Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   hermes_v01 Trojaner ... TR/Gataka.D.57 (https://www.trojaner-board.de/119061-hermes_v01-trojaner-tr-gataka-d-57-a.html)

lively1986 10.07.2012 12:22

hermes_v01 Trojaner ... TR/Gataka.D.57
 
Erst einmal Sorry falls ich ein Thema geöffnte habe, was schon existiert. Bin über Google auf Trojaner-Board gestoßen und habe auch schon einen Eintrag gefunden bzgl. ded o.g. Trojaners hermes_v01.

Habe mir daraufhin das "Vorgehen beim Verschlüsselungs-Trojaner" sowie die "Anleitung: Malwarebytes Anti-Malware" durchgelesen.

Da ich meinen PC zwar regelmäßig nutze, aber maximal ein gesundes Halbwissen habe, bin ich jedoch dem Aufruf gefolgt: Am besten nichts selber machen, sondern Thema starten.

Vorab hatte ich mittels Spybot einen Scan durchgeführt und den Fund (fragt bitte nicht welchen Fund) gelöscht (Sorry, war froh den Fehler gefunden zu haben und hatte nicht vorab die Info "nur in Quarantäne verschieben" ) Beim erneuten Suchlauf wurden keine weiteren Fehler gefunden.

Habe anschließend noch einen Check mit AntiVir durchgeführt und den Fund "TR/Gataka.D.57" in Quarantäne verschoben (Dateiname: C:Users\...\LicenseValidator.exe --- Quarantäne-Onjekt: 573271et.qua --- Wiederhergestellt: NEIN --- Zu Avira hochgeladen: NEIN --- Betriebssystem: Windows XP / VISTA Workstation / Windows 7 usw.)

Habe wie viele die Meldung beim Aufrufen Passwortgeschützer-Seiten: Sicherheitszertifikat abgelaufen...

Kann mir jemand helfen?

Nach dem Hochladen des Theams merke ich jetzt schon, dass ich es an der falschen Stelle platziert habe. Geht ja gut los. Sorry dafür

Hat jemand schon eine Lösung für mein Problem?

t'john 15.07.2012 17:24

:hallo:

1. Schritt

Neue Version! Bitte neu runterladen!
Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Malwarebytes Anti-Malware
- Anwendbar auf Windows 2000, XP, Vista und 7.
- Installiere das Programm in den vorgegebenen Pfad.
- Aktiviere "Komplett Scan durchführen" => Scan.
- Wähle alle verfügbaren Laufwerke (ausser CD/DVD) aus und starte den Scan.
- Funde bitte löschen lassen oder in Quarantäne.
- Wenn der Scan beendet ist, klicke auf "Zeige Resultate".
2. Schritt
Systemscan mit OTL (bebilderte Anleitung)

Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden)- Doppelklick auf die OTL.exe
- Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
- Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
- Unter Extra Registry, wähle bitte Use SafeList
- Klicke nun auf Run Scan links oben
- Wenn der Scan beendet wurde werden 2 Logfiles erstellt
- Poste die Logfiles hier in den Thread.

lively1986 16.07.2012 15:26

Hallo,

habe nun Anti-Malware und OTL ausgeführt.

Anti-Malware:

Malwarebytes Anti-Malware 1.62.0.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: v2012.07.16.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Alexander :: ALEXANDER-PC [Administrator]

16.07.2012 13:52:19
mbam-log-2012-07-16 (13-52-19).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|Q:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 559196
Laufzeit: 1 Stunde(n), 27 Minute(n), 52 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

OTL:OTL Logfile:
Code:

OTL logfile created on: 16.07.2012 16:31:33 - Run 2
OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Alexander\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
5,93 Gb Total Physical Memory | 3,69 Gb Available Physical Memory | 62,31% Memory free
11,85 Gb Paging File | 9,53 Gb Available in Paging File | 80,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 906,34 Gb Total Space | 751,00 Gb Free Space | 82,86% Space Free | Partition Type: NTFS
Drive E: | 1862,98 Gb Total Space | 251,83 Gb Free Space | 13,52% Space Free | Partition Type: NTFS
 
Computer Name: ALEXANDER-PC | User Name: Alexander | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Alexander\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe ()
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Programme\Lenovo\Power Dial\LenovoCOMSvc.exe (Lenovo)
PRC - C:\Programme\Lenovo\HealthCare\HealthCare.exe (Lenovo)
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Program Files (x86)\jmesoft\hotkey.exe (JME)
PRC - C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe (CyberLink)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\635b3aec298ad5e8c903b2323d79cc5a\IAStorUtil.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf ()
MOD - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\IEAWSDC.DLL ()
MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Programme\Lenovo\HealthCare\de-de\de-de.dll ()
MOD - C:\Program Files (x86)\jmesoft\Keyhook.dll ()
MOD - C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\Lenovo\Power2Go\CLMediaLibrary.dll ()
MOD - C:\Programme\Lenovo\HealthCare\HOOK.dll ()
MOD - C:\Program Files (x86)\jmesoft\VistaVolume.dll ()
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TeamViewer6) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (CEEBC40A-FDED-4C59-B354-939132350B01) -- C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe ()
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (LenovoCOMSvc) -- C:\Programme\Lenovo\Power Dial\LenovoCOMSvc.exe (Lenovo)
SRV - (LitModeCtrl) -- C:\Programme\Lenovo\Power Dial\LitModeCtrl.exe (Lenovo)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (PCLEPCI) -- C:\Windows\SysWOW64\drivers\Pclepci.sys (Pinnacle Systems GmbH)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (Fs_Rec) -- C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Netaapl) -- C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (e1kexpress) Intel(R) -- C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:64bit: - (HECIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (wsvd) -- C:\Windows\SysNative\drivers\wsvd.sys (CyberLink)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8023x64) -- C:\Windows\SysNative\drivers\Rtnic64.sys (Realtek Semiconductor Corporation                          )
DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV:64bit: - (WinI2C-DDC) -- C:\Windows\SysNative\drivers\ddcdrv.sys (Nicomsoft Ltd.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinI2C-DDC) -- C:\Windows\SysWOW64\drivers\ddcdrv.sys (Nicomsoft Ltd.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKCU\..\SearchScopes\{3C0BC5EE-509C-4F39-8F86-65E4B0AE88E4}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=kw&q={searchTerms}&locale=&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=e5d19274-dc94-4216-85ec-df91660e1540&apn_sauid=3C3A364D-1570-48D6-AD06-3323E8488717
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..keyword.URL: "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=e5d19274-dc94-4216-85ec-df91660e1540&apn_ptnrs=%5EABT&apn_sauid=3C3A364D-1570-48D6-AD06-3323E8488717&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q="
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.09.02 13:56:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.09 14:49:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.04.23 11:12:44 | 000,000,000 | ---D | M]
 
[2011.05.06 14:53:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alexander\AppData\Roaming\mozilla\Extensions
[2012.07.09 14:43:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alexander\AppData\Roaming\mozilla\Firefox\Profiles\1gj98tvb.default\extensions
[2012.06.26 11:29:36 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Alexander\AppData\Roaming\mozilla\Firefox\Profiles\1gj98tvb.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.07.09 14:43:26 | 000,000,000 | ---D | M] (Avira SearchFree Toolbar plus Web Protection) -- C:\Users\Alexander\AppData\Roaming\mozilla\Firefox\Profiles\1gj98tvb.default\extensions\toolbar@ask.com
[2012.07.09 14:43:26 | 000,002,344 | ---- | M] () -- C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\searchplugins\askcom.xml
[2012.07.09 14:49:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011.09.02 13:58:50 | 000,550,833 | ---- | M] () (No name found) -- C:\USERS\ALEXANDER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1GJ98TVB.DEFAULT\EXTENSIONS\DIVXWEBPLAYER@DIVX.COM.XPI
[2012.06.15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012.03.07 11:53:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.06.15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.06.15 00:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.06.15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2012.06.15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.06.15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.06.15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll File not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Unattend0000000001{BFA3D12B-66DD-4617-923A-E864BC7D20B5}] C:\Windows\test.bat File not found
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Healthcare] C:\Program Files\Lenovo\HealthCare\HealthCare.exe (Lenovo)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [jmekey] C:\Program Files (x86)\jmesoft\hotkey.exe (JME)
O4 - HKLM..\Run: [ModeSwitch] C:\Program Files\Lenovo\Power Dial\LitModeSwitch.exe (Lenovo)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [EPSON SX110 Series] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFBE.EXE /FU "C:\windows\TEMP\E_S625A.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [EPSON SX110 Series (Kopie 1)] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFBE.EXE /FU "C:\windows\TEMP\E_S16CA.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [ICQ] C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [LicenseValidator] C:\Users\Alexander\AppData\Roaming\Media Center Programs\{1B114589-7FD5-4C3D-9BB7-2EC44B676E03}\LicenseValidator.exe File not found
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000 File not found
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 80.69.100.230 80.69.100.214
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3872B74C-739B-46CC-9095-8D391A06950C}: DhcpNameServer = 80.69.100.230 80.69.100.214
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7A615A3-04EE-4D1E-93BB-435A1386C895}: DhcpNameServer = 10.129.32.1 10.111.81.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F156C076-D5C5-4FBC-A0C5-BE53DFFFBE0B}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.07.24 16:23:24 | 000,000,107 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.07.16 13:51:27 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Malwarebytes
[2012.07.16 13:51:19 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012.07.16 13:51:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.07.16 13:51:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.07.16 13:51:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.07.12 15:38:17 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\url.dll
[2012.07.12 15:38:17 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\url.dll
[2012.07.12 15:38:17 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll
[2012.07.12 15:38:17 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll
[2012.07.12 15:38:15 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll
[2012.07.12 15:38:14 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll
[2012.07.12 15:38:14 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieUnatt.exe
[2012.07.12 15:38:14 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieUnatt.exe
[2012.07.12 15:38:12 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll
[2012.07.12 15:38:12 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\inetcpl.cpl
[2012.07.12 15:38:12 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\inetcpl.cpl
[2012.07.12 15:38:12 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll
[2012.07.12 15:38:12 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll
[2012.07.12 15:07:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msxml3r.dll
[2012.07.12 15:07:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msxml3r.dll
[2012.07.12 15:07:31 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ncrypt.dll
[2012.07.12 15:07:30 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\cdosys.dll
[2012.07.12 15:07:29 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cdosys.dll
[2012.07.09 14:48:48 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Avira
[2012.07.09 14:43:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2012.07.09 14:43:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2012.07.09 14:42:53 | 000,132,832 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avipbb.sys
[2012.07.09 14:42:53 | 000,098,848 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avgntflt.sys
[2012.07.09 14:42:53 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avkmgr.sys
[2012.07.09 14:42:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2012.07.09 14:42:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2012.07.05 12:23:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012.07.05 12:23:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012.07.02 13:32:00 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Help
[2012.06.26 11:29:36 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.06.26 11:29:32 | 000,405,176 | ---- | C] (Newtonsoft) -- C:\windows\SysWow64\Newtonsoft.Json.Net20.dll
[2012.06.24 11:45:47 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\Macromedia
[2012.06.22 10:17:58 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wucltux.dll
[2012.06.22 10:17:58 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuauclt.exe
[2012.06.22 10:17:58 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wups2.dll
[2012.06.22 10:17:48 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapi.dll
[2012.06.22 10:17:48 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wudriver.dll
[2012.06.22 10:17:48 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wups.dll
[2012.06.22 10:17:36 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuwebv.dll
[2012.06.22 10:17:36 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapp.exe
[2010.09.18 12:08:18 | 001,914,000 | ---- | C] (Adobe Systems Incorporated) -- C:\ProgramData\flashax10.exe
[2 C:\Users\Alexander\Documents\*.tmp files -> C:\Users\Alexander\Documents\*.tmp -> ]
[1 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.07.16 15:47:00 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012.07.16 13:54:07 | 000,017,136 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.07.16 13:54:07 | 000,017,136 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.07.16 13:51:19 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.16 13:45:32 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012.07.16 13:45:28 | 479,084,543 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.13 15:47:08 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerApp.exe
[2012.07.13 15:47:08 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2012.07.12 15:44:18 | 000,468,272 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012.07.09 14:49:26 | 000,001,049 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.07.09 14:43:33 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.07.05 12:47:22 | 000,671,712 | ---- | M] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT HEIM 2012-2013 ERW..jpg
[2012.07.05 12:46:42 | 000,666,995 | ---- | M] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT AUSWÄRTS 2012-2013 ERW..jpg
[2012.07.05 12:45:33 | 000,683,498 | ---- | M] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT CL 2012-2013 ERW..jpg
[2012.07.03 15:32:41 | 001,508,114 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012.07.03 15:32:41 | 000,657,218 | ---- | M] () -- C:\windows\SysNative\perfh007.dat
[2012.07.03 15:32:41 | 000,619,100 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012.07.03 15:32:41 | 000,131,430 | ---- | M] () -- C:\windows\SysNative\perfc007.dat
[2012.07.03 15:32:41 | 000,107,820 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012.07.02 14:48:02 | 000,299,581 | ---- | M] () -- C:\Users\Alexander\Desktop\IMG_2400.JPG
[2012.06.26 11:29:32 | 000,001,398 | ---- | M] () -- C:\Users\Alexander\Desktop\Free YouTube to MP3 Converter.lnk
[2 C:\Users\Alexander\Documents\*.tmp files -> C:\Users\Alexander\Documents\*.tmp -> ]
[1 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.07.16 13:51:19 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.07.09 14:49:26 | 000,001,049 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.07.09 14:43:33 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012.07.05 12:47:22 | 000,671,712 | ---- | C] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT HEIM 2012-2013 ERW..jpg
[2012.07.05 12:46:41 | 000,666,995 | ---- | C] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT AUSWÄRTS 2012-2013 ERW..jpg
[2012.07.05 12:45:33 | 000,683,498 | ---- | C] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT CL 2012-2013 ERW..jpg
[2012.07.02 14:52:26 | 000,299,581 | ---- | C] () -- C:\Users\Alexander\Desktop\IMG_2400.JPG
[2012.06.26 11:29:32 | 000,001,398 | ---- | C] () -- C:\Users\Alexander\Desktop\Free YouTube to MP3 Converter.lnk
[2012.02.20 14:33:40 | 000,000,637 | ---- | C] () -- C:\windows\wiso.ini
[2011.10.19 13:45:13 | 002,598,496 | ---- | C] () -- C:\Users\Alexander\div_2710_mcc_flyerwinter_96dpi.pdf
[2011.10.17 12:43:13 | 000,000,000 | ---- | C] () -- C:\Users\Alexander\AppData\Local\{3D878AC3-19AB-4A5B-9BEC-AA2A6B33B33F}
[2011.09.14 11:25:52 | 000,000,000 | ---- | C] () -- C:\Users\Alexander\AppData\Local\{4E3A7BAC-D630-438E-A27D-1A16579A8744}
[2011.09.06 14:57:36 | 000,042,672 | ---- | C] () -- C:\windows\SysWow64\drivers\fsbts.sys
[2011.08.15 16:12:07 | 000,005,632 | ---- | C] () -- C:\Users\Alexander\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.24 16:57:07 | 000,000,017 | ---- | C] () -- C:\windows\MovingPicture.ini
[2011.07.24 16:23:24 | 000,196,096 | ---- | C] () -- C:\windows\SysWow64\macd32.dll
[2011.07.24 16:23:24 | 000,138,752 | ---- | C] () -- C:\windows\SysWow64\mase32.dll
[2011.07.24 16:23:24 | 000,136,192 | ---- | C] () -- C:\windows\SysWow64\mamc32.dll
[2011.07.24 16:23:24 | 000,057,856 | ---- | C] () -- C:\windows\SysWow64\masd32.dll
[2011.07.24 16:23:24 | 000,027,648 | ---- | C] () -- C:\windows\SysWow64\ma32.dll
[2011.05.28 15:00:55 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011.05.06 15:30:08 | 001,534,796 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2010.09.18 21:38:51 | 000,201,728 | ---- | C] () -- C:\windows\SetDrive.exe
[2010.09.18 21:38:50 | 000,036,864 | ---- | C] () -- C:\windows\WinWait.exe
 
========== LOP Check ==========
 
[2012.05.04 12:48:26 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\Amazon
[2012.02.22 23:49:05 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\Buhl Data Service
[2012.06.26 11:30:00 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\DVDVideoSoft
[2012.06.26 11:29:36 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\DVDVideoSoftIEHelpers
[2012.07.10 16:05:08 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\ICQ
[2011.07.20 20:11:42 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\ImgBurn
[2011.06.08 17:21:21 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\IrfanView
[2011.07.02 15:50:35 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\MAGIX
[2011.07.24 16:56:05 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\proDAD
[2012.07.09 14:50:19 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\SoftGrid Client
[2012.07.02 13:27:06 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\TeamViewer
[2011.05.06 15:45:24 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\TP
[2012.02.27 18:09:06 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\XMedia Recode
[2011.09.09 15:19:00 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\YoudaGames
[2012.05.06 12:21:10 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 

< End of report >

--- --- ---


es kommt jedoch nur ein otl-file

t'john 16.07.2012 15:53

Bitte poste noch das Logfile von Malwarebytes mit den Funden!


Fixen mit OTL


Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).

  • Deaktiviere etwaige Virenscanner wie Avira, Kaspersky etc.
  • Starte die OTL.exe.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Kopiere folgendes Skript in das Textfeld unterhalb von Benuterdefinierte Scans/Fixes:


Code:

:OTL
PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
IE - HKCU\..\SearchScopes\{3C0BC5EE-509C-4F39-8F86-65E4B0AE88E4}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=kw&q={searchTerms}&locale=&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=e5d19274-dc94-4216-85ec-df91660e1540&apn_sauid=3C3A364D-1570-48D6-AD06-3323E8488717
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=e5d19274-dc94-4216-85ec-df91660e1540&apn_ptnrs=%5EABT&apn_sauid=3C3A364D-1570-48D6-AD06-3323E8488717&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q="
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Unattend0000000001{BFA3D12B-66DD-4617-923A-E864BC7D20B5}] C:\Windows\test.bat File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKCU..\Run: [EPSON SX110 Series] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFBE.EXE /FU "C:\windows\TEMP\E_S625A.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [EPSON SX110 Series (Kopie 1)] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFBE.EXE /FU "C:\windows\TEMP\E_S16CA.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [LicenseValidator] C:\Users\Alexander\AppData\Roaming\Media Center Programs\{1B114589-7FD5-4C3D-9BB7-2EC44B676E03}\LicenseValidator.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O32 - HKLM CDRom: AutoRun - 1

:Files

ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[emptyflash]

  • Schließe alle Programme.
  • Klicke auf den Fix Button.
  • Wenn OTL einen Neustart verlangt, bitte zulassen.
  • Kopiere den Inhalt des Logfiles hier in Code-Tags in Deinen Thread.
    Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\

Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

lively1986 16.07.2012 19:33

Hallo, das ergab Malwarebytes (OTL folgt):

Malwarebytes Anti-Malware 1.62.0.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Datenbank Version: v2012.07.16.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Alexander :: ALEXANDER-PC [Administrator]

16.07.2012 17:21:02
mbam-log-2012-07-16 (17-21-02).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|Q:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 559253
Laufzeit: 1 Stunde(n), 1 Minute(n), 33 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\Alexander\AppData\Roaming\Identities\{1CF46883-13D3-4B50-AE26-C92B644C8A6F}\LicenseValidator.exe (Trojan.Phex.THAGen4) -> Erfolgreich gelöscht und in Quarantäne gestellt.
E:\Musik\NEU JULI 2007 (1)\U W E 6.7.07\Dr.Best Juli 07\DVD 1\DATEN\Winamp v5.05\Key Generator.exe (RiskWare.Tool.CK) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

t'john 16.07.2012 19:34

Bitte den Fix durchfuehren.

http://www.trojaner-board.de/119061-...tml#post866444

lively1986 16.07.2012 19:40

Hallo, habe den Fix durchgeführt und finde auch unter C:\_OTL einen Ordner. Wie kann ich den Log posten? (Sorry, bin da nicht so fit drin)

Hat geklappt:


Error: Unable to interpret <OTL Logfile:
Code:

