![]() |
fbDownloader auf Rechner (Malewarebites Quickscan clean) Hallo! Leider habe ich mir mit einem Fotoprogramm (wie offenbar einige andere auch) den fbDownloader auf mein Notebook geladen :-( Da ich nicht wirklich viel Ahnung von so etwas habe, wollte ich Euch um Hilfe bitten. Was ich bis jetzt getan habe: - bei Firefox habe ich die Suchoption entfernt und auf Google zurückgestellt. - In der Systemsteuerung kann ich das fbDownloader Programm nicht deinstallieren (naja, is ja klar...), es erschein lediglich die Option, das Programm/Name aus der Liste zu entfernen. - Der Quickscan war clean, lasse gerade den ausführlichen Scan laufen. h.e.l.p.! Danke schon mal :-* |
:hallo: Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Schritt 1 Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop (falls noch nicht vorhanden).
Code: activex
Schritt 2 Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop.
Schritt 3 Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit. Schritt 4 Lese bitte folgende Anweisungen genau. Wir wollen hier noch nichts "fixen" sondern nur einen Scan Report sehen. Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Bitte poste mit deiner nächsten Antwort
|
Hallo Matthias! DANKE schon mal für Deine schnelle Hilfe! OTL Logfile: Code: OTL logfile created on: 01.12.2012 15:44:01 - Run 1 OTL Logfile: Code: OTL Extras logfile created on: 01.12.2012 15:44:01 - Run 1 defogger_disable by jpshortstuff (23.02.10.1) Log created at 15:58 on 01/12/2012 (Mme Pri) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Schritt 3 funktiniert nicht richtig, habe den Scan gestartet, aber es wurde durch das Programm abgebrochen. Was tun? Danke* |
Servus, Zitat:
Starte aswMBR nochmal. Wähle links unten in der Ecke none aus und klicke auf Scan. Bericht, ob es jetzt klappt. Auf jeden Fall TDSS-Killer so ausführen wie beschrieben und die Logdatei posten. :) |
Schritt 3 wie beschrieben laufen gelassen, PC ist abgestürzt und hat sich neu gestartet. Schritt 4 ausgeführt, kein Fund. Hier der Report: 16:29:56.0015 3024 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 16:29:56.0327 3024 ============================================================ 16:29:56.0327 3024 Current date / time: 2012/12/01 16:29:56.0327 16:29:56.0327 3024 SystemInfo: 16:29:56.0327 3024 16:29:56.0327 3024 OS Version: 6.1.7601 ServicePack: 1.0 16:29:56.0327 3024 Product type: Workstation 16:29:56.0327 3024 ComputerName: MMEPRI-THINKP 16:29:56.0327 3024 UserName: Mme Pri 16:29:56.0327 3024 Windows directory: C:\Windows 16:29:56.0327 3024 System windows directory: C:\Windows 16:29:56.0327 3024 Running under WOW64 16:29:56.0327 3024 Processor architecture: Intel x64 16:29:56.0327 3024 Number of processors: 4 16:29:56.0327 3024 Page size: 0x1000 16:29:56.0327 3024 Boot type: Normal boot 16:29:56.0327 3024 ============================================================ 16:29:56.0826 3024 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 16:29:56.0826 3024 ============================================================ 16:29:56.0826 3024 \Device\Harddisk0\DR0: 16:29:56.0826 3024 MBR partitions: 16:29:56.0826 3024 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x258000 16:29:56.0826 3024 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x258800, BlocksNum 0x23295800 16:29:56.0826 3024 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x234EE000, BlocksNum 0x1F40000 16:29:56.0826 3024 ============================================================ 16:29:56.0873 3024 C: <-> \Device\Harddisk0\DR0\Partition2 16:29:56.0919 3024 Q: <-> \Device\Harddisk0\DR0\Partition3 16:29:56.0919 3024 ============================================================ 16:29:56.0919 3024 Initialize success 16:29:56.0919 3024 ============================================================ 16:29:59.0603 6120 ============================================================ 16:29:59.0603 6120 Scan started 16:29:59.0603 6120 Mode: Manual; 16:29:59.0603 6120 ============================================================ 16:30:01.0990 6120 ================ Scan system memory ======================== 16:30:01.0990 6120 System memory - ok 16:30:01.0990 6120 ================ Scan services ============================= 16:30:02.0146 6120 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys 16:30:02.0162 6120 1394ohci - ok 16:30:02.0224 6120 [ F4AF97702BAD85BFEF64B9A557F11B6F ] 5U877 C:\Windows\system32\DRIVERS\5U877.sys 16:30:02.0224 6120 5U877 - ok 16:30:02.0271 6120 