47 - 00001085 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2013-10-08 01:47 - 2013-10-08 01:47 - 00000000 ____D C:\ProgramData\Licenses
2013-10-08 01:47 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTDFMT.DLL
2013-10-08 01:43 - 2013-10-08 01:43 - 01032220 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe
2013-10-08 01:41 - 2013-10-08 01:41 - 01032220 _____ (Thisisu) C:\Users\Administrator\Downloads\JRT.exe
2013-10-08 01:40 - 2013-10-08 01:40 - 00000000 ____D C:\ProgramData\Oracle
2013-10-08 01:40 - 2013-10-08 01:39 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-10-08 01:40 - 2013-10-08 01:39 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 01:39 - 2013-10-08 01:39 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-08 01:32 - 2013-10-08 01:32 - 02378752 _____ C:\Users\Administrator\Downloads\Adblock_Installer.msi
2013-10-08 01:24 - 2013-10-08 01:25 - 00000000 ____D C:\AdwCleaner
2013-10-08 01:24 - 2013-10-08 01:24 - 01045226 _____ C:\Users\Administrator\Desktop\adwcleaner.exe
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Local\Threat Expert
2013-10-08 01:15 - 2013-10-08 20:29 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-08 01:15 - 2013-10-08 20:29 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-08 01:15 - 2013-10-08 01:15 - 00115960 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-08 01:15 - 2013-10-08 01:15 - 00001445 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-08 01:15 - 2013-10-08 01:15 - 00001411 _____ C:\Users\Administrator\Desktop\Internet Explorer (64-bit).lnk
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Razer
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\ATI
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Local\Logitech
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Local\ATI
2013-10-08 01:02 - 2013-10-10 08:02 - 00000000 ____D C:\ProgramData\VMware
2013-10-08 00:53 - 2013-10-08 00:53 - 00000000 _____ C:\Users\*****\Desktop\4wcl7hv.txt
2013-09-29 13:43 - 2013-09-29 14:04 - 00000000 ____D C:\Users\*****\AppData\Local\SCE
2013-09-24 22:31 - 2013-09-24 23:56 - 00000000 ____D C:\Users\*****\Desktop\Vermietung
2013-09-17 02:36 - 2013-09-17 02:36 - 00000000 _____ C:\Users\*****\Desktop\Attack on Titan 25.txt
2013-09-13 21:12 - 2013-09-13 21:12 - 00138240 _____ C:\Users\*****\Desktop\Finanzierungsplan.xls
2013-09-10 20:17 - 2013-09-10 20:19 - 00000000 ____D C:\Users\*****\AppData\Roaming\PACE Anti-Piracy
2013-09-10 20:17 - 2013-09-10 20:17 - 00000000 ____D C:\Users\*****\AppData\Local\PACE Anti-Piracy

==================== One Month Modified Files and Folders =======

2013-10-10 22:54 - 2013-10-10 22:53 - 01954124 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-10-10 22:54 - 2011-04-12 09:26 - 00713640 _____ C:\Windows\system32\perfh007.dat
2013-10-10 22:54 - 2011-04-12 09:26 - 00155258 _____ C:\Windows\system32\perfc007.dat
2013-10-10 22:54 - 2009-07-14 07:13 - 01659522 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-10 22:53 - 2012-03-01 23:01 - 01287695 _____ C:\Windows\WindowsUpdate.log
2013-10-10 22:50 - 2012-07-21 17:25 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-10 22:50 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-10 22:50 - 2009-07-14 06:51 - 00089353 _____ C:\Windows\setupact.log
2013-10-10 22:45 - 2012-11-12 13:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-10 22:31 - 2012-08-05 17:00 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000UA.job
2013-10-10 22:10 - 2013-10-10 22:10 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-10-10 22:09 - 2012-07-21 17:25 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-10 22:08 - 2013-10-10 21:20 - 00000000 ____D C:\Users\*****\Desktop\tdsskiller
2013-10-10 21:20 - 2013-10-10 21:13 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\*****\Desktop\TDSSKiller.exe
2013-10-10 21:19 - 2013-10-10 21:17 - 04101172 _____ C:\Users\*****\Desktop\tdsskiller.zip
2013-10-10 20:24 - 2009-07-14 06:45 - 00026080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-10 20:24 - 2009-07-14 06:45 - 00026080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-10 20:15 - 2013-10-10 20:15 - 00000000 ____D C:\_OTL
2013-10-10 20:15 - 2012-03-01 22:59 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-10 20:14 - 2013-10-10 20:13 - 00001183 _____ C:\Users\Administrator\Desktop\OTL FIX.txt
2013-10-10 08:22 - 2013-10-10 08:22 - 00092158 _____ C:\Users\Administrator\Desktop\OTL.Txt
2013-10-10 08:13 - 2013-10-10 08:13 - 00023010 _____ C:\ComboFix.txt
2013-10-10 08:13 - 2013-10-10 07:50 - 00000000 ____D C:\Qoobox
2013-10-10 08:13 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-10-10 08:10 - 2013-10-10 07:49 - 00000000 ____D C:\Windows\erdnt
2013-10-10 08:08 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-10-10 08:02 - 2013-10-08 01:02 - 00000000 ____D C:\ProgramData\VMware
2013-10-10 08:02 - 2010-11-21 05:47 - 00056220 _____ C:\Windows\PFRO.log
2013-10-10 07:59 - 2012-03-01 22:59 - 00000000 ____D C:\Users\*****
2013-10-10 07:47 - 2013-10-10 07:47 - 05131844 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFix.exe
2013-10-10 07:45 - 2012-11-12 14:45 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-10-10 07:45 - 2012-11-12 13:57 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-10 07:45 - 2012-11-12 13:57 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-10 07:45 - 2012-03-01 23:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 20:04 - 2012-07-21 17:25 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-09 20:04 - 2012-07-21 17:25 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-09 19:41 - 2013-10-09 19:41 - 00602112 _____ (OldTimer Tools) C:\Users\Administrator\Desktop\OTL.exe
2013-10-09 05:04 - 2012-08-12 16:19 - 00000000 ____D C:\Users\Administrator
2013-10-09 03:20 - 2012-03-01 22:59 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-09 01:31 - 2013-10-09 01:28 - 00016321 _____ C:\Users\Administrator\Desktop\Gmer.txt
2013-10-09 01:31 - 2012-08-05 17:00 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000Core.job
2013-10-09 01:22 - 2013-10-09 01:22 - 00377856 _____ C:\Users\Administrator\Desktop\gmer_2.1.19163.exe
2013-10-09 01:21 - 2013-10-09 01:20 - 00000320 _____ C:\Users\Administrator\Desktop\Addition.txt
2013-10-09 01:19 - 2013-10-09 01:18 - 01954124 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-10-08 20:46 - 2013-10-08 20:40 - 00010918 _____ C:\Windows\IE10_main.log
2013-10-08 20:31 - 2013-10-08 20:31 - 00000000 ____D C:\FRST
2013-10-08 20:29 - 2013-10-08 01:15 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-08 20:29 - 2013-10-08 01:15 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-08 20:15 - 2009-07-14 06:45 - 00427632 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-08 02:05 - 2013-10-08 02:03 - 00000000 ____D C:\Windows\system32\MRT
2013-10-08 02:03 - 2012-03-02 11:43 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-08 01:52 - 2013-10-08 01:52 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2013-10-08 01:49 - 2013-10-08 01:47 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2013-10-08 01:47 - 2013-10-08 01:47 - 04095448 _____ (BrightFort LLC                                              ) C:\Users\Administrator\Desktop\spywareblastersetup50.exe
2013-10-08 01:47 - 2013-10-08 01:47 - 00001085 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2013-10-08 01:47 - 2013-10-08 01:47 - 00000000 ____D C:\ProgramData\Licenses
2013-10-08 01:43 - 2013-10-08 01:43 - 01032220 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe
2013-10-08 01:41 - 2013-10-08 01:41 - 01032220 _____ (Thisisu) C:\Users\Administrator\Downloads\JRT.exe
2013-10-08 01:40 - 2013-10-08 01:40 - 00000000 ____D C:\ProgramData\Oracle
2013-10-08 01:39 - 2013-10-08 01:40 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-10-08 01:39 - 2013-10-08 01:40 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 01:39 - 2013-10-08 01:39 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-08 01:39 - 2012-03-04 18:42 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-10-08 01:32 - 2013-10-08 01:32 - 02378752 _____ C:\Users\Administrator\Downloads\Adblock_Installer.msi
2013-10-08 01:25 - 2013-10-08 01:24 - 00000000 ____D C:\AdwCleaner
2013-10-08 01:25 - 2012-03-03 20:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-08 01:24 - 2013-10-08 01:24 - 01045226 _____ C:\Users\Administrator\Desktop\adwcleaner.exe
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Local\Threat Expert
2013-10-08 01:15 - 2013-10-08 01:15 - 00115960 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-08 01:15 - 2013-10-08 01:15 - 00001445 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-08 01:15 - 2013-10-08 01:15 - 00001411 _____ C:\Users\Administrator\Desktop\Internet Explorer (64-bit).lnk
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Razer
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\ATI
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Local\Logitech
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Local\ATI
2013-10-08 00:53 - 2013-10-08 00:53 - 00000000 _____ C:\Users\*****\Desktop\4wcl7hv.txt
2013-10-08 00:45 - 2012-03-05 17:25 - 00000000 ____D C:\Program Files (x86)\Steam
2013-10-08 00:29 - 2013-02-28 22:38 - 00000000 ____D C:\Users\*****\AppData\Roaming\Skype
2013-10-08 00:28 - 2012-03-03 23:13 - 00000000 ____D C:\Users\*****\AppData\Roaming\TS3Client
2013-10-05 01:47 - 2012-03-03 22:38 - 00000000 ____D C:\Users\*****\AppData\Local\PMB Files
2013-10-05 01:47 - 2012-03-03 22:38 - 00000000 ____D C:\ProgramData\PMB Files
2013-10-03 02:09 - 2013-05-19 14:41 - 00000000 ____D C:\Program Files (x86)\War Thunder
2013-10-01 11:47 - 2012-03-03 21:42 - 00000000 ____D C:\Users\*****\AppData\Local\TeamSpeak 3 Client
2013-09-29 14:04 - 2013-09-29 13:43 - 00000000 ____D C:\Users\*****\AppData\Local\SCE
2013-09-29 14:04 - 2013-01-07 03:26 - 00000000 ____D C:\Users\*****\Documents\My Games
2013-09-29 13:42 - 2012-03-05 18:10 - 00155388 _____ C:\Windows\DirectX.log
2013-09-24 23:56 - 2013-09-24 22:31 - 00000000 ____D C:\Users\*****\Desktop\Vermietung
2013-09-24 23:56 - 2012-03-29 06:32 - 00000000 ____D C:\Users\*****\Documents\Outlook-Dateien
2013-09-17 02:36 - 2013-09-17 02:36 - 00000000 _____ C:\Users\*****\Desktop\Attack on Titan 25.txt
2013-09-15 21:16 - 2013-08-20 20:17 - 00000000 ____D C:\Users\*****\Documents\Assassin's Creed III
2013-09-15 19:53 - 2013-03-22 00:29 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-09-15 19:52 - 2013-03-22 23:58 - 00281392 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-09-15 19:52 - 2013-03-22 23:58 - 00000000 ____D C:\Users\*****\AppData\Local\PunkBuster
2013-09-15 19:52 - 2013-03-22 00:29 - 00281392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-09-13 21:12 - 2013-09-13 21:12 - 00138240 _____ C:\Users\*****\Desktop\Finanzierungsplan.xls
2013-09-10 20:42 - 2012-03-04 02:10 - 00000000 ____D C:\Users\*****\AppData\Roaming\Digidesign
2013-09-10 20:19 - 2013-09-10 20:17 - 00000000 ____D C:\Users\*****\AppData\Roaming\PACE Anti-Piracy
2013-09-10 20:17 - 2013-09-10 20:17 - 00000000 ____D C:\Users\*****\AppData\Local\PACE Anti-Piracy
2013-09-10 20:17 - 2012-10-27 00:40 - 00000000 ___HD C:\Users\*****\AppData\Local\iBY3HyQdk0QdJ

Some content of TEMP:
====================
C:\Users\*****\AppData\Local\temp\{5FE98B5E-EA8F-4487-AFA3-D1EA5ADCA351}.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-01 11:02

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013
Ran by ***** at 2013-10-10 22:55:22
Running from C:\Users\*****\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Disabled - Up to date) {3F839487-C7A2-C958-E30C-E2825BA31FB5}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spyware Doctor (Disabled - Up to date) {94076BB2-F3DA-227F-9A1E-F060FF73600F}
AS: Microsoft Security Essentials (Disabled - Up to date) {84E27563-E198-C6D6-D9BC-D9F020245508}

==================== Installed Programs ======================

µTorrent (x32 Version: 3.1.2)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Acronis*True*Image*Home (x32 Version: 13.0.7154)
AdblockIE (x32 Version: 1.2)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader X (10.1.3) - Deutsch (x32 Version: 10.1.3)
Age of Empires Online (x32)
AMD Accelerated Video Transcoding (Version: 12.10.100.30328)
AMD Catalyst Install Manager (Version: 8.0.911.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.80328.2204)
Apple Application Support (x32 Version: 2.1.5)
Apple Software Update (x32 Version: 2.1.3.127)
Assassin's Creed(R) III v1.06 (x32 Version: 1.06)
Avid Pro Tools SE 8.0.3 (x32 Version: 8.0.3)
AVM FRITZ!WLAN (x32)
Battlefield 3™ (x32 Version: 1.6.0.0)
Battlelog Web Plugins (x32 Version: 2.1.7)
Borderlands 2 (x32)
Browser Defender 2.0.6.15 (x32 Version: 2.0.6.15)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0928.1532.26058)
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center InstallProxy (x32 Version: 2012.0928.1532.26058)
Catalyst Control Center InstallProxy (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center Localization All (x32 Version: 2013.0328.2218.38225)
CCC Help Chinese Standard (x32 Version: 2012.0928.1531.26058)
CCC Help Chinese Standard (x32 Version: 2013.0328.2217.38225)
CCC Help Chinese Traditional (x32 Version: 2012.0928.1531.26058)
CCC Help Chinese Traditional (x32 Version: 2013.0328.2217.38225)
CCC Help Czech (x32 Version: 2012.0928.1531.26058)
CCC Help Czech (x32 Version: 2013.0328.2217.38225)
CCC Help Danish (x32 Version: 2012.0928.1531.26058)
CCC Help Danish (x32 Version: 2013.0328.2217.38225)
CCC Help Dutch (x32 Version: 2012.0928.1531.26058)
CCC Help Dutch (x32 Version: 2013.0328.2217.38225)
CCC Help English (x32 Version: 2012.0928.1531.26058)
CCC Help English (x32 Version: 2013.0328.2217.38225)
CCC Help Finnish (x32 Version: 2012.0928.1531.26058)
CCC Help Finnish (x32 Version: 2013.0328.2217.38225)
CCC Help French (x32 Version: 2012.0928.1531.26058)
CCC Help French (x32 Version: 2013.0328.2217.38225)
CCC Help German (x32 Version: 2012.0928.1531.26058)
CCC Help German (x32 Version: 2013.0328.2217.38225)
CCC Help Greek (x32 Version: 2012.0928.1531.26058)
CCC Help Greek (x32 Version: 2013.0328.2217.38225)
CCC Help Hungarian (x32 Version: 2012.0928.1531.26058)
CCC Help Hungarian (x32 Version: 2013.0328.2217.38225)
CCC Help Italian (x32 Version: 2012.0928.1531.26058)
CCC Help Italian (x32 Version: 2013.0328.2217.38225)
CCC Help Japanese (x32 Version: 2012.0928.1531.26058)
CCC Help Japanese (x32 Version: 2013.0328.2217.38225)
CCC Help Korean (x32 Version: 2012.0928.1531.26058)
CCC Help Korean (x32 Version: 2013.0328.2217.38225)
CCC Help Norwegian (x32 Version: 2012.0928.1531.26058)
CCC Help Norwegian (x32 Version: 2013.0328.2217.38225)
CCC Help Polish (x32 Version: 2012.0928.1531.26058)
CCC Help Polish (x32 Version: 2013.0328.2217.38225)
CCC Help Portuguese (x32 Version: 2012.0928.1531.26058)
CCC Help Portuguese (x32 Version: 2013.0328.2217.38225)
CCC Help Russian (x32 Version: 2012.0928.1531.26058)
CCC Help Russian (x32 Version: 2013.0328.2217.38225)
CCC Help Spanish (x32 Version: 2012.0928.1531.26058)
CCC Help Spanish (x32 Version: 2013.0328.2217.38225)
CCC Help Swedish (x32 Version: 2012.0928.1531.26058)
CCC Help Swedish (x32 Version: 2013.0328.2217.38225)
CCC Help Thai (x32 Version: 2012.0928.1531.26058)
CCC Help Thai (x32 Version: 2013.0328.2217.38225)
CCC Help Turkish (x32 Version: 2012.0928.1531.26058)
CCC Help Turkish (x32 Version: 2013.0328.2217.38225)
ccc-utility64 (Version: 2012.0928.1532.26058)
ccc-utility64 (Version: 2013.0328.2218.38225)
Company of Heroes - FAKEMSI (x32 Version: 2.0.0.0)
Company of Heroes (x32 Version: 2.0.0.1)
DC Universe Online (x32)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Diablo III (x32 Version: 1.0.6.13644)
Dota 2 (x32)
ESN Sonar (x32 Version: 0.70.4)
Free YouTube to MP3 Converter version 3.12.0.128 (x32 Version: 3.12.0.128)
Google Chrome (HKCU Version: 30.0.1599.69)
Google Earth Plug-in (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
Guild Wars 2 (x32)
High-Definition Video Playback (x32 Version: 7.3.10800.5.0)
Host OpenAL (ADI) (x32)
Intel® Matrix Storage Manager
Interlok driver setup x64 (Version: 5.8.13)
Java 7 Update 40 (x32 Version: 7.0.400)
Java Auto Updater (x32 Version: 2.1.9.8)
JNLP (HKCU)
K-Lite Codec Pack 9.9.5 (Basic) (x32 Version: 9.9.5)
League of Legends (x32 Version: 1.02.0000)
Lightworks (x32 Version: 11.0.3.0)
Logitech Gaming Software (Version: 8.20.74)
Logitech Gaming Software 8.20 (Version: 8.20.74)
marvell 61xx (x32 Version: 1.2.0.7100)
M-Audio FastTrack Driver 6.0.6 (x64) (Version: 6.0.6)
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0)
Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0)
Microsoft Office 2010 Service Pack 1 (SP1) (x32)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Standard 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Security Client (Version: 4.2.0223.1)
Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 4.2.223.1)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Nero 10 Menu TemplatePack Basic (x32 Version: 10.6.10000.0.0)
Nero 10 Movie ThemePack Basic (x32 Version: 10.6.10000.1.0)
Nero BackItUp 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Burning ROM 10 (x32 Version: 10.6.10600.4.100)
Nero BurningROM 10 Help (CHM) (x32 Version: 10.6.10600)
Nero BurnRights 10 (x32 Version: 4.4.10300.1.100)
Nero BurnRights 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Control Center 10 (x32 Version: 10.6.12600.0.5)
Nero ControlCenter 10 Help (CHM) (x32 Version: 10.6.10700)
Nero Core Components 10 (x32 Version: 2.0.19800.9.10)
Nero CoverDesigner 10 (x32 Version: 5.6.10500.3.100)
Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.6.10600)
Nero DiscSpeed 10 (x32 Version: 6.4.10400.0.100)
Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Dolby Files 10 (x32 Version: 2.0.13000.0.10)
Nero Express 10 (x32 Version: 10.6.10600.4.100)
Nero Express 10 Help (CHM) (x32 Version: 10.6.10600)
Nero InfoTool 10 (x32 Version: 7.4.10200.0.100)
Nero InfoTool 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Multimedia Suite 10 (x32 Version: 10.6.11300)
Nero Recode 10 (x32 Version: 4.10.10600.4.100)
Nero Recode 10 Help (CHM) (x32 Version: 10.6.10600)
Nero RescueAgent 10 Help (CHM) (x32 Version: 10.6.10700)
Nero SoundTrax 10 (x32 Version: 4.10.10300.2.100)
Nero SoundTrax 10 Help (CHM) (x32 Version: 10.6.10600)
Nero StartSmart 10 (x32 Version: 10.6.10400.2.100)
Nero StartSmart 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Update (x32 Version: 1.0.10900.31.0)
Nero Vision 10 (x32 Version: 7.4.10800.7.100)
Nero Vision 10 Help (CHM) (x32 Version: 10.6.10600)
Nero WaveEditor 10 (x32 Version: 5.10.10400.3.100)
Nero WaveEditor 10 Help (CHM) (x32 Version: 10.6.10600)
NeroKwikMedia Help (CHM) (x32 Version: 10.6.10700)
Origin (x32 Version: 9.1.10.2728)
Pando Media Booster (x32 Version: 2.6.0.6)
PC VGA Camer@ (x32 Version: 1.0.2.04)
PunkBuster Services (x32 Version: 0.991)
QuickTime (x32 Version: 7.71.80.42)
Razer DeathAdder(TM) Mouse (x32 Version: 3.03)
Security Task Manager 1.8d (x32 Version: 1.8d)
SimCity™ (x32 Version: 1.0.0.0)
Skype™ 5.10 (x32 Version: 5.10.116)
SoundMAX (x32 Version: 6.10.2.6585)
Spybot - Search & Destroy (x32 Version: 1.6.2)
Spyware Doctor 7.0 (x32 Version: 7.0)
SpywareBlaster 5.0 (x32 Version: 5.0.0)
StarCraft II (x32 Version: 2.0.9.26147)
Steam (x32 Version: 1.0.0.0)
TeamSpeak 3 Client (HKCU Version: 3.0.13)
TERA (x32 Version: 19.04.02.03.hf3)
tools-freebsd (x32 Version: 8.4.6.16648)
tools-linux (x32 Version: 8.4.6.16648)
tools-netware (x32 Version: 8.4.6.16648)
tools-solaris (x32 Version: 8.4.6.16648)
tools-windows (x32 Version: 8.4.6.16648)
tools-winPre2k (x32 Version: 8.4.6.16648)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2494150) (x32)
Update for Microsoft Office 2010 (KB2553065) (x32)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2566458) (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32)
Uplay (x32 Version: 3.0)
VirtualCloneDrive (x32)
VLC media player 2.0.0 (x32 Version: 2.0.0)
VMware Workstation (x32 Version: 7.1.4.16648)
War Thunder (x32)
War Thunder Launcher 1.0.1.199 (x32)
Warhammer 40,000 Space Marine (x32)
Warhammer® 40,000™: Dawn of War® II - Chaos Rising™ (x32)
Warhammer® 40,000™: Dawn of War® II – Retribution™ (x32)
Windows Live ID Sign-in Assistant (Version: 6.500.3165.0)

==================== Restore Points  =========================

07-10-2013 20:24:40 Windows Update
07-10-2013 23:39:08 Removed Java(TM) 6 Update 31
07-10-2013 23:39:37 Installed Java 7 Update 40
07-10-2013 23:52:26 Windows Update
08-10-2013 18:35:44 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2013-10-10 08:08 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0F4E9001-C870-4EAB-A187-9E52BA88E7A1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-21] (Google Inc.)
Task: {42F7F6D6-FFA5-4FC7-A224-C0CAACE96272} - System32\Tasks\preispilotSWU => C:\Program Files (x86)\preispilot\swu.vbs"C:\Program Files (x86)\preispilot\swu.vbs"
Task: {6327BBCB-6CB1-40A0-88CC-065AB6D369C6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {6641C950-F758-45B9-A97E-F73FAA4BA591} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000Core => C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-21] (Google Inc.)
Task: {7160B5AA-0163-4361-A8A7-2833E7C09055} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-07-21] (Google Inc.)
Task: {824CDB4A-0255-4960-B783-C9F8438AC3E7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000UA => C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-21] (Google Inc.)
Task: {F34D9388-C0D5-4964-81B7-B2E9EE4EBB61} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated)
Task: {F37E929B-7EFA-4994-92D4-8647F4F3EB18} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000Core.job => C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000UA.job => C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-12-11 20:19 - 2010-12-11 20:19 - 01208560 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll
2012-10-23 01:54 - 2009-11-10 10:26 - 00767952 _____ () C:\Windows\BDTSupport.dll
2011-03-26 00:42 - 2011-03-26 00:42 - 00970352 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll
2011-03-26 00:41 - 2011-03-26 00:41 - 00068720 _____ () C:\Program Files (x86)\VMware\VMware Workstation\zlib1.dll
2013-10-04 03:33 - 2013-10-03 08:02 - 00698832 _____ () C:\Users\*****\AppData\Local\Google\Chrome\Application\30.0.1599.69\libglesv2.dll
2013-10-04 03:33 - 2013-10-03 08:02 - 00099792 _____ () C:\Users\*****\AppData\Local\Google\Chrome\Application\30.0.1599.69\libegl.dll
2013-10-04 03:33 - 2013-10-03 08:03 - 04055504 _____ () C:\Users\*****\AppData\Local\Google\Chrome\Application\30.0.1599.69\pdf.dll
2013-10-04 03:33 - 2013-10-03 08:03 - 00415184 _____ () C:\Users\*****\AppData\Local\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll
2013-10-04 03:33 - 2013-10-03 08:02 - 01604560 _____ () C:\Users\*****\AppData\Local\Google\Chrome\Application\30.0.1599.69\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:A8ADE5D8
AlternateDataStreams: C:\Users\*****\Lokale Einstellungen:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local\Anwendungsdaten:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local\Temporary Internet Files:fFNjQ1aWCMRRdy6DQwtMgGo1
AlternateDataStreams: C:\Users\*****\AppData\Local\Temporary Internet Files:IhXHys7HsOvYZe9lmWQJui