OTL logfile created on: 16.07.2012 16:31:33 - Run 2> in the current context!
Error: Unable to interpret <OTL by OldTimer - Version 3.2.54.0    Folder = C:\Users\Alexander\Downloads> in the current context!
Error: Unable to interpret <64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation> in the current context!
Error: Unable to interpret <Internet Explorer (Version = 9.0.8112.16421)> in the current context!
Error: Unable to interpret <Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <5,93 Gb Total Physical Memory | 3,69 Gb Available Physical Memory | 62,31% Memory free> in the current context!
Error: Unable to interpret <11,85 Gb Paging File | 9,53 Gb Available in Paging File | 80,41% Paging File free> in the current context!
Error: Unable to interpret <Paging file location(s): ?:\pagefile.sys [binary data]> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)> in the current context!
Error: Unable to interpret <Drive C: | 906,34 Gb Total Space | 751,00 Gb Free Space | 82,86% Space Free | Partition Type: NTFS> in the current context!
Error: Unable to interpret <Drive E: | 1862,98 Gb Total Space | 251,83 Gb Free Space | 13,52% Space Free | Partition Type: NTFS> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <Computer Name: ALEXANDER-PC | User Name: Alexander | Logged in as Administrator.> in the current context!
Error: Unable to interpret <Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans> in the current context!
Error: Unable to interpret <Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Processes (SafeList) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <PRC - C:\Users\Alexander\Downloads\OTL.exe (OldTimer Tools)> in the current context!
Error: Unable to interpret <PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe (Adobe Systems, Inc.)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe ()> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)> in the current context!
Error: Unable to interpret <PRC - C:\Programme\Lenovo\Power Dial\LenovoCOMSvc.exe (Lenovo)> in the current context!
Error: Unable to interpret <PRC - C:\Programme\Lenovo\HealthCare\HealthCare.exe (Lenovo)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\jmesoft\hotkey.exe (JME)> in the current context!
Error: Unable to interpret <PRC - C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe (CyberLink)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Modules (No Company Name) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\635b3aec298ad5e8c903b2323d79cc5a\IAStorUtil.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf ()> in the current context!
Error: Unable to interpret <MOD - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\Microsoft Office\Office14\IEAWSDC.DLL ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_de_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Programme\Lenovo\HealthCare\de-de\de-de.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\jmesoft\Keyhook.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvcPS.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\Lenovo\Power2Go\CLMediaLibrary.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Programme\Lenovo\HealthCare\HOOK.dll ()> in the current context!
Error: Unable to interpret <MOD - C:\Program Files (x86)\jmesoft\VistaVolume.dll ()> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Win32 Services (SafeList) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)> in the current context!
Error: Unable to interpret <SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)> in the current context!
Error: Unable to interpret <SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)> in the current context!
Error: Unable to interpret <SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)> in the current context!
Error: Unable to interpret <SRV - (TeamViewer6) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)> in the current context!
Error: Unable to interpret <SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)> in the current context!
Error: Unable to interpret <SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <SRV - (IAStorDataMgrSvc) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)> in the current context!
Error: Unable to interpret <SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)> in the current context!
Error: Unable to interpret <SRV - (CEEBC40A-FDED-4C59-B354-939132350B01) -- C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe ()> in the current context!
Error: Unable to interpret <SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)> in the current context!
Error: Unable to interpret <SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)> in the current context!
Error: Unable to interpret <SRV - (LenovoCOMSvc) -- C:\Programme\Lenovo\Power Dial\LenovoCOMSvc.exe (Lenovo)> in the current context!
Error: Unable to interpret <SRV - (LitModeCtrl) -- C:\Programme\Lenovo\Power Dial\LitModeCtrl.exe (Lenovo)> in the current context!
Error: Unable to interpret <SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)> in the current context!
Error: Unable to interpret <SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)> in the current context!
Error: Unable to interpret <SRV - (PCLEPCI) -- C:\Windows\SysWOW64\drivers\Pclepci.sys (Pinnacle Systems GmbH)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Driver Services (SafeList) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)> in the current context!
Error: Unable to interpret <DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)> in the current context!
Error: Unable to interpret <DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)> in the current context!
Error: Unable to interpret <DRV:64bit: - (Fs_Rec) -- C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (Netaapl) -- C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)> in the current context!
Error: Unable to interpret <DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)> in the current context!
Error: Unable to interpret <DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)> in the current context!
Error: Unable to interpret <DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)> in the current context!
Error: Unable to interpret <DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)> in the current context!
Error: Unable to interpret <DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (e1kexpress) Intel(R) -- C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (HECIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (wsvd) -- C:\Windows\SysNative\drivers\wsvd.sys (CyberLink)> in the current context!
Error: Unable to interpret <DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)> in the current context!
Error: Unable to interpret <DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (RTL8023x64) -- C:\Windows\SysNative\drivers\Rtnic64.sys (Realtek Semiconductor Corporation                          )> in the current context!
Error: Unable to interpret <DRV:64bit: - (yukonw7) -- C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)> in the current context!
Error: Unable to interpret <DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)> in the current context!
Error: Unable to interpret <DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV:64bit: - (WinI2C-DDC) -- C:\Windows\SysNative\drivers\ddcdrv.sys (Nicomsoft Ltd.)> in the current context!
Error: Unable to interpret <DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)> in the current context!
Error: Unable to interpret <DRV - (WinI2C-DDC) -- C:\Windows\SysWOW64\drivers\ddcdrv.sys (Nicomsoft Ltd.)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Standard Registry (SafeList) ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Internet Explorer ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}> in the current context!
Error: Unable to interpret <IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC> in the current context!
Error: Unable to interpret <IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm> in the current context!
Error: Unable to interpret <IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}> in the current context!
Error: Unable to interpret <IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/ [binary data]> in the current context!
Error: Unable to interpret <IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo.msn.com> in the current context!
Error: Unable to interpret <IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}> in the current context!
Error: Unable to interpret <IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox> in the current context!
Error: Unable to interpret <IE - HKCU\..\SearchScopes\{3C0BC5EE-509C-4F39-8F86-65E4B0AE88E4}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=kw&q={searchTerms}&locale=&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=e5d19274-dc94-4216-85ec-df91660e1540&apn_sauid=3C3A364D-1570-48D6-AD06-3323E8488717> in the current context!
Error: Unable to interpret <IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0> in the current context!
Error: Unable to interpret <IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== FireFox ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <FF - prefs.js..browser.search.defaultengine: "Ask.com"> in the current context!
Error: Unable to interpret <FF - prefs.js..browser.search.defaultenginename: "Ask.com"> in the current context!
Error: Unable to interpret <FF - prefs.js..browser.search.order.1: "Ask.com"> in the current context!
Error: Unable to interpret <FF - prefs.js..browser.search.selectedEngine: "Google"> in the current context!
Error: Unable to interpret <FF - prefs.js..keyword.URL: "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=e5d19274-dc94-4216-85ec-df91660e1540&apn_ptnrs=%5EABT&apn_sauid=3C3A364D-1570-48D6-AD06-3323E8488717&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q="> in the current context!
Error: Unable to interpret <FF - user.js - File not found> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found> in the current context!
Error: Unable to interpret <FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)> in the current context!
Error: Unable to interpret <FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)> in the current context!
Error: Unable to interpret <FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.09.02 13:56:38 | 000,000,000 | ---D | M]> in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.07.09 14:49:24 | 000,000,000 | ---D | M]> in the current context!
Error: Unable to interpret <FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.04.23 11:12:44 | 000,000,000 | ---D | M]> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2011.05.06 14:53:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alexander\AppData\Roaming\mozilla\Extensions> in the current context!
Error: Unable to interpret <[2012.07.09 14:43:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alexander\AppData\Roaming\mozilla\Firefox\Profiles\1gj98tvb.default\extensions> in the current context!
Error: Unable to interpret <[2012.06.26 11:29:36 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Alexander\AppData\Roaming\mozilla\Firefox\Profiles\1gj98tvb.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}> in the current context!
Error: Unable to interpret <[2012.07.09 14:43:26 | 000,000,000 | ---D | M] (Avira SearchFree Toolbar plus Web Protection) -- C:\Users\Alexander\AppData\Roaming\mozilla\Firefox\Profiles\1gj98tvb.default\extensions\toolbar@ask.com> in the current context!
Error: Unable to interpret <[2012.07.09 14:43:26 | 000,002,344 | ---- | M] () -- C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\searchplugins\askcom.xml> in the current context!
Error: Unable to interpret <[2012.07.09 14:49:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions> in the current context!
Error: Unable to interpret <[2011.09.02 13:58:50 | 000,550,833 | ---- | M] () (No name found) -- C:\USERS\ALEXANDER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1GJ98TVB.DEFAULT\EXTENSIONS\DIVXWEBPLAYER@DIVX.COM.XPI> in the current context!
Error: Unable to interpret <[2012.06.15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll> in the current context!
Error: Unable to interpret <[2012.03.07 11:53:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll> in the current context!
Error: Unable to interpret <[2012.06.15 00:46:57 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml> in the current context!
Error: Unable to interpret <[2012.06.15 00:46:56 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml> in the current context!
Error: Unable to interpret <[2012.06.15 00:46:57 | 000,001,153 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml> in the current context!
Error: Unable to interpret <[2012.06.15 00:46:57 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml> in the current context!
Error: Unable to interpret <[2012.06.15 00:46:57 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml> in the current context!
Error: Unable to interpret <[2012.06.15 00:46:56 | 000,001,105 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts> in the current context!
Error: Unable to interpret <O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)> in the current context!
Error: Unable to interpret <O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)> in the current context!
Error: Unable to interpret <O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll File not found> in the current context!
Error: Unable to interpret <O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)> in the current context!
Error: Unable to interpret <O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)> in the current context!
Error: Unable to interpret <O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.> in the current context!
Error: Unable to interpret <O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)> in the current context!
Error: Unable to interpret <O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.> in the current context!
Error: Unable to interpret <O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.> in the current context!
Error: Unable to interpret <O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)> in the current context!
Error: Unable to interpret <O4:64bit: - HKLM..\Run: [Unattend0000000001{BFA3D12B-66DD-4617-923A-E864BC7D20B5}] C:\Windows\test.bat File not found> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: []  File not found> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe (CyberLink)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [Healthcare] C:\Program Files\Lenovo\HealthCare\HealthCare.exe (Lenovo)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [jmekey] C:\Program Files (x86)\jmesoft\hotkey.exe (JME)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [ModeSwitch] C:\Program Files\Lenovo\Power Dial\LitModeSwitch.exe (Lenovo)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)> in the current context!
Error: Unable to interpret <O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [EPSON SX110 Series] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFBE.EXE /FU "C:\windows\TEMP\E_S625A.tmp" /EF "HKCU" File not found> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [EPSON SX110 Series (Kopie 1)] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFBE.EXE /FU "C:\windows\TEMP\E_S16CA.tmp" /EF "HKCU" File not found> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [ICQ] C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)> in the current context!
Error: Unable to interpret <O4 - HKCU..\Run: [LicenseValidator] C:\Users\Alexander\AppData\Roaming\Media Center Programs\{1B114589-7FD5-4C3D-9BB7-2EC44B676E03}\LicenseValidator.exe File not found> in the current context!
Error: Unable to interpret <O4 - HKLM..\RunOnce: [ Malwarebytes Anti-Malware ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5> in the current context!
Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3> in the current context!
Error: Unable to interpret <O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105 File not found> in the current context!
Error: Unable to interpret <O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000 File not found> in the current context!
Error: Unable to interpret <O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105 File not found> in the current context!
Error: Unable to interpret <O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000 File not found> in the current context!
Error: Unable to interpret <O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)> in the current context!
Error: Unable to interpret <O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe (ICQ, LLC.)> in the current context!
Error: Unable to interpret <O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)> in the current context!
Error: Unable to interpret <O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)> in the current context!
Error: Unable to interpret <O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)> in the current context!
Error: Unable to interpret <O1364bit: - gopher Prefix: missing> in the current context!
Error: Unable to interpret <O13 - gopher Prefix: missing> in the current context!
Error: Unable to interpret <O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)> in the current context!
Error: Unable to interpret <O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)> in the current context!
Error: Unable to interpret <O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)> in the current context!
Error: Unable to interpret <O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 80.69.100.230 80.69.100.214> in the current context!
Error: Unable to interpret <O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3872B74C-739B-46CC-9095-8D391A06950C}: DhcpNameServer = 80.69.100.230 80.69.100.214> in the current context!
Error: Unable to interpret <O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7A615A3-04EE-4D1E-93BB-435A1386C895}: DhcpNameServer = 10.129.32.1 10.111.81.129> in the current context!
Error: Unable to interpret <O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F156C076-D5C5-4FBC-A0C5-BE53DFFFBE0B}: DhcpNameServer = 192.168.0.1> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\livecall - No CLSID value found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\ms-help - No CLSID value found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\msnim - No CLSID value found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Handler\wlpg - No CLSID value found> in the current context!
Error: Unable to interpret <O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) -  File not found> in the current context!
Error: Unable to interpret <O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found> in the current context!
Error: Unable to interpret <O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.> in the current context!
Error: Unable to interpret <O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.> in the current context!
Error: Unable to interpret <O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL (Microsoft Corporation)> in the current context!
Error: Unable to interpret <O32 - HKLM CDRom: AutoRun - 1> in the current context!
Error: Unable to interpret <O32 - AutoRun File - [2011.07.24 16:23:24 | 000,000,107 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]> in the current context!
Error: Unable to interpret <O34 - HKLM BootExecute: (autocheck autochk *)> in the current context!
Error: Unable to interpret <O35:64bit: - HKLM\..comfile [open] -- "%1" %*> in the current context!
Error: Unable to interpret <O35:64bit: - HKLM\..exefile [open] -- "%1" %*> in the current context!
Error: Unable to interpret <O35 - HKLM\..comfile [open] -- "%1" %*> in the current context!
Error: Unable to interpret <O35 - HKLM\..exefile [open] -- "%1" %*> in the current context!
Error: Unable to interpret <O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*> in the current context!
Error: Unable to interpret <O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*> in the current context!
Error: Unable to interpret <O37 - HKLM\...com [@ = comfile] -- "%1" %*> in the current context!
Error: Unable to interpret <O37 - HKLM\...exe [@ = exefile] -- "%1" %*> in the current context!
Error: Unable to interpret <O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)> in the current context!
Error: Unable to interpret <O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)> in the current context!
Error: Unable to interpret <O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Files/Folders - Created Within 30 Days ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2012.07.16 13:51:27 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Malwarebytes> in the current context!
Error: Unable to interpret <[2012.07.16 13:51:19 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys> in the current context!
Error: Unable to interpret <[2012.07.16 13:51:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware> in the current context!
Error: Unable to interpret <[2012.07.16 13:51:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware> in the current context!
Error: Unable to interpret <[2012.07.16 13:51:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:17 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\url.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:17 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\url.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:17 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\mshtmled.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:17 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\mshtmled.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:15 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieui.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:14 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieui.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:14 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ieUnatt.exe> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:14 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\ieUnatt.exe> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:12 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript9.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:12 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\inetcpl.cpl> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:12 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\inetcpl.cpl> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:12 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\jscript.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:38:12 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\jscript.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:07:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\msxml3r.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:07:41 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\msxml3r.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:07:31 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\ncrypt.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:07:30 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\windows\SysWow64\cdosys.dll> in the current context!
Error: Unable to interpret <[2012.07.12 15:07:29 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\cdosys.dll> in the current context!
Error: Unable to interpret <[2012.07.09 14:48:48 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Avira> in the current context!
Error: Unable to interpret <[2012.07.09 14:43:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira> in the current context!
Error: Unable to interpret <[2012.07.09 14:43:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com> in the current context!
Error: Unable to interpret <[2012.07.09 14:42:53 | 000,132,832 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avipbb.sys> in the current context!
Error: Unable to interpret <[2012.07.09 14:42:53 | 000,098,848 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avgntflt.sys> in the current context!
Error: Unable to interpret <[2012.07.09 14:42:53 | 000,027,760 | ---- | C] (Avira GmbH) -- C:\windows\SysNative\drivers\avkmgr.sys> in the current context!
Error: Unable to interpret <[2012.07.09 14:42:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira> in the current context!
Error: Unable to interpret <[2012.07.09 14:42:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira> in the current context!
Error: Unable to interpret <[2012.07.05 12:23:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy> in the current context!
Error: Unable to interpret <[2012.07.05 12:23:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy> in the current context!
Error: Unable to interpret <[2012.07.02 13:32:00 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\Help> in the current context!
Error: Unable to interpret <[2012.06.26 11:29:36 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Roaming\DVDVideoSoftIEHelpers> in the current context!
Error: Unable to interpret <[2012.06.26 11:29:32 | 000,405,176 | ---- | C] (Newtonsoft) -- C:\windows\SysWow64\Newtonsoft.Json.Net20.dll> in the current context!
Error: Unable to interpret <[2012.06.24 11:45:47 | 000,000,000 | ---D | C] -- C:\Users\Alexander\AppData\Local\Macromedia> in the current context!
Error: Unable to interpret <[2012.06.22 10:17:58 | 002,622,464 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wucltux.dll> in the current context!
Error: Unable to interpret <[2012.06.22 10:17:58 | 000,057,880 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuauclt.exe> in the current context!
Error: Unable to interpret <[2012.06.22 10:17:58 | 000,044,056 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wups2.dll> in the current context!
Error: Unable to interpret <[2012.06.22 10:17:48 | 000,701,976 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapi.dll> in the current context!
Error: Unable to interpret <[2012.06.22 10:17:48 | 000,099,840 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wudriver.dll> in the current context!
Error: Unable to interpret <[2012.06.22 10:17:48 | 000,038,424 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wups.dll> in the current context!
Error: Unable to interpret <[2012.06.22 10:17:36 | 000,186,752 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuwebv.dll> in the current context!
Error: Unable to interpret <[2012.06.22 10:17:36 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\windows\SysNative\wuapp.exe> in the current context!
Error: Unable to interpret <[2010.09.18 12:08:18 | 001,914,000 | ---- | C] (Adobe Systems Incorporated) -- C:\ProgramData\flashax10.exe> in the current context!
Error: Unable to interpret <[2 C:\Users\Alexander\Documents\*.tmp files -> C:\Users\Alexander\Documents\*.tmp -> ]> in the current context!
Error: Unable to interpret <[1 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Files - Modified Within 30 Days ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2012.07.16 15:47:00 | 000,000,884 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job> in the current context!
Error: Unable to interpret <[2012.07.16 13:54:07 | 000,017,136 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0> in the current context!
Error: Unable to interpret <[2012.07.16 13:54:07 | 000,017,136 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0> in the current context!
Error: Unable to interpret <[2012.07.16 13:51:19 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk> in the current context!
Error: Unable to interpret <[2012.07.16 13:45:32 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat> in the current context!
Error: Unable to interpret <[2012.07.16 13:45:28 | 479,084,543 | -HS- | M] () -- C:\hiberfil.sys> in the current context!
Error: Unable to interpret <[2012.07.13 15:47:08 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerApp.exe> in the current context!
Error: Unable to interpret <[2012.07.13 15:47:08 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\SysWow64\FlashPlayerCPLApp.cpl> in the current context!
Error: Unable to interpret <[2012.07.12 15:44:18 | 000,468,272 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT> in the current context!
Error: Unable to interpret <[2012.07.09 14:49:26 | 000,001,049 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk> in the current context!
Error: Unable to interpret <[2012.07.09 14:43:33 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk> in the current context!
Error: Unable to interpret <[2012.07.05 12:47:22 | 000,671,712 | ---- | M] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT HEIM 2012-2013 ERW..jpg> in the current context!
Error: Unable to interpret <[2012.07.05 12:46:42 | 000,666,995 | ---- | M] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT AUSWÄRTS 2012-2013 ERW..jpg> in the current context!
Error: Unable to interpret <[2012.07.05 12:45:33 | 000,683,498 | ---- | M] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT CL 2012-2013 ERW..jpg> in the current context!
Error: Unable to interpret <[2012.07.03 15:32:41 | 001,508,114 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI> in the current context!
Error: Unable to interpret <[2012.07.03 15:32:41 | 000,657,218 | ---- | M] () -- C:\windows\SysNative\perfh007.dat> in the current context!
Error: Unable to interpret <[2012.07.03 15:32:41 | 000,619,100 | ---- | M] () -- C:\windows\SysNative\perfh009.dat> in the current context!
Error: Unable to interpret <[2012.07.03 15:32:41 | 000,131,430 | ---- | M] () -- C:\windows\SysNative\perfc007.dat> in the current context!
Error: Unable to interpret <[2012.07.03 15:32:41 | 000,107,820 | ---- | M] () -- C:\windows\SysNative\perfc009.dat> in the current context!
Error: Unable to interpret <[2012.07.03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys> in the current context!
Error: Unable to interpret <[2012.07.02 14:48:02 | 000,299,581 | ---- | M] () -- C:\Users\Alexander\Desktop\IMG_2400.JPG> in the current context!
Error: Unable to interpret <[2012.06.26 11:29:32 | 000,001,398 | ---- | M] () -- C:\Users\Alexander\Desktop\Free YouTube to MP3 Converter.lnk> in the current context!
Error: Unable to interpret <[2 C:\Users\Alexander\Documents\*.tmp files -> C:\Users\Alexander\Documents\*.tmp -> ]> in the current context!
Error: Unable to interpret <[1 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Files Created - No Company Name ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2012.07.16 13:51:19 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk> in the current context!
Error: Unable to interpret <[2012.07.09 14:49:26 | 000,001,049 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk> in the current context!
Error: Unable to interpret <[2012.07.09 14:43:33 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk> in the current context!
Error: Unable to interpret <[2012.07.05 12:47:22 | 000,671,712 | ---- | C] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT HEIM 2012-2013 ERW..jpg> in the current context!
Error: Unable to interpret <[2012.07.05 12:46:41 | 000,666,995 | ---- | C] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT AUSWÄRTS 2012-2013 ERW..jpg> in the current context!
Error: Unable to interpret <[2012.07.05 12:45:33 | 000,683,498 | ---- | C] () -- C:\Users\Alexander\Desktop\KURZARM-TRIKOT CL 2012-2013 ERW..jpg> in the current context!
Error: Unable to interpret <[2012.07.02 14:52:26 | 000,299,581 | ---- | C] () -- C:\Users\Alexander\Desktop\IMG_2400.JPG> in the current context!
Error: Unable to interpret <[2012.06.26 11:29:32 | 000,001,398 | ---- | C] () -- C:\Users\Alexander\Desktop\Free YouTube to MP3 Converter.lnk> in the current context!
Error: Unable to interpret <[2012.02.20 14:33:40 | 000,000,637 | ---- | C] () -- C:\windows\wiso.ini> in the current context!
Error: Unable to interpret <[2011.10.19 13:45:13 | 002,598,496 | ---- | C] () -- C:\Users\Alexander\div_2710_mcc_flyerwinter_96dpi.pdf> in the current context!
Error: Unable to interpret <[2011.10.17 12:43:13 | 000,000,000 | ---- | C] () -- C:\Users\Alexander\AppData\Local\{3D878AC3-19AB-4A5B-9BEC-AA2A6B33B33F}> in the current context!
Error: Unable to interpret <[2011.09.14 11:25:52 | 000,000,000 | ---- | C] () -- C:\Users\Alexander\AppData\Local\{4E3A7BAC-D630-438E-A27D-1A16579A8744}> in the current context!
Error: Unable to interpret <[2011.09.06 14:57:36 | 000,042,672 | ---- | C] () -- C:\windows\SysWow64\drivers\fsbts.sys> in the current context!
Error: Unable to interpret <[2011.08.15 16:12:07 | 000,005,632 | ---- | C] () -- C:\Users\Alexander\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini> in the current context!
Error: Unable to interpret <[2011.07.24 16:57:07 | 000,000,017 | ---- | C] () -- C:\windows\MovingPicture.ini> in the current context!
Error: Unable to interpret <[2011.07.24 16:23:24 | 000,196,096 | ---- | C] () -- C:\windows\SysWow64\macd32.dll> in the current context!
Error: Unable to interpret <[2011.07.24 16:23:24 | 000,138,752 | ---- | C] () -- C:\windows\SysWow64\mase32.dll> in the current context!
Error: Unable to interpret <[2011.07.24 16:23:24 | 000,136,192 | ---- | C] () -- C:\windows\SysWow64\mamc32.dll> in the current context!
Error: Unable to interpret <[2011.07.24 16:23:24 | 000,057,856 | ---- | C] () -- C:\windows\SysWow64\masd32.dll> in the current context!
Error: Unable to interpret <[2011.07.24 16:23:24 | 000,027,648 | ---- | C] () -- C:\windows\SysWow64\ma32.dll> in the current context!
Error: Unable to interpret <[2011.05.28 15:00:55 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib> in the current context!
Error: Unable to interpret <[2011.05.06 15:30:08 | 001,534,796 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI> in the current context!
Error: Unable to interpret <[2010.09.18 21:38:51 | 000,201,728 | ---- | C] () -- C:\windows\SetDrive.exe> in the current context!
Error: Unable to interpret <[2010.09.18 21:38:50 | 000,036,864 | ---- | C] () -- C:\windows\WinWait.exe> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== LOP Check ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <[2012.05.04 12:48:26 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\Amazon> in the current context!
Error: Unable to interpret <[2012.02.22 23:49:05 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\Buhl Data Service> in the current context!
Error: Unable to interpret <[2012.06.26 11:30:00 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\DVDVideoSoft> in the current context!
Error: Unable to interpret <[2012.06.26 11:29:36 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\DVDVideoSoftIEHelpers> in the current context!
Error: Unable to interpret <[2012.07.10 16:05:08 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\ICQ> in the current context!
Error: Unable to interpret <[2011.07.20 20:11:42 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\ImgBurn> in the current context!
Error: Unable to interpret <[2011.06.08 17:21:21 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\IrfanView> in the current context!
Error: Unable to interpret <[2011.07.02 15:50:35 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\MAGIX> in the current context!
Error: Unable to interpret <[2011.07.24 16:56:05 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\proDAD> in the current context!
Error: Unable to interpret <[2012.07.09 14:50:19 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\SoftGrid Client> in the current context!
Error: Unable to interpret <[2012.07.02 13:27:06 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\TeamViewer> in the current context!
Error: Unable to interpret <[2011.05.06 15:45:24 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\TP> in the current context!
Error: Unable to interpret <[2012.02.27 18:09:06 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\XMedia Recode> in the current context!
Error: Unable to interpret <[2011.09.09 15:19:00 | 000,000,000 | ---D | M] -- C:\Users\Alexander\AppData\Roaming\YoudaGames> in the current context!
Error: Unable to interpret <[2012.05.06 12:21:10 | 000,032,640 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret <========== Purity Check ==========> in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret < > in the current context!
Error: Unable to interpret << End of report >