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 16:30:02.0271 6120 ACPI - ok 16:30:02.0302 6120 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 16:30:02.0318 6120 AcpiPmi - ok 16:30:02.0412 6120 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 16:30:02.0412 6120 AdobeARMservice - ok 16:30:02.0568 6120 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 16:30:02.0568 6120 AdobeFlashPlayerUpdateSvc - ok 16:30:02.0630 6120 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 16:30:02.0630 6120 adp94xx - ok 16:30:02.0677 6120 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 16:30:02.0677 6120 adpahci - ok 16:30:02.0926 6120 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 16:30:02.0926 6120 adpu320 - ok 16:30:02.0958 6120 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 16:30:02.0958 6120 AeLookupSvc - ok 16:30:03.0004 6120 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 16:30:03.0020 6120 AFD - ok 16:30:03.0067 6120 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 16:30:03.0067 6120 agp440 - ok 16:30:03.0098 6120 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 16:30:03.0098 6120 ALG - ok 16:30:03.0114 6120 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 16:30:03.0114 6120 aliide - ok 16:30:03.0129 6120 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 16:30:03.0129 6120 amdide - ok 16:30:03.0145 6120 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 16:30:03.0145 6120 AmdK8 - ok 16:30:03.0145 6120 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 16:30:03.0145 6120 AmdPPM - ok 16:30:03.0207 6120 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 16:30:03.0223 6120 amdsata - ok 16:30:03.0254 6120 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 16:30:03.0254 6120 amdsbs - ok 16:30:03.0285 6120 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 16:30:03.0285 6120 amdxata - ok 16:30:03.0301 6120 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 16:30:03.0301 6120 AppID - ok 16:30:03.0316 6120 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 16:30:03.0332 6120 AppIDSvc - ok 16:30:03.0363 6120 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 16:30:03.0363 6120 Appinfo - ok 16:30:03.0488 6120 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 16:30:03.0488 6120 Apple Mobile Device - ok 16:30:03.0519 6120 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll 16:30:03.0519 6120 AppMgmt - ok 16:30:03.0550 6120 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys 16:30:03.0566 6120 arc - ok 16:30:03.0566 6120 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys 16:30:03.0582 6120 arcsas - ok 16:30:03.0613 6120 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 16:30:03.0613 6120 AsyncMac - ok 16:30:03.0644 6120 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 16:30:03.0660 6120 atapi - ok 16:30:03.0706 6120 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 16:30:03.0722 6120 AudioEndpointBuilder - ok 16:30:03.0753 6120 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 16:30:03.0753 6120 AudioSrv - ok 16:30:03.0847 6120 [ 6C9D5BADC8F83D410A278717C2EEA6F6 ] AVP C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe 16:30:03.0847 6120 AVP - ok 16:30:03.0909 6120 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 16:30:03.0909 6120 AxInstSV - ok 16:30:03.0956 6120 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 16:30:03.0956 6120 b06bdrv - ok 16:30:04.0034 6120 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 16:30:04.0034 6120 b57nd60a - ok 16:30:04.0128 6120 [ 93EE7D9C35AE7E9FFDA148D7805F1421 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE 16:30:04.0128 6120 BBSvc - ok 16:30:04.0174 6120 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 16:30:04.0174 6120 BDESVC - ok 16:30:04.0206 6120 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 16:30:04.0221 6120 Beep - ok 16:30:04.0268 6120 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 16:30:04.0268 6120 BFE - ok 16:30:04.0315 6120 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 16:30:04.0315 6120 BITS - ok 16:30:04.0362 6120 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 16:30:04.0377 6120 blbdrive - ok 16:30:04.0424 6120 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 16:30:04.0440 6120 Bonjour Service - ok 16:30:04.0440 6120 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 16:30:04.0440 6120 bowser - ok 16:30:04.0486 6120 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 16:30:04.0486 6120 BrFiltLo - ok 