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\68380184.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\68380184.sys => ""="Driver"

==================== Faulty Device Manager Devices =============

Name: Logitech Gaming Virtual Mouse
Description: Logitech Gaming Virtual Mouse
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: (Standard system devices)
Service: LGVirHid
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/09/2013 01:18:29 AM) (Source: Application Hang) (User: )
Description: Programm FRST64.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1228

Startzeit: 01cec4785aab6526

Endzeit: 0

Anwendungspfad: C:\Users\Administrator\Desktop\FRST64.exe

Berichts-ID:

Error: (10/09/2013 00:52:27 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16506, Zeitstempel: 0x51f8de05
Name des fehlerhaften Moduls: PCTBDCore.dll, Version: 2.0.6.11, Zeitstempel: 0x4af8a3c7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002696b
ID des fehlerhaften Prozesses: 0x11dc
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3

Error: (10/09/2013 00:52:26 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16506, Zeitstempel: 0x51f8de05
Name des fehlerhaften Moduls: PCTBDCore.dll, Version: 2.0.6.11, Zeitstempel: 0x4af8a3c7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002696b
ID des fehlerhaften Prozesses: 0x124c
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3

Error: (10/09/2013 00:51:58 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16506, Zeitstempel: 0x51f8de05
Name des fehlerhaften Moduls: PCTBDCore.dll, Version: 2.0.6.11, Zeitstempel: 0x4af8a3c7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002696b
ID des fehlerhaften Prozesses: 0x13b0
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3

Error: (10/09/2013 00:51:57 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16506, Zeitstempel: 0x51f8de05
Name des fehlerhaften Moduls: PCTBDCore.dll, Version: 2.0.6.11, Zeitstempel: 0x4af8a3c7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002696b
ID des fehlerhaften Prozesses: 0x10e0
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3

Error: (10/09/2013 00:51:56 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16506, Zeitstempel: 0x51f8de05
Name des fehlerhaften Moduls: PCTBDCore.dll, Version: 2.0.6.11, Zeitstempel: 0x4af8a3c7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002696f
ID des fehlerhaften Prozesses: 0x10e8
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3

Error: (10/09/2013 00:51:34 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16506, Zeitstempel: 0x51f8de05
Name des fehlerhaften Moduls: PCTBDCore.dll, Version: 2.0.6.11, Zeitstempel: 0x4af8a3c7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002696b
ID des fehlerhaften Prozesses: 0xc2c
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3

Error: (10/09/2013 00:51:31 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16506, Zeitstempel: 0x51f8de05
Name des fehlerhaften Moduls: PCTBDCore.dll, Version: 2.0.6.11, Zeitstempel: 0x4af8a3c7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002696f
ID des fehlerhaften Prozesses: 0xe54
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3

Error: (10/08/2013 08:46:58 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WU-IE10-Windows7-x64.exe, Version: 10.0.9200.16521, Zeitstempel: 0x51207d62
Name des fehlerhaften Moduls: WU-IE10-Windows7-x64.exe, Version: 10.0.9200.16521, Zeitstempel: 0x51207d62
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000b1c3
ID des fehlerhaften Prozesses: 0x760
Startzeit der fehlerhaften Anwendung: 0xWU-IE10-Windows7-x64.exe0
Pfad der fehlerhaften Anwendung: WU-IE10-Windows7-x64.exe1
Pfad des fehlerhaften Moduls: WU-IE10-Windows7-x64.exe2
Berichtskennung: WU-IE10-Windows7-x64.exe3

Error: (10/08/2013 01:40:21 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16496, Zeitstempel: 0x51a55c6d
Name des fehlerhaften Moduls: PCTBDCore.dll, Version: 2.0.6.11, Zeitstempel: 0x4af8a3c7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002696b
ID des fehlerhaften Prozesses: 0x1bec
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3


System errors:
=============
Error: (10/10/2013 10:50:20 PM) (Source: Service Control Manager) (User: )
Description: Dienst "VMware NAT Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (10/10/2013 10:50:19 PM) (Source: VMnetDHCP) (User: )
Description: Can't open C:\ProgramData\VMware\vmnetdhcp.conf: Das System kann die angegebene Datei nicht finden.
 / Unknown error 2 (0x2)

Error: (10/10/2013 10:50:14 PM) (Source: hasplms) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!

Error: (10/10/2013 08:17:52 PM) (Source: Service Control Manager) (User: )
Description: Dienst "VMware NAT Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (10/10/2013 08:17:45 PM) (Source: hasplms) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!

Error: (10/10/2013 08:17:43 PM) (Source: VMnetDHCP) (User: )
Description: Can't open C:\ProgramData\VMware\vmnetdhcp.conf: Das System kann die angegebene Datei nicht finden.
 / Unknown error 2 (0x2)

Error: (10/10/2013 08:15:21 PM) (Source: Service Control Manager) (User: )
Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (10/10/2013 08:11:22 PM) (Source: Service Control Manager) (User: )
Description: Dienst "VMware NAT Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (10/10/2013 08:11:16 PM) (Source: hasplms) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!

Error: (10/10/2013 08:11:14 PM) (Source: VMnetDHCP) (User: )
Description: Can't open C:\ProgramData\VMware\vmnetdhcp.conf: Das System kann die angegebene Datei nicht finden.
 / Unknown error 2 (0x2)


Microsoft Office Sessions:
=========================
Error: (10/09/2013 01:18:29 AM) (Source: Application Hang)(User: )
Description: FRST64.exe3.3.8.1122801cec4785aab65260C:\Users\Administrator\Desktop\FRST64.exe

Error: (10/09/2013 00:52:27 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1650651f8de05PCTBDCore.dll2.0.6.114af8a3c7c00000050002696b11dc01cec479100077ddC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\PCTBDCore.dll4db8e99f-306c-11e3-b08e-005056c00008

Error: (10/09/2013 00:52:26 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1650651f8de05PCTBDCore.dll2.0.6.114af8a3c7c00000050002696b124c01cec4790ede0ffcC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\PCTBDCore.dll4c9681bd-306c-11e3-b08e-005056c00008

Error: (10/09/2013 00:51:58 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1650651f8de05PCTBDCore.dll2.0.6.114af8a3c7c00000050002696b13b001cec478fe9f8bfdC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\PCTBDCore.dll3c57fdbf-306c-11e3-b08e-005056c00008

Error: (10/09/2013 00:51:57 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1650651f8de05PCTBDCore.dll2.0.6.114af8a3c7c00000050002696b10e001cec478fde84208C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\PCTBDCore.dll3ba0b3c9-306c-11e3-b08e-005056c00008

Error: (10/09/2013 00:51:56 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1650651f8de05PCTBDCore.dll2.0.6.114af8a3c7c00000050002696f10e801cec478fcb9f345C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\PCTBDCore.dll3ad8c032-306c-11e3-b08e-005056c00008

Error: (10/09/2013 00:51:34 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1650651f8de05PCTBDCore.dll2.0.6.114af8a3c7c00000050002696bc2c01cec478efb30b65C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\PCTBDCore.dll2dd1d853-306c-11e3-b08e-005056c00008

Error: (10/09/2013 00:51:31 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1650651f8de05PCTBDCore.dll2.0.6.114af8a3c7c00000050002696fe5401cec478ebe7d9f5C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\PCTBDCore.dll2be51b7a-306c-11e3-b08e-005056c00008

Error: (10/08/2013 08:46:58 PM) (Source: Application Error)(User: )
Description: WU-IE10-Windows7-x64.exe10.0.9200.1652151207d62WU-IE10-Windows7-x64.exe10.0.9200.1652151207d62c00000050000b1c376001cec455d3365962C:\Windows\SoftwareDistribution\Download\Install\WU-IE10-Windows7-x64.exeC:\Windows\SoftwareDistribution\Download\Install\WU-IE10-Windows7-x64.exe02078b45-304a-11e3-a583-005056c00008

Error: (10/08/2013 01:40:21 AM) (Source: Application Error)(User: )
Description: iexplore.exe9.0.8112.1649651a55c6dPCTBDCore.dll2.0.6.114af8a3c7c00000050002696b1bec01cec3b696061358C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Windows\PCTBDCore.dlld41ae717-2fa9-11e3-acdf-005056c00008


CodeIntegrity Errors:
===================================
  Date: 2013-10-10 07:59:52.586
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-10-10 07:59:52.539
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2012-11-16 01:37:43.338
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-16 01:18:39.647
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-16 01:08:21.381
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-16 01:00:54.643
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-15 20:31:19.656
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-13 21:03:36.209
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-12 17:35:19.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-12 16:24:03.462
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 18%
Total physical RAM: 12279.09 MB
Available physical RAM: 10038.14 MB
Total Pagefile: 24556.37 MB
Available Pagefile: 21930.69 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (System) (Fixed) (Total:273.2 GB) (Free:19.81 GB) NTFS
Drive d: (Daten) (Fixed) (Total:465.76 GB) (Free:313.55 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (Daten) (Fixed) (Total:465.76 GB) (Free:6.35 GB) NTFS
Drive g: (INTENSO) (Removable) (Total:7.26 GB) (Free:7.26 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 466 GB) (Disk ID: 065C96F9)
Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 466 GB) (Disk ID: A5281CF9)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 273 GB) (Disk ID: 5AC2E66E)
Partition 1: (Active) - (Size=110 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=273 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Kurze Frage: Kann man denn auf dem PC schon wieder schalten und walten? Wurde bisher garnichts mehr gemacht, also keine Mails gecheckt, kein Banking usw.

EDIT:

Habe jetzt mal folgende Maßnahmen durchgeführt:

- alle noch ausstehenden Windows-Updates gemacht
- Microsoft Security Essentials auf den neuesten Stand gebracht (aber keinen Scan durchgeführt, mit derartiger Software warte ich mal besser bis wir hier fertig sind)
- die Rechte seines Benutzerkontos von "Admin" auf "Standardnutzer" degradiert und die Geschichte mit Passwort versehen
- Adminkonto mit Passwort versehen
- Sandboxie installiert und ihm erklärt wie man es am sinnvollsten benutzt
- Benutzerkontensteuerung aktiviert (Regler ganz nach oben!!)
- Browser (IE und Firefox werde ich wohl beiseite schieben bzw. deinstallieren, er soll Chrome nutzen) geupdated also folgende Addons installiert:

https://chrome.google.com/webstore/detail/adblock/gighmmpiobklfepjocnamgkkbiglidom?hl=de
https://chrome.google.com/webstore/detail/ghostery/mlomiejdfkolichcflejclcbmpeaniij

Ich hoffe nichts davon beeinträchtigt in irgendeiner Form das weitere Vorgehen nach deinen Anweisungen. Falls doch mache ich betreffende Aktion natürlich direkt wieder rückgängig.

Bezüglich des Malwareprogramms bin ich mir noch unschlüssig. Vielleicht kannst du mir ja später einen Tip geben. Ich weiß, "das Beste" gibts nicht. Soweit bin ich immerhin schonmal :crazy:.

Auch falls ich deiner Meinung nach noch eine sinnvolle Maßnahme vergessen haben sollte (macht Secunia PSI z.B. Sinn?) bitte ich um einen dezenten Hinweis ^^.

aharonov 11.10.2013 08:51

Hallo,

Tipps zur Absicherung geb ich dann zum Schluss noch mit.
Zuerst kontrollieren wir nochmals gründlich:


Schritt 1

Mach bitte nochmals einen Scan mit dem TDSSKiller, um zu sehen, ob das geklappt hat, und poste das Log.



Schritt 2

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

(Den richtigen Benutzernamen wieder einsetzen anstelle der *****!!)
Code:

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\68380184.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\68380184.sys => ""="Driver"
AlternateDataStreams: C:\ProgramData\TEMP:A8ADE5D8
AlternateDataStreams: C:\Users\*****\Lokale Einstellungen:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local\Anwendungsdaten:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local\Temporary Internet Files:fFNjQ1aWCMRRdy6DQwtMgGo1
AlternateDataStreams: C:\Users\*****\AppData\Local\Temporary Internet Files:IhXHys7HsOvYZe9lmWQJui
C:\Users\*****\AppData\Local\temp\{5FE98B5E-EA8F-4487-AFA3-D1EA5ADCA351}.exe
2013-09-10 20:17 - 2012-10-27 00:40 - 00000000 ___HD C:\Users\*****\AppData\Local\iBY3HyQdk0QdJ
2013-10-08 01:52 - 2013-10-08 01:52 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
S1 ajlvsasx; \??\C:\Windows\system32\drivers\ajlvsasx.sys [x]
S1 crtjnuyc; \??\C:\Windows\system32\drivers\crtjnuyc.sys [x]
S1 eaarkkjg; \??\C:\Windows\system32\drivers\eaarkkjg.sys [x]
S1 ktmujbzd; \??\C:\Windows\system32\drivers\ktmujbzd.sys [x]
S1 ptqllcii; \??\C:\Windows\system32\drivers\ptqllcii.sys [x]
S1 rlffuili; \??\C:\Windows\system32\drivers\rlffuili.sys [x]
S1 rmtofanc; \??\C:\Windows\system32\drivers\rmtofanc.sys [x]
S1 ubqgdokm; \??\C:\Windows\system32\drivers\ubqgdokm.sys [x]
S1 varehocl; \??\C:\Windows\system32\drivers\varehocl.sys [x]
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109727&tt=010812_nich_3112_8&babsrc=SP_ss&mntrId=9e1017a8000000000000e0cb4e3e3e0f
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109727&tt=010812_nich_3112_8&babsrc=SP_ss&mntrId=9e1017a8000000000000e0cb4e3e3e0f


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Schritt 3

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




Schritt 4


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset




Schritt 5

Starte noch einmal FRST.
  • Setze bei Optional Scan den Haken bei Addition.txt und drücke Scan.
  • Wenn der Scan abgeschlossen ist, werden zwei neue Logfiles FRST.txt und Addition.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieser beiden Logfiles bitte hier in deinen Thread.

Lou Schalter 11.10.2013 21:12

Code:

19:54:23.0188 0x1100  TDSS rootkit removing tool 3.0.0.12 Oct  9 2013 14:59:22
19:54:23.0586 0x1100  ============================================================
19:54:23.0586 0x1100  Current date / time: 2013/10/11 19:54:23.0586
19:54:23.0586 0x1100  SystemInfo:
19:54:23.0586 0x1100 
19:54:23.0586 0x1100  OS Version: 6.1.7601 ServicePack: 1.0
19:54:23.0586 0x1100  Product type: Workstation
19:54:23.0586 0x1100  ComputerName: *****-PC
19:54:23.0587 0x1100  UserName: Administrator
19:54:23.0587 0x1100  Windows directory: C:\Windows
19:54:23.0587 0x1100  System windows directory: C:\Windows
19:54:23.0587 0x1100  Running under WOW64
19:54:23.0587 0x1100  Processor architecture: Intel x64
19:54:23.0587 0x1100  Number of processors: 8
19:54:23.0587 0x1100  Page size: 0x1000
19:54:23.0587 0x1100  Boot type: Normal boot
19:54:23.0587 0x1100  ============================================================
19:54:25.0553 0x1100  System UUID: {438E91DF-0BCC-791E-3945-FA16759C1496}
19:54:26.0190 0x1100  Drive \Device\Harddisk2\DR2 - Size: 0x4453C00000 (273.31 Gb), SectorSize: 0x200, Cylinders: 0x8B5E, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000048
19:54:26.0196 0x1100  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:54:26.0197 0x1100  Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:54:26.0210 0x1100  Drive \Device\Harddisk3\DR3 - Size: 0x1D1A00000 (7.28 Gb), SectorSize: 0x200, Cylinders: 0x3B5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:54:26.0213 0x1100  ============================================================
19:54:26.0213 0x1100  \Device\Harddisk2\DR2:
19:54:26.0213 0x1100  MBR partitions:
19:54:26.0213 0x1100  \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x37000
19:54:26.0213 0x1100  \Device\Harddisk2\DR2\Partition2: MBR, Type 0x7, StartLBA 0x37800, BlocksNum 0x22266800
19:54:26.0213 0x1100  \Device\Harddisk0\DR0:
19:54:26.0221 0x1100  MBR partitions:
19:54:26.0221 0x1100  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
19:54:26.0221 0x1100  \Device\Harddisk1\DR1:
19:54:26.0221 0x1100  MBR partitions:
19:54:26.0221 0x1100  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C02
19:54:26.0221 0x1100  \Device\Harddisk3\DR3:
19:54:26.0223 0x1100  MBR partitions:
19:54:26.0223 0x1100  \Device\Harddisk3\DR3\Partition1: MBR, Type 0xB, StartLBA 0xB88, BlocksNum 0xE8C478
19:54:26.0223 0x1100  ============================================================
19:54:26.0243 0x1100  C: <-> \Device\Harddisk2\DR2\Partition2
19:54:26.0269 0x1100  E: <-> \Device\Harddisk0\DR0\Partition1
19:54:26.0336 0x1100  D: <-> \Device\Harddisk1\DR1\Partition1
19:54:26.0336 0x1100  ============================================================
19:54:26.0336 0x1100  Initialize success
19:54:26.0336 0x1100  ============================================================
19:54:31.0732 0x0afc  ============================================================
19:54:31.0732 0x0afc  Scan started
19:54:31.0732 0x0afc  Mode: Manual; SigCheck; TDLFS;
19:54:31.0732 0x0afc  ============================================================
19:54:31.0732 0x0afc  KSN ping started
19:54:34.0214 0x0afc  KSN ping finished: true
19:54:34.0974 0x0afc  ================ Scan system memory ========================
19:54:34.0974 0x0afc  System memory - ok
19:54:34.0974 0x0afc  ================ Scan services =============================
19:54:35.0163 0x0afc  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
19:54:35.0302 0x0afc  1394ohci - ok
19:54:35.0323 0x0afc  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
19:54:35.0347 0x0afc  ACPI - ok
19:54:35.0374 0x0afc  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
19:54:35.0439 0x0afc  AcpiPmi - ok
19:54:35.0531 0x0afc  [ 1FE7229F34038D1ABE837688EC0EF15B, BEDCCCC47285DC7B8D43A6F8B69347E53E4165E30C684503D6A8FDAE191D0ABF ] AcrSch2Svc      C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
19:54:35.0571 0x0afc  AcrSch2Svc - ok
19:54:35.0601 0x0afc  [ 1C090E86AFD15231377AD37436C3C719, 7C8C679ADB7AF0A965508012C4F3F2FA68D0BFE0E04941B94693D94DB0931B53 ] ADIHdAudAddService C:\Windows\system32\drivers\ADIHdAud.sys
19:54:35.0644 0x0afc  ADIHdAudAddService - ok
19:54:35.0686 0x0afc  [ 62B7936F9036DD6ED36E6A7EFA805DC0, C58EA1B46CB3595386C9217A7785F2A436916FB1E0BDC0E4BE484292C55AA455 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:54:35.0696 0x0afc  AdobeARMservice - ok
19:54:35.0783 0x0afc  [ A283108E14F3970432C21AF4C0CB1BCE, 1D3219EF916D54232838870EDE557296AACB714B456ED0AAE0DE3CE3822F4643 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:54:35.0799 0x0afc  AdobeFlashPlayerUpdateSvc - ok
19:54:35.0826 0x0afc  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
19:54:35.0850 0x0afc  adp94xx - ok
19:54:35.0873 0x0afc  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci        C:\Windows\system32\drivers\adpahci.sys
19:54:35.0894 0x0afc  adpahci - ok
19:54:35.0912 0x0afc  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320        C:\Windows\system32\drivers\adpu320.sys
19:54:35.0927 0x0afc  adpu320 - ok
19:54:35.0941 0x0afc  [ 3BDB13C79CC8C06E2F8182595903ED69, 9E00D6649E862DE6812718B091C350E05A2C5C4D28DE8E05E3DD1F789A04EE96 ] AEADIFilters    C:\Windows\system32\AEADISRV.EXE
19:54:35.0960 0x0afc  AEADIFilters - ok
19:54:35.0971 0x0afc  [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
19:54:36.0054 0x0afc  AeLookupSvc - ok
19:54:36.0081 0x0afc  [ AE1FCE2CD1E99BEA89183BA8CD320872, 96F14BCA0C2479F39A5027A71922907D0F35CAD8E9A5037674DF7995BBDB2B51 ] afcdp          C:\Windows\system32\DRIVERS\afcdp.sys
19:54:36.0104 0x0afc  afcdp - ok
19:54:36.0194 0x0afc  [ AF44F7E027037628F1FAC3C13CDE73E6, 56A95EBF2241C275FD401487C5F0E86859F8637D8B1BD01B7157EE9BC22B1907 ] afcdpsrv        C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
19:54:36.0288 0x0afc  afcdpsrv - ok
19:54:36.0332 0x0afc  [ 1C7857B62DE5994A75B054A9FD4C3825, 83F963D7E636532B1AD30B1E727EC429317CA540F6EB3BB268FCC0B163B67767 ] AFD            C:\Windows\system32\drivers\afd.sys
19:54:36.0371 0x0afc  AFD - ok
19:54:36.0394 0x0afc  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\drivers\agp440.sys
19:54:36.0410 0x0afc  agp440 - ok
19:54:36.0428 0x0afc  ajlvsasx - ok
19:54:36.0450 0x0afc  [ 44F360B65C37A42EB5B71C2E5179FDD5, A7E65515FEE1698C96F647111F5C7D009C5FAC9A1F62D027802861A699AF1F93 ] aksdf          C:\Windows\system32\drivers\aksdf.sys
19:54:36.0482 0x0afc  aksdf - ok
19:54:36.0515 0x0afc  [ BC61697103C9EFC3DBA83777CEA8E76B, 15F55C9E4ACB695A5A9BEF52D69AFE9D8D50F8307B81349FB4300368B52493D3 ] aksfridge      C:\Windows\system32\drivers\aksfridge.sys
19:54:36.0526 0x0afc  aksfridge - ok
19:54:36.0541 0x0afc  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG            C:\Windows\System32\alg.exe
19:54:36.0579 0x0afc  ALG - ok
19:54:36.0597 0x0afc  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
19:54:36.0608 0x0afc  aliide - ok
19:54:36.0629 0x0afc  [ 310F86335B0505DDC6D2DD48E66EF06B, 936273CA046B3AE0944E6C1557CECB2A0C61D034977BBB9FACBE062617CF3A2C ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
19:54:36.0773 0x0afc  AMD External Events Utility - ok
19:54:36.0792 0x0afc  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
19:54:36.0803 0x0afc  amdide - ok
19:54:36.0821 0x0afc  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
19:54:36.0845 0x0afc  AmdK8 - ok
19:54:37.0121 0x0afc  [ 79CC9BE187E3144E1B58A54B842475E7, 89DD3177B5CE649AC0093603CE13FBFD93AC24F8E16C52672549110141106F4A ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
19:54:37.0566 0x0afc  amdkmdag - ok
19:54:37.0599 0x0afc  [ 07561D3B7FD99F6E186C49C2D0628E38, D2D72EB45EAD29A3099C040E99A4F1F4902D3BDC0466800C63ECD33343DC1224 ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
19:54:37.0640 0x0afc  amdkmdap - ok
19:54:37.0654 0x0afc  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
19:54:37.0675 0x0afc  AmdPPM - ok
19:54:37.0696 0x0afc  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
19:54:37.0710 0x0afc  amdsata - ok
19:54:37.0730 0x0afc  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
19:54:37.0747 0x0afc  amdsbs - ok
19:54:37.0767 0x0afc  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata        C:\Windows\system32\drivers\amdxata.sys
19:54:37.0777 0x0afc  amdxata - ok
19:54:37.0796 0x0afc  [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644ED2E50CF9BB491A ] AppID          C:\Windows\system32\drivers\appid.sys
19:54:37.0933 0x0afc  AppID - ok
19:54:37.0943 0x0afc  [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
19:54:37.0979 0x0afc  AppIDSvc - ok
19:54:38.0000 0x0afc  [ 9D2A2369AB4B08A4905FE72DB104498F, D6FA1705018BABABFA2362E05691A0D6408D14DE7B76129B16D0A1DAD6378E58 ] Appinfo        C:\Windows\System32\appinfo.dll
19:54:38.0027 0x0afc  Appinfo - ok
19:54:38.0045 0x0afc  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt        C:\Windows\System32\appmgmts.dll
19:54:38.0076 0x0afc  AppMgmt - ok
19:54:38.0086 0x0afc  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc            C:\Windows\system32\drivers\arc.sys
19:54:38.0099 0x0afc  arc - ok
19:54:38.0112 0x0afc  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\drivers\arcsas.sys
19:54:38.0125 0x0afc  arcsas - ok
19:54:38.0208 0x0afc  [ 9217D874131AE6FF8F642F124F00A555, BE2923D5AA7748FDAAED73AF567D015517B36F1C739C6E5637DD15112EFDF495 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
19:54:38.0254 0x0afc  aspnet_state - ok
19:54:38.0275 0x0afc  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
19:54:38.0309 0x0afc  AsyncMac - ok
19:54:38.0325 0x0afc  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi          C:\Windows\system32\drivers\atapi.sys
19:54:38.0335 0x0afc  atapi - ok
19:54:38.0355 0x0afc  [ ED3A041014FBBFDC23D6C04F9C7A5D79, A039D8F4C0EA2101898A253E13DFED5FA8500C412ACC47835415E27C9BD068FF ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
19:54:38.0386 0x0afc  AtiHDAudioService - ok
19:54:38.0409 0x0afc  [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:54:38.0464 0x0afc  AudioEndpointBuilder - ok
19:54:38.0481 0x0afc  [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
19:54:38.0523 0x0afc  AudioSrv - ok
19:54:38.0557 0x0afc  [ C6F4C466B654C1BE98AF31418BB5AC30, 62AA4456F8E22A6E508EB44DE4309615057117AAF923C13BBED15AA39630E76B ] AVM WLAN Connection Service C:\Program Files (x86)\avmwlanstick\WlanNetService.exe
19:54:38.0651 0x0afc  AVM WLAN Connection Service - detected UnsignedFile.Multi.Generic ( 1 )
19:54:41.0084 0x0afc  Detect skipped due to KSN trusted
19:54:41.0084 0x0afc  AVM WLAN Connection Service - ok
19:54:41.0113 0x0afc  [ 1DC2F715792CF33428AD7993ACBD224D, 129FBD517E016914CD61C35894C0B9B2074E680F1EB21201597E5C13CAF4529F ] avmeject        C:\Windows\system32\drivers\avmeject.sys
19:54:41.0123 0x0afc  avmeject - ok
19:54:41.0153 0x0afc  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\Windows\System32\AxInstSV.dll
19:54:41.0209 0x0afc  AxInstSV - ok
19:54:41.0237 0x0afc  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv        C:\Windows\system32\drivers\bxvbda.sys
19:54:41.0274 0x0afc  b06bdrv - ok
19:54:41.0297 0x0afc  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
19:54:41.0322 0x0afc  b57nd60a - ok
19:54:41.0340 0x0afc  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
19:54:41.0364 0x0afc  BDESVC - ok
19:54:41.0378 0x0afc  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
19:54:41.0411 0x0afc  Beep - ok
19:54:41.0450 0x0afc  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE            C:\Windows\System32\bfe.dll
19:54:41.0506 0x0afc  BFE - ok
19:54:41.0534 0x0afc  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\system32\qmgr.dll
19:54:41.0593 0x0afc  BITS - ok
19:54:41.0605 0x0afc  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
19:54:41.0623 0x0afc  blbdrive - ok
19:54:41.0641 0x0afc  [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
19:54:41.0665 0x0afc  bowser - ok
19:54:41.0671 0x0afc  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
19:54:41.0692 0x0afc  BrFiltLo - ok
19:54:41.0700 0x0afc  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
19:54:41.0715 0x0afc  BrFiltUp - ok
19:54:41.0737 0x0afc  [ 5C2F352A4E961D72518261257AAE204B, 9EE1001E1D46A414A7A86FE1DBBE232203E26F54D9EF43ED31ED8EACD4D09853 ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
19:54:41.0769 0x0afc  BridgeMP - ok
19:54:41.0786 0x0afc  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser        C:\Windows\System32\browser.dll
19:54:41.0809 0x0afc  Browser - ok
19:54:41.0864 0x0afc  [ 21FA3E51618FF8E2F4B29964ABC5884F, AB6E5ACEBC426354C7CD7D297D8D2CA086755F0E410320CA15B989E8963ECC78 ] Browser Defender Update Service C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
19:54:41.0875 0x0afc  Browser Defender Update Service - ok
19:54:41.0886 0x0afc  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
19:54:41.0929 0x0afc  Brserid - ok
19:54:41.0935 0x0afc  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
19:54:41.0953 0x0afc  BrSerWdm - ok
19:54:41.0961 0x0afc  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
19:54:41.0983 0x0afc  BrUsbMdm - ok
19:54:41.0990 0x0afc  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
19:54:42.0007 0x0afc  BrUsbSer - ok
19:54:42.0016 0x0afc  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
19:54:42.0037 0x0afc  BTHMODEM - ok
19:54:42.0059 0x0afc  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv        C:\Windows\system32\bthserv.dll
19:54:42.0089 0x0afc  bthserv - ok
19:54:42.0100 0x0afc  catchme - ok
19:54:42.0111 0x0afc  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
19:54:42.0146 0x0afc  cdfs - ok
19:54:42.0156 0x0afc  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
19:54:42.0173 0x0afc  cdrom - ok
19:54:42.0193 0x0afc  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc    C:\Windows\System32\certprop.dll
19:54:42.0229 0x0afc  CertPropSvc - ok
19:54:42.0238 0x0afc  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\drivers\circlass.sys
19:54:42.0258 0x0afc  circlass - ok
19:54:42.0272 0x0afc  [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS            C:\Windows\system32\CLFS.sys
19:54:42.0294 0x0afc  CLFS - ok
19:54:42.0321 0x0afc  [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:54:42.0333 0x0afc  clr_optimization_v2.0.50727_32 - ok
19:54:42.0364 0x0afc  [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:54:42.0376 0x0afc  clr_optimization_v2.0.50727_64 - ok
19:54:42.0430 0x0afc  [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:54:42.0534 0x0afc  clr_optimization_v4.0.30319_32 - ok
19:54:42.0544 0x0afc  [ C6F9AF94DCD58122A4D7E89DB6BED29D, CB0E5AE60EC76323585FB86D89E8DB7ADB5EDF6EA3D0B27E9ECE75B8CAA8BFDE ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:54:42.0605 0x0afc  clr_optimization_v4.0.30319_64 - ok
19:54:42.0613 0x0afc  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
19:54:42.0630 0x0afc  CmBatt - ok
19:54:42.0639 0x0afc  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
19:54:42.0650 0x0afc  cmdide - ok
19:54:42.0667 0x0afc  [ 9AC4F97C2D3E93367E2148EA940CD2CD, 530E089E5CF868AECDB2B5548EBE76E0CA98FC74A72897292AB2485734402E3B ] CNG            C:\Windows\system32\Drivers\cng.sys
19:54:42.0704 0x0afc  CNG - ok
19:54:42.0716 0x0afc  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
19:54:42.0728 0x0afc  Compbatt - ok
19:54:42.0737 0x0afc  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
19:54:42.0756 0x0afc  CompositeBus - ok
19:54:42.0758 0x0afc  COMSysApp - ok
19:54:42.0767 0x0afc  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
19:54:42.0781 0x0afc  crcdisk - ok
19:54:42.0810 0x0afc  crtjnuyc - ok
19:54:42.0829 0x0afc  [ 6B400F211BEE880A37A1ED0368776BF4, 2F27C6FA96A1C8CBDA467846DA57E63949A7EA37DB094B13397DDD30114295BD ] CryptSvc        C:\Windows\system32\cryptsvc.dll
19:54:42.0868 0x0afc  CryptSvc - ok
19:54:42.0886 0x0afc  [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC            C:\Windows\system32\drivers\csc.sys
19:54:42.0925 0x0afc  CSC - ok
19:54:42.0951 0x0afc  [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService      C:\Windows\System32\cscsvc.dll
19:54:42.0989 0x0afc  CscService - ok
19:54:43.0022 0x0afc  [ 8EC96B753727B380089D66D4AB5869DF, F8E36B68EED9680291610C83E7DF16A04D278E3E7BC807CF8A870D01C4E5A95E ] CYUSB          C:\Windows\system32\Drivers\CYUSB.sys
19:54:43.0045 0x0afc  CYUSB - ok
19:54:43.0059 0x0afc  [ 003626F7CA17C204F16CD5047AF0703A, BA9063D77A60AF1107A1A6B3C1DD6F1EF3D9DCE7616BAC67DF13AEDD67B683F3 ] danewFltr      C:\Windows\system32\drivers\danew.sys
19:54:43.0081 0x0afc  danewFltr - ok
19:54:43.0108 0x0afc  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch      C:\Windows\system32\rpcss.dll
19:54:43.0160 0x0afc  DcomLaunch - ok
19:54:43.0175 0x0afc  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc      C:\Windows\System32\defragsvc.dll
19:54:43.0211 0x0afc  defragsvc - ok
19:54:43.0224 0x0afc  [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
19:54:43.0258 0x0afc  DfsC - ok
19:54:43.0274 0x0afc  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
19:54:43.0312 0x0afc  Dhcp - ok
19:54:43.0327 0x0afc  DigiRefresh - ok
19:54:43.0336 0x0afc  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
19:54:43.0372 0x0afc  discache - ok
19:54:43.0384 0x0afc  [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk            C:\Windows\system32\drivers\disk.sys
19:54:43.0397 0x0afc  Disk - ok
19:54:43.0406 0x0afc  [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc          C:\Windows\system32\drivers\dmvsc.sys
19:54:43.0428 0x0afc  dmvsc - ok
19:54:43.0448 0x0afc  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
19:54:43.0473 0x0afc  Dnscache - ok
19:54:43.0484 0x0afc  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc        C:\Windows\System32\dot3svc.dll
19:54:43.0526 0x0afc  dot3svc - ok
19:54:43.0546 0x0afc  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS            C:\Windows\system32\dps.dll
19:54:43.0583 0x0afc  DPS - ok
19:54:43.0595 0x0afc  [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
19:54:43.0610 0x0afc  drmkaud - ok
19:54:43.0643 0x0afc  [ 88612F1CE3BF42256913BF6E61C70D52, 7CF190F83FA8F15C33008EB381D3E345CEF37CBC046227DED26B36799EF4D9A7 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
19:54:43.0682 0x0afc  DXGKrnl - ok
19:54:43.0693 0x0afc  eaarkkjg - ok
19:54:43.0712 0x0afc  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost        C:\Windows\System32\eapsvc.dll
19:54:43.0745 0x0afc  EapHost - ok
19:54:43.0827 0x0afc  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv          C:\Windows\system32\drivers\evbda.sys
19:54:43.0940 0x0afc  ebdrv - ok
19:54:43.0951 0x0afc  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] EFS            C:\Windows\System32\lsass.exe
19:54:43.0972 0x0afc  EFS - ok
19:54:44.0012 0x0afc  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
19:54:44.0072 0x0afc  ehRecvr - ok
19:54:44.0086 0x0afc  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched        C:\Windows\ehome\ehsched.exe
19:54:44.0105 0x0afc  ehSched - ok
19:54:44.0127 0x0afc  [ A05FC7ECA0966EBB70E4D17B855A853B, 16A0C8138A3BBD8BE2658261131F9777940CFB1431018A10710E5C1A88AB70EA ] ElbyCDIO        C:\Windows\system32\Drivers\ElbyCDIO.sys
19:54:44.0138 0x0afc  ElbyCDIO - ok
19:54:44.0155 0x0afc  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor        C:\Windows\system32\drivers\elxstor.sys
19:54:44.0182 0x0afc  elxstor - ok
19:54:44.0189 0x0afc  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
19:54:44.0206 0x0afc  ErrDev - ok
19:54:44.0230 0x0afc  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem    C:\Windows\system32\es.dll
19:54:44.0275 0x0afc  EventSystem - ok
19:54:44.0286 0x0afc  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat          C:\Windows\system32\drivers\exfat.sys
19:54:44.0320 0x0afc  exfat - ok
19:54:44.0331 0x0afc  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
19:54:44.0370 0x0afc  fastfat - ok
19:54:44.0394 0x0afc  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax            C:\Windows\system32\fxssvc.exe
19:54:44.0438 0x0afc  Fax - ok
19:54:44.0449 0x0afc  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc            C:\Windows\system32\drivers\fdc.sys
19:54:44.0468 0x0afc  fdc - ok
19:54:44.0494 0x0afc  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost        C:\Windows\system32\fdPHost.dll
19:54:44.0530 0x0afc  fdPHost - ok
19:54:44.0542 0x0afc  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
19:54:44.0578 0x0afc  FDResPub - ok
19:54:44.0588 0x0afc  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
19:54:44.0600 0x0afc  FileInfo - ok
19:54:44.0605 0x0afc  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
19:54:44.0638 0x0afc  Filetrace - ok
19:54:44.0644 0x0afc  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
19:54:44.0656 0x0afc  flpydisk - ok
19:54:44.0668 0x0afc  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
19:54:44.0686 0x0afc  FltMgr - ok
19:54:44.0725 0x0afc  [ 76C196B109E4BFA50132EF50AF6A1C1B, 6452E96C3C9D35433890FFE72CDBBECBD1D0F56BBAD92DDC31551C1EE44B5860 ] FontCache      C:\Windows\system32\FntCache.dll
19:54:44.0781 0x0afc  FontCache - ok
19:54:44.0806 0x0afc  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:54:44.0818 0x0afc  FontCache3.0.0.0 - ok
19:54:44.0826 0x0afc  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
19:54:44.0838 0x0afc  FsDepends - ok
19:54:44.0853 0x0afc  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
19:54:44.0863 0x0afc  Fs_Rec - ok
19:54:44.0877 0x0afc  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
19:54:44.0894 0x0afc  fvevol - ok
19:54:44.0911 0x0afc  [ 444534CBA693DD23C1CC589681E01656, DF8ED7FFA66E0A88EBB58A491A177D8CEB35B08B0911D7A1F4B8865755DC27CE ] FWLANUSB        C:\Windows\system32\DRIVERS\fwlanusb.sys
19:54:44.0944 0x0afc  FWLANUSB - ok
19:54:44.0954 0x0afc  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
19:54:44.0968 0x0afc  gagp30kx - ok
19:54:44.0991 0x0afc  [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc          C:\Windows\System32\gpsvc.dll
19:54:45.0042 0x0afc  gpsvc - ok
19:54:45.0082 0x0afc  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:54:45.0093 0x0afc  gupdate - ok
19:54:45.0111 0x0afc  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:54:45.0121 0x0afc  gupdatem - ok
19:54:45.0152 0x0afc  [ D619BA1712B83D14149850E758B835AD, AD18807EC4DA6FA8C6846C1A0D914071FD59BD3273AFC103E5F2A7141F18C5F4 ] hardlock        C:\Windows\system32\drivers\hardlock.sys
19:54:45.0185 0x0afc  hardlock - ok
19:54:45.0193 0x0afc  hasplms - ok
19:54:45.0208 0x0afc  [ D5FA01185A7D5A65724FD87B34E53F5B, 4951DC34E0E0EA598C3599B619D5DEEF527D0B5D2C2C6392469865C6420B31C0 ] hcmon          C:\Windows\system32\drivers\hcmon.sys
19:54:45.0217 0x0afc  hcmon - ok
19:54:45.0225 0x0afc  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
19:54:45.0253 0x0afc  hcw85cir - ok
19:54:45.0278 0x0afc  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:54:45.0311 0x0afc  HdAudAddService - ok
19:54:45.0325 0x0afc  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
19:54:45.0345 0x0afc  HDAudBus - ok
19:54:45.0350 0x0afc  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt        C:\Windows\system32\drivers\HidBatt.sys
19:54:45.0368 0x0afc  HidBatt - ok
19:54:45.0377 0x0afc  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
19:54:45.0400 0x0afc  HidBth - ok
19:54:45.0414 0x0afc  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr          C:\Windows\system32\drivers\hidir.sys
19:54:45.0430 0x0afc  HidIr - ok
19:54:45.0437 0x0afc  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv        C:\Windows\System32\hidserv.dll
19:54:45.0471 0x0afc  hidserv - ok
19:54:45.0482 0x0afc  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\Windows\system32\drivers\hidusb.sys
19:54:45.0512 0x0afc  HidUsb - ok
19:54:45.0529 0x0afc  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
19:54:45.0566 0x0afc  hkmsvc - ok
19:54:45.0579 0x0afc  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
19:54:45.0605 0x0afc  HomeGroupListener - ok
19:54:45.0617 0x0afc  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
19:54:45.0640 0x0afc  HomeGroupProvider - ok
19:54:45.0651 0x0afc  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
19:54:45.0664 0x0afc  HpSAMD - ok
19:54:45.0692 0x0afc  [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
19:54:45.0749 0x0afc  HTTP - ok
19:54:45.0762 0x0afc  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
19:54:45.0771 0x0afc  hwpolicy - ok
19:54:45.0782 0x0afc  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
19:54:45.0798 0x0afc  i8042prt - ok
19:54:45.0837 0x0afc  [ 7548066DF68A8A1A56B043359F915F37, 6225DDE554E45858374CBD284A85A00F773089A667C08492187A637232B8BD9A ] IAANTMON        C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
19:54:45.0857 0x0afc  IAANTMON - ok
19:54:45.0877 0x0afc  [ 1D004CB1DA6323B1F55CAEF7F94B61D9, 8FFFB429BA46938724BBB87AB9B3EC77EA17C4B893BABDBDD38309F02963D405 ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
19:54:45.0893 0x0afc  iaStor - ok
19:54:45.0913 0x0afc  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
19:54:45.0936 0x0afc  iaStorV - ok
19:54:45.0973 0x0afc  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209AFC22A34D2BE99 ] idsvc          C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:54:46.0006 0x0afc  idsvc - ok
19:54:46.0017 0x0afc  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
19:54:46.0030 0x0afc  iirsp - ok
19:54:46.0059 0x0afc  [ FCD84C381E0140AF901E58D48882D26B, 76955FFC230C801E8ED890E32076075F04CD6E5EC79E594FDE6D23797A36B406 ] IKEEXT          C:\Windows\System32\ikeext.dll
19:54:46.0123 0x0afc  IKEEXT - ok
19:54:46.0140 0x0afc  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
19:54:46.0151 0x0afc  intelide - ok
19:54:46.0160 0x0afc  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
19:54:46.0179 0x0afc  intelppm - ok
19:54:46.0189 0x0afc  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
19:54:46.0224 0x0afc  IPBusEnum - ok
19:54:46.0233 0x0afc  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:54:46.0264 0x0afc  IpFilterDriver - ok
19:54:46.0285 0x0afc  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
19:54:46.0330 0x0afc  iphlpsvc - ok
19:54:46.0339 0x0afc  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
19:54:46.0359 0x0afc  IPMIDRV - ok
19:54:46.0369 0x0afc  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
19:54:46.0408 0x0afc  IPNAT - ok
19:54:46.0415 0x0afc  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
19:54:46.0434 0x0afc  IRENUM - ok
19:54:46.0440 0x0afc  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
19:54:46.0450 0x0afc  isapnp - ok
19:54:46.0467 0x0afc  [ D931D7309DEB2317035B07C9F9E6B0BD, 13AD84172ED8C6153F8A98499C01733B74E48464CE07D099508E38D409913ED3 ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
19:54:46.0483 0x0afc  iScsiPrt - ok
19:54:46.0492 0x0afc  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
19:54:46.0503 0x0afc  kbdclass - ok
19:54:46.0514 0x0afc  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
19:54:46.0533 0x0afc  kbdhid - ok
19:54:46.0540 0x0afc  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] KeyIso          C:\Windows\system32\lsass.exe
19:54:46.0552 0x0afc  KeyIso - ok
19:54:46.0563 0x0afc  [ 97A7070AEA4C058B6418519E869A63B4, 15345C2D6CA159BD498002974A0BD21CAB611124D85E3320248B47652AEF23C8 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
19:54:46.0574 0x0afc  KSecDD - ok
19:54:46.0588 0x0afc  [ 26C43A7C2862447EC59DEDA188D1DA07, 5363BF87E650FE2010ACA9417D6920FF4ED752256FF47732882E9B2BA1ED154B ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
19:54:46.0601 0x0afc  KSecPkg - ok
19:54:46.0608 0x0afc  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk        C:\Windows\system32\drivers\ksthunk.sys
19:54:46.0641 0x0afc  ksthunk - ok
19:54:46.0659 0x0afc  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm          C:\Windows\system32\msdtckrm.dll
19:54:46.0708 0x0afc  KtmRm - ok
19:54:46.0721 0x0afc  ktmujbzd - ok
19:54:46.0741 0x0afc  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\Windows\System32\srvsvc.dll
19:54:46.0781 0x0afc  LanmanServer - ok
19:54:46.0798 0x0afc  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:54:46.0829 0x0afc  LanmanWorkstation - ok
19:54:46.0854 0x0afc  [ FA529FB35694C24BF98A9EF67C1CD9D0, 7B3C587C38CF13D514140F0A55E58997D6071D1DEFD97E274E3F490660AC6075 ] LGBusEnum      C:\Windows\system32\drivers\LGBusEnum.sys
19:54:46.0863 0x0afc  LGBusEnum - ok
19:54:46.0879 0x0afc  [ 94B29CE153765E768F004FB3440BE2B0, E74C01CEBDA589CDDE35CBCBAA18700E3742DD3B48A90DB3630992467FFC5024 ] LGVirHid        C:\Windows\system32\drivers\LGVirHid.sys
19:54:46.0888 0x0afc  LGVirHid - ok
19:54:46.0899 0x0afc  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
19:54:46.0931 0x0afc  lltdio - ok
19:54:46.0948 0x0afc  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
19:54:46.0996 0x0afc  lltdsvc - ok
19:54:47.0004 0x0afc  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts        C:\Windows\System32\lmhsvc.dll
19:54:47.0037 0x0afc  lmhosts - ok
19:54:47.0052 0x0afc  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
19:54:47.0065 0x0afc  LSI_FC - ok
19:54:47.0075 0x0afc  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
19:54:47.0088 0x0afc  LSI_SAS - ok
19:54:47.0094 0x0afc  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
19:54:47.0106 0x0afc  LSI_SAS2 - ok
19:54:47.0113 0x0afc  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
19:54:47.0126 0x0afc  LSI_SCSI - ok
19:54:47.0133 0x0afc  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv          C:\Windows\system32\drivers\luafv.sys
19:54:47.0170 0x0afc  luafv - ok
19:54:47.0194 0x0afc  [ E2C6A3F80C1979B911408C17E3893371, 56FD7B743303BDC751C031372D7242C5CD25DAF927942D2D90F71033E7DE625C ] MAUSBFASTTRACK  C:\Windows\system32\DRIVERS\MAudioFastTrack.sys
19:54:47.0221 0x0afc  MAUSBFASTTRACK - ok
19:54:47.0237 0x0afc  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
19:54:47.0258 0x0afc  Mcx2Svc - ok
19:54:47.0267 0x0afc  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas        C:\Windows\system32\drivers\megasas.sys
19:54:47.0279 0x0afc  megasas - ok
19:54:47.0291 0x0afc  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
19:54:47.0308 0x0afc  MegaSR - ok
19:54:47.0319 0x0afc  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS          C:\Windows\system32\mmcss.dll
19:54:47.0353 0x0afc  MMCSS - ok
19:54:47.0362 0x0afc  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem          C:\Windows\system32\drivers\modem.sys
19:54:47.0397 0x0afc  Modem - ok
19:54:47.0409 0x0afc  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
19:54:47.0427 0x0afc  monitor - ok
19:54:47.0439 0x0afc  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
19:54:47.0449 0x0afc  mouclass - ok
19:54:47.0455 0x0afc  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
19:54:47.0473 0x0afc  mouhid - ok
19:54:47.0483 0x0afc  [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
19:54:47.0495 0x0afc  mountmgr - ok
19:54:47.0516 0x0afc  [ F8A10560B35C66F9DE212F03DAD5BFA7, 3ADCBC309A55494326EE8D152F92DFD11E1F97C897C8019BAB547E75D735FE92 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
19:54:47.0534 0x0afc  MpFilter - ok
19:54:47.0546 0x0afc  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
19:54:47.0559 0x0afc  mpio - ok
19:54:47.0578 0x0afc  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
19:54:47.0608 0x0afc  mpsdrv - ok
19:54:47.0634 0x0afc  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\Windows\system32\mpssvc.dll
19:54:47.0688 0x0afc  MpsSvc - ok
19:54:47.0697 0x0afc  [ DC722758B8261E1ABAFD31A3C0A66380, 88BBE073E2CCD1DAB4656DDC53D5161E8A91D035ADAC1465D0CEBA86F1BB6D9A ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
19:54:47.0717 0x0afc  MRxDAV - ok
19:54:47.0731 0x0afc  [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
19:54:47.0753 0x0afc  mrxsmb - ok
19:54:47.0771 0x0afc  [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD590580E8BAE3EFF ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:54:47.0793 0x0afc  mrxsmb10 - ok
19:54:47.0804 0x0afc  [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:54:47.0819 0x0afc  mrxsmb20 - ok
19:54:47.0829 0x0afc  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
19:54:47.0839 0x0afc  msahci - ok
19:54:47.0850 0x0afc  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
19:54:47.0863 0x0afc  msdsm - ok
19:54:47.0875 0x0afc  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC          C:\Windows\System32\msdtc.exe
19:54:47.0893 0x0afc  MSDTC - ok
19:54:47.0903 0x0afc  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
19:54:47.0939 0x0afc  Msfs - ok
19:54:47.0944 0x0afc  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
19:54:47.0978 0x0afc  mshidkmdf - ok
19:54:47.0984 0x0afc  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
19:54:47.0995 0x0afc  msisadrv - ok
19:54:48.0007 0x0afc  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
19:54:48.0047 0x0afc  MSiSCSI - ok
19:54:48.0050 0x0afc  msiserver - ok
19:54:48.0064 0x0afc  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
19:54:48.0106 0x0afc  MSKSSRV - ok
19:54:48.0145 0x0afc  [ E07DEC52FF801841BA9B6878A60304FB, A57A999F411559EA97C830C9FE0234578E2E98EDAF72F9949891F901B83B22A4 ] MsMpSvc        C:\Program Files\Microsoft Security Client\MsMpEng.exe
19:54:48.0157 0x0afc  MsMpSvc - ok
19:54:48.0167 0x0afc  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
19:54:48.0200 0x0afc  MSPCLOCK - ok
19:54:48.0209 0x0afc  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
19:54:48.0241 0x0afc  MSPQM - ok
19:54:48.0254 0x0afc  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
19:54:48.0276 0x0afc  MsRPC - ok
19:54:48.0285 0x0afc  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
19:54:48.0295 0x0afc  mssmbios - ok
19:54:48.0302 0x0afc  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
19:54:48.0334 0x0afc  MSTEE - ok
19:54:48.0342 0x0afc  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
19:54:48.0357 0x0afc  MTConfig - ok
19:54:48.0368 0x0afc  [ 03B7145C889603537E9FFEABB1AD1089, B3CD93B893D4A2370CBF382366C6F596372857F8711EF6FFF83BFE2B449F424E ] MTsensor        C:\Windows\system32\DRIVERS\ASACPI.sys
19:54:48.0387 0x0afc  MTsensor - ok
19:54:48.0394 0x0afc  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup            C:\Windows\system32\Drivers\mup.sys
19:54:48.0405 0x0afc  Mup - ok
19:54:48.0421 0x0afc  [ 1CA758BC0DEAF35D21ECAACC30427527, DAC9839E2602365C9B867C602A739450CF7F2C5F65A6539F310B55F9D3C8447E ] mv64xx          C:\Windows\system32\DRIVERS\mv64xx.sys
19:54:48.0435 0x0afc  mv64xx - ok
19:54:48.0457 0x0afc  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
19:54:48.0505 0x0afc  napagent - ok
19:54:48.0525 0x0afc  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
19:54:48.0555 0x0afc  NativeWifiP - ok
19:54:48.0597 0x0afc  [ 13AA2130F2A104DD775EAD0F0EE5417B, EBA07599FC2D10750CE6372EA6BA94EDDAFFF732223A1135F1971B958A6B57A2 ] NAUpdate        C:\Program Files (x86)\Nero\Update\NASvc.exe
19:54:48.0621 0x0afc  NAUpdate - ok
19:54:48.0660 0x0afc  [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS            C:\Windows\system32\drivers\ndis.sys
19:54:48.0696 0x0afc  NDIS - ok
19:54:48.0711 0x0afc  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
19:54:48.0744 0x0afc  NdisCap - ok
19:54:48.0782 0x0afc  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
19:54:48.0812 0x0afc  NdisTapi - ok
19:54:48.0835 0x0afc  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
19:54:48.0880 0x0afc  Ndisuio - ok
19:54:48.0922 0x0afc  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
19:54:48.0982 0x0afc  NdisWan - ok
19:54:48.0992 0x0afc  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
19:54:49.0022 0x0afc  NDProxy - ok
19:54:49.0041 0x0afc  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
19:54:49.0081 0x0afc  NetBIOS - ok
19:54:49.0090 0x0afc  [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
19:54:49.0126 0x0afc  NetBT - ok
19:54:49.0137 0x0afc  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] Netlogon        C:\Windows\system32\lsass.exe
19:54:49.0150 0x0afc  Netlogon - ok
19:54:49.0190 0x0afc  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
19:54:49.0270 0x0afc  Netman - ok
19:54:49.0397 0x0afc  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:54:49.0525 0x0afc  NetMsmqActivator - ok
19:54:49.0531 0x0afc  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:54:49.0541 0x0afc  NetPipeActivator - ok
19:54:49.0817 0x0afc  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
19:54:49.0870 0x0afc  netprofm - ok
19:54:49.0884 0x0afc  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:54:49.0894 0x0afc  NetTcpActivator - ok
19:54:49.0900 0x0afc  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:54:49.0911 0x0afc  NetTcpPortSharing - ok
19:54:49.0930 0x0afc  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
19:54:49.0946 0x0afc  nfrd960 - ok
19:54:49.0976 0x0afc  [ 162100E0BC8377710F9D170631921C03, B4FC4F6BCCA5A61EC86F9D10F4FE284E9393CE4599CE64BC8360202F0108B499 ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
19:54:49.0990 0x0afc  NisDrv - ok
19:54:50.0013 0x0afc  [ C6E15F2F95F9C0A6098D43510B604E52, 7B621846EC4DD066657536755455ADB016207A45D49FC5E5F1D50EAD2CCB6B13 ] NisSrv          C:\Program Files\Microsoft Security Client\NisSrv.exe
19:54:50.0041 0x0afc  NisSrv - ok
19:54:50.0057 0x0afc  [ 8AD77806D336673F270DB31645267293, E23F324913554A23CD043DD27D4305AF62F48C0561A0FC7B7811E55B74B1BE79 ] NlaSvc          C:\Windows\System32\nlasvc.dll
19:54:50.0089 0x0afc  NlaSvc - ok
19:54:50.0097 0x0afc  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
19:54:50.0134 0x0afc  Npfs - ok
19:54:50.0150 0x0afc  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi            C:\Windows\system32\nsisvc.dll
19:54:50.0196 0x0afc  nsi - ok
19:54:50.0211 0x0afc  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
19:54:50.0252 0x0afc  nsiproxy - ok
19:54:50.0326 0x0afc  [ B98F8C6E31CD07B2E6F71F7F648E38C0, 2FEA100B80680FBBF644CB6763738804155DF1E94A6542CAE2B2786D770D554E ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
19:54:50.0377 0x0afc  Ntfs - ok
19:54:50.0392 0x0afc  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
19:54:50.0432 0x0afc  Null - ok
19:54:50.0456 0x0afc  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
19:54:50.0474 0x0afc  nvraid - ok
19:54:50.0496 0x0afc  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
19:54:50.0515 0x0afc  nvstor - ok
19:54:50.0540 0x0afc  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
19:54:50.0559 0x0afc  nv_agp - ok
19:54:50.0575 0x0afc  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
19:54:50.0601 0x0afc  ohci1394 - ok
19:54:50.0632 0x0afc  [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose            C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:54:50.0648 0x0afc  ose - ok
19:54:50.0812 0x0afc  [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc        C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
19:54:50.0964 0x0afc  osppsvc - ok
19:54:51.0005 0x0afc  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
19:54:51.0069 0x0afc  p2pimsvc - ok
19:54:51.0092 0x0afc  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
19:54:51.0126 0x0afc  p2psvc - ok
19:54:51.0147 0x0afc  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport        C:\Windows\system32\drivers\parport.sys
19:54:51.0176 0x0afc  Parport - ok
19:54:51.0198 0x0afc  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr        C:\Windows\system32\drivers\partmgr.sys
19:54:51.0217 0x0afc  partmgr - ok
19:54:51.0237 0x0afc  [ 3AEAA8B561E63452C655DC0584922257, 04C072969B58657602EB0C21CEDF24FCEE14E61B90A0F758F93925EF2C9FC32D ] PcaSvc          C:\Windows\System32\pcasvc.dll
19:54:51.0266 0x0afc  PcaSvc - ok
19:54:51.0281 0x0afc  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci            C:\Windows\system32\drivers\pci.sys
19:54:51.0299 0x0afc  pci - ok
19:54:51.0324 0x0afc  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
19:54:51.0340 0x0afc  pciide - ok
19:54:51.0356 0x0afc  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
19:54:51.0374 0x0afc  pcmcia - ok
19:54:51.0399 0x0afc  [ 3A68080572B81577791A7B19BB880DA9, 9F64FAB46BF6B5AB46EF77A7077295587F4A6C4851D5EB04D9EC8ECC4C7C67D1 ] PCTCore        C:\Windows\system32\drivers\PCTCore64.sys
19:54:51.0415 0x0afc  PCTCore - ok
19:54:51.0428 0x0afc  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw            C:\Windows\system32\drivers\pcw.sys
19:54:51.0440 0x0afc  pcw - ok
19:54:51.0463 0x0afc  [ 68769C3356B3BE5D1C732C97B9A80D6E, FB2D61145980A2899D1B7729184C54070315B0E63C9A22400A76CCD39E00029C ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
19:54:51.0527 0x0afc  PEAUTH - ok
19:54:51.0572 0x0afc  [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc    C:\Windows\system32\peerdistsvc.dll
19:54:51.0636 0x0afc  PeerDistSvc - ok
19:54:51.0685 0x0afc  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
19:54:51.0704 0x0afc  PerfHost - ok
19:54:51.0744 0x0afc  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla            C:\Windows\system32\pla.dll
19:54:51.0815 0x0afc  pla - ok
19:54:51.0841 0x0afc  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
19:54:51.0870 0x0afc  PlugPlay - ok
19:54:51.0889 0x0afc  PnkBstrA - ok
19:54:51.0902 0x0afc  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
19:54:51.0920 0x0afc  PNRPAutoReg - ok
19:54:51.0929 0x0afc  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
19:54:51.0948 0x0afc  PNRPsvc - ok
19:54:51.0969 0x0afc  [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
19:54:52.0019 0x0afc  PolicyAgent - ok
19:54:52.0035 0x0afc  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power          C:\Windows\system32\umpo.dll
19:54:52.0071 0x0afc  Power - ok
19:54:52.0082 0x0afc  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
19:54:52.0121 0x0afc  PptpMiniport - ok
19:54:52.0130 0x0afc  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor      C:\Windows\system32\drivers\processr.sys
19:54:52.0148 0x0afc  Processor - ok
19:54:52.0164 0x0afc  [ 53E83F1F6CF9D62F32801CF66D8352A8, 1225FED810BE8E0729EEAE5B340035CCBB9BACD3EF247834400F9B72D05ACE48 ] ProfSvc        C:\Windows\system32\profsvc.dll
19:54:52.0188 0x0afc  ProfSvc - ok
19:54:52.0196 0x0afc  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] ProtectedStorage C:\Windows\system32\lsass.exe
19:54:52.0208 0x0afc  ProtectedStorage - ok
19:54:52.0223 0x0afc  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
19:54:52.0259 0x0afc  Psched - ok
19:54:52.0262 0x0afc  ptqllcii - ok
19:54:52.0304 0x0afc  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
19:54:52.0354 0x0afc  ql2300 - ok
19:54:52.0369 0x0afc  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
19:54:52.0382 0x0afc  ql40xx - ok
19:54:52.0393 0x0afc  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE          C:\Windows\system32\qwave.dll
19:54:52.0416 0x0afc  QWAVE - ok
19:54:52.0421 0x0afc  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
19:54:52.0444 0x0afc  QWAVEdrv - ok
19:54:52.0452 0x0afc  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
19:54:52.0486 0x0afc  RasAcd - ok
19:54:52.0501 0x0afc  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
19:54:52.0531 0x0afc  RasAgileVpn - ok
19:54:52.0540 0x0afc  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto        C:\Windows\System32\rasauto.dll
19:54:52.0579 0x0afc  RasAuto - ok
19:54:52.0587 0x0afc  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
19:54:52.0624 0x0afc  Rasl2tp - ok
19:54:52.0639 0x0afc  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
19:54:52.0681 0x0afc  RasMan - ok
19:54:52.0687 0x0afc  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
19:54:52.0720 0x0afc  RasPppoe - ok
19:54:52.0726 0x0afc  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
19:54:52.0760 0x0afc  RasSstp - ok
19:54:52.0773 0x0afc  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
19:54:52.0814 0x0afc  rdbss - ok
19:54:52.0822 0x0afc  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
19:54:52.0841 0x0afc  rdpbus - ok
19:54:52.0855 0x0afc  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
19:54:52.0884 0x0afc  RDPCDD - ok
19:54:52.0896 0x0afc  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR          C:\Windows\system32\drivers\rdpdr.sys
19:54:52.0916 0x0afc  RDPDR - ok
19:54:52.0927 0x0afc  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
19:54:52.0961 0x0afc  RDPENCDD - ok
19:54:52.0971 0x0afc  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
19:54:53.0008 0x0afc  RDPREFMP - ok
19:54:53.0024 0x0afc  [ E61608AA35E98999AF9AAEEEA6114B0A, F754CDE89DC96786D2A3C4D19EE2AEF1008E634E4DE3C0CBF927436DE90C04A6 ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
19:54:53.0055 0x0afc  RDPWD - ok
19:54:53.0072 0x0afc  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
19:54:53.0090 0x0afc  rdyboost - ok
19:54:53.0101 0x0afc  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
19:54:53.0135 0x0afc  RemoteAccess - ok
19:54:53.0150 0x0afc  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
19:54:53.0187 0x0afc  RemoteRegistry - ok
19:54:53.0189 0x0afc  rlffuili - ok
19:54:53.0198 0x0afc  rmtofanc - ok
19:54:53.0206 0x0afc  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
19:54:53.0242 0x0afc  RpcEptMapper - ok
19:54:53.0247 0x0afc  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
19:54:53.0267 0x0afc  RpcLocator - ok
19:54:53.0289 0x0afc  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs          C:\Windows\system32\rpcss.dll
19:54:53.0328 0x0afc  RpcSs - ok
19:54:53.0340 0x0afc  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
19:54:53.0373 0x0afc  rspndr - ok
19:54:53.0398 0x0afc  [ ABCB5A38A0D85BDF69B7877E1AD1EED5, 44DF1A92E8FA53677A04C46088B0AD49F1F6A090820BE550A514C4FBFD91444D ] RTL8167        C:\Windows\system32\DRIVERS\Rt64win7.sys
19:54:53.0438 0x0afc  RTL8167 - ok
19:54:53.0453 0x0afc  [ AE4FDA46C0A644DC9FB2545BDF4CB496, 35C911D94B887E64395EC3F493971E5D36176A3632D2F9FB7B4D5A886E9464F1 ] rzdaendpt      C:\Windows\system32\DRIVERS\rzdaendpt.sys
19:54:53.0476 0x0afc  rzdaendpt - ok
19:54:53.0503 0x0afc  [ D28AB8D41CA4633EA69F2897F0B45565, B8FF66583530787419D04EEA75A49B61FB184523E652C720B1EF1F1695864F0A ] rzudd          C:\Windows\system32\DRIVERS\rzudd.sys
19:54:53.0528 0x0afc  rzudd - ok
19:54:53.0551 0x0afc  [ 4CE040A51CFA6614F46419CB5F5B7BB6, 91DD7B91287800E96EF0DB9DD69B3315629BFA690592C2D0A3E596386A84CD95 ] rzvkeyboard    C:\Windows\system32\DRIVERS\rzvkeyboard.sys
19:54:53.0573 0x0afc  rzvkeyboard - ok
19:54:53.0579 0x0afc  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap          C:\Windows\system32\drivers\vms3cap.sys
19:54:53.0598 0x0afc  s3cap - ok
19:54:53.0601 0x0afc  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] SamSs          C:\Windows\system32\lsass.exe
19:54:53.0614 0x0afc  SamSs - ok
19:54:53.0664 0x0afc  [ 53E618640032FF0511901551D7F77424, 10679F1B0FBF2B0C4B8D53BACB238119EC5E48A4C1A9EE73F121BCBC9A1EEFA6 ] SbieDrv        C:\Program Files\Sandboxie\SbieDrv.sys
19:54:53.0677 0x0afc  SbieDrv - ok
19:54:53.0716 0x0afc  [ DD78D286FF9032D9E0938F815928C2FD, C85B65CC5B56DFE6D700BA98B607B934C7447C6AF8B59E98E4E4855FA83BDD51 ] SbieSvc        C:\Program Files\Sandboxie\SbieSvc.exe
19:54:53.0730 0x0afc  SbieSvc - ok
19:54:53.0742 0x0afc  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
19:54:53.0756 0x0afc  sbp2port - ok
19:54:53.0819 0x0afc  [ 794D4B48DFB6E999537C7C3947863463, 93DA8AA20D6B02A3360E7F56150F126E75266E9372E6409D42B89DA588EF49C3 ] SBSDWSCService  C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
19:54:53.0858 0x0afc  SBSDWSCService - ok
19:54:53.0875 0x0afc  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
19:54:53.0911 0x0afc  SCardSvr - ok
19:54:53.0918 0x0afc  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
19:54:53.0949 0x0afc  scfilter - ok
19:54:53.0980 0x0afc  [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule        C:\Windows\system32\schedsvc.dll
19:54:54.0041 0x0afc  Schedule - ok
19:54:54.0054 0x0afc  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc    C:\Windows\System32\certprop.dll
19:54:54.0083 0x0afc  SCPolicySvc - ok
19:54:54.0116 0x0afc  [ EE088B31F5EB673A62E7E0D09B0007B0, 686B697F554E02ACADD5E44F707EF1E7DD87539FF8156F4FF67533E5D26BC160 ] sdAuxService    C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe
19:54:54.0135 0x0afc  sdAuxService - ok
19:54:54.0173 0x0afc  [ 747FFE0A5A34C349A363BE97C632B7C4, 7AC092581CCED5080DA8ED3B7243B0DC99B648493ACDE7EB02461DB0DDB1C0B0 ] sdCoreService  C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe
19:54:54.0213 0x0afc  sdCoreService - ok
19:54:54.0231 0x0afc  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
19:54:54.0254 0x0afc  SDRSVC - ok
19:54:54.0268 0x0afc  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
19:54:54.0304 0x0afc  secdrv - ok
19:54:54.0316 0x0afc  [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon        C:\Windows\system32\seclogon.dll
19:54:54.0348 0x0afc  seclogon - ok
19:54:54.0356 0x0afc  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\system32\sens.dll
19:54:54.0389 0x0afc  SENS - ok
19:54:54.0397 0x0afc  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
19:54:54.0413 0x0afc  SensrSvc - ok
19:54:54.0428 0x0afc  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum        C:\Windows\system32\drivers\serenum.sys
19:54:54.0446 0x0afc  Serenum - ok
19:54:54.0457 0x0afc  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\drivers\serial.sys
19:54:54.0475 0x0afc  Serial - ok
19:54:54.0489 0x0afc  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\drivers\sermouse.sys
19:54:54.0510 0x0afc  sermouse - ok
19:54:54.0522 0x0afc  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
19:54:54.0556 0x0afc  SessionEnv - ok
19:54:54.0563 0x0afc  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
19:54:54.0580 0x0afc  sffdisk - ok
19:54:54.0583 0x0afc  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
19:54:54.0599 0x0afc  sffp_mmc - ok
19:54:54.0603 0x0afc  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
19:54:54.0622 0x0afc  sffp_sd - ok
19:54:54.0631 0x0afc  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
19:54:54.0647 0x0afc  sfloppy - ok
19:54:54.0693 0x0afc  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
19:54:54.0740 0x0afc  SharedAccess - ok
19:54:54.0759 0x0afc  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:54:54.0804 0x0afc  ShellHWDetection - ok
19:54:54.0813 0x0afc  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
19:54:54.0825 0x0afc  SiSRaid2 - ok
19:54:54.0831 0x0afc  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
19:54:54.0844 0x0afc  SiSRaid4 - ok
19:54:54.0867 0x0afc  [ F07AF60B152221472FBDB2FECEC4896D, A18FDCE8462A48429E249C44F0E49F844F2E3A4B5215349DE104F34D935EF983 ] SkypeUpdate    C:\Program Files (x86)\Skype\Updater\Updater.exe
19:54:54.0879 0x0afc  SkypeUpdate - ok
19:54:54.0893 0x0afc  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
19:54:54.0929 0x0afc  Smb - ok
19:54:54.0951 0x0afc  [ B2C19AE46C5A109679B4FB38058DF05A, 93DD4D356650C51348795653286E6C627FF5F7071F2787DF7C50B75A3120E308 ] snapman        C:\Windows\system32\DRIVERS\snapman.sys
19:54:54.0965 0x0afc  snapman - ok
19:54:54.0983 0x0afc  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
19:54:55.0003 0x0afc  SNMPTRAP - ok
19:54:55.0007 0x0afc  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr          C:\Windows\system32\drivers\spldr.sys
19:54:55.0017 0x0afc  spldr - ok
19:54:55.0047 0x0afc  [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler        C:\Windows\System32\spoolsv.exe
19:54:55.0089 0x0afc  Spooler - ok
19:54:55.0175 0x0afc  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
19:54:55.0311 0x0afc  sppsvc - ok
19:54:55.0324 0x0afc  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify    C:\Windows\system32\sppuinotify.dll
19:54:55.0356 0x0afc  sppuinotify - ok
19:54:55.0374 0x0afc  [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv            C:\Windows\system32\DRIVERS\srv.sys
19:54:55.0408 0x0afc  srv - ok
19:54:55.0423 0x0afc  [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
19:54:55.0455 0x0afc  srv2 - ok
19:54:55.0468 0x0afc  [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
19:54:55.0485 0x0afc  srvnet - ok
19:54:55.0499 0x0afc  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
19:54:55.0535 0x0afc  SSDPSRV - ok
19:54:55.0546 0x0afc  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc        C:\Windows\system32\sstpsvc.dll
19:54:55.0577 0x0afc  SstpSvc - ok
19:54:55.0597 0x0afc  Steam Client Service - ok
19:54:55.0605 0x0afc  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
19:54:55.0617 0x0afc  stexstor - ok
19:54:55.0641 0x0afc  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\Windows\System32\wiaservc.dll
19:54:55.0678 0x0afc  stisvc - ok
19:54:55.0688 0x0afc  [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt        C:\Windows\system32\drivers\vmstorfl.sys
19:54:55.0699 0x0afc  storflt - ok
19:54:55.0707 0x0afc  [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc        C:\Windows\system32\storsvc.dll
19:54:55.0727 0x0afc  StorSvc - ok
19:54:55.0736 0x0afc  [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc        C:\Windows\system32\drivers\storvsc.sys
19:54:55.0748 0x0afc  storvsc - ok
19:54:55.0754 0x0afc  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
19:54:55.0765 0x0afc  swenum - ok
19:54:55.0786 0x0afc  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv          C:\Windows\System32\swprv.dll
19:54:55.0833 0x0afc  swprv - ok
19:54:55.0876 0x0afc  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain        C:\Windows\system32\sysmain.dll
19:54:55.0952 0x0afc  SysMain - ok
19:54:55.0962 0x0afc  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:54:55.0982 0x0afc  TabletInputService - ok
19:54:55.0995 0x0afc  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv        C:\Windows\System32\tapisrv.dll
19:54:56.0041 0x0afc  TapiSrv - ok
19:54:56.0049 0x0afc  [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS            C:\Windows\System32\tbssvc.dll
19:54:56.0081 0x0afc  TBS - ok
19:54:56.0135 0x0afc  [ DB74544B75566C974815E79A62433F29, 035EBF70FDA28CF2B6C1FD7EE0ED703DB4B647064B5DBA6E258878A19B1BCCA4 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
19:54:56.0199 0x0afc  Tcpip - ok
19:54:56.0257 0x0afc  [ DB74544B75566C974815E79A62433F29, 035EBF70FDA28CF2B6C1FD7EE0ED703DB4B647064B5DBA6E258878A19B1BCCA4 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
19:54:56.0306 0x0afc  TCPIP6 - ok
19:54:56.0324 0x0afc  [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
19:54:56.0336 0x0afc  tcpipreg - ok
19:54:56.0346 0x0afc  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
19:54:56.0369 0x0afc  TDPIPE - ok
19:54:56.0411 0x0afc  [ 99527D49EE0A96FC25537C61B270A372, 519E23F86EC86349F92C4A88DBD19C097AEE0A6E152776B32B45D293ED14946B ] tdrpman273      C:\Windows\system32\DRIVERS\tdrpm273.sys
19:54:56.0452 0x0afc  tdrpman273 - ok
19:54:56.0467 0x0afc  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
19:54:56.0484 0x0afc  TDTCP - ok
19:54:56.0494 0x0afc  [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719C48B08FAFA9661 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
19:54:56.0525 0x0afc  tdx - ok
19:54:56.0535 0x0afc  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
19:54:56.0546 0x0afc  TermDD - ok
19:54:56.0575 0x0afc  [ 2E648163254233755035B46DD7B89123, 6FA0D07CE18A3A69D82EE49D875F141E39406E92C34EAC76AC4EB052E6EBCBCD ] TermService    C:\Windows\System32\termsrv.dll
19:54:56.0630 0x0afc  TermService - ok
19:54:56.0640 0x0afc  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
19:54:56.0658 0x0afc  Themes - ok
19:54:56.0670 0x0afc  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER    C:\Windows\system32\mmcss.dll
19:54:56.0701 0x0afc  THREADORDER - ok
19:54:56.0730 0x0afc  [ 2C1CAF5563548A15515EAB07D2A069C6, 863405BAC725C7DC6CC86613365A099A2370781018996DD3E74981565AD0DDF5 ] timounter      C:\Windows\system32\DRIVERS\timntr.sys
19:54:56.0762 0x0afc  timounter - ok
19:54:56.0779 0x0afc  [ C676B0F52F2B6483AFB88F79CABB011E, 8F10C7C91B47F87C3E29785BDACA49831857849F688C34A1F097C9D6593003AA ] Tpkd            C:\Windows\system32\drivers\Tpkd.sys
19:54:56.0886 0x0afc  Tpkd - ok
19:54:56.0899 0x0afc  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
19:54:56.0935 0x0afc  TrkWks - ok
19:54:56.0954 0x0afc  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:54:56.0989 0x0afc  TrustedInstaller - ok
19:54:57.0002 0x0afc  [ 4CE278FC9671BA81A138D70823FCAA09, CBE501436696E32A3701B9F377B823AC36647B6626595F76CC63E2396AD7D300 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
19:54:57.0034 0x0afc  tssecsrv - ok
19:54:57.0049 0x0afc  [ D11C783E3EF9A3C52C0EBE83CC5000E9, A136C355D4C8945729163D15801364A614E23217B15F9313C85BA45BB71A74EB ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
19:54:57.0074 0x0afc  TsUsbFlt - ok
19:54:57.0083 0x0afc  [ 9CC2CCAE8A84820EAECB886D477CBCB8, 50D8AA2D7477A6618A0C31BB4D1C4887B457865FB1105E2E7B984EEFA337B804 ] TsUsbGD        C:\Windows\system32\drivers\TsUsbGD.sys
19:54:57.0101 0x0afc  TsUsbGD - ok
19:54:57.0118 0x0afc  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
19:54:57.0153 0x0afc  tunnel - ok
19:54:57.0163 0x0afc  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
19:54:57.0175 0x0afc  uagp35 - ok
19:54:57.0177 0x0afc  ubqgdokm - ok
19:54:57.0192 0x0afc  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
19:54:57.0234 0x0afc  udfs - ok
19:54:57.0268 0x0afc  [ 215462AE7E6A897D675E84DD1E3B3B56, 7F45E77F971E9AC3E1402663EF5F6A2D496F9BB758C8E50D2D329E834E20B7D8 ] ufad-ws60      C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe
19:54:57.0282 0x0afc  ufad-ws60 - ok
19:54:57.0289 0x0afc  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect      C:\Windows\system32\UI0Detect.exe
19:54:57.0310 0x0afc  UI0Detect - ok
19:54:57.0329 0x0afc  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
19:54:57.0341 0x0afc  uliagpkx - ok
19:54:57.0354 0x0afc  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
19:54:57.0371 0x0afc  umbus - ok
19:54:57.0387 0x0afc  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\drivers\umpass.sys
19:54:57.0404 0x0afc  UmPass - ok
19:54:57.0416 0x0afc  [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService    C:\Windows\System32\umrdp.dll
19:54:57.0437 0x0afc  UmRdpService - ok
19:54:57.0451 0x0afc  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
19:54:57.0498 0x0afc  upnphost - ok
19:54:57.0516 0x0afc  [ B0435098C81D04CAFFF80DDB746CD3A2, A17B207740382E38729571F0B0BC98FF874E856A7C7CE9EB930328A2AD88F52A ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
19:54:57.0552 0x0afc  usbaudio - ok
19:54:57.0568 0x0afc  [ 6F1A3157A1C89435352CEB543CDB359C, 325B46220779C5FE3B6F19FF794474837FAB9675D9C98ACB68CCE47B1CFE5F12 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
19:54:57.0587 0x0afc  usbccgp - ok
19:54:57.0602 0x0afc  [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir          C:\Windows\system32\drivers\usbcir.sys
19:54:57.0638 0x0afc  usbcir - ok
19:54:57.0656 0x0afc  [ C025055FE7B87701EB042095DF1A2D7B, D7B34B6C2C5BD3C8141895AC21BB637EA5E3C4F7A85EEF4C4C36E6BB2045A3D9 ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
19:54:57.0671 0x0afc  usbehci - ok
19:54:57.0690 0x0afc  [ 287C6C9410B111B68B52CA298F7B8C24, 98900C08FE662A00DF8B37837B2BEBF9ACB7989C387AF36B2109B05A4F462D4E ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
19:54:57.0718 0x0afc  usbhub - ok
19:54:57.0725 0x0afc  [ 9840FC418B4CBD632D3D0A667A725C31, 776D86A032DCA2842EF7AADB35473193CA80547223EFAA7F110F296C377077B0 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
19:54:57.0744 0x0afc  usbohci - ok
19:54:57.0750 0x0afc  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\drivers\usbprint.sys
19:54:57.0771 0x0afc  usbprint - ok
19:54:57.0784 0x0afc  [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:54:57.0816 0x0afc  USBSTOR - ok
19:54:57.0829 0x0afc  [ 62069A34518BCF9C1FD9E74B3F6DB7CD, C58E21424718729324B285BEE1C96551540FCC3FD650B2D10895EBA48D981E25 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
19:54:57.0847 0x0afc  usbuhci - ok
19:54:57.0856 0x0afc  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms          C:\Windows\System32\uxsms.dll
19:54:57.0887 0x0afc  UxSms - ok
19:54:57.0895 0x0afc  varehocl - ok
19:54:57.0903 0x0afc  [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF8B1207F81B284D ] VaultSvc        C:\Windows\system32\lsass.exe
19:54:57.0915 0x0afc  VaultSvc - ok
19:54:57.0929 0x0afc  [ FD911873C0BB6945FA38C16E9A2B58F9, EF8C833321449A6E8B671890F2EBC82ABC276B890D274AADDB626D763EE98964 ] VClone          C:\Windows\system32\DRIVERS\VClone.sys
19:54:57.0948 0x0afc  VClone - ok
19:54:57.0955 0x0afc  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
19:54:57.0965 0x0afc  vdrvroot - ok
19:54:57.0986 0x0afc  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds            C:\Windows\System32\vds.exe
19:54:58.0036 0x0afc  vds - ok
19:54:58.0043 0x0afc  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
19:54:58.0058 0x0afc  vga - ok
19:54:58.0067 0x0afc  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave        C:\Windows\System32\drivers\vga.sys
19:54:58.0099 0x0afc  VgaSave - ok
19:54:58.0110 0x0afc  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
19:54:58.0128 0x0afc  vhdmp - ok
19:54:58.0142 0x0afc  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\drivers\viaide.sys
19:54:58.0153 0x0afc  viaide - ok
19:54:58.0167 0x0afc  [ 3B59BB6D10CF969DBE4DB93D9EAD7FB4, 8BD4648AAD460F276C79AF81D1479E781E62D292F3318D39B53703403E57E52F ] VKbms          C:\Windows\system32\DRIVERS\VKbms.sys
19:54:58.0185 0x0afc  VKbms - ok
19:54:58.0202 0x0afc  [ 7AC6239C65DADE55DEFD573B98616C3F, 39EC745BFA38C70DA80DC121CB24C12ED9AF9AFDCFE38FCD853CFA53D6E538A8 ] VMAuthdService  C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
19:54:58.0213 0x0afc  VMAuthdService - ok
19:54:58.0224 0x0afc  [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus          C:\Windows\system32\drivers\vmbus.sys
19:54:58.0239 0x0afc  vmbus - ok
19:54:58.0246 0x0afc  [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
19:54:58.0262 0x0afc  VMBusHID - ok
19:54:58.0275 0x0afc  [ 312AEC23A85424543AF898A59209B479, 7423643ACA900824CCC44B6347AD81E027A9C2A42C12C7F7FD9B89F3D5B5F654 ] vmci            C:\Windows\system32\drivers\vmci.sys
19:54:58.0284 0x0afc  vmci - ok
19:54:58.0303 0x0afc  [ FFC30CAEEB2FC5FEE8568CFF74EDEAED, 56DA6F766906A160C326AAA901E0B50E5CA8B054BDE1B95DD6EA14BBB5286E65 ] vmkbd          C:\Windows\system32\drivers\VMkbd.sys
19:54:58.0311 0x0afc  vmkbd - ok
19:54:58.0326 0x0afc  [ 9D54F1339E78C95BF3D9939EBCB66378, 99E29225443049B35E633BB7E709AC89B555F6A1EC5FAE075825A74F088FDC9A ] VMnetAdapter    C:\Windows\system32\DRIVERS\vmnetadapter.sys
19:54:58.0334 0x0afc  VMnetAdapter - ok
19:54:58.0352 0x0afc  [ FB54EF3AA613D2832FD3812E7CB2FC75, 2D638EFE2E457C4F9B50AF49C7A0B0DA82A98FF10049C2E5DABE32B7E0BA2B23 ] VMnetBridge    C:\Windows\system32\DRIVERS\vmnetbridge.sys
19:54:58.0362 0x0afc  VMnetBridge - ok
19:54:58.0370 0x0afc  VMnetDHCP - ok
19:54:58.0379 0x0afc  [ 56D547BFC3F1619FA82EC9EF5D24E802, D82DDC1E15F87E3E5809991CEFD81CE24BC8C9249108F36F7B854CEDBDB56FFC ] VMnetuserif    C:\Windows\system32\drivers\vmnetuserif.sys
19:54:58.0387 0x0afc  VMnetuserif - ok
19:54:58.0414 0x0afc  [ 19368F7C4DC6EF444B826249FC8A0E30, 6F26729EA0BD651FCCC8657BF7C40174AC06926373B467BC3BD3ED352421D2FA ] VMUSBArbService C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
19:54:58.0438 0x0afc  VMUSBArbService - ok
19:54:58.0442 0x0afc  VMware NAT Service - ok
19:54:58.0462 0x0afc  [ 62CD5A87FDE14701506D4E0DD8F13D2E, C449E52039BAF7B262BEE4D1389239B196965A0A08E002441CE56B89EF6688E8 ] vmx86          C:\Windows\system32\drivers\vmx86.sys
19:54:58.0471 0x0afc  vmx86 - ok
19:54:58.0479 0x0afc  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
19:54:58.0490 0x0afc  volmgr - ok
19:54:58.0503 0x0afc  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
19:54:58.0522 0x0afc  volmgrx - ok
19:54:58.0534 0x0afc  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap        C:\Windows\system32\drivers\volsnap.sys
19:54:58.0552 0x0afc  volsnap - ok
19:54:58.0564 0x0afc  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
19:54:58.0578 0x0afc  vsmraid - ok
19:54:58.0617 0x0afc  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS            C:\Windows\system32\vssvc.exe
19:54:58.0695 0x0afc  VSS - ok
19:54:58.0715 0x0afc  [ E61C910E2DDF4797C1B1F9239636E894, BEC555AB66BD0D33BBC9ABFF7F3955F7D0821383549C8BAC1944B63A85F897E8 ] vstor2-ws60    C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys
19:54:58.0724 0x0afc  vstor2-ws60 - ok
19:54:58.0732 0x0afc  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
19:54:58.0752 0x0afc  vwifibus - ok
19:54:58.0768 0x0afc  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time        C:\Windows\system32\w32time.dll
19:54:58.0812 0x0afc  W32Time - ok
19:54:58.0824 0x0afc  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
19:54:58.0838 0x0afc  WacomPen - ok
19:54:58.0845 0x0afc  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
19:54:58.0879 0x0afc  WANARP - ok
19:54:58.0883 0x0afc  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
19:54:58.0912 0x0afc  Wanarpv6 - ok
19:54:58.0951 0x0afc  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\Windows\system32\wbengine.exe
19:54:59.0014 0x0afc  wbengine - ok
19:54:59.0028 0x0afc  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
19:54:59.0051 0x0afc  WbioSrvc - ok
19:54:59.0065 0x0afc  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
19:54:59.0097 0x0afc  wcncsvc - ok
19:54:59.0104 0x0afc  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:54:59.0128 0x0afc  WcsPlugInService - ok
19:54:59.0140 0x0afc  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\drivers\wd.sys
19:54:59.0151 0x0afc  Wd - ok
19:54:59.0179 0x0afc  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
19:54:59.0210 0x0afc  Wdf01000 - ok
19:54:59.0231 0x0afc  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost  C:\Windows\system32\wdi.dll
19:54:59.0304 0x0afc  WdiServiceHost - ok
19:54:59.0309 0x0afc  [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost  C:\Windows\system32\wdi.dll
19:54:59.0327 0x0afc  WdiSystemHost - ok
19:54:59.0337 0x0afc  [ 3DB6D04E1C64272F8B14EB8BC4616280, 9138642B1C19F895D4ECFD930160C80FBF15813CE63BBF4C899842C300FD3026 ] WebClient      C:\Windows\System32\webclnt.dll
19:54:59.0366 0x0afc  WebClient - ok
19:54:59.0377 0x0afc  [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc          C:\Windows\system32\wecsvc.dll
19:54:59.0423 0x0afc  Wecsvc - ok
19:54:59.0432 0x0afc  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
19:54:59.0464 0x0afc  wercplsupport - ok
19:54:59.0474 0x0afc  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
19:54:59.0507 0x0afc  WerSvc - ok
19:54:59.0516 0x0afc  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
19:54:59.0544 0x0afc  WfpLwf - ok
19:54:59.0555 0x0afc  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
19:54:59.0566 0x0afc  WIMMount - ok
19:54:59.0575 0x0afc  WinDefend - ok
19:54:59.0582 0x0afc  WinHttpAutoProxySvc - ok
19:54:59.0613 0x0afc  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
19:54:59.0648 0x0afc  Winmgmt - ok
19:54:59.0698 0x0afc  [ BCB1310604AA415C4508708975B3931E, 9D943F086D454345153A0DD426B4432532A44FD87950386B186E1CAD2AC70565 ] WinRM          C:\Windows\system32\WsmSvc.dll
19:54:59.0786 0x0afc  WinRM - ok
19:54:59.0820 0x0afc  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
19:54:59.0839 0x0afc  WinUsb - ok
19:54:59.0861 0x0afc  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc        C:\Windows\System32\wlansvc.dll
19:54:59.0905 0x0afc  Wlansvc - ok
19:54:59.0979 0x0afc  [ 98F138897EF4246381D197CB81846D62, A9FA88475AFBB8883297708608EC7C1AC29F229C3299A84D557172604813A18C ] wlidsvc        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
19:55:00.0046 0x0afc  wlidsvc - ok
19:55:00.0057 0x0afc  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi        C:\Windows\system32\DRIVERS\wmiacpi.sys
19:55:00.0074 0x0afc  WmiAcpi - ok
19:55:00.0091 0x0afc  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
19:55:00.0115 0x0afc  wmiApSrv - ok
19:55:00.0127 0x0afc  WMPNetworkSvc - ok
19:55:00.0143 0x0afc  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
19:55:00.0158 0x0afc  WPCSvc - ok
19:55:00.0167 0x0afc  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
19:55:00.0185 0x0afc  WPDBusEnum - ok
19:55:00.0190 0x0afc  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
19:55:00.0221 0x0afc  ws2ifsl - ok
19:55:00.0230 0x0afc  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\system32\wscsvc.dll
19:55:00.0254 0x0afc  wscsvc - ok
19:55:00.0257 0x0afc  WSearch - ok
19:55:00.0324 0x0afc  [ D9EF901DCA379CFE914E9FA13B73B4C4, 3BE9693B7B2AFEE23D72AF5DA211379724D752F0EC18ACB7D3DE3DDFC5AE0004 ] wuauserv        C:\Windows\system32\wuaueng.dll
19:55:00.0398 0x0afc  wuauserv - ok
19:55:00.0417 0x0afc  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
19:55:00.0440 0x0afc  WudfPf - ok
19:55:00.0453 0x0afc  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
19:55:00.0478 0x0afc  WUDFRd - ok
19:55:00.0488 0x0afc  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
19:55:00.0507 0x0afc  wudfsvc - ok
19:55:00.0521 0x0afc  [ FE90B750AB808FB9DD8FBB428B5FF83B, 3F8F592EC813BE292D305A87C5BA852F8BC3D7CE610612D9871F209A17326AA8 ] WwanSvc        C:\Windows\System32\wwansvc.dll
19:55:00.0550 0x0afc  WwanSvc - ok
19:55:00.0569 0x0afc  ================ Scan global ===============================
19:55:00.0580 0x0afc  [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll
19:55:00.0596 0x0afc  [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll
19:55:00.0620 0x0afc  [ 88EDD0B34EED542745931E581AD21A32, DC2B93E1CEF5B0BCEE08D72669BB0F3AD0E8E6E75BDC08858407ED92F6FFA031 ] C:\Windows\system32\winsrv.dll
19:55:00.0635 0x0afc  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
19:55:00.0650 0x0afc  [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe
19:55:00.0656 0x0afc  [ Global ] - ok
19:55:00.0657 0x0afc  ================ Scan MBR ==================================
19:55:00.0661 0x0afc  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2
19:55:01.0079 0x0afc  \Device\Harddisk2\DR2 - ok
19:55:01.0105 0x0afc  [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
19:55:01.0211 0x0afc  \Device\Harddisk0\DR0 - ok
19:55:01.0213 0x0afc  [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
19:55:01.0616 0x0afc  \Device\Harddisk1\DR1 - ok
19:55:01.0621 0x0afc  [ DDAE9D649DB12F6AFF24483F2C298989 ] \Device\Harddisk3\DR3
19:55:02.0627 0x0afc  \Device\Harddisk3\DR3 - ok
19:55:02.0628 0x0afc  ================ Scan VBR ==================================
19:55:02.0637 0x0afc  [ 648FC44956DAA6F6D2A8D210255768CC ] \Device\Harddisk2\DR2\Partition1
19:55:02.0638 0x0afc  \Device\Harddisk2\DR2\Partition1 - ok
19:55:02.0641 0x0afc  [ EE9BD2983364C91FDF0753BA7BC6215D ] \Device\Harddisk2\DR2\Partition2
19:55:02.0642 0x0afc  \Device\Harddisk2\DR2\Partition2 - ok
19:55:02.0644 0x0afc  [ 3541107D5B9039B36E7DAD4CDEDD327F ] \Device\Harddisk0\DR0\Partition1
19:55:02.0646 0x0afc  \Device\Harddisk0\DR0\Partition1 - ok
19:55:02.0648 0x0afc  [ A59F8BF144837A8162BE68CC117745D5 ] \Device\Harddisk1\DR1\Partition1
19:55:02.0650 0x0afc  \Device\Harddisk1\DR1\Partition1 - ok
19:55:02.0660 0x0afc  [ 7698342B4FE72C6E6A589CB4E9B83B22 ] \Device\Harddisk3\DR3\Partition1
19:55:02.0662 0x0afc  \Device\Harddisk3\DR3\Partition1 - ok
19:55:02.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:03.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:04.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:05.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:06.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:07.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:08.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:09.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:10.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:11.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:12.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:13.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:14.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:15.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:16.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:17.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:18.0663 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:19.0664 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:20.0664 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:21.0664 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:22.0664 0x0afc  Waiting for KSN requests completion. In queue: 109
19:55:23.0673 0x0afc  AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.2.223.0 ), 0x61000 ( enabled : updated )
19:55:23.0721 0x0afc  Win FW state via NFP2: enabled
19:55:26.0223 0x0afc  ============================================================
19:55:26.0223 0x0afc  Scan finished
19:55:26.0223 0x0afc  ============================================================
19:55:26.0229 0x0634  Detected object count: 0
19:55:26.0229 0x0634  Actual detected object count: 0