--- --- ---
> in the current context!
Error: Unable to interpret < > in the current context!

OTL by OldTimer - Version 3.2.54.0 log created on 07162012_204814

t'john 16.07.2012 19:52

FALSCH!

du hast dein Log ins Fenster reinkopiert statt des FIX!

Nochmal: http://www.trojaner-board.de/119061-...tml#post866444

lively1986 16.07.2012 19:58

Jetzt korrekt?

All processes killed
========== OTL ==========
No active process named Program Files was found!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3C0BC5EE-509C-4F39-8F86-65E4B0AE88E4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C0BC5EE-509C-4F39-8F86-65E4B0AE88E4}\ not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "Google" removed from browser.search.selectedEngine
Prefs.js: "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=e5d19274-dc94-4216-85ec-df91660e1540&apn_ptnrs=%5EABT&apn_sauid=3C3A364D-1570-48D6-AD06-3323E8488717&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q=" removed from keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Unattend0000000001{BFA3D12B-66DD-4617-923A-E864BC7D20B5} not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater not found.
File C:\Program Files (x86)\Ask.com\Updater\Updater.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate not found.
File C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EPSON SX110 Series not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EPSON SX110 Series (Kopie 1) not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LicenseValidator not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Alexander\Desktop\cmd.bat deleted successfully.
C:\Users\Alexander\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Alexander
->Temp folder emptied: 20950582 bytes
->Temporary Internet Files folder emptied: 337174517 bytes
->Java cache emptied: 1062074 bytes
->FireFox cache emptied: 50318397 bytes
->Flash cache emptied: 1474 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 468653050 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 838,00 mb


[EMPTYFLASH]

User: Alexander
->Flash cache emptied: 0 bytes

User: All Users

User: Default

User: Default User

User: Public

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.54.0 log created on 07162012_205439

Files\Folders moved on Reboot...
C:\Users\Alexander\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...
File C:\Users\Alexander\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!

Registry entries deleted on Reboot...

t'john 16.07.2012 19:59

Ja, das war korrekt!

Downloade Dir bitte AdwCleaner auf deinen Desktop.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

lively1986 16.07.2012 20:01

# AdwCleaner v1.702 - Logfile created 07/16/2012 at 21:01:07
# Updated 13/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Alexander - ALEXANDER-PC
# Running from : C:\Users\Alexander\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\Alexander\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Alexander\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\extensions\toolbar@ask.com
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Found : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\searchplugins\Askcom.xml

***** [Registry] *****

Key Found : HKCU\Software\APN
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKLM\SOFTWARE\APN
Key Found : HKLM\SOFTWARE\AskToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
[x64] Key Found : HKCU\Software\APN
[x64] Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
[x64] Key Found : HKCU\Software\Ask.com
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Classes\S
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\prefs.js

Found : user_pref("extensions.asktb.ff-original-keyword-url", "");
Found : user_pref("extensions.enabledAddons", "DivXWebPlayer@divx.com:2.0.2.039,{972ce4c6-7e08-4474-a285-320[...]

*************************

AdwCleaner[R1].txt - [4576 octets] - [16/07/2012 21:01:07]

########## EOF - C:\AdwCleaner[R1].txt - [4704 octets] ##########

# AdwCleaner v1.702 - Logfile created 07/16/2012 at 21:01:07
# Updated 13/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Alexander - ALEXANDER-PC
# Running from : C:\Users\Alexander\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : C:\Users\Alexander\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Alexander\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\extensions\toolbar@ask.com
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Found : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\searchplugins\Askcom.xml

***** [Registry] *****

Key Found : HKCU\Software\APN
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKLM\SOFTWARE\APN
Key Found : HKLM\SOFTWARE\AskToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
[x64] Key Found : HKCU\Software\APN
[x64] Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
[x64] Key Found : HKCU\Software\Ask.com
[x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
[x64] Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
[x64] Key Found : HKLM\SOFTWARE\Classes\S
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar
[x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

***** [Registre - GUID] *****

Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
[x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
[x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
[x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
[x64] Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\prefs.js

Found : user_pref("extensions.asktb.ff-original-keyword-url", "");
Found : user_pref("extensions.enabledAddons", "DivXWebPlayer@divx.com:2.0.2.039,{972ce4c6-7e08-4474-a285-320[...]

*************************

AdwCleaner[R1].txt - [4576 octets] - [16/07/2012 21:01:07]

########## EOF - C:\AdwCleaner[R1].txt - [4704 octets] ##########

t'john 16.07.2012 20:03

Sehr gut! :daumenhoc

Wie laeuft der Rechner?

  • Schließe alle offenen Programme und Browser.
  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Delete.
  • Bestätige jeweils mit Ok.
  • Dein Rechner wird neu gestartet. Nach dem Neustart öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[S1].txt.

lively1986 16.07.2012 20:09

Läuft super. Tausend Dank! Ohne Dich wäre ich aufgeschmissen gewesen... ***TOP***

# AdwCleaner v1.702 - Logfile created 07/16/2012 at 21:05:27
# Updated 13/07/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Alexander - ALEXANDER-PC
# Running from : C:\Users\Alexander\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Alexander\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Alexander\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\extensions\toolbar@ask.com
Folder Deleted : C:\Program Files (x86)\Ask.com
Folder Deleted : C:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
File Deleted : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\searchplugins\Askcom.xml

***** [Registry] *****

Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\APN
Key Deleted : HKLM\SOFTWARE\AskToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v13.0.1 (de)

Profile name : default
File : C:\Users\Alexander\AppData\Roaming\Mozilla\Firefox\Profiles\1gj98tvb.default\prefs.js

Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");
Deleted : user_pref("extensions.enabledAddons", "DivXWebPlayer@divx.com:2.0.2.039,{972ce4c6-7e08-4474-a285-320[...]

*************************

AdwCleaner[R1].txt - [4669 octets] - [16/07/2012 21:01:07]
AdwCleaner[S1].txt - [3552 octets] - [16/07/2012 21:05:27]

########## EOF - C:\AdwCleaner[S1].txt - [3680 octets] ##########

t'john 16.07.2012 20:11

Sehr gut! :daumenhoc

zur Kontrolle:

Malware-Scan mit Emsisoft Anti-Malware

Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm.
Lade über Jetzt Updaten die aktuellen Signaturen herunter.
Wähle den Freeware-Modus aus.

Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers.
Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten.

Anleitung: http://www.trojaner-board.de/103809-...i-malware.html

lively1986 16.07.2012 23:32

also, der scan läuft noch... aber dennoch schon 1 fund: Packer.Crunchy.!AE2

Emsisoft Anti-Malware - Version 6.6
Letztes Update: N/A

Scan Einstellungen:

Scan Methode: Detail Scan
Objekte: Rootkits, Speicher, Traces, C:\, E:\, Q:\
Archiv Scan: An
ADS Scan: An

Scan Beginn: 16.07.2012 22:23:26

C:\Users\Alexander\Pflegemanagement B.A\Gregor Studium\Neuer Ordner (3)\SPSS15keygen.zip -> SPSS15keygen.exe gefunden: Packer.Krunchy.A!E2

Gescannt 785756
Gefunden 1

Scan Ende: 17.07.2012 04:18:57
Scan Zeit: 5:55:31


Quarantäne 0


Quarantäne 0


Beim Versuch den Fund in Quarantäne zu schieben schrieb Emisoft: File not found

t'john 17.07.2012 16:14

Sehr gut! :daumenhoc

Lasse den Fund entfernen.

dann:

Deinstalliere:
Emsisoft Anti-Malware


dann:


TDSSKiller von Kaspersky
- Lade den TDSSKiller und entpacke das Archiv auf Deinen Desktop.
- Vergewissere Dich, dass die TDSSKiller.exe direkt auf dem Desktop liegt (nicht in einem Ordner auf dem Desktop).
- deaktiviere vorübergehend dein AntiVirus-Programm
- Starte die TDSSKiller.exe durch Doppelklick.
- Nach Beendigung der Arbeit schlägt das Tool vor, das System neu zu starten.
- Bestätige das ggfs. mit Y(es).
- Beim Hochfahren des Systems führt der Treiber alle geplanten Operationen aus löscht sich danach.
- Poste den Inhalt von C:\TDSSKiller.txt hier in den Thread.
Hier findest Du eine ausführlichere TDSSKiller Anleitung.

lively1986 18.07.2012 09:40

Der Fund lässt sich nicht entfernen. Beim Versuch zu löschen/in Quarantäne zu verschieben, kommt halt die Meldung: Nicht möglich, Datei nicht gefunden

Trotzdem TDSSKiller installieren?

t'john 18.07.2012 09:43

Ja mit TDSSKiller fortfahren.

lively1986 18.07.2012 09:59

10:52:09.0438 4000 TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
10:52:09.0508 4000 ============================================================
10:52:09.0508 4000 Current date / time: 2012/07/18 10:52:09.0508
10:52:09.0508 4000 SystemInfo:
10:52:09.0508 4000
10:52:09.0518 4000 OS Version: 6.1.7601 ServicePack: 1.0
10:52:09.0518 4000 Product type: Workstation
10:52:09.0518 4000 ComputerName: ALEXANDER-PC
10:52:09.0518 4000 UserName: Alexander
10:52:09.0518 4000 Windows directory: C:\windows
10:52:09.0518 4000 System windows directory: C:\windows
10:52:09.0518 4000 Running under WOW64
10:52:09.0518 4000 Processor architecture: Intel x64
10:52:09.0518 4000 Number of processors: 4
10:52:09.0518 4000 Page size: 0x1000
10:52:09.0518 4000 Boot type: Normal boot
10:52:09.0518 4000 ============================================================
10:52:09.0918 4000 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:52:09.0928 4000 Drive \Device\Harddisk1\DR1 - Size: 0x1D1BF100000 (1862.99 Gb), SectorSize: 0x200, Cylinders: 0x1D1BF1, SectorsPerTrack: 0x20, TracksPerCylinder: 0x40, Type 'W'
10:52:09.0958 4000 ============================================================
10:52:09.0958 4000 \Device\Harddisk0\DR0:
10:52:09.0958 4000 MBR partitions:
10:52:09.0958 4000 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
10:52:09.0958 4000 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x714AE800
10:52:09.0958 4000 \Device\Harddisk1\DR1:
10:52:09.0958 4000 MBR partitions:
10:52:09.0958 4000 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8DF8000
10:52:09.0958 4000 ============================================================
10:52:09.0988 4000 C: <-> \Device\Harddisk0\DR0\Partition1
10:52:09.0998 4000 E: <-> \Device\Harddisk1\DR1\Partition0
10:52:09.0998 4000 ============================================================
10:52:09.0998 4000 Initialize success
10:52:09.0998 4000 ============================================================
10:52:24.0921 3784 ============================================================
10:52:24.0921 3784 Scan started
10:52:24.0921 3784 Mode: Manual;
10:52:24.0921 3784 ============================================================
10:52:25.0281 3784 1394ohci (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
10:52:25.0291 3784 1394ohci - ok
10:52:25.0331 3784 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
10:52:25.0331 3784 ACPI - ok
10:52:25.0361 3784 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
10:52:25.0361 3784 AcpiPmi - ok
10:52:25.0451 3784 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
10:52:25.0461 3784 AdobeARMservice - ok
10:52:25.0591 3784 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
10:52:25.0591 3784 AdobeFlashPlayerUpdateSvc - ok
10:52:25.0631 3784 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys
10:52:25.0651 3784 adp94xx - ok
10:52:25.0681 3784 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys
10:52:25.0701 3784 adpahci - ok
10:52:25.0711 3784 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys
10:52:25.0721 3784 adpu320 - ok
10:52:25.0751 3784 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\windows\System32\aelupsvc.dll
10:52:25.0751 3784 AeLookupSvc - ok
10:52:25.0811 3784 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
10:52:25.0821 3784 AFD - ok
10:52:25.0851 3784 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
10:52:25.0861 3784 agp440 - ok
10:52:25.0871 3784 ALG (3290d6946b5e30e70414990574883ddb) C:\windows\System32\alg.exe
10:52:25.0881 3784 ALG - ok
10:52:25.0911 3784 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
10:52:25.0921 3784 aliide - ok
10:52:25.0961 3784 AMD External Events Utility (b4143cb1dd16ae73c6177c72f33450a6) C:\windows\system32\atiesrxx.exe
10:52:25.0971 3784 AMD External Events Utility - ok
10:52:26.0001 3784 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
10:52:26.0001 3784 amdide - ok
10:52:26.0041 3784 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys
10:52:26.0041 3784 AmdK8 - ok
10:52:26.0365 3784 amdkmdag (d1d06810bf7e21f5763eb06cb7e7262b) C:\windows\system32\DRIVERS\atipmdag.sys
10:52:26.0458 3784 amdkmdag - ok
10:52:26.0598 3784 amdkmdap (6ba71d6616b56816e57394d77dd1bb6f) C:\windows\system32\DRIVERS\atikmpag.sys
10:52:26.0608 3784 amdkmdap - ok
10:52:26.0658 3784 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys
10:52:26.0668 3784 AmdPPM - ok
10:52:26.0748 3784 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
10:52:26.0748 3784 amdsata - ok
10:52:26.0768 3784 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys
10:52:26.0778 3784 amdsbs - ok
10:52:26.0798 3784 amdxata (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
10:52:26.0798 3784 amdxata - ok
10:52:26.0868 3784 AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
10:52:26.0878 3784 AntiVirSchedulerService - ok
10:52:26.0918 3784 AntiVirService (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
10:52:26.0928 3784 AntiVirService - ok
10:52:26.0968 3784 AntiVirWebService (676894fa57b671fec5c3f05f8929e03b) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
10:52:26.0988 3784 AntiVirWebService - ok
10:52:27.0038 3784 AppID (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
10:52:27.0038 3784 AppID - ok
10:52:27.0068 3784 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\windows\System32\appidsvc.dll
10:52:27.0078 3784 AppIDSvc - ok
10:52:27.0108 3784 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\windows\System32\appinfo.dll
10:52:27.0118 3784 Appinfo - ok
10:52:27.0168 3784 Apple Mobile Device (3debbecf665dcdde3a95d9b902010817) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
10:52:27.0168 3784 Apple Mobile Device - ok
10:52:27.0208 3784 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys
10:52:27.0218 3784 arc - ok
10:52:27.0218 3784 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys
10:52:27.0228 3784 arcsas - ok
10:52:27.0258 3784 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
10:52:27.0258 3784 AsyncMac - ok
10:52:27.0298 3784 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
10:52:27.0298 3784 atapi - ok
10:52:27.0388 3784 athr (e857eee6b92aaa473ebb3465add8f7e7) C:\windows\system32\DRIVERS\athrx.sys
10:52:27.0408 3784 athr - ok
10:52:27.0549 3784 AtiHdmiService (77c149e6d702737b2e372dee166faef8) C:\windows\system32\drivers\AtiHdmi.sys
10:52:27.0559 3784 AtiHdmiService - ok
10:52:27.0899 3784 atikmdag (d1d06810bf7e21f5763eb06cb7e7262b) C:\windows\system32\DRIVERS\atikmdag.sys
10:52:27.0969 3784 atikmdag - ok
10:52:28.0109 3784 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
10:52:28.0139 3784 AudioEndpointBuilder - ok
10:52:28.0149 3784 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
10:52:28.0159 3784 AudioSrv - ok
10:52:28.0229 3784 avgntflt (26e38b5a58c6c55fafbc563eeddb0867) C:\windows\system32\DRIVERS\avgntflt.sys
10:52:28.0239 3784 avgntflt - ok
10:52:28.0269 3784 avipbb (9d1f00beff84cbbf46d7f052bc7e0565) C:\windows\system32\DRIVERS\avipbb.sys
10:52:28.0269 3784 avipbb - ok
10:52:28.0289 3784 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\windows\system32\DRIVERS\avkmgr.sys
10:52:28.0289 3784 avkmgr - ok
10:52:28.0339 3784 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\windows\System32\AxInstSV.dll
10:52:28.0349 3784 AxInstSV - ok
10:52:28.0399 3784 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys
10:52:28.0419 3784 b06bdrv - ok
10:52:28.0449 3784 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
10:52:28.0459 3784 b57nd60a - ok
10:52:28.0489 3784 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\windows\System32\bdesvc.dll
10:52:28.0499 3784 BDESVC - ok
10:52:28.0509 3784 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
10:52:28.0519 3784 Beep - ok
10:52:28.0589 3784 BFE (82974d6a2fd19445cc5171fc378668a4) C:\windows\System32\bfe.dll
10:52:28.0609 3784 BFE - ok
10:52:28.0669 3784 BITS (1ea7969e3271cbc59e1730697dc74682) C:\windows\System32\qmgr.dll
10:52:28.0679 3784 BITS - ok
10:52:28.0719 3784 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
10:52:28.0719 3784 blbdrive - ok
10:52:28.0799 3784 Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
10:52:28.0819 3784 Bonjour Service - ok
10:52:28.0849 3784 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
10:52:28.0849 3784 bowser - ok
10:52:28.0879 3784 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys
10:52:28.0879 3784 BrFiltLo - ok
10:52:28.0889 3784 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys
10:52:28.0899 3784 BrFiltUp - ok
10:52:28.0939 3784 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\windows\System32\browser.dll
10:52:28.0949 3784 Browser - ok
10:52:28.0969 3784 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
10:52:28.0989 3784 Brserid - ok
10:52:28.0989 3784 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
10:52:28.0999 3784 BrSerWdm - ok
10:52:29.0009 3784 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
10:52:29.0009 3784 BrUsbMdm - ok
10:52:29.0009 3784 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
10:52:29.0019 3784 BrUsbSer - ok
10:52:29.0019 3784 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys
10:52:29.0029 3784 BTHMODEM - ok
10:52:29.0059 3784 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\windows\system32\bthserv.dll
10:52:29.0069 3784 bthserv - ok
10:52:29.0089 3784 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
10:52:29.0099 3784 cdfs - ok
10:52:29.0139 3784 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\drivers\cdrom.sys
10:52:29.0139 3784 cdrom - ok
10:52:29.0217 3784 CEEBC40A-FDED-4C59-B354-939132350B01 (91d0953e414e475878d07ee79765c17c) C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe
10:52:29.0233 3784 CEEBC40A-FDED-4C59-B354-939132350B01 - ok
10:52:29.0280 3784 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
10:52:29.0295 3784 CertPropSvc - ok
10:52:29.0311 3784 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys
10:52:29.0326 3784 circlass - ok
10:52:29.0358 3784 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
10:52:29.0368 3784 CLFS - ok
10:52:29.0418 3784 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:52:29.0428 3784 clr_optimization_v2.0.50727_32 - ok
10:52:29.0458 3784 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
10:52:29.0468 3784 clr_optimization_v2.0.50727_64 - ok
10:52:29.0518 3784 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:52:29.0518 3784 clr_optimization_v4.0.30319_32 - ok
10:52:29.0538 3784 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
10:52:29.0538 3784 clr_optimization_v4.0.30319_64 - ok
10:52:29.0578 3784 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
10:52:29.0578 3784 CmBatt - ok
10:52:29.0618 3784 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
10:52:29.0618 3784 cmdide - ok
10:52:29.0678 3784 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\windows\system32\Drivers\cng.sys
10:52:29.0688 3784 CNG - ok
10:52:29.0698 3784 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys
10:52:29.0698 3784 Compbatt - ok
10:52:29.0748 3784 CompositeBus (03edb043586cceba243d689bdda370a8) C:\windows\system32\drivers\CompositeBus.sys
10:52:29.0748 3784 CompositeBus - ok
10:52:29.0758 3784 COMSysApp - ok
10:52:29.0758 3784 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys
10:52:29.0768 3784 crcdisk - ok
10:52:29.0808 3784 CryptSvc (4f5414602e2544a4554d95517948b705) C:\windows\system32\cryptsvc.dll
10:52:29.0818 3784 CryptSvc - ok
10:52:29.0948 3784 cvhsvc (72794d112cbaff3bc0c29bf7350d4741) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
10:52:29.0958 3784 cvhsvc - ok
10:52:30.0018 3784 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
10:52:30.0028 3784 DcomLaunch - ok
10:52:30.0058 3784 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\windows\System32\defragsvc.dll
10:52:30.0068 3784 defragsvc - ok
10:52:30.0118 3784 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
10:52:30.0128 3784 DfsC - ok
10:52:30.0168 3784 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\windows\system32\dhcpcore.dll
10:52:30.0168 3784 Dhcp - ok
10:52:30.0198 3784 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
10:52:30.0198 3784 discache - ok
10:52:30.0228 3784 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys
10:52:30.0248 3784 Disk - ok
10:52:30.0268 3784 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\windows\System32\dnsrslvr.dll
10:52:30.0278 3784 Dnscache - ok
10:52:30.0318 3784 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\windows\System32\dot3svc.dll
10:52:30.0328 3784 dot3svc - ok
10:52:30.0368 3784 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\windows\system32\dps.dll
10:52:30.0368 3784 DPS - ok
10:52:30.0378 3784 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
10:52:30.0378 3784 drmkaud - ok
10:52:30.0468 3784 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\windows\System32\drivers\dxgkrnl.sys
10:52:30.0478 3784 DXGKrnl - ok
10:52:30.0528 3784 e1kexpress (52a482dc61f24b498c8268866b90bb44) C:\windows\system32\DRIVERS\e1k62x64.sys
10:52:30.0538 3784 e1kexpress - ok
10:52:30.0568 3784 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\windows\System32\eapsvc.dll
10:52:30.0578 3784 EapHost - ok
10:52:30.0758 3784 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys
10:52:30.0818 3784 ebdrv - ok
10:52:30.0918 3784 EFS (c118a82cd78818c29ab228366ebf81c3) C:\windows\System32\lsass.exe
10:52:30.0918 3784 EFS - ok
10:52:31.0008 3784 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\windows\ehome\ehRecvr.exe
10:52:31.0028 3784 ehRecvr - ok
10:52:31.0058 3784 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\windows\ehome\ehsched.exe
10:52:31.0068 3784 ehSched - ok
10:52:31.0108 3784 ElbyCDIO (a05fc7eca0966ebb70e4d17b855a853b) C:\windows\system32\Drivers\ElbyCDIO.sys
10:52:31.0108 3784 ElbyCDIO - ok
10:52:31.0158 3784 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys
10:52:31.0168 3784 elxstor - ok
10:52:31.0198 3784 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
10:52:31.0208 3784 ErrDev - ok
10:52:31.0258 3784 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\windows\system32\es.dll
10:52:31.0278 3784 EventSystem - ok
10:52:31.0298 3784 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
10:52:31.0308 3784 exfat - ok
10:52:31.0398 3784 Fabs - ok
10:52:31.0428 3784 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
10:52:31.0438 3784 fastfat - ok
10:52:31.0519 3784 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\windows\system32\fxssvc.exe
10:52:31.0539 3784 Fax - ok
10:52:31.0559 3784 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys
10:52:31.0559 3784 fdc - ok
10:52:31.0589 3784 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\windows\system32\fdPHost.dll
10:52:31.0589 3784 fdPHost - ok
10:52:31.0609 3784 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\windows\system32\fdrespub.dll
10:52:31.0609 3784 FDResPub - ok
10:52:31.0619 3784 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
10:52:31.0629 3784 FileInfo - ok
10:52:31.0639 3784 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
10:52:31.0649 3784 Filetrace - ok
10:52:31.0819 3784 FirebirdServerMAGIXInstance (fff1130f7c9fa01d093a1edfc5cce8fc) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
10:52:31.0859 3784 FirebirdServerMAGIXInstance - ok
10:52:31.0959 3784 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys
10:52:31.0959 3784 flpydisk - ok
10:52:32.0019 3784 FltMgr (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
10:52:32.0029 3784 FltMgr - ok
10:52:32.0119 3784 FontCache (b4447f606bb19fd8ad0bafb59b90f5d9) C:\windows\system32\FntCache.dll
10:52:32.0149 3784 FontCache - ok
10:52:32.0209 3784 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
10:52:32.0219 3784 FontCache3.0.0.0 - ok
10:52:32.0259 3784 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
10:52:32.0269 3784 FsDepends - ok
10:52:32.0299 3784 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\windows\system32\DRIVERS\fssfltr.sys
10:52:32.0309 3784 fssfltr - ok
10:52:32.0429 3784 fsssvc (4ce9dac1518ff7e77bd213e6394b9d77) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
10:52:32.0469 3784 fsssvc - ok
10:52:32.0569 3784 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\windows\system32\drivers\Fs_Rec.sys
10:52:32.0579 3784 Fs_Rec - ok
10:52:32.0639 3784 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
10:52:32.0639 3784 fvevol - ok
10:52:32.0669 3784 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys
10:52:32.0669 3784 gagp30kx - ok
10:52:32.0699 3784 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
10:52:32.0709 3784 GEARAspiWDM - ok
10:52:32.0779 3784 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\windows\System32\gpsvc.dll
10:52:32.0799 3784 gpsvc - ok
10:52:32.0819 3784 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
10:52:32.0829 3784 hcw85cir - ok
10:52:32.0889 3784 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
10:52:32.0899 3784 HdAudAddService - ok
10:52:32.0919 3784 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\drivers\HDAudBus.sys
10:52:32.0929 3784 HDAudBus - ok
10:52:32.0949 3784 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys
10:52:32.0959 3784 HECIx64 - ok
10:52:32.0969 3784 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys
10:52:32.0969 3784 HidBatt - ok
10:52:32.0979 3784 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys
10:52:32.0989 3784 HidBth - ok
10:52:32.0999 3784 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys
10:52:33.0009 3784 HidIr - ok
10:52:33.0029 3784 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\windows\system32\hidserv.dll
10:52:33.0029 3784 hidserv - ok
10:52:33.0099 3784 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\drivers\hidusb.sys
10:52:33.0099 3784 HidUsb - ok
10:52:33.0139 3784 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\windows\system32\kmsvc.dll
10:52:33.0149 3784 hkmsvc - ok
10:52:33.0189 3784 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\windows\system32\ListSvc.dll
10:52:33.0209 3784 HomeGroupListener - ok
10:52:33.0259 3784 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\windows\system32\provsvc.dll
10:52:33.0269 3784 HomeGroupProvider - ok
10:52:33.0279 3784 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
10:52:33.0289 3784 HpSAMD - ok
10:52:33.0369 3784 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
10:52:33.0379 3784 HTTP - ok
10:52:33.0420 3784 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
10:52:33.0420 3784 hwpolicy - ok
10:52:33.0467 3784 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\drivers\i8042prt.sys
10:52:33.0467 3784 i8042prt - ok
10:52:33.0529 3784 iaStor (abbf174cb394f5c437410a788b7e404a) C:\windows\system32\DRIVERS\iaStor.sys
10:52:33.0529 3784 iaStor - ok
10:52:33.0576 3784 IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
10:52:33.0576 3784 IAStorDataMgrSvc - ok
10:52:33.0623 3784 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
10:52:33.0638 3784 iaStorV - ok
10:52:33.0732 3784 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
10:52:33.0763 3784 idsvc - ok
10:52:34.0106 3784 igfx (a87261ef1546325b559374f5689cf5bc) C:\windows\system32\DRIVERS\igdkmd64.sys
10:52:34.0169 3784 igfx - ok
10:52:34.0247 3784 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys
10:52:34.0247 3784 iirsp - ok
10:52:34.0325 3784 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\windows\System32\ikeext.dll
10:52:34.0340 3784 IKEEXT - ok
10:52:34.0465 3784 IntcAzAudAddService (9aa6a93852e36fe76c3f7fc2904f3b01) C:\windows\system32\drivers\RTKVHD64.sys
10:52:34.0481 3784 IntcAzAudAddService - ok
10:52:34.0563 3784 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
10:52:34.0563 3784 intelide - ok
10:52:34.0603 3784 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
10:52:34.0603 3784 intelppm - ok
10:52:34.0623 3784 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\windows\system32\ipbusenum.dll
10:52:34.0633 3784 IPBusEnum - ok
10:52:34.0673 3784 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
10:52:34.0673 3784 IpFilterDriver - ok
10:52:34.0733 3784 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\windows\System32\iphlpsvc.dll
10:52:34.0753 3784 iphlpsvc - ok
10:52:34.0793 3784 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
10:52:34.0803 3784 IPMIDRV - ok
10:52:34.0823 3784 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
10:52:34.0833 3784 IPNAT - ok
10:52:34.0953 3784 iPod Service (ee4c2a137c7088911a8919effc9812e7) C:\Program Files\iPod\bin\iPodService.exe
10:52:34.0953 3784 iPod Service - ok
10:52:34.0983 3784 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
10:52:34.0983 3784 IRENUM - ok
10:52:35.0013 3784 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
10:52:35.0013 3784 isapnp - ok
10:52:35.0063 3784 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
10:52:35.0063 3784 iScsiPrt - ok
10:52:35.0093 3784 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\drivers\kbdclass.sys
10:52:35.0093 3784 kbdclass - ok
10:52:35.0113 3784 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\drivers\kbdhid.sys
10:52:35.0123 3784 kbdhid - ok
10:52:35.0133 3784 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:52:35.0143 3784 KeyIso - ok
10:52:35.0183 3784 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\windows\system32\Drivers\ksecdd.sys
10:52:35.0183 3784 KSecDD - ok
10:52:35.0233 3784 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\windows\system32\Drivers\ksecpkg.sys
10:52:35.0233 3784 KSecPkg - ok
10:52:35.0263 3784 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
10:52:35.0263 3784 ksthunk - ok
10:52:35.0293 3784 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\windows\system32\msdtckrm.dll
10:52:35.0313 3784 KtmRm - ok
10:52:35.0363 3784 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\windows\system32\srvsvc.dll
10:52:35.0373 3784 LanmanServer - ok
10:52:35.0413 3784 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\windows\System32\wkssvc.dll
10:52:35.0413 3784 LanmanWorkstation - ok
10:52:35.0493 3784 LenovoCOMSvc (57ead1ca5c1ffc88905fd96b119bb286) C:\Program Files\Lenovo\Power Dial\LenovoCOMSvc.exe
10:52:35.0503 3784 LenovoCOMSvc - ok
10:52:35.0513 3784 LitModeCtrl (47f2b11a3567aa0e921edab0969e7aa7) C:\Program Files\Lenovo\Power Dial\LitModeCtrl.exe
10:52:35.0523 3784 LitModeCtrl - ok
10:52:35.0551 3784 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
10:52:35.0555 3784 lltdio - ok
10:52:35.0581 3784 lltdsvc (c1185803384ab3feed115f79f109427f) C:\windows\System32\lltdsvc.dll
10:52:35.0581 3784 lltdsvc - ok
10:52:35.0601 3784 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\windows\System32\lmhsvc.dll
10:52:35.0601 3784 lmhosts - ok
10:52:35.0671 3784 LMS (e38775922d4a4c05b5d96733ab4ce169) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
10:52:35.0671 3784 LMS - ok
10:52:35.0701 3784 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys
10:52:35.0711 3784 LSI_FC - ok
10:52:35.0711 3784 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys
10:52:35.0721 3784 LSI_SAS - ok
10:52:35.0721 3784 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys
10:52:35.0731 3784 LSI_SAS2 - ok
10:52:35.0741 3784 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys
10:52:35.0741 3784 LSI_SCSI - ok
10:52:35.0761 3784 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
10:52:35.0771 3784 luafv - ok
10:52:35.0811 3784 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\windows\system32\Mcx2Svc.dll
10:52:35.0821 3784 Mcx2Svc - ok
10:52:35.0821 3784 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys
10:52:35.0821 3784 megasas - ok
10:52:35.0841 3784 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys
10:52:35.0851 3784 MegaSR - ok
10:52:35.0901 3784 Microsoft SharePoint Workspace Audit Service - ok
10:52:35.0931 3784 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
10:52:35.0941 3784 MMCSS - ok
10:52:35.0941 3784 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
10:52:35.0951 3784 Modem - ok
10:52:35.0971 3784 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
10:52:35.0971 3784 monitor - ok
10:52:36.0011 3784 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\drivers\mouclass.sys
10:52:36.0021 3784 mouclass - ok
10:52:36.0041 3784 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
10:52:36.0041 3784 mouhid - ok
10:52:36.0071 3784 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
10:52:36.0071 3784 mountmgr - ok
10:52:36.0141 3784 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
10:52:36.0141 3784 MozillaMaintenance - ok
10:52:36.0181 3784 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
10:52:36.0191 3784 mpio - ok
10:52:36.0201 3784 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
10:52:36.0211 3784 mpsdrv - ok
10:52:36.0271 3784 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\windows\system32\mpssvc.dll
10:52:36.0281 3784 MpsSvc - ok
10:52:36.0321 3784 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
10:52:36.0331 3784 MRxDAV - ok
10:52:36.0351 3784 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
10:52:36.0361 3784 mrxsmb - ok
10:52:36.0401 3784 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
10:52:36.0411 3784 mrxsmb10 - ok
10:52:36.0431 3784 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
10:52:36.0441 3784 mrxsmb20 - ok
10:52:36.0481 3784 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\drivers\msahci.sys
10:52:36.0481 3784 msahci - ok
10:52:36.0541 3784 msdsm (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
10:52:36.0551 3784 msdsm - ok
10:52:36.0591 3784 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\windows\System32\msdtc.exe
10:52:36.0601 3784 MSDTC - ok
10:52:36.0641 3784 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
10:52:36.0651 3784 Msfs - ok
10:52:36.0661 3784 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
10:52:36.0661 3784 mshidkmdf - ok
10:52:36.0701 3784 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
10:52:36.0701 3784 msisadrv - ok
10:52:36.0741 3784 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\windows\system32\iscsiexe.dll
10:52:36.0751 3784 MSiSCSI - ok
10:52:36.0761 3784 msiserver - ok
10:52:36.0781 3784 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
10:52:36.0781 3784 MSKSSRV - ok
10:52:36.0781 3784 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
10:52:36.0791 3784 MSPCLOCK - ok
10:52:36.0791 3784 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
10:52:36.0791 3784 MSPQM - ok
10:52:36.0841 3784 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
10:52:36.0841 3784 MsRPC - ok
10:52:36.0881 3784 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\drivers\mssmbios.sys
10:52:36.0881 3784 mssmbios - ok
10:52:36.0891 3784 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