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2013
Ran by ***** at 2013-10-11 19:58:41 Run:1
Running from C:\Users\*****\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\68380184.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\68380184.sys => ""="Driver"
AlternateDataStreams: C:\ProgramData\TEMP:A8ADE5D8
AlternateDataStreams: C:\Users\*****\Lokale Einstellungen:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local\Anwendungsdaten:jBiCmiIbIlyrVCVyNieZi
AlternateDataStreams: C:\Users\*****\AppData\Local\Temporary Internet Files:fFNjQ1aWCMRRdy6DQwtMgGo1
AlternateDataStreams: C:\Users\*****\AppData\Local\Temporary Internet Files:IhXHys7HsOvYZe9lmWQJui
C:\Users\*****\AppData\Local\temp\{5FE98B5E-EA8F-4487-AFA3-D1EA5ADCA351}.exe
2013-09-10 20:17 - 2012-10-27 00:40 - 00000000 ___HD C:\Users\*****\AppData\Local\iBY3HyQdk0QdJ
2013-10-08 01:52 - 2013-10-08 01:52 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
S1 ajlvsasx; \??\C:\Windows\system32\drivers\ajlvsasx.sys [x]
S1 crtjnuyc; \??\C:\Windows\system32\drivers\crtjnuyc.sys [x]
S1 eaarkkjg; \??\C:\Windows\system32\drivers\eaarkkjg.sys [x]
S1 ktmujbzd; \??\C:\Windows\system32\drivers\ktmujbzd.sys [x]
S1 ptqllcii; \??\C:\Windows\system32\drivers\ptqllcii.sys [x]
S1 rlffuili; \??\C:\Windows\system32\drivers\rlffuili.sys [x]
S1 rmtofanc; \??\C:\Windows\system32\drivers\rmtofanc.sys [x]
S1 ubqgdokm; \??\C:\Windows\system32\drivers\ubqgdokm.sys [x]
S1 varehocl; \??\C:\Windows\system32\drivers\varehocl.sys [x]
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109727&tt=010812_nich_3112_8&babsrc=SP_ss&mntrId=9e1017a8000000000000e0cb4e3e3e0f
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=109727&tt=010812_nich_3112_8&babsrc=SP_ss&mntrId=9e1017a8000000000000e0cb4e3e3e0f
       