10:52:36.0891 3784 MSTEE - ok
10:52:36.0901 3784 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys
10:52:36.0901 3784 MTConfig - ok
10:52:36.0921 3784 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
10:52:36.0931 3784 Mup - ok
10:52:36.0961 3784 napagent (582ac6d9873e31dfa28a4547270862dd) C:\windows\system32\qagentRT.dll
10:52:36.0961 3784 napagent - ok
10:52:37.0001 3784 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
10:52:37.0011 3784 NativeWifiP - ok
10:52:37.0061 3784 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\windows\system32\drivers\ndis.sys
10:52:37.0071 3784 NDIS - ok
10:52:37.0081 3784 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
10:52:37.0081 3784 NdisCap - ok
10:52:37.0101 3784 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
10:52:37.0101 3784 NdisTapi - ok
10:52:37.0141 3784 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
10:52:37.0151 3784 Ndisuio - ok
10:52:37.0191 3784 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
10:52:37.0191 3784 NdisWan - ok
10:52:37.0231 3784 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
10:52:37.0231 3784 NDProxy - ok
10:52:37.0291 3784 Netaapl (6f4607e2333fe21e9e3ff8133a88b35b) C:\windows\system32\DRIVERS\netaapl64.sys
10:52:37.0301 3784 Netaapl - ok
10:52:37.0331 3784 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
10:52:37.0331 3784 NetBIOS - ok
10:52:37.0381 3784 NetBT (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
10:52:37.0381 3784 NetBT - ok
10:52:37.0401 3784 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:52:37.0401 3784 Netlogon - ok
10:52:37.0441 3784 Netman (847d3ae376c0817161a14a82c8922a9e) C:\windows\System32\netman.dll
10:52:37.0441 3784 Netman - ok
10:52:37.0461 3784 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\windows\System32\netprofm.dll
10:52:37.0471 3784 netprofm - ok
10:52:37.0531 3784 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
10:52:37.0531 3784 NetTcpPortSharing - ok
10:52:37.0561 3784 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys
10:52:37.0571 3784 nfrd960 - ok
10:52:37.0621 3784 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\windows\System32\nlasvc.dll
10:52:37.0621 3784 NlaSvc - ok
10:52:37.0641 3784 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
10:52:37.0641 3784 Npfs - ok
10:52:37.0661 3784 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\windows\system32\nsisvc.dll
10:52:37.0671 3784 nsi - ok
10:52:37.0681 3784 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
10:52:37.0681 3784 nsiproxy - ok
10:52:37.0761 3784 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
10:52:37.0791 3784 Ntfs - ok
10:52:37.0891 3784 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
10:52:37.0891 3784 Null - ok
10:52:37.0951 3784 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
10:52:37.0961 3784 nvraid - ok
10:52:37.0981 3784 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
10:52:37.0981 3784 nvstor - ok
10:52:38.0011 3784 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
10:52:38.0021 3784 nv_agp - ok
10:52:38.0061 3784 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
10:52:38.0071 3784 ohci1394 - ok
10:52:38.0141 3784 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:52:38.0141 3784 ose - ok
10:52:38.0421 3784 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
10:52:38.0471 3784 osppsvc - ok
10:52:38.0571 3784 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
10:52:38.0581 3784 p2pimsvc - ok
10:52:38.0611 3784 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\windows\system32\p2psvc.dll
10:52:38.0621 3784 p2psvc - ok
10:52:38.0661 3784 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys
10:52:38.0671 3784 Parport - ok
10:52:38.0701 3784 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\windows\system32\drivers\partmgr.sys
10:52:38.0701 3784 partmgr - ok
10:52:38.0731 3784 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\windows\System32\pcasvc.dll
10:52:38.0741 3784 PcaSvc - ok
10:52:38.0771 3784 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
10:52:38.0771 3784 pci - ok
10:52:38.0801 3784 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\drivers\pciide.sys
10:52:38.0811 3784 pciide - ok
10:52:38.0921 3784 PCLEPCI (1bebe7de8508a02650cdce45c664c2a2) C:\windows\SysWOW64\drivers\pclepci.sys
10:52:38.0931 3784 PCLEPCI - ok
10:52:38.0961 3784 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys
10:52:38.0971 3784 pcmcia - ok
10:52:38.0981 3784 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
10:52:38.0991 3784 pcw - ok
10:52:39.0031 3784 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
10:52:39.0041 3784 PEAUTH - ok
10:52:39.0091 3784 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\windows\SysWow64\perfhost.exe
10:52:39.0101 3784 PerfHost - ok
10:52:39.0201 3784 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\windows\system32\pla.dll
10:52:39.0221 3784 pla - ok
10:52:39.0271 3784 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\windows\system32\umpnpmgr.dll
10:52:39.0281 3784 PlugPlay - ok
10:52:39.0301 3784 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\windows\system32\pnrpauto.dll
10:52:39.0301 3784 PNRPAutoReg - ok
10:52:39.0321 3784 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
10:52:39.0331 3784 PNRPsvc - ok
10:52:39.0361 3784 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\windows\System32\ipsecsvc.dll
10:52:39.0381 3784 PolicyAgent - ok
10:52:39.0401 3784 Power (6ba9d927dded70bd1a9caded45f8b184) C:\windows\system32\umpo.dll
10:52:39.0401 3784 Power - ok
10:52:39.0471 3784 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
10:52:39.0481 3784 PptpMiniport - ok
10:52:39.0501 3784 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys
10:52:39.0511 3784 Processor - ok
10:52:39.0591 3784 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\windows\system32\profsvc.dll
10:52:39.0601 3784 ProfSvc - ok
10:52:39.0631 3784 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:52:39.0631 3784 ProtectedStorage - ok
10:52:39.0681 3784 Psched (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
10:52:39.0681 3784 Psched - ok
10:52:39.0701 3784 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\windows\system32\Drivers\PxHlpa64.sys
10:52:39.0711 3784 PxHlpa64 - ok
10:52:39.0791 3784 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys
10:52:39.0821 3784 ql2300 - ok
10:52:39.0911 3784 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys
10:52:39.0921 3784 ql40xx - ok
10:52:39.0951 3784 QWAVE (906191634e99aea92c4816150bda3732) C:\windows\system32\qwave.dll
10:52:39.0961 3784 QWAVE - ok
10:52:39.0961 3784 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
10:52:39.0971 3784 QWAVEdrv - ok
10:52:39.0971 3784 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
10:52:39.0971 3784 RasAcd - ok
10:52:39.0991 3784 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
10:52:40.0001 3784 RasAgileVpn - ok
10:52:40.0011 3784 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\windows\System32\rasauto.dll
10:52:40.0021 3784 RasAuto - ok
10:52:40.0051 3784 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
10:52:40.0061 3784 Rasl2tp - ok
10:52:40.0111 3784 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\windows\System32\rasmans.dll
10:52:40.0121 3784 RasMan - ok
10:52:40.0141 3784 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
10:52:40.0151 3784 RasPppoe - ok
10:52:40.0161 3784 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
10:52:40.0161 3784 RasSstp - ok
10:52:40.0201 3784 rdbss (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
10:52:40.0211 3784 rdbss - ok
10:52:40.0231 3784 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys
10:52:40.0231 3784 rdpbus - ok
10:52:40.0241 3784 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
10:52:40.0241 3784 RDPCDD - ok
10:52:40.0251 3784 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
10:52:40.0251 3784 RDPENCDD - ok
10:52:40.0261 3784 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
10:52:40.0261 3784 RDPREFMP - ok
10:52:40.0311 3784 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\windows\system32\drivers\RDPWD.sys
10:52:40.0311 3784 RDPWD - ok
10:52:40.0371 3784 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
10:52:40.0371 3784 rdyboost - ok
10:52:40.0391 3784 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\windows\System32\mprdim.dll
10:52:40.0401 3784 RemoteAccess - ok
10:52:40.0431 3784 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\windows\system32\regsvc.dll
10:52:40.0441 3784 RemoteRegistry - ok
10:52:40.0451 3784 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\windows\System32\RpcEpMap.dll
10:52:40.0461 3784 RpcEptMapper - ok
10:52:40.0461 3784 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\windows\system32\locator.exe
10:52:40.0471 3784 RpcLocator - ok
10:52:40.0531 3784 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
10:52:40.0531 3784 RpcSs - ok
10:52:40.0571 3784 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
10:52:40.0581 3784 rspndr - ok
10:52:40.0601 3784 RSUSBSTOR (b1d04ed92d148b54169499d9568a3c55) C:\windows\system32\Drivers\RtsUStor.sys
10:52:40.0611 3784 RSUSBSTOR - ok
10:52:40.0621 3784 RTL8023x64 (68dd0457d18fccef7384ae84022f0c86) C:\windows\system32\DRIVERS\Rtnic64.sys
10:52:40.0621 3784 RTL8023x64 - ok
10:52:40.0621 3784 RtsUIR - ok
10:52:40.0641 3784 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:52:40.0651 3784 SamSs - ok
10:52:40.0681 3784 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
10:52:40.0681 3784 sbp2port - ok
10:52:40.0721 3784 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\windows\System32\SCardSvr.dll
10:52:40.0721 3784 SCardSvr - ok
10:52:40.0761 3784 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
10:52:40.0761 3784 scfilter - ok
10:52:40.0851 3784 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\windows\system32\schedsvc.dll
10:52:40.0871 3784 Schedule - ok
10:52:40.0911 3784 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
10:52:40.0911 3784 SCPolicySvc - ok
10:52:40.0931 3784 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\windows\System32\SDRSVC.dll
10:52:40.0941 3784 SDRSVC - ok
10:52:40.0991 3784 SeaPort - ok
10:52:41.0021 3784 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
10:52:41.0031 3784 secdrv - ok
10:52:41.0031 3784 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\windows\system32\seclogon.dll
10:52:41.0041 3784 seclogon - ok
10:52:41.0061 3784 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\windows\System32\sens.dll
10:52:41.0061 3784 SENS - ok
10:52:41.0081 3784 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\windows\system32\sensrsvc.dll
10:52:41.0081 3784 SensrSvc - ok
10:52:41.0091 3784 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys
10:52:41.0101 3784 Serenum - ok
10:52:41.0121 3784 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys
10:52:41.0131 3784 Serial - ok
10:52:41.0161 3784 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys
10:52:41.0161 3784 sermouse - ok
10:52:41.0201 3784 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\windows\system32\sessenv.dll
10:52:41.0201 3784 SessionEnv - ok
10:52:41.0231 3784 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
10:52:41.0231 3784 sffdisk - ok
10:52:41.0241 3784 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
10:52:41.0241 3784 sffp_mmc - ok
10:52:41.0251 3784 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
10:52:41.0251 3784 sffp_sd - ok
10:52:41.0271 3784 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys
10:52:41.0281 3784 sfloppy - ok
10:52:41.0341 3784 Sftfs (c6cc9297bd53e5229653303e556aa539) C:\windows\system32\DRIVERS\Sftfslh.sys
10:52:41.0351 3784 Sftfs - ok
10:52:41.0431 3784 sftlist (13693b6354dd6e72dc5131da7d764b90) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
10:52:41.0441 3784 sftlist - ok
10:52:41.0471 3784 Sftplay (390aa7bc52cee43f6790cdea1e776703) C:\windows\system32\DRIVERS\Sftplaylh.sys
10:52:41.0471 3784 Sftplay - ok
10:52:41.0491 3784 Sftredir (617e29a0b0a2807466560d4c4e338d3e) C:\windows\system32\DRIVERS\Sftredirlh.sys
10:52:41.0491 3784 Sftredir - ok
10:52:41.0501 3784 Sftvol (8f571f016fa1976f445147e9e6c8ae9b) C:\windows\system32\DRIVERS\Sftvollh.sys
10:52:41.0511 3784 Sftvol - ok
10:52:41.0521 3784 sftvsa (c3cddd18f43d44ab713cf8c4916f7696) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
10:52:41.0531 3784 sftvsa - ok
10:52:41.0561 3784 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\windows\System32\ipnathlp.dll
10:52:41.0571 3784 SharedAccess - ok
10:52:41.0621 3784 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\windows\System32\shsvcs.dll
10:52:41.0631 3784 ShellHWDetection - ok
10:52:41.0661 3784 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys
10:52:41.0661 3784 SiSRaid2 - ok
10:52:41.0671 3784 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys
10:52:41.0671 3784 SiSRaid4 - ok
10:52:41.0691 3784 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
10:52:41.0691 3784 Smb - ok
10:52:41.0721 3784 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\windows\System32\snmptrap.exe
10:52:41.0731 3784 SNMPTRAP - ok
10:52:41.0731 3784 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
10:52:41.0741 3784 spldr - ok
10:52:41.0761 3784 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\windows\System32\spoolsv.exe
10:52:41.0771 3784 Spooler - ok
10:52:42.0001 3784 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\windows\system32\sppsvc.exe
10:52:42.0031 3784 sppsvc - ok
10:52:42.0121 3784 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\windows\system32\sppuinotify.dll
10:52:42.0121 3784 sppuinotify - ok
10:52:42.0161 3784 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
10:52:42.0181 3784 srv - ok
10:52:42.0201 3784 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
10:52:42.0211 3784 srv2 - ok
10:52:42.0231 3784 srvnet (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
10:52:42.0241 3784 srvnet - ok
10:52:42.0261 3784 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\windows\System32\ssdpsrv.dll
10:52:42.0271 3784 SSDPSRV - ok
10:52:42.0291 3784 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\windows\system32\sstpsvc.dll
10:52:42.0291 3784 SstpSvc - ok
10:52:42.0321 3784 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys
10:52:42.0321 3784 stexstor - ok
10:52:42.0361 3784 StillCam (decacb6921ded1a38642642685d77dac) C:\windows\system32\DRIVERS\serscan.sys
10:52:42.0361 3784 StillCam - ok
10:52:42.0421 3784 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\windows\System32\wiaservc.dll
10:52:42.0441 3784 stisvc - ok
10:52:42.0471 3784 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\drivers\swenum.sys
10:52:42.0481 3784 swenum - ok
10:52:42.0501 3784 swprv (e08e46fdd841b7184194011ca1955a0b) C:\windows\System32\swprv.dll
10:52:42.0511 3784 swprv - ok
10:52:42.0611 3784 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\windows\system32\sysmain.dll
10:52:42.0631 3784 SysMain - ok
10:52:42.0721 3784 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\windows\System32\TabSvc.dll
10:52:42.0731 3784 TabletInputService - ok
10:52:42.0751 3784 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\windows\System32\tapisrv.dll
10:52:42.0761 3784 TapiSrv - ok
10:52:42.0791 3784 TBS (1be03ac720f4d302ea01d40f588162f6) C:\windows\System32\tbssvc.dll
10:52:42.0791 3784 TBS - ok
10:52:42.0921 3784 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\windows\system32\drivers\tcpip.sys
10:52:42.0941 3784 Tcpip - ok
10:52:43.0111 3784 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\windows\system32\DRIVERS\tcpip.sys
10:52:43.0131 3784 TCPIP6 - ok
10:52:43.0211 3784 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
10:52:43.0221 3784 tcpipreg - ok
10:52:43.0241 3784 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
10:52:43.0241 3784 TDPIPE - ok
10:52:43.0271 3784 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\windows\system32\drivers\tdtcp.sys
10:52:43.0271 3784 TDTCP - ok
10:52:43.0311 3784 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
10:52:43.0321 3784 tdx - ok
10:52:43.0521 3784 TeamViewer6 (01a402d34732ca3da91786adcc765069) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
10:52:43.0551 3784 TeamViewer6 - ok
10:52:43.0651 3784 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\drivers\termdd.sys
10:52:43.0661 3784 TermDD - ok
10:52:43.0721 3784 TermService (2e648163254233755035b46dd7b89123) C:\windows\System32\termsrv.dll
10:52:43.0731 3784 TermService - ok
10:52:43.0751 3784 Themes (f0344071948d1a1fa732231785a0664c) C:\windows\system32\themeservice.dll
10:52:43.0751 3784 Themes - ok
10:52:43.0771 3784 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
10:52:43.0771 3784 THREADORDER - ok
10:52:43.0781 3784 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\windows\System32\trkwks.dll
10:52:43.0791 3784 TrkWks - ok
10:52:43.0841 3784 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\windows\servicing\TrustedInstaller.exe
10:52:43.0851 3784 TrustedInstaller - ok
10:52:43.0881 3784 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
10:52:43.0891 3784 tssecsrv - ok
10:52:43.0931 3784 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
10:52:43.0941 3784 TsUsbFlt - ok
10:52:44.0141 3784 TuneUp.UtilitiesSvc (811a229718c85356bc81eb20f35eb7f6) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
10:52:44.0161 3784 TuneUp.UtilitiesSvc - ok
10:52:44.0191 3784 TuneUpUtilitiesDrv (dcc94c51d27c7ec0dadeca8f64c94fcf) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys
10:52:44.0201 3784 TuneUpUtilitiesDrv - ok
10:52:44.0321 3784 tunnel (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
10:52:44.0321 3784 tunnel - ok
10:52:44.0341 3784 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys
10:52:44.0351 3784 uagp35 - ok
10:52:44.0391 3784 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
10:52:44.0401 3784 udfs - ok
10:52:44.0421 3784 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\windows\system32\UI0Detect.exe
10:52:44.0431 3784 UI0Detect - ok
10:52:44.0461 3784 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
10:52:44.0471 3784 uliagpkx - ok
10:52:44.0521 3784 umbus (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\drivers\umbus.sys
10:52:44.0531 3784 umbus - ok
10:52:44.0541 3784 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys
10:52:44.0541 3784 UmPass - ok
10:52:44.0731 3784 UNS (02c298382359653bec4c737c2ab7f9c5) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
10:52:44.0751 3784 UNS - ok
10:52:44.0851 3784 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\windows\System32\upnphost.dll
10:52:44.0861 3784 upnphost - ok
10:52:44.0901 3784 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\windows\system32\Drivers\usbaapl64.sys
10:52:44.0901 3784 USBAAPL64 - ok
10:52:44.0941 3784 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\windows\system32\DRIVERS\usbccgp.sys
10:52:44.0941 3784 usbccgp - ok
10:52:44.0941 3784 USBCCID - ok
10:52:44.0981 3784 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
10:52:44.0991 3784 usbcir - ok
10:52:45.0021 3784 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\drivers\usbehci.sys
10:52:45.0031 3784 usbehci - ok
10:52:45.0051 3784 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\DRIVERS\usbhub.sys
10:52:45.0061 3784 usbhub - ok
10:52:45.0101 3784 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\drivers\usbohci.sys
10:52:45.0101 3784 usbohci - ok
10:52:45.0131 3784 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys
10:52:45.0131 3784 usbprint - ok
10:52:45.0151 3784 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys
10:52:45.0161 3784 usbscan - ok
10:52:45.0191 3784 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
10:52:45.0201 3784 USBSTOR - ok
10:52:45.0211 3784 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\windows\system32\drivers\usbuhci.sys
10:52:45.0221 3784 usbuhci - ok
10:52:45.0231 3784 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\windows\System32\uxsms.dll
10:52:45.0231 3784 UxSms - ok
10:52:45.0241 3784 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:52:45.0251 3784 VaultSvc - ok
10:52:45.0281 3784 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
10:52:45.0291 3784 vdrvroot - ok
10:52:45.0341 3784 vds (8d6b481601d01a456e75c3210f1830be) C:\windows\System32\vds.exe
10:52:45.0351 3784 vds - ok
10:52:45.0381 3784 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
10:52:45.0391 3784 vga - ok
10:52:45.0401 3784 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
10:52:45.0401 3784 VgaSave - ok
10:52:45.0441 3784 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
10:52:45.0451 3784 vhdmp - ok
10:52:45.0461 3784 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
10:52:45.0471 3784 viaide - ok
10:52:45.0481 3784 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
10:52:45.0481 3784 volmgr - ok
10:52:45.0531 3784 volmgrx (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
10:52:45.0531 3784 volmgrx - ok
10:52:45.0551 3784 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\windows\system32\drivers\volsnap.sys
10:52:45.0561 3784 volsnap - ok
10:52:45.0591 3784 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys
10:52:45.0591 3784 vsmraid - ok
10:52:45.0711 3784 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\windows\system32\vssvc.exe
10:52:45.0731 3784 VSS - ok
10:52:45.0821 3784 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
10:52:45.0821 3784 vwifibus - ok
10:52:45.0841 3784 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
10:52:45.0851 3784 vwififlt - ok
10:52:45.0891 3784 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\windows\system32\w32time.dll
10:52:45.0911 3784 W32Time - ok
10:52:45.0931 3784 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys
10:52:45.0931 3784 WacomPen - ok
10:52:45.0971 3784 WANARP (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
10:52:45.0981 3784 WANARP - ok
10:52:45.0981 3784 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
10:52:45.0981 3784 Wanarpv6 - ok
10:52:46.0091 3784 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\windows\system32\wbengine.exe
10:52:46.0131 3784 wbengine - ok
10:52:46.0231 3784 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\windows\System32\wbiosrvc.dll
10:52:46.0241 3784 WbioSrvc - ok
10:52:46.0291 3784 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\windows\System32\wcncsvc.dll
10:52:46.0301 3784 wcncsvc - ok
10:52:46.0311 3784 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\windows\System32\WcsPlugInService.dll
10:52:46.0321 3784 WcsPlugInService - ok
10:52:46.0351 3784 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys
10:52:46.0351 3784 Wd - ok
10:52:46.0391 3784 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
10:52:46.0401 3784 Wdf01000 - ok
10:52:46.0411 3784 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
10:52:46.0421 3784 WdiServiceHost - ok
10:52:46.0421 3784 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
10:52:46.0431 3784 WdiSystemHost - ok
10:52:46.0471 3784 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\windows\System32\webclnt.dll
10:52:46.0491 3784 WebClient - ok
10:52:46.0511 3784 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\windows\system32\wecsvc.dll
10:52:46.0521 3784 Wecsvc - ok
10:52:46.0541 3784 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\windows\System32\wercplsupport.dll
10:52:46.0541 3784 wercplsupport - ok
10:52:46.0561 3784 WerSvc (6d137963730144698cbd10f202e9f251) C:\windows\System32\WerSvc.dll
10:52:46.0571 3784 WerSvc - ok
10:52:46.0611 3784 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
10:52:46.0621 3784 WfpLwf - ok
10:52:46.0641 3784 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\windows\system32\DRIVERS\wimfltr.sys
10:52:46.0651 3784 WimFltr - ok
10:52:46.0671 3784 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
10:52:46.0671 3784 WIMMount - ok
10:52:46.0691 3784 WinDefend - ok
10:52:46.0691 3784 WinHttpAutoProxySvc - ok
10:52:46.0721 3784 WinI2C-DDC (66c365b542195c1f6e2ff4a7d8f3827c) C:\windows\system32\drivers\DDCDrv.sys
10:52:46.0721 3784 WinI2C-DDC - ok
10:52:46.0771 3784 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\windows\system32\wbem\WMIsvc.dll
10:52:46.0771 3784 Winmgmt - ok
10:52:46.0901 3784 WinRM (bcb1310604aa415c4508708975b3931e) C:\windows\system32\WsmSvc.dll
10:52:46.0931 3784 WinRM - ok
10:52:47.0091 3784 WinUsb (fe88b288356e7b47b74b13372add906d) C:\windows\system32\DRIVERS\WinUsb.sys
10:52:47.0091 3784 WinUsb - ok
10:52:47.0151 3784 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\windows\System32\wlansvc.dll
10:52:47.0171 3784 Wlansvc - ok
10:52:47.0221 3784 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
10:52:47.0231 3784 wlcrasvc - ok
10:52:47.0371 3784 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
10:52:47.0391 3784 wlidsvc - ok
10:52:47.0491 3784 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\drivers\wmiacpi.sys
10:52:47.0491 3784 WmiAcpi - ok
10:52:47.0541 3784 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\windows\system32\wbem\WmiApSrv.exe
10:52:47.0551 3784 wmiApSrv - ok
10:52:47.0591 3784 WMPNetworkSvc - ok
10:52:47.0601 3784 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\windows\System32\wpcsvc.dll
10:52:47.0611 3784 WPCSvc - ok
10:52:47.0641 3784 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\windows\system32\wpdbusenum.dll
10:52:47.0651 3784 WPDBusEnum - ok
10:52:47.0661 3784 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
10:52:47.0671 3784 ws2ifsl - ok
10:52:47.0681 3784 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\windows\System32\wscsvc.dll
10:52:47.0691 3784 wscsvc - ok
10:52:47.0691 3784 WSearch - ok
10:52:47.0721 3784 wsvd (83575c43b2bfe9ab0661a7f957e843c0) C:\windows\system32\DRIVERS\wsvd.sys
10:52:47.0721 3784 wsvd - ok
10:52:47.0881 3784 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\windows\system32\wuaueng.dll
10:52:47.0901 3784 wuauserv - ok
10:52:48.0021 3784 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
10:52:48.0031 3784 WudfPf - ok
10:52:48.0061 3784 WUDFRd (cf8d590be3373029d57af80914190682) C:\windows\system32\DRIVERS\WUDFRd.sys
10:52:48.0071 3784 WUDFRd - ok
10:52:48.0111 3784 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\windows\System32\WUDFSvc.dll
10:52:48.0121 3784 wudfsvc - ok
10:52:48.0151 3784 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\windows\System32\wwansvc.dll
10:52:48.0161 3784 WwanSvc - ok
10:52:48.0201 3784 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\windows\system32\DRIVERS\yk62x64.sys
10:52:48.0211 3784 yukonw7 - ok
10:52:48.0231 3784 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
10:52:48.0371 3784 \Device\Harddisk0\DR0 - ok
10:52:48.0381 3784 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
10:52:48.0381 3784 \Device\Harddisk1\DR1 - ok
10:52:48.0381 3784 Boot (0x1200) (2223329836bf626dbdd3e858fe7e0bf8) \Device\Harddisk0\DR0\Partition0
10:52:48.0381 3784 \Device\Harddisk0\DR0\Partition0 - ok
10:52:48.0391 3784 Boot (0x1200) (d76da93ece00c16f437acc914502b150) \Device\Harddisk0\DR0\Partition1
10:52:48.0391 3784 \Device\Harddisk0\DR0\Partition1 - ok
10:52:48.0401 3784 Boot (0x1200) (97793c6ebe782489632be676e2c9be30) \Device\Harddisk1\DR1\Partition0
10:52:48.0401 3784 \Device\Harddisk1\DR1\Partition0 - ok
10:52:48.0401 3784 ============================================================
10:52:48.0401 3784 Scan finished
10:52:48.0401 3784 ============================================================
10:52:48.0411 2100 Detected object count: 0
10:52:48.0411 2100 Actual detected object count: 0
10:56:29.0017 4448 ============================================================
10:56:29.0017 4448 Scan started
10:56:29.0017 4448 Mode: Manual;
10:56:29.0017 4448 ============================================================
10:56:29.0177 4448 1394ohci (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
10:56:29.0178 4448 1394ohci - ok
10:56:29.0231 4448 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
10:56:29.0232 4448 ACPI - ok
10:56:29.0261 4448 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
10:56:29.0261 4448 AcpiPmi - ok
10:56:29.0360 4448 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
10:56:29.0361 4448 AdobeARMservice - ok
10:56:29.0487 4448 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
10:56:29.0490 4448 AdobeFlashPlayerUpdateSvc - ok
10:56:29.0544 4448 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys
10:56:29.0546 4448 adp94xx - ok
10:56:29.0569 4448 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys
10:56:29.0571 4448 adpahci - ok
10:56:29.0583 4448 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys
10:56:29.0584 4448 adpu320 - ok
10:56:29.0606 4448 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\windows\System32\aelupsvc.dll
10:56:29.0607 4448 AeLookupSvc - ok
10:56:29.0657 4448 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
10:56:29.0659 4448 AFD - ok
10:56:29.0688 4448 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
10:56:29.0688 4448 agp440 - ok
10:56:29.0705 4448 ALG (3290d6946b5e30e70414990574883ddb) C:\windows\System32\alg.exe
10:56:29.0706 4448 ALG - ok
10:56:29.0717 4448 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
10:56:29.0717 4448 aliide - ok
10:56:29.0745 4448 AMD External Events Utility (b4143cb1dd16ae73c6177c72f33450a6) C:\windows\system32\atiesrxx.exe
10:56:29.0746 4448 AMD External Events Utility - ok
10:56:29.0761 4448 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
10:56:29.0761 4448 amdide - ok
10:56:29.0767 4448 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys
10:56:29.0768 4448 AmdK8 - ok
10:56:30.0107 4448 amdkmdag (d1d06810bf7e21f5763eb06cb7e7262b) C:\windows\system32\DRIVERS\atipmdag.sys
10:56:30.0131 4448 amdkmdag - ok
10:56:30.0235 4448 amdkmdap (6ba71d6616b56816e57394d77dd1bb6f) C:\windows\system32\DRIVERS\atikmpag.sys
10:56:30.0236 4448 amdkmdap - ok
10:56:30.0250 4448 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys
10:56:30.0250 4448 AmdPPM - ok
10:56:30.0289 4448 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
10:56:30.0290 4448 amdsata - ok
10:56:30.0302 4448 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys
10:56:30.0304 4448 amdsbs - ok
10:56:30.0318 4448 amdxata (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
10:56:30.0318 4448 amdxata - ok
10:56:30.0370 4448 AntiVirSchedulerService (466a0d95960dad3222c896d2cea99993) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
10:56:30.0371 4448 AntiVirSchedulerService - ok
10:56:30.0393 4448 AntiVirService (a489be6bb0aa1ff406b488b60542314b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
10:56:30.0394 4448 AntiVirService - ok
10:56:30.0418 4448 AntiVirWebService (676894fa57b671fec5c3f05f8929e03b) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
10:56:30.0421 4448 AntiVirWebService - ok
10:56:30.0456 4448 AppID (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
10:56:30.0457 4448 AppID - ok
10:56:30.0479 4448 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\windows\System32\appidsvc.dll
10:56:30.0480 4448 AppIDSvc - ok
10:56:30.0510 4448 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\windows\System32\appinfo.dll
10:56:30.0511 4448 Appinfo - ok
10:56:30.0549 4448 Apple Mobile Device (3debbecf665dcdde3a95d9b902010817) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
10:56:30.0550 4448 Apple Mobile Device - ok
10:56:30.0575 4448 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys
10:56:30.0576 4448 arc - ok
10:56:30.0583 4448 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys
10:56:30.0583 4448 arcsas - ok
10:56:30.0593 4448 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
10:56:30.0593 4448 AsyncMac - ok
10:56:30.0622 4448 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
10:56:30.0623 4448 atapi - ok
10:56:30.0706 4448 athr (e857eee6b92aaa473ebb3465add8f7e7) C:\windows\system32\DRIVERS\athrx.sys
10:56:30.0713 4448 athr - ok
10:56:30.0805 4448 AtiHdmiService (77c149e6d702737b2e372dee166faef8) C:\windows\system32\drivers\AtiHdmi.sys
10:56:30.0806 4448 AtiHdmiService - ok
10:56:31.0108 4448 atikmdag (d1d06810bf7e21f5763eb06cb7e7262b) C:\windows\system32\DRIVERS\atikmdag.sys
10:56:31.0132 4448 atikmdag - ok
10:56:31.0227 4448 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
10:56:31.0234 4448 AudioEndpointBuilder - ok
10:56:31.0243 4448 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
10:56:31.0249 4448 AudioSrv - ok
10:56:31.0296 4448 avgntflt (26e38b5a58c6c55fafbc563eeddb0867) C:\windows\system32\DRIVERS\avgntflt.sys
10:56:31.0297 4448 avgntflt - ok
10:56:31.0312 4448 avipbb (9d1f00beff84cbbf46d7f052bc7e0565) C:\windows\system32\DRIVERS\avipbb.sys
10:56:31.0313 4448 avipbb - ok
10:56:31.0323 4448 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\windows\system32\DRIVERS\avkmgr.sys
10:56:31.0324 4448 avkmgr - ok
10:56:31.0364 4448 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\windows\System32\AxInstSV.dll
10:56:31.0365 4448 AxInstSV - ok
10:56:31.0403 4448 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys
10:56:31.0405 4448 b06bdrv - ok
10:56:31.0428 4448 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
10:56:31.0430 4448 b57nd60a - ok
10:56:31.0446 4448 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\windows\System32\bdesvc.dll
10:56:31.0447 4448 BDESVC - ok
10:56:31.0457 4448 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
10:56:31.0458 4448 Beep - ok
10:56:31.0523 4448 BFE (82974d6a2fd19445cc5171fc378668a4) C:\windows\System32\bfe.dll
10:56:31.0527 4448 BFE - ok
10:56:31.0580 4448 BITS (1ea7969e3271cbc59e1730697dc74682) C:\windows\System32\qmgr.dll
10:56:31.0585 4448 BITS - ok
10:56:31.0621 4448 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
10:56:31.0622 4448 blbdrive - ok
10:56:31.0687 4448 Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
10:56:31.0690 4448 Bonjour Service - ok
10:56:31.0706 4448 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
10:56:31.0707 4448 bowser - ok
10:56:31.0730 4448 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys
10:56:31.0730 4448 BrFiltLo - ok
10:56:31.0733 4448 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys
10:56:31.0733 4448 BrFiltUp - ok
10:56:31.0765 4448 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\windows\System32\browser.dll
10:56:31.0766 4448 Browser - ok
10:56:31.0784 4448 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
10:56:31.0786 4448 Brserid - ok
10:56:31.0796 4448 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
10:56:31.0797 4448 BrSerWdm - ok
10:56:31.0800 4448 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
10:56:31.0801 4448 BrUsbMdm - ok
10:56:31.0804 4448 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
10:56:31.0805 4448 BrUsbSer - ok
10:56:31.0811 4448 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys
10:56:31.0811 4448 BTHMODEM - ok
10:56:31.0830 4448 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\windows\system32\bthserv.dll
10:56:31.0831 4448 bthserv - ok
10:56:31.0861 4448 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
10:56:31.0861 4448 cdfs - ok
10:56:31.0925 4448 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\drivers\cdrom.sys
10:56:31.0926 4448 cdrom - ok
10:56:31.0980 4448 CEEBC40A-FDED-4C59-B354-939132350B01 (91d0953e414e475878d07ee79765c17c) C:\Program Files (x86)\Roxio\BackOnTrack\File Backup\FileBackupSVC.exe
10:56:31.0981 4448 CEEBC40A-FDED-4C59-B354-939132350B01 - ok
10:56:32.0012 4448 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
10:56:32.0013 4448 CertPropSvc - ok
10:56:32.0018 4448 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys
10:56:32.0019 4448 circlass - ok
10:56:32.0045 4448 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
10:56:32.0046 4448 CLFS - ok
10:56:32.0099 4448 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:56:32.0100 4448 clr_optimization_v2.0.50727_32 - ok
10:56:32.0139 4448 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
10:56:32.0140 4448 clr_optimization_v2.0.50727_64 - ok
10:56:32.0175 4448 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:56:32.0176 4448 clr_optimization_v4.0.30319_32 - ok
10:56:32.0190 4448 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
10:56:32.0191 4448 clr_optimization_v4.0.30319_64 - ok
10:56:32.0211 4448 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
10:56:32.0211 4448 CmBatt - ok
10:56:32.0243 4448 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
10:56:32.0243 4448 cmdide - ok
10:56:32.0298 4448 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\windows\system32\Drivers\cng.sys
10:56:32.0300 4448 CNG - ok
10:56:32.0311 4448 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys
10:56:32.0311 4448 Compbatt - ok
10:56:32.0348 4448 CompositeBus (03edb043586cceba243d689bdda370a8) C:\windows\system32\drivers\CompositeBus.sys
10:56:32.0348 4448 CompositeBus - ok
10:56:32.0351 4448 COMSysApp - ok
10:56:32.0356 4448 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys
10:56:32.0357 4448 crcdisk - ok
10:56:32.0395 4448 CryptSvc (4f5414602e2544a4554d95517948b705) C:\windows\system32\cryptsvc.dll
10:56:32.0396 4448 CryptSvc - ok
10:56:32.0500 4448 cvhsvc (72794d112cbaff3bc0c29bf7350d4741) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
10:56:32.0504 4448 cvhsvc - ok
10:56:32.0560 4448 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
10:56:32.0563 4448 DcomLaunch - ok
10:56:32.0594 4448 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\windows\System32\defragsvc.dll
10:56:32.0596 4448 defragsvc - ok
10:56:32.0642 4448 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
10:56:32.0643 4448 DfsC - ok
10:56:32.0668 4448 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\windows\system32\dhcpcore.dll
10:56:32.0670 4448 Dhcp - ok
10:56:32.0688 4448 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
10:56:32.0689 4448 discache - ok
10:56:32.0697 4448 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys
10:56:32.0698 4448 Disk - ok
10:56:32.0724 4448 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\windows\System32\dnsrslvr.dll
10:56:32.0725 4448 Dnscache - ok
10:56:32.0762 4448 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\windows\System32\dot3svc.dll
10:56:32.0763 4448 dot3svc - ok
10:56:32.0801 4448 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\windows\system32\dps.dll
10:56:32.0802 4448 DPS - ok
10:56:32.0816 4448 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
10:56:32.0816 4448 drmkaud - ok
10:56:32.0896 4448 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\windows\System32\drivers\dxgkrnl.sys
10:56:32.0901 4448 DXGKrnl - ok
10:56:32.0926 4448 e1kexpress (52a482dc61f24b498c8268866b90bb44) C:\windows\system32\DRIVERS\e1k62x64.sys
10:56:32.0928 4448 e1kexpress - ok
10:56:32.0951 4448 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\windows\System32\eapsvc.dll
10:56:32.0952 4448 EapHost - ok
10:56:33.0113 4448 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys
10:56:33.0129 4448 ebdrv - ok
10:56:33.0216 4448 EFS (c118a82cd78818c29ab228366ebf81c3) C:\windows\System32\lsass.exe
10:56:33.0217 4448 EFS - ok
10:56:33.0305 4448 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\windows\ehome\ehRecvr.exe
10:56:33.0308 4448 ehRecvr - ok
10:56:33.0334 4448 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\windows\ehome\ehsched.exe
10:56:33.0335 4448 ehSched - ok
10:56:33.0369 4448 ElbyCDIO (a05fc7eca0966ebb70e4d17b855a853b) C:\windows\system32\Drivers\ElbyCDIO.sys
10:56:33.0370 4448 ElbyCDIO - ok
10:56:33.0405 4448 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys
10:56:33.0408 4448 elxstor - ok
10:56:33.0439 4448 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
10:56:33.0440 4448 ErrDev - ok
10:56:33.0495 4448 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\windows\system32\es.dll
10:56:33.0497 4448 EventSystem - ok
10:56:33.0513 4448 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
10:56:33.0514 4448 exfat - ok
10:56:33.0564 4448 Fabs - ok
10:56:33.0589 4448 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
10:56:33.0590 4448 fastfat - ok
10:56:33.0654 4448 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\windows\system32\fxssvc.exe
10:56:33.0658 4448 Fax - ok
10:56:33.0662 4448 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys
10:56:33.0662 4448 fdc - ok
10:56:33.0675 4448 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\windows\system32\fdPHost.dll
10:56:33.0676 4448 fdPHost - ok
10:56:33.0692 4448 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\windows\system32\fdrespub.dll
10:56:33.0693 4448 FDResPub - ok
10:56:33.0711 4448 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
10:56:33.0711 4448 FileInfo - ok
10:56:33.0720 4448 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
10:56:33.0720 4448 Filetrace - ok
10:56:33.0868 4448 FirebirdServerMAGIXInstance (fff1130f7c9fa01d093a1edfc5cce8fc) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
10:56:33.0885 4448 FirebirdServerMAGIXInstance - ok
10:56:33.0995 4448 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys
10:56:33.0995 4448 flpydisk - ok
10:56:34.0046 4448 FltMgr (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
10:56:34.0047 4448 FltMgr - ok
10:56:34.0130 4448 FontCache (b4447f606bb19fd8ad0bafb59b90f5d9) C:\windows\system32\FntCache.dll
10:56:34.0135 4448 FontCache - ok
10:56:34.0190 4448 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
10:56:34.0191 4448 FontCache3.0.0.0 - ok
10:56:34.0225 4448 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
10:56:34.0225 4448 FsDepends - ok
10:56:34.0250 4448 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\windows\system32\DRIVERS\fssfltr.sys
10:56:34.0251 4448 fssfltr - ok
10:56:34.0361 4448 fsssvc (4ce9dac1518ff7e77bd213e6394b9d77) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
10:56:34.0366 4448 fsssvc - ok
10:56:34.0460 4448 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\windows\system32\drivers\Fs_Rec.sys
10:56:34.0461 4448 Fs_Rec - ok
10:56:34.0505 4448 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
10:56:34.0506 4448 fvevol - ok
10:56:34.0527 4448 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys
10:56:34.0527 4448 gagp30kx - ok
10:56:34.0552 4448 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
10:56:34.0553 4448 GEARAspiWDM - ok
10:56:34.0618 4448 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\windows\System32\gpsvc.dll
10:56:34.0621 4448 gpsvc - ok
10:56:34.0628 4448 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
10:56:34.0629 4448 hcw85cir - ok
10:56:34.0673 4448 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
10:56:34.0674 4448 HdAudAddService - ok
10:56:34.0693 4448 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\drivers\HDAudBus.sys
10:56:34.0693 4448 HDAudBus - ok
10:56:34.0714 4448 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys
10:56:34.0714 4448 HECIx64 - ok
10:56:34.0728 4448 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys
10:56:34.0728 4448 HidBatt - ok
10:56:34.0734 4448 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys
10:56:34.0735 4448 HidBth - ok
10:56:34.0740 4448 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys
10:56:34.0741 4448 HidIr - ok
10:56:34.0761 4448 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\windows\system32\hidserv.dll
10:56:34.0762 4448 hidserv - ok
10:56:34.0799 4448 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\drivers\hidusb.sys
10:56:34.0800 4448 HidUsb - ok
10:56:34.0830 4448 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\windows\system32\kmsvc.dll
10:56:34.0831 4448 hkmsvc - ok
10:56:34.0879 4448 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\windows\system32\ListSvc.dll
10:56:34.0881 4448 HomeGroupListener - ok
10:56:34.0924 4448 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\windows\system32\provsvc.dll
10:56:34.0926 4448 HomeGroupProvider - ok
10:56:34.0944 4448 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
10:56:34.0944 4448 HpSAMD - ok
10:56:35.0014 4448 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
10:56:35.0018 4448 HTTP - ok
10:56:35.0047 4448 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
10:56:35.0047 4448 hwpolicy - ok
10:56:35.0083 4448 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\drivers\i8042prt.sys
10:56:35.0084 4448 i8042prt - ok
10:56:35.0124 4448 iaStor (abbf174cb394f5c437410a788b7e404a) C:\windows\system32\DRIVERS\iaStor.sys
10:56:35.0127 4448 iaStor - ok
10:56:35.0160 4448 IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
10:56:35.0160 4448 IAStorDataMgrSvc - ok
10:56:35.0208 4448 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
10:56:35.0211 4448 iaStorV - ok
10:56:35.0319 4448 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
10:56:35.0323 4448 idsvc - ok
10:56:35.0634 4448 igfx (a87261ef1546325b559374f5689cf5bc) C:\windows\system32\DRIVERS\igdkmd64.sys
10:56:35.0664 4448 igfx - ok
10:56:35.0740 4448 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys
10:56:35.0741 4448 iirsp - ok
10:56:35.0818 4448 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\windows\System32\ikeext.dll
10:56:35.0826 4448 IKEEXT - ok
10:56:35.0956 4448 IntcAzAudAddService (9aa6a93852e36fe76c3f7fc2904f3b01) C:\windows\system32\drivers\RTKVHD64.sys
10:56:35.0968 4448 IntcAzAudAddService - ok
10:56:36.0076 4448 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
10:56:36.0076 4448 intelide - ok
10:56:36.0095 4448 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
10:56:36.0096 4448 intelppm - ok
10:56:36.0122 4448 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\windows\system32\ipbusenum.dll
10:56:36.0124 4448 IPBusEnum - ok
10:56:36.0157 4448 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
10:56:36.0158 4448 IpFilterDriver - ok
10:56:36.0219 4448 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\windows\System32\iphlpsvc.dll
10:56:36.0225 4448 iphlpsvc - ok
10:56:36.0263 4448 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
10:56:36.0264 4448 IPMIDRV - ok
10:56:36.0296 4448 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
10:56:36.0297 4448 IPNAT - ok
10:56:36.0374 4448 iPod Service (ee4c2a137c7088911a8919effc9812e7) C:\Program Files\iPod\bin\iPodService.exe
10:56:36.0383 4448 iPod Service - ok
10:56:36.0400 4448 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
10:56:36.0401 4448 IRENUM - ok
10:56:36.0432 4448 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
10:56:36.0432 4448 isapnp - ok
10:56:36.0473 4448 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
10:56:36.0475 4448 iScsiPrt - ok
10:56:36.0486 4448 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\drivers\kbdclass.sys
10:56:36.0487 4448 kbdclass - ok
10:56:36.0520 4448 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\drivers\kbdhid.sys
10:56:36.0521 4448 kbdhid - ok
10:56:36.0541 4448 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:56:36.0542 4448 KeyIso - ok
10:56:36.0579 4448 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\windows\system32\Drivers\ksecdd.sys
10:56:36.0580 4448 KSecDD - ok
10:56:36.0617 4448 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\windows\system32\Drivers\ksecpkg.sys
10:56:36.0618 4448 KSecPkg - ok
10:56:36.0638 4448 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
10:56:36.0639 4448 ksthunk - ok
10:56:36.0670 4448 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\windows\system32\msdtckrm.dll
10:56:36.0673 4448 KtmRm - ok
10:56:36.0714 4448 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\windows\system32\srvsvc.dll
10:56:36.0716 4448 LanmanServer - ok
10:56:36.0754 4448 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\windows\System32\wkssvc.dll
10:56:36.0756 4448 LanmanWorkstation - ok
10:56:36.0818 4448 LenovoCOMSvc (57ead1ca5c1ffc88905fd96b119bb286) C:\Program Files\Lenovo\Power Dial\LenovoCOMSvc.exe
10:56:36.0819 4448 LenovoCOMSvc - ok
10:56:36.0834 4448 LitModeCtrl (47f2b11a3567aa0e921edab0969e7aa7) C:\Program Files\Lenovo\Power Dial\LitModeCtrl.exe
10:56:36.0835 4448 LitModeCtrl - ok
10:56:36.0850 4448 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
10:56:36.0851 4448 lltdio - ok
10:56:36.0883 4448 lltdsvc (c1185803384ab3feed115f79f109427f) C:\windows\System32\lltdsvc.dll
10:56:36.0885 4448 lltdsvc - ok
10:56:36.0896 4448 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\windows\System32\lmhsvc.dll
10:56:36.0896 4448 lmhosts - ok
10:56:36.0956 4448 LMS (e38775922d4a4c05b5d96733ab4ce169) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
10:56:36.0958 4448 LMS - ok
10:56:36.0983 4448 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys
10:56:36.0984 4448 LSI_FC - ok
10:56:36.0993 4448 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys
10:56:36.0995 4448 LSI_SAS - ok
10:56:37.0005 4448 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys
10:56:37.0006 4448 LSI_SAS2 - ok
10:56:37.0015 4448 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys
10:56:37.0016 4448 LSI_SCSI - ok
10:56:37.0034 4448 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
10:56:37.0035 4448 luafv - ok
10:56:37.0078 4448 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\windows\system32\Mcx2Svc.dll
10:56:37.0081 4448 Mcx2Svc - ok
10:56:37.0089 4448 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys
10:56:37.0090 4448 megasas - ok
10:56:37.0112 4448 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys
10:56:37.0113 4448 MegaSR - ok
10:56:37.0160 4448 Microsoft SharePoint Workspace Audit Service - ok
10:56:37.0205 4448 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
10:56:37.0206 4448 MMCSS - ok
10:56:37.0210 4448 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
10:56:37.0211 4448 Modem - ok
10:56:37.0235 4448 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
10:56:37.0235 4448 monitor - ok
10:56:37.0292 4448 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\drivers\mouclass.sys
10:56:37.0293 4448 mouclass - ok
10:56:37.0297 4448 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
10:56:37.0297 4448 mouhid - ok
10:56:37.0341 4448 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
10:56:37.0342 4448 mountmgr - ok
10:56:37.0383 4448 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
10:56:37.0384 4448 MozillaMaintenance - ok
10:56:37.0442 4448 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
10:56:37.0444 4448 mpio - ok
10:56:37.0470 4448 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
10:56:37.0471 4448 mpsdrv - ok
10:56:37.0542 4448 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\windows\system32\mpssvc.dll
10:56:37.0551 4448 MpsSvc - ok
10:56:37.0588 4448 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
10:56:37.0589 4448 MRxDAV - ok
10:56:37.0616 4448 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
10:56:37.0617 4448 mrxsmb - ok
10:56:37.0663 4448 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
10:56:37.0664 4448 mrxsmb10 - ok
10:56:37.0688 4448 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
10:56:37.0689 4448 mrxsmb20 - ok
10:56:37.0724 4448 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\drivers\msahci.sys
10:56:37.0725 4448 msahci - ok
10:56:37.0768 4448 msdsm (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
10:56:37.0769 4448 msdsm - ok
10:56:37.0797 4448 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\windows\System32\msdtc.exe
10:56:37.0798 4448 MSDTC - ok
10:56:37.0820 4448 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
10:56:37.0821 4448 Msfs - ok
10:56:37.0833 4448 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
10:56:37.0833 4448 mshidkmdf - ok
10:56:37.0869 4448 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
10:56:37.0870 4448 msisadrv - ok
10:56:37.0896 4448 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\windows\system32\iscsiexe.dll
10:56:37.0897 4448 MSiSCSI - ok
10:56:37.0905 4448 msiserver - ok
10:56:37.0924 4448 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
10:56:37.0925 4448 MSKSSRV - ok
10:56:37.0927 4448 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
10:56:37.0927 4448 MSPCLOCK - ok
10:56:37.0930 4448 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
10:56:37.0931 4448 MSPQM - ok
10:56:37.0983 4448 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
10:56:37.0984 4448 MsRPC - ok
10:56:38.0016 4448 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\drivers\mssmbios.sys
10:56:38.0017 4448 mssmbios - ok
10:56:38.0019 4448 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
10:56:38.0019 4448 MSTEE - ok
10:56:38.0022 4448 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys
10:56:38.0023 4448 MTConfig - ok
10:56:38.0034 4448 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
10:56:38.0035 4448 Mup - ok
10:56:38.0062 4448 napagent (582ac6d9873e31dfa28a4547270862dd) C:\windows\system32\qagentRT.dll
10:56:38.0064 4448 napagent - ok
10:56:38.0086 4448 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
10:56:38.0088 4448 NativeWifiP - ok
10:56:38.0145 4448 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\windows\system32\drivers\ndis.sys
10:56:38.0154 4448 NDIS - ok
10:56:38.0180 4448 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
10:56:38.0181 4448 NdisCap - ok
10:56:38.0195 4448 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
10:56:38.0196 4448 NdisTapi - ok
10:56:38.0235 4448 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
10:56:38.0236 4448 Ndisuio - ok