*****************

HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\68380184.sys => Key not found.
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\68380184.sys => Key not found.
"C:\ProgramData\TEMP" => ":A8ADE5D8" ADS not found.
"C:\Users\*****\Lokale Einstellungen" => ":jBiCmiIbIlyrVCVyNieZi" ADS not found.
C:\Users\*****\AppData\Local => ":jBiCmiIbIlyrVCVyNieZi" ADS removed successfully.
"C:\Users\*****\AppData\Local\Anwendungsdaten" => ":jBiCmiIbIlyrVCVyNieZi" ADS not found.
"C:\Users\*****\AppData\Local\Temporary Internet Files" => ":fFNjQ1aWCMRRdy6DQwtMgGo1" ADS not found.
"C:\Users\*****\AppData\Local\Temporary Internet Files" => ":IhXHys7HsOvYZe9lmWQJui" ADS not found.
"C:\Users\*****\AppData\Local\temp\{5FE98B5E-EA8F-4487-AFA3-D1EA5ADCA351}.exe" => File/Directory not found.
C:\Users\*****\AppData\Local\iBY3HyQdk0QdJ => Moved successfully.

"C:\Windows\SysWOW64\%APPDATA%" directory move:

Could not move "C:\Windows\SysWOW64\%APPDATA%\Microsoft\Windows\IETldCache\index.dat" => Scheduled to move on reboot.
Could not move "C:\Windows\SysWOW64\%APPDATA%" directory. => Scheduled to move on reboot.

ajlvsasx => Service not found.
crtjnuyc => Service not found.
eaarkkjg => Service not found.
ktmujbzd => Service not found.
ptqllcii => Service not found.
rlffuili => Service not found.
rmtofanc => Service not found.
ubqgdokm => Service not found.
varehocl => Service not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully.
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found.

=========== Result of Scheduled Files to move ===========

"C:\Windows\SysWOW64\%APPDATA%\Microsoft\Windows\IETldCache\index.dat" => File could not move.
"C:\Windows\SysWOW64\%APPDATA%" => Directory could not move.

==== End of Fixlog ====

Code:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.10.11.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Administrator :: *****-PC [Administrator]

11.10.2013 20:06:44
mbam-log-2013-10-11 (20-06-44).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 229416
Laufzeit: 3 Minute(n), 55 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

Info: Nach dem Scannen mit Malwarebytes Anti-Malware ist mir aufgefallen dass Spybot bislang noch aktiv war. Da waren auch "Prozesse blockiert". Soll ich das mal deinstallieren? Habe es vor dem Eset-Scan deaktiviert.

Bislang hat ESET 2 Infizierte Dateien gefunden: "a variant of Win32/Kryptik.BMDL trojan Win 32/Rootkit.Whistler.A trojan". Gescannt wurden 309000 Dateien, bin derzeit bei 66% ... . Ist das normal, dass das so lange dauert?

aharonov 11.10.2013 22:46

Hallo,

Zitat:

Ist das normal, dass das so lange dauert?
Ja, das ist völlig normal.
Wenn die Festplatte gut gefüllt ist, ist eine Scanzeit von mehreren Stunden üblich.
ESET ist dafür sehr gründlich und scannt zum Abschluss nochmals auch die hintersten Ecken durch. Nicht alles, was da zum Vorschein kommt, stellt noch eine aktive Bedrohung dar. (Der Rootkit.Whistler-Fund beispielsweise ist nur noch entweder in der TDSSKiller-Quarantäne oder im MBR-Dump, den Combofix erstellt hat - also nicht mehr aktiv.)

Lou Schalter 11.10.2013 23:15

O.k., dann sind wir ja beruhigt hier. Hatten ein Sixpack Bier und nen Film am Start, nachdem das Bier alle und der Film vorüber war, ESET aber noch lang keine Anstalten gemacht hatte alle bzw. vorüber zu sein warf das einige Fragen auf :dummguck:.

Jetzt ist es gerade bei 92%, dürfte also demnächst beendet sein. *jippie*

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=dd2cf20c96daec47bb4c1bc028c5767b
# engine=15452
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-10-11 10:13:02
# local_time=2013-10-12 12:13:02 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 6760671 133159432 0 0
# scanned=573738
# found=2
# cleaned=0
# scan_time=14258
sh=FAA080341857F582DC02F086A503680F6AB7CE49 ft=0 fh=0000000000000000 vn="Win32/Rootkit.Whistler.A trojan" ac=I fn="C:\Qoobox\Quarantine\MBR_HardDisk0.mbr"
sh=CAABC402F6D8B97E1917E17C6501BA44834DA173 ft=1 fh=b3b1f4995b1c8cbf vn="a variant of Win32/Kryptik.BMDL trojan" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\4wcl7hv.plz.vir"


aharonov 11.10.2013 23:17

Sehr gut, das sind in der Tat nur noch zwei inaktive Funde, welche sich in Combofix-Quarantäne-Ordnern befinden.
Dann fehlen nur noch die frischen FRST-Logs (Schritt 5).