10:56:38.0273 4448 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
10:56:38.0274 4448 NdisWan - ok
10:56:38.0315 4448 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
10:56:38.0315 4448 NDProxy - ok
10:56:38.0338 4448 Netaapl (6f4607e2333fe21e9e3ff8133a88b35b) C:\windows\system32\DRIVERS\netaapl64.sys
10:56:38.0338 4448 Netaapl - ok
10:56:38.0350 4448 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
10:56:38.0350 4448 NetBIOS - ok
10:56:38.0397 4448 NetBT (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
10:56:38.0399 4448 NetBT - ok
10:56:38.0416 4448 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:56:38.0417 4448 Netlogon - ok
10:56:38.0442 4448 Netman (847d3ae376c0817161a14a82c8922a9e) C:\windows\System32\netman.dll
10:56:38.0445 4448 Netman - ok
10:56:38.0469 4448 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\windows\System32\netprofm.dll
10:56:38.0473 4448 netprofm - ok
10:56:38.0533 4448 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
10:56:38.0535 4448 NetTcpPortSharing - ok
10:56:38.0552 4448 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys
10:56:38.0553 4448 nfrd960 - ok
10:56:38.0576 4448 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\windows\System32\nlasvc.dll
10:56:38.0579 4448 NlaSvc - ok
10:56:38.0590 4448 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
10:56:38.0591 4448 Npfs - ok
10:56:38.0601 4448 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\windows\system32\nsisvc.dll
10:56:38.0602 4448 nsi - ok
10:56:38.0613 4448 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
10:56:38.0613 4448 nsiproxy - ok
10:56:38.0702 4448 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
10:56:38.0711 4448 Ntfs - ok
10:56:38.0795 4448 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
10:56:38.0796 4448 Null - ok
10:56:38.0839 4448 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
10:56:38.0841 4448 nvraid - ok
10:56:38.0849 4448 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
10:56:38.0851 4448 nvstor - ok
10:56:38.0885 4448 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
10:56:38.0886 4448 nv_agp - ok
10:56:38.0924 4448 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
10:56:38.0925 4448 ohci1394 - ok
10:56:38.0975 4448 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:56:38.0976 4448 ose - ok
10:56:39.0255 4448 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
10:56:39.0278 4448 osppsvc - ok
10:56:39.0381 4448 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
10:56:39.0385 4448 p2pimsvc - ok
10:56:39.0416 4448 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\windows\system32\p2psvc.dll
10:56:39.0422 4448 p2psvc - ok
10:56:39.0458 4448 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys
10:56:39.0459 4448 Parport - ok
10:56:39.0494 4448 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\windows\system32\drivers\partmgr.sys
10:56:39.0495 4448 partmgr - ok
10:56:39.0518 4448 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\windows\System32\pcasvc.dll
10:56:39.0521 4448 PcaSvc - ok
10:56:39.0559 4448 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
10:56:39.0561 4448 pci - ok
10:56:39.0607 4448 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\drivers\pciide.sys
10:56:39.0607 4448 pciide - ok
10:56:39.0693 4448 PCLEPCI (1bebe7de8508a02650cdce45c664c2a2) C:\windows\SysWOW64\drivers\pclepci.sys
10:56:39.0694 4448 PCLEPCI - ok
10:56:39.0721 4448 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys
10:56:39.0723 4448 pcmcia - ok
10:56:39.0737 4448 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
10:56:39.0738 4448 pcw - ok
10:56:39.0773 4448 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
10:56:39.0777 4448 PEAUTH - ok
10:56:39.0824 4448 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\windows\SysWow64\perfhost.exe
10:56:39.0825 4448 PerfHost - ok
10:56:39.0941 4448 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\windows\system32\pla.dll
10:56:39.0949 4448 pla - ok
10:56:39.0990 4448 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\windows\system32\umpnpmgr.dll
10:56:39.0993 4448 PlugPlay - ok
10:56:40.0000 4448 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\windows\system32\pnrpauto.dll
10:56:40.0002 4448 PNRPAutoReg - ok
10:56:40.0029 4448 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
10:56:40.0032 4448 PNRPsvc - ok
10:56:40.0068 4448 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\windows\System32\ipsecsvc.dll
10:56:40.0072 4448 PolicyAgent - ok
10:56:40.0103 4448 Power (6ba9d927dded70bd1a9caded45f8b184) C:\windows\system32\umpo.dll
10:56:40.0104 4448 Power - ok
10:56:40.0166 4448 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
10:56:40.0167 4448 PptpMiniport - ok
10:56:40.0192 4448 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys
10:56:40.0193 4448 Processor - ok
10:56:40.0252 4448 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\windows\system32\profsvc.dll
10:56:40.0256 4448 ProfSvc - ok
10:56:40.0283 4448 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:56:40.0284 4448 ProtectedStorage - ok
10:56:40.0347 4448 Psched (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
10:56:40.0348 4448 Psched - ok
10:56:40.0374 4448 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\windows\system32\Drivers\PxHlpa64.sys
10:56:40.0374 4448 PxHlpa64 - ok
10:56:40.0475 4448 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys
10:56:40.0490 4448 ql2300 - ok
10:56:40.0594 4448 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys
10:56:40.0595 4448 ql40xx - ok
10:56:40.0619 4448 QWAVE (906191634e99aea92c4816150bda3732) C:\windows\system32\qwave.dll
10:56:40.0621 4448 QWAVE - ok
10:56:40.0628 4448 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
10:56:40.0628 4448 QWAVEdrv - ok
10:56:40.0632 4448 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
10:56:40.0633 4448 RasAcd - ok
10:56:40.0657 4448 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
10:56:40.0657 4448 RasAgileVpn - ok
10:56:40.0673 4448 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\windows\System32\rasauto.dll
10:56:40.0675 4448 RasAuto - ok
10:56:40.0710 4448 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
10:56:40.0711 4448 Rasl2tp - ok
10:56:40.0760 4448 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\windows\System32\rasmans.dll
10:56:40.0762 4448 RasMan - ok
10:56:40.0772 4448 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
10:56:40.0772 4448 RasPppoe - ok
10:56:40.0788 4448 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
10:56:40.0789 4448 RasSstp - ok
10:56:40.0834 4448 rdbss (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
10:56:40.0836 4448 rdbss - ok
10:56:40.0856 4448 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys
10:56:40.0856 4448 rdpbus - ok
10:56:40.0866 4448 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
10:56:40.0867 4448 RDPCDD - ok
10:56:40.0880 4448 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
10:56:40.0881 4448 RDPENCDD - ok
10:56:40.0894 4448 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
10:56:40.0895 4448 RDPREFMP - ok
10:56:40.0930 4448 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\windows\system32\drivers\RDPWD.sys
10:56:40.0932 4448 RDPWD - ok
10:56:40.0983 4448 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
10:56:40.0984 4448 rdyboost - ok
10:56:41.0006 4448 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\windows\System32\mprdim.dll
10:56:41.0008 4448 RemoteAccess - ok
10:56:41.0032 4448 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\windows\system32\regsvc.dll
10:56:41.0034 4448 RemoteRegistry - ok
10:56:41.0046 4448 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\windows\System32\RpcEpMap.dll
10:56:41.0048 4448 RpcEptMapper - ok
10:56:41.0059 4448 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\windows\system32\locator.exe
10:56:41.0060 4448 RpcLocator - ok
10:56:41.0118 4448 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
10:56:41.0121 4448 RpcSs - ok
10:56:41.0142 4448 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
10:56:41.0143 4448 rspndr - ok
10:56:41.0168 4448 RSUSBSTOR (b1d04ed92d148b54169499d9568a3c55) C:\windows\system32\Drivers\RtsUStor.sys
10:56:41.0170 4448 RSUSBSTOR - ok
10:56:41.0181 4448 RTL8023x64 (68dd0457d18fccef7384ae84022f0c86) C:\windows\system32\DRIVERS\Rtnic64.sys
10:56:41.0181 4448 RTL8023x64 - ok
10:56:41.0185 4448 RtsUIR - ok
10:56:41.0208 4448 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:56:41.0209 4448 SamSs - ok
10:56:41.0243 4448 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
10:56:41.0245 4448 sbp2port - ok
10:56:41.0280 4448 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\windows\System32\SCardSvr.dll
10:56:41.0284 4448 SCardSvr - ok
10:56:41.0324 4448 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
10:56:41.0325 4448 scfilter - ok
10:56:41.0418 4448 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\windows\system32\schedsvc.dll
10:56:41.0426 4448 Schedule - ok
10:56:41.0462 4448 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
10:56:41.0463 4448 SCPolicySvc - ok
10:56:41.0482 4448 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\windows\System32\SDRSVC.dll
10:56:41.0484 4448 SDRSVC - ok
10:56:41.0515 4448 SeaPort - ok
10:56:41.0554 4448 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
10:56:41.0555 4448 secdrv - ok
10:56:41.0562 4448 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\windows\system32\seclogon.dll
10:56:41.0564 4448 seclogon - ok
10:56:41.0588 4448 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\windows\System32\sens.dll
10:56:41.0589 4448 SENS - ok
10:56:41.0600 4448 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\windows\system32\sensrsvc.dll
10:56:41.0602 4448 SensrSvc - ok
10:56:41.0615 4448 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys
10:56:41.0616 4448 Serenum - ok
10:56:41.0628 4448 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys
10:56:41.0629 4448 Serial - ok
10:56:41.0665 4448 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys
10:56:41.0665 4448 sermouse - ok
10:56:41.0703 4448 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\windows\system32\sessenv.dll
10:56:41.0705 4448 SessionEnv - ok
10:56:41.0737 4448 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
10:56:41.0737 4448 sffdisk - ok
10:56:41.0748 4448 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
10:56:41.0748 4448 sffp_mmc - ok
10:56:41.0752 4448 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
10:56:41.0752 4448 sffp_sd - ok
10:56:41.0763 4448 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys
10:56:41.0763 4448 sfloppy - ok
10:56:41.0828 4448 Sftfs (c6cc9297bd53e5229653303e556aa539) C:\windows\system32\DRIVERS\Sftfslh.sys
10:56:41.0836 4448 Sftfs - ok
10:56:41.0921 4448 sftlist (13693b6354dd6e72dc5131da7d764b90) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
10:56:41.0923 4448 sftlist - ok
10:56:41.0955 4448 Sftplay (390aa7bc52cee43f6790cdea1e776703) C:\windows\system32\DRIVERS\Sftplaylh.sys
10:56:41.0957 4448 Sftplay - ok
10:56:41.0966 4448 Sftredir (617e29a0b0a2807466560d4c4e338d3e) C:\windows\system32\DRIVERS\Sftredirlh.sys
10:56:41.0967 4448 Sftredir - ok
10:56:41.0974 4448 Sftvol (8f571f016fa1976f445147e9e6c8ae9b) C:\windows\system32\DRIVERS\Sftvollh.sys
10:56:41.0975 4448 Sftvol - ok
10:56:41.0993 4448 sftvsa (c3cddd18f43d44ab713cf8c4916f7696) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
10:56:41.0994 4448 sftvsa - ok
10:56:42.0026 4448 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\windows\System32\ipnathlp.dll
10:56:42.0028 4448 SharedAccess - ok
10:56:42.0071 4448 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\windows\System32\shsvcs.dll
10:56:42.0074 4448 ShellHWDetection - ok
10:56:42.0106 4448 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys
10:56:42.0106 4448 SiSRaid2 - ok
10:56:42.0112 4448 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys
10:56:42.0113 4448 SiSRaid4 - ok
10:56:42.0122 4448 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
10:56:42.0123 4448 Smb - ok
10:56:42.0146 4448 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\windows\System32\snmptrap.exe
10:56:42.0147 4448 SNMPTRAP - ok
10:56:42.0155 4448 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
10:56:42.0155 4448 spldr - ok
10:56:42.0187 4448 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\windows\System32\spoolsv.exe
10:56:42.0191 4448 Spooler - ok
10:56:42.0378 4448 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\windows\system32\sppsvc.exe
10:56:42.0397 4448 sppsvc - ok
10:56:42.0482 4448 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\windows\system32\sppuinotify.dll
10:56:42.0484 4448 sppuinotify - ok
10:56:42.0546 4448 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
10:56:42.0551 4448 srv - ok
10:56:42.0586 4448 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
10:56:42.0589 4448 srv2 - ok
10:56:42.0612 4448 srvnet (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
10:56:42.0613 4448 srvnet - ok
10:56:42.0627 4448 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\windows\System32\ssdpsrv.dll
10:56:42.0629 4448 SSDPSRV - ok
10:56:42.0644 4448 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\windows\system32\sstpsvc.dll
10:56:42.0645 4448 SstpSvc - ok
10:56:42.0663 4448 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys
10:56:42.0664 4448 stexstor - ok
10:56:42.0700 4448 StillCam (decacb6921ded1a38642642685d77dac) C:\windows\system32\DRIVERS\serscan.sys
10:56:42.0700 4448 StillCam - ok
10:56:42.0756 4448 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\windows\System32\wiaservc.dll
10:56:42.0759 4448 stisvc - ok
10:56:42.0794 4448 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\drivers\swenum.sys
10:56:42.0795 4448 swenum - ok
10:56:42.0828 4448 swprv (e08e46fdd841b7184194011ca1955a0b) C:\windows\System32\swprv.dll
10:56:42.0832 4448 swprv - ok
10:56:42.0939 4448 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\windows\system32\sysmain.dll
10:56:42.0949 4448 SysMain - ok
10:56:43.0047 4448 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\windows\System32\TabSvc.dll
10:56:43.0049 4448 TabletInputService - ok
10:56:43.0072 4448 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\windows\System32\tapisrv.dll
10:56:43.0075 4448 TapiSrv - ok
10:56:43.0099 4448 TBS (1be03ac720f4d302ea01d40f588162f6) C:\windows\System32\tbssvc.dll
10:56:43.0101 4448 TBS - ok
10:56:43.0224 4448 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\windows\system32\drivers\tcpip.sys
10:56:43.0235 4448 Tcpip - ok
10:56:43.0354 4448 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\windows\system32\DRIVERS\tcpip.sys
10:56:43.0364 4448 TCPIP6 - ok
10:56:43.0432 4448 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
10:56:43.0433 4448 tcpipreg - ok
10:56:43.0451 4448 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
10:56:43.0451 4448 TDPIPE - ok
10:56:43.0484 4448 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\windows\system32\drivers\tdtcp.sys
10:56:43.0485 4448 TDTCP - ok
10:56:43.0519 4448 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
10:56:43.0520 4448 tdx - ok
10:56:43.0672 4448 TeamViewer6 (01a402d34732ca3da91786adcc765069) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
10:56:43.0685 4448 TeamViewer6 - ok
10:56:43.0801 4448 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\drivers\termdd.sys
10:56:43.0802 4448 TermDD - ok
10:56:43.0868 4448 TermService (2e648163254233755035b46dd7b89123) C:\windows\System32\termsrv.dll
10:56:43.0876 4448 TermService - ok
10:56:43.0901 4448 Themes (f0344071948d1a1fa732231785a0664c) C:\windows\system32\themeservice.dll
10:56:43.0904 4448 Themes - ok
10:56:43.0929 4448 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
10:56:43.0930 4448 THREADORDER - ok
10:56:43.0947 4448 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\windows\System32\trkwks.dll
10:56:43.0949 4448 TrkWks - ok
10:56:44.0018 4448 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\windows\servicing\TrustedInstaller.exe
10:56:44.0020 4448 TrustedInstaller - ok
10:56:44.0056 4448 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
10:56:44.0056 4448 tssecsrv - ok
10:56:44.0087 4448 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
10:56:44.0088 4448 TsUsbFlt - ok
10:56:44.0267 4448 TuneUp.UtilitiesSvc (811a229718c85356bc81eb20f35eb7f6) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
10:56:44.0277 4448 TuneUp.UtilitiesSvc - ok
10:56:44.0298 4448 TuneUpUtilitiesDrv (dcc94c51d27c7ec0dadeca8f64c94fcf) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys
10:56:44.0298 4448 TuneUpUtilitiesDrv - ok
10:56:44.0418 4448 tunnel (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
10:56:44.0420 4448 tunnel - ok
10:56:44.0441 4448 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys
10:56:44.0441 4448 uagp35 - ok
10:56:44.0492 4448 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
10:56:44.0496 4448 udfs - ok
10:56:44.0522 4448 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\windows\system32\UI0Detect.exe
10:56:44.0523 4448 UI0Detect - ok
10:56:44.0559 4448 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
10:56:44.0560 4448 uliagpkx - ok
10:56:44.0594 4448 umbus (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\drivers\umbus.sys
10:56:44.0594 4448 umbus - ok
10:56:44.0604 4448 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys
10:56:44.0604 4448 UmPass - ok
10:56:44.0758 4448 UNS (02c298382359653bec4c737c2ab7f9c5) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
10:56:44.0771 4448 UNS - ok
10:56:44.0862 4448 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\windows\System32\upnphost.dll
10:56:44.0867 4448 upnphost - ok
10:56:44.0894 4448 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\windows\system32\Drivers\usbaapl64.sys
10:56:44.0895 4448 USBAAPL64 - ok
10:56:44.0936 4448 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\windows\system32\DRIVERS\usbccgp.sys
10:56:44.0938 4448 usbccgp - ok
10:56:44.0942 4448 USBCCID - ok
10:56:44.0977 4448 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
10:56:44.0978 4448 usbcir - ok
10:56:45.0021 4448 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\drivers\usbehci.sys
10:56:45.0021 4448 usbehci - ok
10:56:45.0047 4448 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\DRIVERS\usbhub.sys
10:56:45.0049 4448 usbhub - ok
10:56:45.0060 4448 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\drivers\usbohci.sys
10:56:45.0060 4448 usbohci - ok
10:56:45.0076 4448 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys
10:56:45.0077 4448 usbprint - ok
10:56:45.0091 4448 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys
10:56:45.0091 4448 usbscan - ok
10:56:45.0109 4448 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
10:56:45.0109 4448 USBSTOR - ok
10:56:45.0144 4448 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\windows\system32\drivers\usbuhci.sys
10:56:45.0145 4448 usbuhci - ok
10:56:45.0167 4448 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\windows\System32\uxsms.dll
10:56:45.0169 4448 UxSms - ok
10:56:45.0183 4448 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
10:56:45.0184 4448 VaultSvc - ok
10:56:45.0215 4448 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
10:56:45.0216 4448 vdrvroot - ok
10:56:45.0276 4448 vds (8d6b481601d01a456e75c3210f1830be) C:\windows\System32\vds.exe
10:56:45.0283 4448 vds - ok
10:56:45.0297 4448 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
10:56:45.0298 4448 vga - ok
10:56:45.0311 4448 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
10:56:45.0312 4448 VgaSave - ok
10:56:45.0353 4448 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
10:56:45.0354 4448 vhdmp - ok
10:56:45.0368 4448 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
10:56:45.0369 4448 viaide - ok
10:56:45.0383 4448 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
10:56:45.0383 4448 volmgr - ok
10:56:45.0434 4448 volmgrx (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
10:56:45.0436 4448 volmgrx - ok
10:56:45.0459 4448 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\windows\system32\drivers\volsnap.sys
10:56:45.0461 4448 volsnap - ok
10:56:45.0485 4448 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys
10:56:45.0487 4448 vsmraid - ok
10:56:45.0600 4448 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\windows\system32\vssvc.exe
10:56:45.0620 4448 VSS - ok
10:56:45.0705 4448 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
10:56:45.0705 4448 vwifibus - ok
10:56:45.0715 4448 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
10:56:45.0717 4448 vwififlt - ok
10:56:45.0756 4448 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\windows\system32\w32time.dll
10:56:45.0762 4448 W32Time - ok
10:56:45.0783 4448 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys
10:56:45.0783 4448 WacomPen - ok
10:56:45.0821 4448 WANARP (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
10:56:45.0822 4448 WANARP - ok
10:56:45.0825 4448 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
10:56:45.0826 4448 Wanarpv6 - ok
10:56:45.0935 4448 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\windows\system32\wbengine.exe
10:56:45.0943 4448 wbengine - ok
10:56:46.0039 4448 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\windows\System32\wbiosrvc.dll
10:56:46.0041 4448 WbioSrvc - ok
10:56:46.0093 4448 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\windows\System32\wcncsvc.dll
10:56:46.0096 4448 wcncsvc - ok
10:56:46.0111 4448 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\windows\System32\WcsPlugInService.dll
10:56:46.0112 4448 WcsPlugInService - ok
10:56:46.0143 4448 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys
10:56:46.0143 4448 Wd - ok
10:56:46.0179 4448 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
10:56:46.0182 4448 Wdf01000 - ok
10:56:46.0193 4448 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
10:56:46.0195 4448 WdiServiceHost - ok
10:56:46.0198 4448 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
10:56:46.0200 4448 WdiSystemHost - ok
10:56:46.0258 4448 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\windows\System32\webclnt.dll
10:56:46.0260 4448 WebClient - ok
10:56:46.0284 4448 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\windows\system32\wecsvc.dll
10:56:46.0286 4448 Wecsvc - ok
10:56:46.0299 4448 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\windows\System32\wercplsupport.dll
10:56:46.0301 4448 wercplsupport - ok
10:56:46.0309 4448 WerSvc (6d137963730144698cbd10f202e9f251) C:\windows\System32\WerSvc.dll
10:56:46.0310 4448 WerSvc - ok
10:56:46.0343 4448 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
10:56:46.0343 4448 WfpLwf - ok
10:56:46.0374 4448 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\windows\system32\DRIVERS\wimfltr.sys
10:56:46.0375 4448 WimFltr - ok
10:56:46.0389 4448 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
10:56:46.0389 4448 WIMMount - ok
10:56:46.0412 4448 WinDefend - ok
10:56:46.0416 4448 WinHttpAutoProxySvc - ok
10:56:46.0437 4448 WinI2C-DDC (66c365b542195c1f6e2ff4a7d8f3827c) C:\windows\system32\drivers\DDCDrv.sys
10:56:46.0438 4448 WinI2C-DDC - ok
10:56:46.0485 4448 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\windows\system32\wbem\WMIsvc.dll
10:56:46.0486 4448 Winmgmt - ok
10:56:46.0613 4448 WinRM (bcb1310604aa415c4508708975b3931e) C:\windows\system32\WsmSvc.dll
10:56:46.0625 4448 WinRM - ok
10:56:46.0744 4448 WinUsb (fe88b288356e7b47b74b13372add906d) C:\windows\system32\DRIVERS\WinUsb.sys
10:56:46.0744 4448 WinUsb - ok
10:56:46.0801 4448 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\windows\System32\wlansvc.dll
10:56:46.0807 4448 Wlansvc - ok
10:56:46.0846 4448 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
10:56:46.0847 4448 wlcrasvc - ok
10:56:46.0985 4448 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
10:56:46.0996 4448 wlidsvc - ok
10:56:47.0107 4448 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\drivers\wmiacpi.sys
10:56:47.0107 4448 WmiAcpi - ok
10:56:47.0160 4448 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\windows\system32\wbem\WmiApSrv.exe
10:56:47.0161 4448 wmiApSrv - ok
10:56:47.0186 4448 WMPNetworkSvc - ok
10:56:47.0210 4448 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\windows\System32\wpcsvc.dll
10:56:47.0211 4448 WPCSvc - ok
10:56:47.0246 4448 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\windows\system32\wpdbusenum.dll
10:56:47.0248 4448 WPDBusEnum - ok
10:56:47.0260 4448 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
10:56:47.0261 4448 ws2ifsl - ok
10:56:47.0275 4448 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\windows\System32\wscsvc.dll
10:56:47.0276 4448 wscsvc - ok
10:56:47.0279 4448 WSearch - ok
10:56:47.0312 4448 wsvd (83575c43b2bfe9ab0661a7f957e843c0) C:\windows\system32\DRIVERS\wsvd.sys
10:56:47.0313 4448 wsvd - ok
10:56:47.0445 4448 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\windows\system32\wuaueng.dll
10:56:47.0456 4448 wuauserv - ok
10:56:47.0564 4448 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
10:56:47.0565 4448 WudfPf - ok
10:56:47.0584 4448 WUDFRd (cf8d590be3373029d57af80914190682) C:\windows\system32\DRIVERS\WUDFRd.sys
10:56:47.0585 4448 WUDFRd - ok
10:56:47.0628 4448 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\windows\System32\WUDFSvc.dll
10:56:47.0629 4448 wudfsvc - ok
10:56:47.0666 4448 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\windows\System32\wwansvc.dll
10:56:47.0669 4448 WwanSvc - ok
10:56:47.0719 4448 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\windows\system32\DRIVERS\yk62x64.sys
10:56:47.0720 4448 yukonw7 - ok
10:56:47.0733 4448 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
10:56:47.0877 4448 \Device\Harddisk0\DR0 - ok
10:56:47.0880 4448 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
10:56:47.0883 4448 \Device\Harddisk1\DR1 - ok
10:56:47.0885 4448 Boot (0x1200) (2223329836bf626dbdd3e858fe7e0bf8) \Device\Harddisk0\DR0\Partition0
10:56:47.0887 4448 \Device\Harddisk0\DR0\Partition0 - ok
10:56:47.0898 4448 Boot (0x1200) (d76da93ece00c16f437acc914502b150) \Device\Harddisk0\DR0\Partition1
10:56:47.0902 4448 \Device\Harddisk0\DR0\Partition1 - ok
10:56:47.0905 4448 Boot (0x1200) (97793c6ebe782489632be676e2c9be30) \Device\Harddisk1\DR1\Partition0
10:56:47.0907 4448 \Device\Harddisk1\DR1\Partition0 - ok
10:56:47.0907 4448 ============================================================
10:56:47.0907 4448 Scan finished
10:56:47.0907 4448 ============================================================
10:56:47.0913 5572 Detected object count: 0
10:56:47.0913 5572 Actual detected object count: 0