Lou Schalter 11.10.2013 23:18


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by ***** (ATTENTION: The logged in user is not administrator) on *****-PC on 12-10-2013 00:15:31
Running from C:\Users\*****\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Avid Technology, Inc.) C:\Windows\System32\M-AudioTaskBarIcon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
() C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Razer Inc.) C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
() C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [358944 2010-12-11] (Acronis)
HKLM\...\Run: [M-Audio Taskbar Icon] - C:\Windows\system32\M-AudioTaskBarIcon.exe [798728 2010-12-07] (Avid Technology, Inc.)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [5889816 2011-12-07] (Logitech Inc.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation)
HKLM\...\Runonce: [MSPCLOCK] - rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
HKLM\...\Runonce: [MSPQM] - rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
HKLM\...\Runonce: [MSKSSRV] - rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
HKLM\...\Runonce: [MSTEE.CxTransform] - rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install
HKLM\...\Runonce: [MSTEE.Splitter] - rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install
HKLM\...\Runonce: [WDM_DRMKAUD] - rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD.Interface.Install
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKCU\...\Run: [Google Update] - C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-21] (Google Inc.)
HKCU\...\Run: [SandboxieControl] - C:\Program Files\Sandboxie\SbieCtrl.exe [759384 2013-07-08] (Sandboxie Holdings, LLC)
MountPoints2: {3aaca747-f6ae-11e2-81cf-005056c00008} - G:\Startme.exe
MountPoints2: {7561e1d3-6444-11e1-9b58-00040ecc87e4} - H:\SETUP.EXE
MountPoints2: {f27fbd11-63df-11e1-a2c1-e0cb4e3e42d0} - E:\pushinst.exe
HKLM-x32\...\Run: [SoundMAXPnP] - C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1310720 2009-06-05] (Analog Devices, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [vmware-tray] - C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [129648 2011-03-26] (VMware, Inc.)
HKLM-x32\...\Run: [DigidesignMMERefresh] - C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe [77824 2010-06-24] (Avid Technology, Inc..)
HKLM-x32\...\Run: [DeathAdder] - C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe [248320 2011-03-21] ()
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x70AC4DD3F3F7CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: PC Tools Browser Guard BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll ()
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: af0.Adblock.BHO - {90EFF544-3981-4d46-85C9-C0361D0931D6} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: No Name - {C4415769-1588-4AD6-9624-B2E69DB78D1A} -  No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -  No File
Toolbar: HKLM-x32 - PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll ()
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [321464] (PC Tools Research Pty Ltd.)
Winsock: Catalog9 02 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [321464] (PC Tools Research Pty Ltd.)
Winsock: Catalog9 03 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [321464] (PC Tools Research Pty Ltd.)
Winsock: Catalog9 14 C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll [346736] (VMware, Inc.)
Winsock: Catalog9 15 C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll [346736] (VMware, Inc.)
Winsock: Catalog9 16 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll [321464] (PC Tools Research Pty Ltd.)
Winsock: Catalog9-x64 01 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [233912] (PC Tools Research Pty Ltd.)
Winsock: Catalog9-x64 02 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [233912] (PC Tools Research Pty Ltd.)
Winsock: Catalog9-x64 03 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [233912] (PC Tools Research Pty Ltd.)
Winsock: Catalog9-x64 14 C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll [446576] (VMware, Inc.)
Winsock: Catalog9-x64 15 C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll [446576] (VMware, Inc.)
Winsock: Catalog9-x64 16 C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll [233912] (PC Tools Research Pty Ltd.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage: hxxp://www.google.de/
CHR Extension: (Google Docs) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Adblock Plus) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6_0
CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.10_0
CHR Extension: (Ghostery) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\5.0.0_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1
CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

==================== Services (Whitelisted) =================

R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2009-06-05] (Andrea Electronics Corporation)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
R2 Browser Defender Update Service; C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe [112592 2010-01-22] ()
R2 DigiRefresh; C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe [77824 2010-06-24] (Avid Technology, Inc..)
R2 hasplms; C:\Windows\system32\hasplms.exe [4941768 2012-06-28] (SafeNet Inc.)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-09-15] ()
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [183896 2013-07-08] (Sandboxie Holdings, LLC)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 sdAuxService; C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe [365280 2009-12-09] (PC Tools)
S4 sdCoreService; C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe [1141712 2010-01-18] (PC Tools)
S3 ufad-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe [191024 2010-08-19] (VMware, Inc.)

==================== Drivers (Whitelisted) ====================

S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin)
S3 CYUSB; C:\Windows\System32\Drivers\CYUSB.sys [47104 2009-08-10] (Cypress Semiconductor)
S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [321536 2011-09-28] (SafeNet Inc.)
R3 MAUSBFASTTRACK; C:\Windows\System32\DRIVERS\MAudioFastTrack.sys [187912 2010-12-07] (Avid Technology, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R0 mv64xx; C:\Windows\System32\DRIVERS\mv64xx.sys [331816 2009-09-16] (Marvell Semiconductor, Inc.)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
R0 PCTCore; C:\Windows\System32\drivers\PCTCore64.sys [218056 2009-09-23] (PC Tools)
S3 rzdaendpt; C:\Windows\System32\DRIVERS\rzdaendpt.sys [25600 2012-11-07] (Razer USA Ltd)
S3 rzvkeyboard; C:\Windows\System32\DRIVERS\rzvkeyboard.sys [23040 2012-11-07] (Razer USA Ltd)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [199384 2013-07-08] (Sandboxie Holdings, LLC)
R2 vstor2-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.)
R2 vstor2-ws60; C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys [32816 2010-08-19] (VMware, Inc.)
S1 ajlvsasx; \??\C:\Windows\system32\drivers\ajlvsasx.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S1 crtjnuyc; \??\C:\Windows\system32\drivers\crtjnuyc.sys [x]
S1 eaarkkjg; \??\C:\Windows\system32\drivers\eaarkkjg.sys [x]
S1 ktmujbzd; \??\C:\Windows\system32\drivers\ktmujbzd.sys [x]
S1 ptqllcii; \??\C:\Windows\system32\drivers\ptqllcii.sys [x]
S1 rlffuili; \??\C:\Windows\system32\drivers\rlffuili.sys [x]
S1 rmtofanc; \??\C:\Windows\system32\drivers\rmtofanc.sys [x]
S1 ubqgdokm; \??\C:\Windows\system32\drivers\ubqgdokm.sys [x]
S1 varehocl; \??\C:\Windows\system32\drivers\varehocl.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-11 20:13 - 2013-10-11 20:13 - 02347384 _____ (ESET) C:\Users\*****\Downloads\esetsmartinstaller_enu.exe
2013-10-11 20:13 - 2013-10-11 20:13 - 00000000 ____D C:\Program Files (x86)\ESET
2013-10-11 20:04 - 2013-10-11 20:04 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Malwarebytes
2013-10-11 20:03 - 2013-10-11 20:03 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-11 20:03 - 2013-10-11 20:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-11 20:03 - 2013-10-11 20:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-11 20:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-11 20:02 - 2013-10-11 20:03 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\*****\Desktop\mbam-setup-1.75.0.1300.exe
2013-10-10 23:38 - 2013-09-22 16:42 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 23:38 - 2013-09-22 16:36 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 23:38 - 2013-09-22 16:33 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-10-10 23:38 - 2013-09-22 16:33 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 23:38 - 2013-09-22 16:30 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-10 23:38 - 2013-09-22 16:27 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 23:38 - 2013-09-22 16:23 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-10-10 23:38 - 2013-09-22 16:19 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 23:38 - 2013-09-22 16:16 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-10 23:38 - 2013-09-22 16:15 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 23:38 - 2013-09-22 16:07 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 23:38 - 2013-09-22 12:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-10-10 23:38 - 2013-09-22 12:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-10 23:38 - 2013-09-22 12:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-10 23:38 - 2013-09-22 12:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-10-10 23:38 - 2013-09-22 12:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-10-10 23:38 - 2013-09-22 12:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-10-10 23:38 - 2013-09-22 12:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-10 23:38 - 2013-09-22 12:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-10 23:38 - 2013-09-22 12:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-10-10 23:38 - 2013-09-22 11:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-10 23:37 - 2013-09-22 17:43 - 17833984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 23:37 - 2013-09-22 17:01 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 23:37 - 2013-09-22 16:22 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 23:37 - 2013-09-22 16:21 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-10-10 23:37 - 2013-09-22 16:19 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 23:37 - 2013-09-22 12:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-10 23:37 - 2013-09-22 12:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-10 23:37 - 2013-09-22 12:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-10 23:37 - 2013-09-22 12:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-10 23:37 - 2013-09-22 12:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-10 23:37 - 2013-09-22 12:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-10 23:33 - 2013-10-10 23:33 - 00000000 ___RD C:\Sandbox
2013-10-10 23:32 - 2013-10-11 01:07 - 00001596 _____ C:\Windows\Sandboxie.ini
2013-10-10 23:32 - 2013-10-10 23:32 - 00000920 _____ C:\Users\*****\Desktop\Sandboxed Web Browser.lnk
2013-10-10 23:32 - 2013-10-10 23:32 - 00000000 ____D C:\Program Files\Sandboxie
2013-10-10 23:31 - 2013-10-10 23:31 - 02590808 _____ (Sandboxie Holdings, LLC) C:\Users\*****\Downloads\Sandboxie404Install.exe
2013-10-10 23:31 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 23:31 - 2013-08-27 11:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-10-10 23:31 - 2013-08-27 11:01 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-10-10 23:31 - 2013-08-27 10:21 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-10-10 23:31 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 23:31 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 23:31 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 23:31 - 2013-07-12 12:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2013-10-10 23:31 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 23:31 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-10 23:31 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 23:31 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 23:31 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 23:31 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 23:31 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 23:31 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 23:31 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 23:31 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-10 23:31 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-10 23:31 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-10 23:31 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 23:31 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-10 23:31 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 23:30 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 22:55 - 2013-10-10 22:55 - 00034103 _____ C:\Users\*****\Desktop\Addition.txt
2013-10-10 22:53 - 2013-10-10 22:54 - 01954124 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-10-10 22:10 - 2013-10-10 22:10 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-10-10 21:13 - 2013-10-10 21:20 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\*****\Desktop\TDSSKiller.exe
2013-10-10 20:15 - 2013-10-10 20:15 - 00000000 ____D C:\_OTL
2013-10-10 08:13 - 2013-10-10 08:13 - 00023010 _____ C:\ComboFix.txt
2013-10-10 07:51 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-10 07:51 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-10 07:51 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-10 07:51 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-10 07:50 - 2013-10-10 08:13 - 00000000 ____D C:\Qoobox
2013-10-10 07:49 - 2013-10-10 08:10 - 00000000 ____D C:\Windows\erdnt
2013-10-08 20:40 - 2013-10-08 20:46 - 00010918 _____ C:\Windows\IE10_main.log
2013-10-08 20:31 - 2013-10-11 20:00 - 00000000 ____D C:\FRST
2013-10-08 02:03 - 2013-10-10 23:33 - 00000000 ____D C:\Windows\system32\MRT
2013-10-08 01:52 - 2013-10-08 01:52 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2013-10-08 01:51 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-10-08 01:51 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-10-08 01:51 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-10-08 01:51 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-10-08 01:51 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-10-08 01:51 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-10-08 01:51 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-10-08 01:51 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-10-08 01:51 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-10-08 01:51 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-10-08 01:50 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-10-08 01:50 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-08 01:50 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-08 01:50 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-10-08 01:50 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-08 01:50 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-10-08 01:50 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-10-08 01:50 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-10-08 01:50 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-10-08 01:50 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-08 01:50 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-08 01:50 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-08 01:50 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-10-08 01:50 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-10-08 01:50 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-10-08 01:50 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-10-08 01:50 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-08 01:50 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-08 01:50 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-08 01:50 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-08 01:50 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-10-08 01:50 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-10-08 01:50 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-10-08 01:50 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-10-08 01:50 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-10-08 01:50 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-10-08 01:50 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-10-08 01:50 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-10-08 01:50 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-10-08 01:50 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-10-08 01:50 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-08 01:50 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-10-08 01:47 - 2013-10-08 01:49 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2013-10-08 01:47 - 2013-10-08 01:47 - 00001085 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2013-10-08 01:47 - 2013-10-08 01:47 - 00000000 ____D C:\ProgramData\Licenses
2013-10-08 01:47 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTDFMT.DLL
2013-10-08 01:40 - 2013-10-08 01:40 - 00000000 ____D C:\ProgramData\Oracle
2013-10-08 01:40 - 2013-10-08 01:39 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-10-08 01:40 - 2013-10-08 01:39 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 01:39 - 2013-10-08 01:39 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-08 01:24 - 2013-10-08 01:25 - 00000000 ____D C:\AdwCleaner
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Razer
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\ATI
2013-10-08 01:02 - 2013-10-10 08:02 - 00000000 ____D C:\ProgramData\VMware
2013-09-29 13:43 - 2013-09-29 14:04 - 00000000 ____D C:\Users\*****\AppData\Local\SCE
2013-09-24 22:31 - 2013-09-24 23:56 - 00000000 ____D C:\Users\*****\Desktop\Vermietung
2013-09-17 02:36 - 2013-09-17 02:36 - 00000000 _____ C:\Users\*****\Desktop\Attack on Titan 25.txt
2013-09-13 21:12 - 2013-09-13 21:12 - 00138240 _____ C:\Users\*****\Desktop\Finanzierungsplan.xls

==================== One Month Modified Files and Folders =======

2013-10-12 00:09 - 2012-07-21 17:25 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-11 23:45 - 2012-11-12 13:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-11 23:37 - 2012-08-05 17:00 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000UA.job
2013-10-11 20:37 - 2012-08-05 17:00 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000Core.job
2013-10-11 20:13 - 2013-10-11 20:13 - 02347384 _____ (ESET) C:\Users\*****\Downloads\esetsmartinstaller_enu.exe
2013-10-11 20:13 - 2013-10-11 20:13 - 00000000 ____D C:\Program Files (x86)\ESET
2013-10-11 20:09 - 2012-07-21 17:25 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-11 20:07 - 2009-07-14 06:45 - 00026080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-11 20:07 - 2009-07-14 06:45 - 00026080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-11 20:04 - 2013-10-11 20:04 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Malwarebytes
2013-10-11 20:04 - 2011-04-12 09:26 - 00714112 _____ C:\Windows\system32\perfh007.dat
2013-10-11 20:04 - 2011-04-12 09:26 - 00155624 _____ C:\Windows\system32\perfc007.dat
2013-10-11 20:04 - 2009-07-14 07:13 - 01661196 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-11 20:03 - 2013-10-11 20:03 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-11 20:03 - 2013-10-11 20:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-11 20:03 - 2013-10-11 20:03 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-11 20:03 - 2013-10-11 20:02 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\*****\Desktop\mbam-setup-1.75.0.1300.exe
2013-10-11 20:03 - 2012-03-01 23:01 - 01550909 _____ C:\Windows\WindowsUpdate.log
2013-10-11 20:00 - 2013-10-08 20:31 - 00000000 ____D C:\FRST
2013-10-11 20:00 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-11 20:00 - 2009-07-14 06:51 - 00089521 _____ C:\Windows\setupact.log
2013-10-11 19:52 - 2010-11-21 05:47 - 00056812 _____ C:\Windows\PFRO.log
2013-10-11 01:07 - 2013-10-10 23:32 - 00001596 _____ C:\Windows\Sandboxie.ini
2013-10-11 01:02 - 2012-12-24 01:47 - 00000000 ____D C:\Program Files (x86)\Lightworks
2013-10-11 01:02 - 2012-03-05 17:25 - 00000000 ____D C:\Program Files (x86)\Steam
2013-10-11 00:59 - 2012-03-29 06:32 - 00000000 ____D C:\Users\*****\Documents\Outlook-Dateien
2013-10-10 23:45 - 2009-07-14 06:45 - 00427632 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-10 23:37 - 2012-03-02 00:19 - 01638154 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-10 23:33 - 2013-10-10 23:33 - 00000000 ___RD C:\Sandbox
2013-10-10 23:33 - 2013-10-08 02:03 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 23:32 - 2013-10-10 23:32 - 00000920 _____ C:\Users\*****\Desktop\Sandboxed Web Browser.lnk
2013-10-10 23:32 - 2013-10-10 23:32 - 00000000 ____D C:\Program Files\Sandboxie
2013-10-10 23:32 - 2012-03-01 23:15 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-10 23:31 - 2013-10-10 23:31 - 02590808 _____ (Sandboxie Holdings, LLC) C:\Users\*****\Downloads\Sandboxie404Install.exe
2013-10-10 22:55 - 2013-10-10 22:55 - 00034103 _____ C:\Users\*****\Desktop\Addition.txt
2013-10-10 22:54 - 2013-10-10 22:53 - 01954124 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2013-10-10 22:10 - 2013-10-10 22:10 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-10-10 21:20 - 2013-10-10 21:13 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\*****\Desktop\TDSSKiller.exe
2013-10-10 20:15 - 2013-10-10 20:15 - 00000000 ____D C:\_OTL
2013-10-10 20:15 - 2012-03-01 22:59 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-10 08:13 - 2013-10-10 08:13 - 00023010 _____ C:\ComboFix.txt
2013-10-10 08:13 - 2013-10-10 07:50 - 00000000 ____D C:\Qoobox
2013-10-10 08:13 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-10-10 08:10 - 2013-10-10 07:49 - 00000000 ____D C:\Windows\erdnt
2013-10-10 08:08 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-10-10 08:02 - 2013-10-08 01:02 - 00000000 ____D C:\ProgramData\VMware
2013-10-10 07:59 - 2012-03-01 22:59 - 00000000 ____D C:\Users\*****
2013-10-10 07:45 - 2012-11-12 14:45 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-10-10 07:45 - 2012-11-12 13:57 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-10 07:45 - 2012-03-01 23:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 05:04 - 2012-08-12 16:19 - 00000000 ____D C:\Users\Administrator
2013-10-09 03:20 - 2012-03-01 22:59 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-10-08 20:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-10-08 20:46 - 2013-10-08 20:40 - 00010918 _____ C:\Windows\IE10_main.log
2013-10-08 02:03 - 2012-03-02 11:43 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-08 01:52 - 2013-10-08 01:52 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2013-10-08 01:49 - 2013-10-08 01:47 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2013-10-08 01:47 - 2013-10-08 01:47 - 00001085 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2013-10-08 01:47 - 2013-10-08 01:47 - 00000000 ____D C:\ProgramData\Licenses
2013-10-08 01:40 - 2013-10-08 01:40 - 00000000 ____D C:\ProgramData\Oracle
2013-10-08 01:39 - 2013-10-08 01:40 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-10-08 01:39 - 2013-10-08 01:40 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-08 01:39 - 2013-10-08 01:39 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 01:39 - 2013-10-08 01:39 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-08 01:39 - 2012-03-04 18:42 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-10-08 01:25 - 2013-10-08 01:24 - 00000000 ____D C:\AdwCleaner
2013-10-08 01:25 - 2012-03-03 20:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
2013-10-08 01:18 - 2013-10-08 01:18 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Razer
2013-10-08 01:15 - 2013-10-08 01:15 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\ATI
2013-10-08 00:29 - 2013-02-28 22:38 - 00000000 ____D C:\Users\*****\AppData\Roaming\Skype
2013-10-08 00:28 - 2012-03-03 23:13 - 00000000 ____D C:\Users\*****\AppData\Roaming\TS3Client
2013-10-05 01:47 - 2012-03-03 22:38 - 00000000 ____D C:\Users\*****\AppData\Local\PMB Files
2013-10-05 01:47 - 2012-03-03 22:38 - 00000000 ____D C:\ProgramData\PMB Files
2013-10-03 02:09 - 2013-05-19 14:41 - 00000000 ____D C:\Program Files (x86)\War Thunder
2013-10-01 11:47 - 2012-03-03 21:42 - 00000000 ____D C:\Users\*****\AppData\Local\TeamSpeak 3 Client
2013-09-29 14:04 - 2013-09-29 13:43 - 00000000 ____D C:\Users\*****\AppData\Local\SCE
2013-09-29 14:04 - 2013-01-07 03:26 - 00000000 ____D C:\Users\*****\Documents\My Games
2013-09-29 13:42 - 2012-03-05 18:10 - 00155388 _____ C:\Windows\DirectX.log
2013-09-24 23:56 - 2013-09-24 22:31 - 00000000 ____D C:\Users\*****\Desktop\Vermietung
2013-09-22 17:43 - 2013-10-10 23:37 - 17833984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-22 17:01 - 2013-10-10 23:37 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-22 16:42 - 2013-10-10 23:38 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-22 16:36 - 2013-10-10 23:38 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-22 16:33 - 2013-10-10 23:38 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-22 16:33 - 2013-10-10 23:38 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-22 16:30 - 2013-10-10 23:38 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-22 16:27 - 2013-10-10 23:38 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-22 16:23 - 2013-10-10 23:38 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-22 16:22 - 2013-10-10 23:37 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-22 16:21 - 2013-10-10 23:37 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-22 16:19 - 2013-10-10 23:38 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-22 16:19 - 2013-10-10 23:37 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-22 16:16 - 2013-10-10 23:38 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-22 16:15 - 2013-10-10 23:38 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-22 16:07 - 2013-10-10 23:38 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-22 12:29 - 2013-10-10 23:37 - 12336128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-22 12:22 - 2013-10-10 23:37 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-22 12:22 - 2013-10-10 23:37 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-22 12:14 - 2013-10-10 23:38 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-09-22 12:13 - 2013-10-10 23:38 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-22 12:13 - 2013-10-10 23:38 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-22 12:12 - 2013-10-10 23:38 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-09-22 12:09 - 2013-10-10 23:37 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-22 12:08 - 2013-10-10 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-09-22 12:07 - 2013-10-10 23:37 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-22 12:06 - 2013-10-10 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-09-22 12:05 - 2013-10-10 23:38 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-22 12:03 - 2013-10-10 23:38 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-22 12:03 - 2013-10-10 23:38 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-09-22 12:03 - 2013-10-10 23:37 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-22 11:59 - 2013-10-10 23:38 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-17 02:36 - 2013-09-17 02:36 - 00000000 _____ C:\Users\*****\Desktop\Attack on Titan 25.txt
2013-09-15 21:16 - 2013-08-20 20:17 - 00000000 ____D C:\Users\*****\Documents\Assassin's Creed III
2013-09-15 19:53 - 2013-03-22 00:29 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-09-15 19:52 - 2013-03-22 23:58 - 00281392 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-09-15 19:52 - 2013-03-22 23:58 - 00000000 ____D C:\Users\*****\AppData\Local\PunkBuster
2013-09-15 19:52 - 2013-03-22 00:29 - 00281392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-09-13 21:12 - 2013-09-13 21:12 - 00138240 _____ C:\Users\*****\Desktop\Finanzierungsplan.xls

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013
Ran by ***** at 2013-10-12 00:16:30
Running from C:\Users\*****\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Disabled - Up to date) {3F839487-C7A2-C958-E30C-E2825BA31FB5}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spyware Doctor (Disabled - Up to date) {94076BB2-F3DA-227F-9A1E-F060FF73600F}
AS: Microsoft Security Essentials (Disabled - Up to date) {84E27563-E198-C6D6-D9BC-D9F020245508}

==================== Installed Programs ======================

µTorrent (x32 Version: 3.1.2)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Acronis*True*Image*Home (x32 Version: 13.0.7154)
AdblockIE (x32 Version: 1.2)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader X (10.1.3) - Deutsch (x32 Version: 10.1.3)
Age of Empires Online (x32)
AMD Accelerated Video Transcoding (Version: 12.10.100.30328)
AMD Catalyst Install Manager (Version: 8.0.911.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.80328.2204)
Apple Application Support (x32 Version: 2.1.5)
Apple Software Update (x32 Version: 2.1.3.127)
Assassin's Creed(R) III v1.06 (x32 Version: 1.06)
Avid Pro Tools SE 8.0.3 (x32 Version: 8.0.3)
AVM FRITZ!WLAN (x32)
Battlefield 3™ (x32 Version: 1.6.0.0)
Battlelog Web Plugins (x32 Version: 2.1.7)
Borderlands 2 (x32)
Browser Defender 2.0.6.15 (x32 Version: 2.0.6.15)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0928.1532.26058)
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center InstallProxy (x32 Version: 2012.0928.1532.26058)
Catalyst Control Center InstallProxy (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center Localization All (x32 Version: 2013.0328.2218.38225)
CCC Help Chinese Standard (x32 Version: 2012.0928.1531.26058)
CCC Help Chinese Standard (x32 Version: 2013.0328.2217.38225)
CCC Help Chinese Traditional (x32 Version: 2012.0928.1531.26058)
CCC Help Chinese Traditional (x32 Version: 2013.0328.2217.38225)
CCC Help Czech (x32 Version: 2012.0928.1531.26058)
CCC Help Czech (x32 Version: 2013.0328.2217.38225)
CCC Help Danish (x32 Version: 2012.0928.1531.26058)
CCC Help Danish (x32 Version: 2013.0328.2217.38225)
CCC Help Dutch (x32 Version: 2012.0928.1531.26058)
CCC Help Dutch (x32 Version: 2013.0328.2217.38225)
CCC Help English (x32 Version: 2012.0928.1531.26058)
CCC Help English (x32 Version: 2013.0328.2217.38225)
CCC Help Finnish (x32 Version: 2012.0928.1531.26058)
CCC Help Finnish (x32 Version: 2013.0328.2217.38225)
CCC Help French (x32 Version: 2012.0928.1531.26058)
CCC Help French (x32 Version: 2013.0328.2217.38225)
CCC Help German (x32 Version: 2012.0928.1531.26058)
CCC Help German (x32 Version: 2013.0328.2217.38225)
CCC Help Greek (x32 Version: 2012.0928.1531.26058)
CCC Help Greek (x32 Version: 2013.0328.2217.38225)
CCC Help Hungarian (x32 Version: 2012.0928.1531.26058)
CCC Help Hungarian (x32 Version: 2013.0328.2217.38225)
CCC Help Italian (x32 Version: 2012.0928.1531.26058)
CCC Help Italian (x32 Version: 2013.0328.2217.38225)
CCC Help Japanese (x32 Version: 2012.0928.1531.26058)
CCC Help Japanese (x32 Version: 2013.0328.2217.38225)
CCC Help Korean (x32 Version: 2012.0928.1531.26058)
CCC Help Korean (x32 Version: 2013.0328.2217.38225)
CCC Help Norwegian (x32 Version: 2012.0928.1531.26058)
CCC Help Norwegian (x32 Version: 2013.0328.2217.38225)
CCC Help Polish (x32 Version: 2012.0928.1531.26058)
CCC Help Polish (x32 Version: 2013.0328.2217.38225)
CCC Help Portuguese (x32 Version: 2012.0928.1531.26058)
CCC Help Portuguese (x32 Version: 2013.0328.2217.38225)
CCC Help Russian (x32 Version: 2012.0928.1531.26058)
CCC Help Russian (x32 Version: 2013.0328.2217.38225)
CCC Help Spanish (x32 Version: 2012.0928.1531.26058)
CCC Help Spanish (x32 Version: 2013.0328.2217.38225)
CCC Help Swedish (x32 Version: 2012.0928.1531.26058)
CCC Help Swedish (x32 Version: 2013.0328.2217.38225)
CCC Help Thai (x32 Version: 2012.0928.1531.26058)
CCC Help Thai (x32 Version: 2013.0328.2217.38225)
CCC Help Turkish (x32 Version: 2012.0928.1531.26058)
CCC Help Turkish (x32 Version: 2013.0328.2217.38225)
ccc-utility64 (Version: 2012.0928.1532.26058)
ccc-utility64 (Version: 2013.0328.2218.38225)
Company of Heroes - FAKEMSI (x32 Version: 2.0.0.0)
Company of Heroes (x32 Version: 2.0.0.1)
DC Universe Online (x32)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
Diablo III (x32 Version: 1.0.6.13644)
ESET Online Scanner v3 (x32)
ESN Sonar (x32 Version: 0.70.4)
Free YouTube to MP3 Converter version 3.12.0.128 (x32 Version: 3.12.0.128)
Google Chrome (HKCU Version: 30.0.1599.69)
Google Earth Plug-in (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
Guild Wars 2 (x32)
High-Definition Video Playback (x32 Version: 7.3.10800.5.0)
Host OpenAL (ADI) (x32)
Intel® Matrix Storage Manager
Interlok driver setup x64 (Version: 5.8.13)
Java 7 Update 40 (x32 Version: 7.0.400)
Java Auto Updater (x32 Version: 2.1.9.8)
JNLP (HKCU)
K-Lite Codec Pack 9.9.5 (Basic) (x32 Version: 9.9.5)
League of Legends (x32 Version: 1.02.0000)
Logitech Gaming Software (Version: 8.20.74)
Logitech Gaming Software 8.20 (Version: 8.20.74)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
marvell 61xx (x32 Version: 1.2.0.7100)
M-Audio FastTrack Driver 6.0.6 (x64) (Version: 6.0.6)
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0)
Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0)
Microsoft Office 2010 Service Pack 1 (SP1) (x32)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Standard 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Security Client (Version: 4.2.0223.1)
Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 4.2.223.1)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Nero 10 Menu TemplatePack Basic (x32 Version: 10.6.10000.0.0)
Nero 10 Movie ThemePack Basic (x32 Version: 10.6.10000.1.0)
Nero BackItUp 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Burning ROM 10 (x32 Version: 10.6.10600.4.100)
Nero BurningROM 10 Help (CHM) (x32 Version: 10.6.10600)
Nero BurnRights 10 (x32 Version: 4.4.10300.1.100)
Nero BurnRights 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Control Center 10 (x32 Version: 10.6.12600.0.5)
Nero ControlCenter 10 Help (CHM) (x32 Version: 10.6.10700)
Nero Core Components 10 (x32 Version: 2.0.19800.9.10)
Nero CoverDesigner 10 (x32 Version: 5.6.10500.3.100)
Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.6.10600)
Nero DiscSpeed 10 (x32 Version: 6.4.10400.0.100)
Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Dolby Files 10 (x32 Version: 2.0.13000.0.10)
Nero Express 10 (x32 Version: 10.6.10600.4.100)
Nero Express 10 Help (CHM) (x32 Version: 10.6.10600)
Nero InfoTool 10 (x32 Version: 7.4.10200.0.100)
Nero InfoTool 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Multimedia Suite 10 (x32 Version: 10.6.11300)
Nero Recode 10 (x32 Version: 4.10.10600.4.100)
Nero Recode 10 Help (CHM) (x32 Version: 10.6.10600)
Nero RescueAgent 10 Help (CHM) (x32 Version: 10.6.10700)
Nero SoundTrax 10 (x32 Version: 4.10.10300.2.100)
Nero SoundTrax 10 Help (CHM) (x32 Version: 10.6.10600)
Nero StartSmart 10 (x32 Version: 10.6.10400.2.100)
Nero StartSmart 10 Help (CHM) (x32 Version: 10.6.10600)
Nero Update (x32 Version: 1.0.10900.31.0)
Nero Vision 10 (x32 Version: 7.4.10800.7.100)
Nero Vision 10 Help (CHM) (x32 Version: 10.6.10600)
Nero WaveEditor 10 (x32 Version: 5.10.10400.3.100)
Nero WaveEditor 10 Help (CHM) (x32 Version: 10.6.10600)
NeroKwikMedia Help (CHM) (x32 Version: 10.6.10700)
Origin (x32 Version: 9.1.10.2728)
Pando Media Booster (x32 Version: 2.6.0.6)
PC VGA Camer@ (x32 Version: 1.0.2.04)
PunkBuster Services (x32 Version: 0.991)
QuickTime (x32 Version: 7.71.80.42)
Razer DeathAdder(TM) Mouse (x32 Version: 3.03)
Sandboxie 4.04 (64-bit) (Version: 4.04)
Security Task Manager 1.8d (x32 Version: 1.8d)
SimCity™ (x32 Version: 1.0.0.0)
Skype™ 5.10 (x32 Version: 5.10.116)
SoundMAX (x32 Version: 6.10.2.6585)
Spybot - Search & Destroy (x32 Version: 1.6.2)
Spyware Doctor 7.0 (x32 Version: 7.0)
SpywareBlaster 5.0 (x32 Version: 5.0.0)
StarCraft II (x32 Version: 2.0.9.26147)
Steam (x32 Version: 1.0.0.0)
TeamSpeak 3 Client (HKCU Version: 3.0.13)
tools-freebsd (x32 Version: 8.4.6.16648)
tools-linux (x32 Version: 8.4.6.16648)
tools-netware (x32 Version: 8.4.6.16648)
tools-solaris (x32 Version: 8.4.6.16648)
tools-windows (x32 Version: 8.4.6.16648)
tools-winPre2k (x32 Version: 8.4.6.16648)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2494150) (x32)
Update for Microsoft Office 2010 (KB2553065) (x32)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2566458) (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32)
Uplay (x32 Version: 3.0)
VirtualCloneDrive (x32)
VLC media player 2.0.0 (x32 Version: 2.0.0)
VMware Workstation (x32 Version: 7.1.4.16648)
War Thunder (x32)
War Thunder Launcher 1.0.1.199 (x32)
Warhammer 40,000 Space Marine (x32)
Warhammer® 40,000™: Dawn of War® II - Chaos Rising™ (x32)
Warhammer® 40,000™: Dawn of War® II – Retribution™ (x32)
Windows Live ID Sign-in Assistant (Version: 6.500.3165.0)

==================== Restore Points  =========================

Could not list Restore Points.


==================== Hosts content: ==========================

2009-07-14 04:34 - 2013-10-10 08:08 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1      localhost

==================== Scheduled Tasks (whitelisted) =============

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000Core.job => C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1037283242-4171337582-128212150-1000UA.job => C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-12-11 20:19 - 2010-12-11 20:19 - 01208560 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:A8ADE5D8
AlternateDataStreams: C:\Users\*****\AppData\Local\Temporary Internet Files:fFNjQ1aWCMRRdy6DQwtMgGo1
AlternateDataStreams: C:\Users\*****\AppData\Local\Temporary Internet Files:IhXHys7HsOvYZe9lmWQJui

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\68380184.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\68380184.sys => ""="Driver"

==================== Faulty Device Manager Devices =============

Name: Logitech Gaming Virtual Mouse
Description: Logitech Gaming Virtual Mouse
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: (Standard system devices)
Service: LGVirHid
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/12/2013 00:13:53 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/11/2013 08:13:28 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/11/2013 08:13:23 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/11/2013 08:13:12 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/11/2013 08:00:49 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.20.74.0, Zeitstempel: 0x4edfc6d9
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe06d7363
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0xff4
Startzeit der fehlerhaften Anwendung: 0xLCore.exe0
Pfad der fehlerhaften Anwendung: LCore.exe1
Pfad des fehlerhaften Moduls: LCore.exe2
Berichtskennung: LCore.exe3

Error: (10/11/2013 07:53:06 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.20.74.0, Zeitstempel: 0x4edfc6d9
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe06d7363
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x11c8
Startzeit der fehlerhaften Anwendung: 0xLCore.exe0
Pfad der fehlerhaften Anwendung: LCore.exe1
Pfad des fehlerhaften Moduls: LCore.exe2
Berichtskennung: LCore.exe3

Error: (10/10/2013 11:45:51 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.20.74.0, Zeitstempel: 0x4edfc6d9
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe06d7363
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x1204
Startzeit der fehlerhaften Anwendung: 0xLCore.exe0
Pfad der fehlerhaften Anwendung: LCore.exe1
Pfad des fehlerhaften Moduls: LCore.exe2
Berichtskennung: LCore.exe3

Error: (10/10/2013 11:45:42 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to execute command from the offline queue: uninstall "System.Security, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil" /NoDependencies .  The error returned was Error: The specified assembly is not installed.
.

Error: (10/10/2013 11:45:41 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to execute command from the offline queue: uninstall "System.Security, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil" /NoDependencies .  The error returned was Error: The specified assembly is not installed.
.

Error: (10/09/2013 01:18:29 AM) (Source: Application Hang) (User: )
Description: Programm FRST64.exe, Version 3.3.8.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1228

Startzeit: 01cec4785aab6526

Endzeit: 0

Anwendungspfad: C:\Users\Administrator\Desktop\FRST64.exe

Berichts-ID:


System errors:
=============
Error: (10/11/2013 09:18:04 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (10/11/2013 08:00:41 PM) (Source: Service Control Manager) (User: )
Description: Dienst "VMware NAT Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (10/11/2013 08:00:34 PM) (Source: hasplms) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!

Error: (10/11/2013 08:00:34 PM) (Source: VMnetDHCP) (User: )
Description: Can't open C:\ProgramData\VMware\vmnetdhcp.conf: Das System kann die angegebene Datei nicht finden.
 / Unknown error 2 (0x2)

Error: (10/11/2013 07:52:32 PM) (Source: Service Control Manager) (User: )
Description: Dienst "VMware NAT Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (10/11/2013 07:52:28 PM) (Source: hasplms) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!

Error: (10/11/2013 07:52:25 PM) (Source: hasplms) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!

Error: (10/11/2013 07:52:24 PM) (Source: VMnetDHCP) (User: )
Description: Can't open C:\ProgramData\VMware\vmnetdhcp.conf: Das System kann die angegebene Datei nicht finden.
 / Unknown error 2 (0x2)

Error: (10/10/2013 11:45:30 PM) (Source: Service Control Manager) (User: )
Description: Dienst "VMware NAT Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (10/10/2013 11:45:27 PM) (Source: VMnetDHCP) (User: )
Description: Can't open C:\ProgramData\VMware\vmnetdhcp.conf: Das System kann die angegebene Datei nicht finden.
 / Unknown error 2 (0x2)


Microsoft Office Sessions:
=========================
Error: (10/12/2013 00:13:53 AM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe

Error: (10/11/2013 08:13:28 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\*****\Downloads\esetsmartinstaller_enu.exe

Error: (10/11/2013 08:13:23 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\*****\Downloads\esetsmartinstaller_enu.exe

Error: (10/11/2013 08:13:12 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\*****\Downloads\esetsmartinstaller_enu.exe

Error: (10/11/2013 08:00:49 PM) (Source: Application Error)(User: )
Description: LCore.exe8.20.74.04edfc6d9KERNELBASE.dll6.1.7601.1822951fb1677e06d7363000000000000940dff401cec6abca6eaa19C:\Program Files\Logitech Gaming Software\LCore.exeC:\Windows\system32\KERNELBASE.dll0f37668d-329f-11e3-8ad6-005056c00008

Error: (10/11/2013 07:53:06 PM) (Source: Application Error)(User: )
Description: LCore.exe8.20.74.04edfc6d9KERNELBASE.dll6.1.7601.1822951fb1677e06d7363000000000000940d11c801cec6aabab397fbC:\Program Files\Logitech Gaming Software\LCore.exeC:\Windows\system32\KERNELBASE.dllfae1fba6-329d-11e3-873e-005056c00008

Error: (10/10/2013 11:45:51 PM) (Source: Application Error)(User: )
Description: LCore.exe8.20.74.04edfc6d9KERNELBASE.dll6.1.7601.1822951fb1677e06d7363000000000000940d120401cec602141d71f6C:\Program Files\Logitech Gaming Software\LCore.exeC:\Windows\system32\KERNELBASE.dll54800506-31f5-11e3-b17e-005056c00008

Error: (10/10/2013 11:45:42 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to execute command from the offline queue: uninstall "System.Security, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil" /NoDependencies .  The error returned was Error: The specified assembly is not installed.
.

Error: (10/10/2013 11:45:41 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to execute command from the offline queue: uninstall "System.Security, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil" /NoDependencies .  The error returned was Error: The specified assembly is not installed.
.

Error: (10/09/2013 01:18:29 AM) (Source: Application Hang)(User: )
Description: FRST64.exe3.3.8.1122801cec4785aab65260C:\Users\Administrator\Desktop\FRST64.exe


CodeIntegrity Errors:
===================================
  Date: 2013-10-10 07:59:52.586
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-10-10 07:59:52.539
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2012-11-16 01:37:43.338
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-16 01:18:39.647
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-16 01:08:21.381
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-16 01:00:54.643
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-15 20:31:19.656
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-13 21:03:36.209
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-12 17:35:19.454
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-12 16:24:03.462
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Spyware Doctor\smum64.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 28%
Total physical RAM: 12279.09 MB
Available physical RAM: 8769.79 MB
Total Pagefile: 24556.37 MB
Available Pagefile: 20916.47 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (System) (Fixed) (Total:273.2 GB) (Free:57.76 GB) NTFS
Drive d: (Daten) (Fixed) (Total:465.76 GB) (Free:313.55 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (Daten) (Fixed) (Total:465.76 GB) (Free:6.35 GB) NTFS
Drive g: (INTENSO) (Removable) (Total:7.26 GB) (Free:7.26 GB) FAT32

==================== MBR & Partition Table ==================

==================== End Of Log ============================


Lou Schalter 11.10.2013 23:24

Schau mal: Hat Spybot da irgendwas ausgebremst vorher? Hatte das ja noch laufen bis kurz vorm ESET Scan. Wäre schon cool sowas selbst rauslesen zu können, aber ich hab leider nicht den leistesten Hauch -.-

Code:

05.08.2012 15:44:50 Erlaubt (based on user decision) value "{98889811-442D-49dd-99D7-DC866BE87DBC}" (new data: "") gelöscht in Global browser toolbar!
05.08.2012 15:44:50 Erlaubt (based on user decision) value "{2EECD738-5844-4a99-B4B6-146BF802613B}" (new data: "") gelöscht in Browser Helper Object!
05.08.2012 15:44:51 Erlaubt (based on user decision) value "Start Page" (new data: "about:blank") geändert in Browser page!
05.08.2012 15:45:02 Erlaubt (based on authenticode whitelist) value "SpybotSnD" (new data: ""C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe" /autocheck") hinzugefügt in System Startup global entry!
05.08.2012 16:34:03 Erlaubt (based on user decision) value "SpybotSnD" (new data: "") gelöscht in System Startup global entry!
05.08.2012 16:36:08 Erlaubt (based on user decision) value "Start Page" (new data: "hxxp://www.google.de/") geändert in Browser page!
05.08.2012 16:46:32 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\*****\AppData\Local\Temp\IXP000.TMP\"") hinzugefügt in System Startup global entry!
05.08.2012 16:46:43 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "") gelöscht in System Startup global entry!
05.08.2012 16:46:47 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\*****\AppData\Local\Temp\IXP000.TMP\"") hinzugefügt in System Startup global entry!
05.08.2012 16:47:02 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "") gelöscht in System Startup global entry!
05.08.2012 17:00:33 Erlaubt (based on user decision) value "Google Update" (new data: ""C:\Users\*****\AppData\Local\Google\Update\GoogleUpdate.exe" /c") hinzugefügt in System Startup user entry!
13.08.2012 17:47:45 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
24.08.2012 01:56:07 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
30.08.2012 02:35:11 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
30.08.2012 02:47:33 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
30.08.2012 03:00:10 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
02.09.2012 03:08:54 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
02.09.2012 03:09:13 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\system32\Macromed\Flash\FlashUtil64_11_1_102_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
02.09.2012 03:20:29 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
02.09.2012 03:23:30 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
02.09.2012 20:08:10 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
03.09.2012 04:24:29 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
03.09.2012 04:25:35 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
03.09.2012 04:36:28 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
03.09.2012 04:41:49 Verweigert (based on user decision) value "ITBar7Height64" (new data: "21") hinzugefügt in User-specific browser toolbar!
11.09.2012 10:55:49 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
19.09.2012 11:40:47 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
27.09.2012 02:01:50 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
04.10.2012 02:02:02 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
08.10.2012 19:04:11 Erlaubt (based on user decision) value "StartCCC" (new data: "") gelöscht in System Startup global entry!
08.10.2012 19:04:21 Erlaubt (based on user decision) value "StartCCC" (new data: ""C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun") hinzugefügt in System Startup global entry!
12.10.2012 01:40:16 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
19.10.2012 22:24:01 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
22.10.2012 01:05:57 Erlaubt (based on user decision) value "  ISSetupPrerequisistes" (new data: ""C:\Users\*****\Downloads\Razer_Synapse2_v1.04.13.exe"") hinzugefügt in System Startup user entry!
22.10.2012 01:09:17 Erlaubt (based on user decision) value "  ISSetupPrerequisistes" (new data: "") gelöscht in System Startup user entry!
22.10.2012 01:09:18 Erlaubt (based on user decision) value "" (new data: "") hinzugefügt in System Startup global entry!
22.10.2012 01:09:24 Erlaubt (based on user decision) value "Razer Synapse" (new data: ""C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"") hinzugefügt in System Startup global entry!
22.10.2012 01:23:46 Erlaubt (based on user decision) value "DeathAdder" (new data: "") gelöscht in System Startup global entry!
23.10.2012 02:00:13 Verweigert (based on user decision) value "ISTray" (new data: ""C:\Program Files (x86)\Spyware Doctor\pctsTray.exe"") hinzugefügt in System Startup global entry!
23.10.2012 02:04:44 Erlaubt (based on user decision) value "Razer Synapse" (new data: "") gelöscht in System Startup global entry!
23.10.2012 03:38:13 Erlaubt (based on user decision) value "ISTray" (new data: ""C:\Program Files (x86)\Spyware Doctor\pctsTray.exe"") hinzugefügt in System Startup global entry!
27.10.2012 01:06:52 Erlaubt (based on authenticode whitelist) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
27.10.2012 18:43:11 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "") gelöscht in System Startup user entry!
28.10.2012 08:57:13 Erlaubt (based on user decision) value "FlashPlayerUpdate" (new data: "") gelöscht in System Startup user entry!
03.11.2012 02:07:48 Erlaubt (based on authenticode whitelist) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
03.11.2012 19:43:18 Erlaubt (based on user decision) value "FlashPlayerUpdate" (new data: "") gelöscht in System Startup user entry!
05.11.2012 13:34:32 Erlaubt (based on user decision) value "StartCCC" (new data: "") gelöscht in System Startup global entry!
05.11.2012 13:34:39 Erlaubt (based on user decision) value "AMD AVT" (new data: "") gelöscht in System Startup global entry!
10.11.2012 03:47:51 Erlaubt (based on authenticode whitelist) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11f_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
10.11.2012 12:29:03 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "") gelöscht in System Startup user entry!
11.11.2012 10:58:38 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "") gelöscht in System Startup user entry!
11.11.2012 12:05:23 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "") gelöscht in System Startup user entry!
11.11.2012 22:09:38 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "") gelöscht in System Startup user entry!
12.11.2012 12:56:36 Erlaubt (based on user decision) value "FlashPlayerUpdate" (new data: "") gelöscht in System Startup user entry!
16.11.2012 01:33:15 Erlaubt (based on user decision) value "Steam" (new data: "") gelöscht in System Startup user entry!
16.11.2012 01:33:16 Erlaubt (based on user decision) value "AVMWlanClient" (new data: "") gelöscht in System Startup global entry!
16.11.2012 01:33:16 Erlaubt (based on user decision) value "TrueImageMonitor.exe" (new data: "") gelöscht in System Startup global entry!
16.11.2012 01:33:17 Erlaubt (based on user decision) value "Adobe ARM" (new data: "") gelöscht in System Startup global entry!
16.11.2012 01:33:18 Erlaubt (based on user decision) value "APSDaemon" (new data: "") gelöscht in System Startup global entry!
16.11.2012 01:33:18 Erlaubt (based on user decision) value "QuickTime Task" (new data: "") gelöscht in System Startup global entry!
16.11.2012 01:33:19 Erlaubt (based on user decision) value "ISTray" (new data: "") gelöscht in System Startup global entry!
20.12.2012 01:40:50 Erlaubt (based on user decision) value "Razer Synapse" (new data: ""C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"") hinzugefügt in System Startup global entry!
24.12.2012 00:47:33 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\*****\AppData\Local\Temp\IXP000.TMP\"") hinzugefügt in System Startup global entry!
24.12.2012 00:47:36 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "") gelöscht in System Startup global entry!
07.01.2013 02:22:46 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\*****\AppData\Local\Temp\IXP000.TMP\"") hinzugefügt in System Startup global entry!
07.01.2013 02:22:52 Erlaubt (based on user decision) value "wextract_cleanup1" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\*****\AppData\Local\Temp\IXP001.TMP\"") hinzugefügt in System Startup global entry!
07.01.2013 02:23:27 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "") gelöscht in System Startup global entry!
07.01.2013 02:23:28 Erlaubt (based on user decision) value "wextract_cleanup1" (new data: "") gelöscht in System Startup global entry!
18.01.2013 19:58:31 Verweigert (based on user decision) value "Isuftup" (new data: "C:\Users\*****\AppData\Roaming\Paabyw\yxeno.exe") hinzugefügt in System Startup user entry!
18.01.2013 19:58:36 Verweigert (based on user decision) value "Isuftup" (new data: "C:\Users\*****\AppData\Roaming\Paabyw\yxeno.exe") hinzugefügt in System Startup user entry!
18.01.2013 19:58:46 Verweigert (based on user decision) value "Isuftup" (new data: "C:\Users\*****\AppData\Roaming\Paabyw\yxeno.exe") hinzugefügt in System Startup user entry!
18.01.2013 19:58:52 Verweigert (based on user decision) value "Isuftup" (new data: "C:\Users\*****\AppData\Roaming\Paabyw\yxeno.exe") hinzugefügt in System Startup user entry!
27.01.2013 13:40:21 Erlaubt (based on user decision) value "scrnsave.exe" (new data: "C:\Windows\system32\Mystify.scr") geändert in Desktop settings!
29.01.2013 01:33:32 Erlaubt (based on user decision) value "DeathAdder" (new data: "C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe") hinzugefügt in System Startup global entry!
03.02.2013 23:18:01 Erlaubt (based on user decision) value "Skype" (new data: "") gelöscht in System Startup user entry!
03.02.2013 23:18:03 Erlaubt (based on user decision) value "Razer Synapse" (new data: "") gelöscht in System Startup global entry!
07.02.2013 01:42:12 Erlaubt (based on authenticode whitelist) value "{90EFF544-3981-4d46-85C9-C0361D0931D6}" (new data: "") hinzugefügt in Browser Helper Object!
13.02.2013 19:32:29 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_5_502_149_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
17.02.2013 15:34:25 Erlaubt (based on user decision) value "{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}" (new data: "") hinzugefügt in Browser Helper Object!
17.02.2013 15:34:32 Erlaubt (based on user decision) value "Free YouTube Download" (new data: "") hinzugefügt in Browser menu extension!
17.02.2013 15:34:36 Erlaubt (based on user decision) value "Free YouTube to MP3 Converter" (new data: "") hinzugefügt in Browser menu extension!
17.02.2013 18:28:33 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
17.02.2013 22:48:07 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
18.02.2013 10:22:03 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
18.02.2013 14:48:03 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
19.02.2013 19:48:30 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
20.02.2013 20:41:17 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
21.02.2013 01:56:44 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_5_502_149_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
22.02.2013 19:56:27 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
23.02.2013 18:50:03 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
24.02.2013 12:17:31 Verweigert (based on user decision) value "GoogleChromeAutoLaunch_9A83AADA066CCEA6F8C613E0AB5C7E19" (new data: ""C:\Users\*****\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window") hinzugefügt in System Startup user entry!
26.02.2013 01:37:27 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:37:35 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:37:41 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:37:43 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:37:48 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:37:53 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:38:02 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:43:20 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:43:26 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:43:31 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:31 Verweigert (based on user decision) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:32 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:33 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:34 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:35 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:36 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:37 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:38 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:39 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:40 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:41 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:42 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:43 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:44 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:45 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:46 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:47 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:48 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:49 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:50 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:51 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:52 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:53 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:54 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:55 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:56 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:57 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:58 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:44:59 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:00 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:01 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:02 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:03 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:04 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:05 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:06 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:07 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:08 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:09 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:10 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:11 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:12 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:13 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:14 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
26.02.2013 01:45:16 Verweigert (based on user blacklist) value "Akeni" (new data: "C:\Users\*****\AppData\Roaming\Rybe\pays.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:24:55 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:25:01 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:25:08 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:25:21 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:27:18 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:28:13 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:28:18 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:28:42 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:28:48 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 02:31:05 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
18.03.2013 14:28:39 Verweigert (based on user decision) value "Itcywy" (new data: "C:\Users\*****\AppData\Roaming\Xyym\igako.exe") hinzugefügt in System Startup user entry!
22.03.2013 22:26:40 Verweigert (based on user decision) value "Shell" (new data: "explorer.exe,C:\Users\*****\AppData\Roaming\skype.dat") hinzugefügt in Winlogon!
13.04.2013 03:23:13 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
20.04.2013 21:02:32 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
28.04.2013 02:46:49 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
05.05.2013 02:20:36 Verweigert (based on user decision) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:20:42 Verweigert (based on user decision) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:20:50 Verweigert (based on user decision) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:20:55 Verweigert (based on user decision) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:21:04 Verweigert (based on user decision) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:09 Verweigert (based on user decision) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:10 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:11 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:12 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:13 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:14 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:15 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:16 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:17 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:18 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:19 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:20 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:21 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:22 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:23 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:24 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:25 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:26 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:27 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:28 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:29 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:30 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:31 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:32 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:33 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:34 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:35 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:36 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:37 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:38 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:39 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:40 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:41 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:42 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:43 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:44 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:45 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:46 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:47 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:48 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:49 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:50 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:51 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:52 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:53 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:54 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:55 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:56 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:57 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:58 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:25:59 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:00 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:01 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:02 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:03 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:04 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:05 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:06 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:07 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:08 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:09 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:10 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:11 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:12 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:13 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:14 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:15 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:16 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:17 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:18 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:19 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:20 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:21 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:22 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:23 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:24 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:25 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:26 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:27 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:28 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:29 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:30 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:32 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:33 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:34 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:35 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:36 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:37 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:38 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:39 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:40 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:41 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:42 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:43 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:44 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:45 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:46 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:47 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:48 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:49 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:50 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:51 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:52 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:53 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:54 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:55 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:56 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:57 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:58 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:26:59 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:00 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:01 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:02 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:03 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:04 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:05 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:06 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:07 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:08 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:09 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:10 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:11 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:12 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:13 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:14 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:15 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:16 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:17 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:18 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:19 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:20 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:21 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:22 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:23 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:24 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:25 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:26 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:27 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:28 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:29 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:30 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:31 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:32 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:33 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:34 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:35 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:36 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:37 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:38 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:39 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:40 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:41 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:42 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:43 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:44 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:45 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:46 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:47 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:48 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:49 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:50 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:51 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:52 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:53 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:54 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:55 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:56 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:57 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:58 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:27:59 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:00 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:01 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:02 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:03 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:04 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:05 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:06 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:07 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:08 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:09 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:10 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:11 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:12 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:13 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:14 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:15 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:16 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:17 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:18 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:19 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:20 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:21 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:22 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:24 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:25 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:26 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:27 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:28 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:29 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:30 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:31 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:32 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:33 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:34 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:35 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:36 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:37 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:38 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:39 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:40 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:41 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:42 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:43 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:44 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:45 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:46 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:47 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:48 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:49 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:50 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:51 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:52 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:53 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:54 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:55 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:56 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:57 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:58 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:28:59 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:00 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:01 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:02 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:03 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:04 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:05 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:06 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:07 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:08 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:09 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:10 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:11 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:12 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:13 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:14 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:15 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:16 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:17 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:18 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:19 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:20 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:21 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:22 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:23 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:24 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:25 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:26 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:27 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:28 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:29 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:30 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:31 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:32 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:33 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:34 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:35 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:36 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:37 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:38 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:39 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:40 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:41 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:42 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:43 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:44 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:45 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:46 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:47 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:48 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:49 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:50 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:51 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:52 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:53 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:54 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:55 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:56 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:57 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:58 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:29:59 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:00 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:01 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:02 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:03 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:04 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:05 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:06 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:07 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:08 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:09 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:10 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:12 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:13 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:14 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:15 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:16 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:17 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:18 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:19 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:20 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:21 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:22 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:23 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:24 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:25 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:26 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:27 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:28 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:29 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:30 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:31 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:32 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:34 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:35 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:36 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:37 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:38 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:39 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:40 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:41 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:42 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:43 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:44 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:45 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:46 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:47 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:48 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:49 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:50 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:51 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:52 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:53 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:54 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:55 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:56 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:57 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:58 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:30:59 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:00 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:01 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:02 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:03 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:05 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:06 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:07 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:08 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:09 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:10 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:11 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:12 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:13 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:14 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:15 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:16 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:17 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:18 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:19 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:20 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:21 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:22 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:23 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:24 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:25 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:26 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:27 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:28 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:29 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:30 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:31 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:32 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:33 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:34 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:35 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:36 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:37 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:38 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:39 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:40 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:41 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:42 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:43 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:44 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:45 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:46 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:47 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:48 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:49 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:50 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:51 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:52 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:53 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:54 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:55 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:56 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:57 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:58 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:31:59 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:00 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:01 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:02 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:03 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:04 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:05 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:06 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:07 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:08 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:09 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:10 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:11 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:12 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:13 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:14 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:15 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:16 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:17 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:18 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:19 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:20 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:21 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:22 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:23 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:32:24 Verweigert (based on user blacklist) value "Beviziaf" (new data: "C:\Users\*****\AppData\Roaming\Eciza\peyq.exe") hinzugefügt in System Startup user entry!
05.05.2013 02:46:10 Erlaubt (based on user decision) value "SpybotDeletingB9900" (new data: "command.com /c del "C:\Users\*****\AppData\Roaming\skype.dat"") hinzugefügt in System Startup user entry!
05.05.2013 02:46:16 Erlaubt (based on user decision) value "SpybotDeletingD9158" (new data: "cmd.exe /c del "C:\Users\*****\AppData\Roaming\skype.dat"") hinzugefügt in System Startup user entry!
05.05.2013 02:46:18 Erlaubt (based on user decision) value "SpybotDeletingA2355" (new data: "command.com /c del "C:\Users\*****\AppData\Roaming\skype.dat"") hinzugefügt in System Startup global entry!
05.05.2013 02:46:24 Erlaubt (based on user decision) value "SpybotDeletingC2226" (new data: "cmd.exe /c del "C:\Users\*****\AppData\Roaming\skype.dat"") hinzugefügt in System Startup global entry!
05.05.2013 11:16:05 Erlaubt (based on user decision) value "SpybotDeletingB9900" (new data: "") gelöscht in System Startup user entry!
05.05.2013 11:16:07 Erlaubt (based on user decision) value "SpybotDeletingD9158" (new data: "") gelöscht in System Startup user entry!
05.05.2013 11:16:07 Erlaubt (based on user decision) value "SpybotDeletingA2355" (new data: "") gelöscht in System Startup global entry!
05.05.2013 11:16:12 Erlaubt (based on user decision) value "SpybotDeletingC2226" (new data: "") gelöscht in System Startup global entry!
09.05.2013 14:30:13 Erlaubt (based on user decision) value "DeathAdder" (new data: "") gelöscht in System Startup global entry!
09.05.2013 14:36:49 Erlaubt (based on user decision) value "DeathAdder" (new data: "C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe") hinzugefügt in System Startup global entry!
13.05.2013 00:35:05 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
19.05.2013 21:33:12 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\*****\AppData\Local\Temp\IXP000.TMP\"") hinzugefügt in System Startup global entry!
19.05.2013 21:33:17 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "") gelöscht in System Startup global entry!
05.06.2013 21:55:13 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\*****\AppData\Local\Temp\IXP000.TMP\"") hinzugefügt in System Startup global entry!
05.06.2013 21:57:04 Erlaubt (based on user decision) value "wextract_cleanup0" (new data: "") gelöscht in System Startup global entry!
15.07.2013 01:18:44 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
15.07.2013 16:38:01 Erlaubt (based on user decision) value "DeathAdder" (new data: "") gelöscht in System Startup global entry!
15.07.2013 16:59:52 Erlaubt (based on user decision) value "Razer Synapse" (new data: ""C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"") hinzugefügt in System Startup global entry!
15.07.2013 23:11:23 Erlaubt (based on user decision) value "" (new data: "") gelöscht in System Startup global entry!
15.07.2013 23:11:24 Erlaubt (based on user decision) value "Razer Synapse" (new data: "") gelöscht in System Startup global entry!
15.07.2013 23:17:34 Erlaubt (based on user decision) value "DeathAdder" (new data: "C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe") hinzugefügt in System Startup global entry!
16.07.2013 00:59:45 Erlaubt (based on user decision) value "StartCCC" (new data: ""C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun") hinzugefügt in System Startup global entry!
24.07.2013 01:09:29 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
31.07.2013 03:29:13 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
05.08.2013 20:47:34 Verweigert (based on user decision) value "scrnsave.exe" (new data: "") gelöscht in Desktop settings!
08.08.2013 01:07:45 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
17.08.2013 02:02:55 Verweigert (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe -update activex") hinzugefügt in System Startup user entry!
20.08.2013 20:16:36 Erlaubt (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~2\INSTAL~1\{9D15E~1\setup.exe -rebootC:\PROGRA~2\INSTAL~1\{9D15E~1\reboot.ini") hinzugefügt in System Startup global entry!
22.08.2013 22:44:00 Verweigert (based on user decision) value "InstallShieldSetup" (new data: "") gelöscht in System Startup global entry!
23.08.2013 22:48:04 Verweigert (based on user decision) value "InstallShieldSetup" (new data: "") gelöscht in System Startup global entry!
23.08.2013 22:55:14 Erlaubt (based on user decision) value "InstallShieldSetup1" (new data: "C:\PROGRA~2\INSTAL~1\{9D15E~1\setup.exe -rebootC:\PROGRA~2\INSTAL~1\{9D15E~1\reboot.ini") hinzugefügt in System Startup global entry!
24.08.2013 19:22:19 Erlaubt (based on user decision) value "InstallShieldSetup" (new data: "") gelöscht in System Startup global entry!
24.08.2013 19:22:21 Erlaubt (based on user decision) value "InstallShieldSetup1" (new data: "") gelöscht in System Startup global entry!
25.08.2013 14:03:21 Erlaubt (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~2\INSTAL~1\{9D15E~1\setup.exe -rebootC:\PROGRA~2\INSTAL~1\{9D15E~1\reboot.ini") hinzugefügt in System Startup global entry!
26.08.2013 21:46:51 Erlaubt (based on user decision) value "InstallShieldSetup" (new data: "") gelöscht in System Startup global entry!
26.08.2013 21:50:42 Erlaubt (based on user decision) value "InstallShieldSetup" (new data: "C:\PROGRA~2\INSTAL~1\{9D15E~1\setup.exe -rebootC:\PROGRA~2\INSTAL~1\{9D15E~1\reboot.ini") hinzugefügt in System Startup global entry!
27.08.2013 23:36:22 Erlaubt (based on user decision) value "InstallShieldSetup" (new data: "") gelöscht in System Startup global entry!
10.10.2013 23:32:38 Erlaubt (based on user decision) value "SandboxieControl" (new data: ""C:\Program Files\Sandboxie\SbieCtrl.exe"") hinzugefügt in System Startup user entry!
11.10.2013 20:03:56 Erlaubt (based on authenticode whitelist) value "Malwarebytes Anti-Malware" (new data: "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent") hinzugefügt in System Startup global entry!