t'john 18.07.2012 10:01

Sehr gut! :daumenhoc

Hinweis: ESET zeigt durchaus öfter ein paar Fehlalarme. Deswegen soll auch von ESET immer nur erst das Log gepostet und nichts entfernt werden.


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

lively1986 19.07.2012 04:38

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=bf5cf0f8bff48d4aa17e423201f40c04
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-18 09:30:27
# local_time=2012-07-18 11:30:27 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 764899 764899 0 0
# compatibility_mode=2304 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776574 100 94 1025750 94232522 0 0
# compatibility_mode=8192 67108863 100 0 69 69 0 0
# scanned=65301
# found=0
# cleaned=0
# scan_time=1155
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=bf5cf0f8bff48d4aa17e423201f40c04
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-07-18 09:26:50
# local_time=2012-07-18 11:26:50 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1792 16777215 100 0 802765 802765 0 0
# compatibility_mode=2304 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776574 100 94 1063616 94270388 0 0
# compatibility_mode=8192 67108863 100 0 37935 37935 0 0
# scanned=358997
# found=0
# cleaned=0
# scan_time=6272


t'john 19.07.2012 09:19

Sehr gut! :daumenhoc

damit bist Du sauber und entlassen! :)


Tool-Bereinigung mit OTL


Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
  • Bitte lade Dir (falls noch nicht vorhanden) OTL von OldTimer herunter.
  • Speichere es auf Deinem Desktop.
  • Doppelklick auf OTL.exe um das Programm auszuführen.
    Vista- und Windows 7-User starten mit Rechtsklick auf das Programm-Icon und wählen "Als Administrator ausführen".
  • Klicke auf den Button "Bereinigung"
  • OTL fragt eventuell nach einem Neustart.
    Sollte es dies tun, so lasse dies bitte zu.
Anmerkung: Nach dem Neustart werden OTL und andere Helferprogramme, die Du im Laufe der Bereinigung heruntergeladen hast, nicht mehr vorhanden sein. Sie wurden entfernt. Es ist daher Ok, wenn diese Programme nicht mehr vorhanden sind. Sollten noch welche übrig geblieben sein, lösche sie manuell.



Lektuere zum abarbeiten:
http://www.trojaner-board.de/90880-d...tallation.html
http://www.trojaner-board.de/105213-...tellungen.html
PluginCheck
http://www.trojaner-board.de/96344-a...-rechners.html
Secunia Online Software Inspector
http://www.trojaner-board.de/71715-k...iendungen.html
http://www.trojaner-board.de/83238-a...sschalten.html


Alle Zeitangaben in WEZ +1. Es ist jetzt 10:31 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19