EDIT:

Wobei ... . Also im Prinzip ist das ja nur ein Haufen alter Mist. Höhö. Das seh' ich auch als Laie, wenn ich mirs wirklich mal genauer angucke. Die einzigen zwei aktuellen Einträge sind von gestern und heute und da steht ja was von "erlaubt". Wäre vielleicht höchstens interessant zu sehen was Spybot so alles durchgehen lässt was es nicht sollte bzw. blockt was es nicht sollte.

EDIT2:

"based on user decision" => Alles klar, vergiss was ich gefragt habe ^^

aharonov 12.10.2013 13:16

Hallo,

genau. Die meisten Einträge betreffen alte Sachen (darunter auch einige Malware). Die einzigen beiden aktuellen Einträge betreffen die Erlaubnis für Sandboxie und Malwarebytes_Anti-Malware, und das erscheint mir ok.. ;)

Update noch den Internet Explorer und den Adobe PDF Reader auf die aktuellste Version. Dann bleibt noch das Aufräumen.


Cleanup

Zum Schluss werden wir jetzt noch unsere Tools (inklusive der Quarantäne-Ordner) wegräumen, die verseuchten Systemwiederherstellungspunkte löschen und alle Einstellungen wieder herrichten. Auch diese Schritte sind noch wichtig und sollten in der angegebenen Reihenfolge ausgeführt werden.
  1. Deaktiviere jetzt temporär das Antivirenprogramm, benenne bei der auf dem Desktop vorhandenen Combofix.exe das "Combofix" im Dateinamen um in Uninstall und führe sie mit Doppelklick aus.
  2. Bei MBAM würd ich dir unbedingt empfehlen, es zu behalten und wöchentlich einen Quick-Scan durchzuführen. Wenn du es nicht weiter verwenden möchtest, kannst du es jetzt normal über die Systemsteuerung deinstallieren.
  3. Auch den ESET Online Scanner kannst du behalten, um ab und zu (monatlich) für eine Zweitmeinung dein System damit zu scannen. Falls du ESET deinstallieren möchtest, dann kannst du das ebenfalls über die Systemsteuerung tun.
  4. Downloade dir bitte auf jeden Fall DelFix auf deinen Desktop.
    • Schliesse alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • DelFix entfernt u.a. alle von uns verwendeten Programme und löscht sich anschliessend selbst.
  5. Wenn jetzt noch etwas übriggeblieben ist, dann kannst du es einfach manuell löschen.




>> OK <<
Wir sind durch, deine Logs sehen für mich im Moment sauber aus. :daumenhoc

Ich habe dir nachfolgend ein paar Hinweise und Tipps zusammengestellt, die dazu beitragen sollen, dass du in Zukunft unsere Hilfe nicht mehr brauchen wirst.

Bitte gib mir danach noch eine kurze Rückmeldung, wenn auch von deiner Seite keine Probleme oder Fragen mehr offen sind, damit ich dieses Thema als erledigt betrachten kann.




Epilog: Tipps, Dos & Don'ts

Aktualität von System und Software

Das Betriebsystem Windows muss zwingend immer auf dem neusten Stand sein. Stelle sicher, dass die automatischen Updates aktiviert sind:
  • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
  • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren

Auch die installierte Software sollte immer in der aktuellsten Version vorliegen.
Speziell gilt das für den Browser, Java, Flash-Player und PDF-Reader, denn bekannte Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim blossen Besuch einer präparierten Website per Drive-by Download Malware zu installieren. Das kann sogar auf normalerweise legitimen Websites geschehen, wenn es einem Angreifer gelungen ist, seinen Code in die Seite einzuschleusen, und ist deshalb relativ unberechenbar.
  • Mit diesem kleinen Plugin-Check kannst du regelmässig diese Komponenten auf deren Aktualität überprüfen.
  • Achte auch darauf, dass alte, nicht mehr verwendete Versionen deinstalliert sind.
  • Optional: Das Programm Secunia Personal Software Inspector kann dich dabei unterstützen, stets die aktuellen Versionen sämtlicher installierter Software zu nutzen.

Sicherheits-Software

Eine Bemerkung vorneweg: Jede Softwarelösung hat ihre Schwächen. Die gesamte Verantwortung für die Sicherheit auf Software zu übertragen und einen Rundum-Schutz zu erwarten, wäre eine gefährliche Illusion. Bei unbedachtem oder bewusst risikoreichem Verhalten wird auch das beste Programm früher oder später seinen Dienst versagen (z.B. ein Virenscanner, der eine verseuchte Datei nicht erkennt).
Trotzdem ist entsprechende Software natürlich wichtig und hilft dir in Kombination mit einem gut gewarteten (up-to-date) System und durchdachtem Verhalten, deinen Rechner sauber zu halten.
  • Nutze einen Virenscanner mit Hintergrundwächter mit stets aktueller Datenbank. Welches Produkt gewählt wird, spielt keine so entscheidende Rolle. Es gibt kommerzielle Versionen, aber ein kostenloser Scanner mit den Grundfunktionen wie beispielsweise Avast! Free Antivirus sollte ausreichen. Betreibe aber keinesfalls zwei Wächter parallel, die würden sich gegenseitig behindern.
  • Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.
  • Zusätzlich zum Virenscanner kannst du dein System regelmässig mit einem On-Demand Antimalwareprogramm scannen. Empfehlenswert ist die Free-Version von Malwarebytes Anti-Malware. Vor jedem Scan die Datenbank updaten.
  • Optional: Das Programm Sandboxie führt Anwendungen in einer isolierten Umgebung ("Sandkasten") aus, so dass keine Änderungen am System vorgenommen werden können. Wenn du deinen Browser darin startest, vermindert sich die Chance, dass beim Surfen eingefangene Malware sich dauerhaft im System festsetzen kann.
  • Optional: Das Addon WOT (web of trust) warnt dich vor einer als schädlich gemeldeten Website, bevor sie geladen wird. Für verschiedene Browser erhältlich.

Es liegt in der Natur der Sache, dass die am weitesten verbreitete Anwendungs-Software auch am häufigsten von Malware-Autoren attackiert wird. Es kann daher bereits einen kleinen Sicherheitsgewinn darstellen, wenn man alternative Software (z.B. einen alternativen PDF Reader) benutzt.
Anstelle des Internet Explorers kann man beispielsweise den Mozilla Firefox einsetzen, für welchen es zwei nützliche Addons zur Empfehlung gibt:
  • NoScript verhindert standardmässig das Ausführen von aktiven Inhalten (Java, JavaScript, Flash, ..) für sämtliche Websites. Du kannst selber nach dem Prinzip einer Whitelist festlegen, welchen Seiten du vertrauen und Scripts erlauben willst, auch temporär.
  • Adblock Plus blockt die meisten Werbebanner weg. Solche Banner können nebst ihrer störenden Erscheinung auch als Infektionsherde fungieren.

(Un-)Sicheres Verhalten im Internet

Nebst unbemerkten Drive-by Installationen wird Malware aber auch oft mehr oder weniger aktiv vom Benutzer selbst installiert.

Der Besuch zwielichtiger Websites kann bereits Risiken bergen. Und Downloads aus dubiosen Quellen sind immer russisches Roulette. Auch wenn der Virenscanner im Moment darin keine Bedrohung erkennt, muss das nichts bedeuten.
  • Illegale Cracks, Keygens und Serials sind ein ausgesprochen einfacher (und ein beliebter) Weg, um Malware zu verbreiten.
  • Bei Dateien aus Peer-to-Peer- und Filesharingprogrammen oder von Filehostern kannst du dir nie sicher sein, ob auch wirklich drin ist, was drauf steht.

Oft wird auch versucht, den Benutzer mit mehr oder weniger trickreichen Methoden dazu zu bringen, eine für ihn verhängnisvolle Handlung selbst auszuführen (Überbegriff Social Engineering).
  • Surfe mit Vorsicht und lass dich nicht von irgendwie interessant erscheinenden Elementen zu einem vorschnellen Klick verleiten. Lass dich nicht von Popups täuschen, die aussehen wie System- oder Virenmeldungen.
  • Sei skeptisch bei unerwarteten E-Mails, insbesondere wenn sie Anhänge enthalten. Auch wenn sie auf den ersten Blick authentisch wirken, persönliche Daten von dir enthalten oder vermeintlich von einem bekannten Absender stammen: Lieber nochmals in Ruhe überdenken oder nachfragen, anstatt einfach mal Links oder ausführbare Anhänge öffnen oder irgendwo deine Daten eingeben.
  • Auch in sozialen Netzwerken oder über Instant Messaging Systeme können schädliche Links oder Dateien die Runde machen. Erhältst du von einem deiner Freunde eine Nachricht, die merkwürdig ist oder so sensationell interessant oder skandalös tönt, dass man einfach draufklicken muss, dann hat bei ihm/ihr wahrscheinlich Neugier über Verstand gesiegt und du solltest nicht denselben Fehler machen.
  • Lass die Dateiendungen anzeigen, so dass du dich nicht täuschen lässt, wenn eine ausführbare Datei über ein doppelte Dateiendung kaschiert wird, z.B. Nacktfoto.jpg.exe.

Nervige Adware (Werbung) und unnötige Toolbars werden auch meist durch den Benutzer selbst mitinstalliert.
  • Lade Software in erster Priorität immer direkt vom Hersteller herunter. Viele Softwareportale (z.B. Softonic) packen noch unnützes Zeug mit in die Installation. Alternativ dazu wähle ein sauberes Portal wie Filepony oder heise.
  • Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen fürs Programm irrelevanten Ergänzungen.

Allgemeine Hinweise

Abschliessend noch ein paar grundsätzliche Bemerkungen:
  • Dein Benutzerkonto für den alltäglichen Gebrauch sollte nicht über Administratorenrechte verfügen. Nutze ein Konto mit eingeschränkten Rechten (Windows XP) bzw. aktiviere die Benutzerkontensteuerung (UAC) auf der höchsten Stufe (Windows Vista / 7).
  • Erstelle regelmässig Backups deiner Daten und Dokumente auf externen Datenträgern, bei wichtigen Dateien mindestens zweifach. Nicht nur ein Malwarebefall kann schmerzhaften Datenverlust nach sich ziehen sondern auch ein gewöhnlicher Festplattendefekt.
  • Die Autorun/Autoplay-Funktion stellt ein Risiko dar, denn sie ermöglicht es, dass beispielsweise beim Einstecken eines entsprechend infizierten USB-Sticks der Befall auf den Rechner überspringt. Überlege dir, ob du diese Funktion nicht besser deaktivieren möchtest.
  • Wähle deine Passwörter gemäss den gängigen Regeln, um besser gegen Brute-Force- und Wörterbuchattacken gewappnet zu sein. Benutze jedes deiner Passwörter nur einmal und ändere sie regelmässig.
  • Der Nutzen von Registry-Cleanern zur Performancesteigerung ist umstritten. Auf jeden Fall lässt sich damit grosser Schaden anrichten, wenn man nicht weiss, was man tut. Wir empfehlen deshalb, die Finger von der Registry zu lassen. Um von Zeit zu Zeit die temporären Dateien zu löschen, genügt TFC.

Wenn du möchtest, kannst du das Forum mit einer kleinen Spende unterstützen.
Es bleibt mir nur noch, dir unbeschwertes und sicheres Surfen zu wünschen und dass wir uns hier so bald nicht wiedersehen. ;)

Lou Schalter 12.10.2013 16:47

Habe alle Punkte soweit durchgeführt (Glaube für die Installation von IE10 muss ich neustarten, sonst hat alles geklappt).

Code:

# DelFix v10.4 - Datei am 12/10/2013 um 17:10:30 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Benutzer : Administrator - *****-PC
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)

~ Aktiviere die Benutzerkontensteuerung ... OK

~ Entferne die Bereinigungsprogramme ...

Gelöscht : \_OTL
Gelöscht : \FRST
Gelöscht : \TDSSKiller_Quarantine
Gelöscht : \ComboFix.txt
Gelöscht : \TDSSKiller.2.8.16.0_10.10.2013_21.16.17_log.txt
Gelöscht : \TDSSKiller.2.8.16.0_10.10.2013_22.08.17_log.txt
Gelöscht : \TDSSKiller.3.0.0.12_10.10.2013_21.20.30_log.txt
Gelöscht : \TDSSKiller.3.0.0.12_10.10.2013_22.08.30_log.txt
Gelöscht : \TDSSKiller.3.0.0.12_10.10.2013_22.08.44_log.txt
Gelöscht : \TDSSKiller.3.0.0.12_10.10.2013_22.50.46_log.txt
Gelöscht : \TDSSKiller.3.0.0.12_11.10.2013_19.54.19_log.txt
Gelöscht : C:\Users\Administrator\Desktop\Addition.txt
Gelöscht : C:\Users\Administrator\Desktop\adwcleaner.exe
Gelöscht : C:\Users\Administrator\Desktop\FRST64.exe
Gelöscht : C:\Users\Administrator\Desktop\JRT.exe
Gelöscht : C:\Users\Administrator\Desktop\OTL FIX.txt
Gelöscht : C:\Users\Administrator\Desktop\OTL.Txt
Gelöscht : C:\Users\Administrator\Desktop\OTL.exe
Gelöscht : C:\Users\Administrator\Downloads\JRT.exe
Gelöscht : HKLM\SOFTWARE\OldTimer Tools
Gelöscht : HKLM\SOFTWARE\AdwCleaner
Gelöscht : HKLM\SOFTWARE\Swearware

~ Erstelle ein Backup der Registrierungsdatenbank ... OK

~ Lösche die Wiederherstellungspunkte ...

Gelöscht : RP #232 [ComboFix created restore point | 10/12/2013 15:08:33]

Ein neuer Wiederherstellungspunkt wurde erstellt !

~ Stelle die Systemeinstellungen wieder her ... OK

########## - EOF - ##########

EDIT:

Beim Plugincheck zeigts mir die ganze Zeit an der Adobe Reader wäre nicht installiert oder aktiviert ... aber ich habe hier die neueste Version drauf (gerade eben Update gemacht und neu gestartet) und auch schon auf "Installation Reparieren" geklickt oO.

aharonov 12.10.2013 19:28

Zitat:

Beim Plugincheck zeigts mir die ganze Zeit an der Adobe Reader wäre nicht installiert oder aktiviert
Ja der Plugincheck haut auch mal daneben.
Wenn du die alte Version deinstalliert und die neuste installiert hast, ist alles in Ordnung.

Sonst alles ok und wir können das Thema beschliessen?

Lou Schalter 12.10.2013 21:12

Hey Leo,

es passt alles soweit, ich danke dir und der Trojaner-Board-Community (selbstverständlich auch im Namen meines Freundes) vielmals!

Ist nicht selbstverständlich, dass es ein kostenloses (!!) Forum in dem man sich kostenfrei (!!) anmelden kann, in dem fachkundige, freiwillige Helfer während ihrer Freizeit (!!) den sich Anmeldenden bei ihren Computer-Schwulitäten zur Seite stehen, gibt.

Und das wohlgemerkt in einem äußerst professionellen Rahmen. Ihr seid super organisiert, die Strukturen sind bis ins kleinste Detail durchdacht.

Wir werden uns selbstverständlich gerne auch in Form eines kleinen Obulus bei euch bedanken und hoffen, dass ihr eure Servicequalität hier bei Trojaner-Board.de noch lange in dieser Form aufrecht erhaltet.

Herzliche Grüße,
Lou Schalter & Co.

aharonov 12.10.2013 23:29

Danke für die Rückmeldung.
Und im Namen des Teams vielen Dank für dei kleinen Obulus!


Freut mich, dass wir helfen konnten. :abklatsch:

Falls du dem Forum noch Verbesserungsvorschläge, Kritik oder ein Lob mitgeben möchtest, kannst du das hier tun.

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Ich bekomme somit keine Benachrichtigung mehr über neue Antworten.
Solltest du das Thema erneut brauchen, schicke mir bitte eine PM und wir machen hier weiter.

Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 09:37 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129