16:30:04.0486 6120 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 16:30:04.0486 6120 BrFiltUp - ok 16:30:04.0518 6120 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 16:30:04.0518 6120 Browser - ok 16:30:04.0549 6120 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 16:30:04.0549 6120 Brserid - ok 16:30:04.0564 6120 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 16:30:04.0564 6120 BrSerWdm - ok 16:30:04.0580 6120 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 16:30:04.0580 6120 BrUsbMdm - ok 16:30:04.0580 6120 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 16:30:04.0580 6120 BrUsbSer - ok 16:30:04.0611 6120 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 16:30:04.0611 6120 BthEnum - ok 16:30:04.0674 6120 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 16:30:04.0689 6120 BTHMODEM - ok 16:30:04.0705 6120 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 16:30:04.0705 6120 BthPan - ok 16:30:04.0767 6120 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 16:30:04.0783 6120 BTHPORT - ok 16:30:04.0861 6120 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 16:30:04.0861 6120 bthserv - ok 16:30:04.0908 6120 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 16:30:04.0908 6120 BTHUSB - ok 16:30:05.0048 6120 [ 8834F87A6A745872894DF8223201A6C3 ] BTWAMPFL C:\Windows\system32\DRIVERS\btwampfl.sys 16:30:05.0064 6120 BTWAMPFL - ok 16:30:05.0126 6120 [ 9863D82ECBEC6106D377ED73680D99D8 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys 16:30:05.0126 6120 btwaudio - ok 16:30:05.0173 6120 [ 3432DD66AE75AB2DE6D0527AD78DBFC7 ] btwavdt C:\Windows\system32\drivers\btwavdt.sys 16:30:05.0173 6120 btwavdt - ok 16:30:05.0313 6120 [ EB4AFE08FB39BB444F221D7D501E0915 ] btwdins C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe 16:30:05.0329 6120 btwdins - ok 16:30:05.0360 6120 [ 382DC5A631CED0462EA09B7EB898BDBF ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys 16:30:05.0360 6120 btwl2cap - ok 16:30:05.0391 6120 [ 13A9C2CEDD44C175E6CA39A536795CA6 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys 16:30:05.0391 6120 btwrchid - ok 16:30:05.0469 6120 [ 48360B88C4BF45850653BB7C86888ED4 ] CAXHWAZL C:\Windows\system32\DRIVERS\CAXHWAZL.sys 16:30:05.0485 6120 CAXHWAZL - ok 16:30:05.0516 6120 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 16:30:05.0516 6120 cdfs - ok 16:30:05.0563 6120 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 16:30:05.0563 6120 cdrom - ok 16:30:05.0610 6120 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 16:30:05.0610 6120 CertPropSvc - ok 16:30:05.0641 6120 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys 16:30:05.0641 6120 circlass - ok 16:30:05.0656 6120 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 16:30:05.0656 6120 CLFS - ok 16:30:05.0766 6120 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 16:30:05.0766 6120 clr_optimization_v2.0.50727_32 - ok 16:30:05.0828 6120 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 16:30:05.0828 6120 clr_optimization_v2.0.50727_64 - ok 16:30:05.0906 6120 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 16:30:05.0906 6120 clr_optimization_v4.0.30319_32 - ok 16:30:05.0953 6120 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 16:30:05.0953 6120 clr_optimization_v4.0.30319_64 - ok 16:30:05.0984 6120 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 16:30:05.0984 6120 CmBatt - ok 16:30:06.0000 6120 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 16:30:06.0000 6120 cmdide - ok 16:30:06.0031 6120 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 16:30:06.0046 6120 CNG - ok 16:30:06.0140 6120 [ DB6F09464C57606892BF6D2458483417 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys 16:30:06.0156 6120 CnxtHdAudService - ok 16:30:06.0218 6120 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys 16:30:06.0218 6120 Compbatt - ok 16:30:06.0249 6120 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 16:30:06.0249 6120 CompositeBus - ok 16:30:06.0280 6120 COMSysApp - ok 16:30:06.0296 6120 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 16:30:06.0296 6120 crcdisk - ok 16:30:06.0327 6120 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 16:30:06.0327 6120 CryptSvc - ok 16:30:06.0343 6120 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys 16:30:06.0358 6120 CSC - ok 16:30:06.0421 6120 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll 16:30:06.0452 6120 CscService - ok 16:30:06.0499 6120 [ 44BDDEB03C84A1C993C992FFB5700357 ] CVirtA C:\Windows\system32\DRIVERS\CVirtA64.sys 16:30:06.0514 6120 CVirtA - ok 16:30:06.0577 6120 [ 66257CB4E4FB69887CDDC71663741435 ] CVPND C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe 16:30:06.0608 6120 CVPND - ok 16:30:06.0639 6120 [ CC8E52DAA9826064BA464DBE531F2BB5 ] CVPNDRVA C:\Windows\system32\Drivers\CVPNDRVA.sys 16:30:06.0639 6120 CVPNDRVA - ok 16:30:06.0686 6120 [ 9D0D050170D47E778B624A28C90F23DE ] CxAudMsg C:\Windows\system32\CxAudMsg64.exe 16:30:06.0686 6120 CxAudMsg - ok 16:30:06.0733 6120 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 16:30:06.0748 6120 DcomLaunch - ok 16:30:06.0842 6120 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 16:30:06.0858 6120 defragsvc - ok 16:30:06.0920 6120 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 16:30:06.0920 6120 DfsC - ok 16:30:06.0998 6120 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 16:30:07.0014 6120 Dhcp - ok 16:30:07.0029 6120 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 16:30:07.0029 6120 discache - ok 16:30:07.0076 6120 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys 16:30:07.0076 6120 Disk - ok 16:30:07.0092 6120 [ 5DB085A8A6600BE6401F2B24EECB5415 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys 16:30:07.0092 6120 dmvsc - ok 16:30:07.0123 6120 [ 05CB5910B3CA6019FC3CCA815EE06FFB ] DNE C:\Windows\system32\DRIVERS\dne64x.sys 16:30:07.0123 6120 DNE - ok 16:30:07.0170 6120 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 16:30:07.0170 6120 Dnscache - ok 16:30:07.0201 6120 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 16:30:07.0201 6120 dot3svc - ok 16:30:07.0294 6120 [ E6987F7818154791A6937BCC6655599B ] DozeSvc C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE 16:30:07.0310 6120 DozeSvc - ok 16:30:07.0357 6120 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 16:30:07.0357 6120 DPS - ok 16:30:07.0388 6120 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 16:30:07.0388 6120 drmkaud - ok 16:30:07.0419 6120 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 16:30:07.0419 6120 DXGKrnl - ok 16:30:07.0466 6120 [ CE4CFFD9F64B86BCEB1C343FC9924D72 ] DzHDD64 C:\Windows\system32\DRIVERS\DzHDD64.sys 16:30:07.0466 6120 DzHDD64 - ok 16:30:07.0528 6120 [ DC1776D086AA9733B1929A3D979D9FDD ] e1cexpress C:\Windows\system32\DRIVERS\e1c62x64.sys 16:30:07.0528 6120 e1cexpress - ok 16:30:07.0591 6120 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 16:30:07.0591 6120 EapHost - ok 16:30:08.0341 6120 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys 16:30:08.0403 6120 ebdrv - ok 16:30:08.0481 6120 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 16:30:08.0497 6120 EFS - ok 16:30:08.0621 6120 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 16:30:08.0637 6120 ehRecvr - ok 16:30:08.0668 6120 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 16:30:08.0668 6120 ehSched - ok 16:30:08.0746 6120 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys 16:30:08.0746 6120 elxstor - ok 16:30:08.0762 6120 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 16:30:08.0762 6120 ErrDev - ok 16:30:08.0809 6120 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 16:30:08.0809 6120 EventSystem - ok 16:30:08.0933 6120 [ 8B6C9924B0D333DBF76086B8258A0891 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 16:30:08.0996 6120 EvtEng - ok 16:30:09.0058 6120 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 16:30:09.0058 6120 exfat - ok 16:30:09.0089 6120 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 16:30:09.0105 6120 fastfat - ok 16:30:09.0167 6120 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 16:30:09.0199 6120 Fax - ok 16:30:09.0230 6120 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys 16:30:09.0245 6120 fdc - ok 16:30:09.0261 6120 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 16:30:09.0261 6120 fdPHost - ok 16:30:09.0277 6120 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 16:30:09.0277 6120 FDResPub - ok 16:30:09.0323 6120 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 16:30:09.0323 6120 FileInfo - ok 16:30:09.0339 6120 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 16:30:09.0339 6120 Filetrace - ok 16:30:09.0417 6120 [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 16:30:09.0433 6120 FLEXnet Licensing Service - ok 16:30:09.0464 6120 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 16:30:09.0479 6120 flpydisk - ok 16:30:09.0526 6120 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 16:30:09.0526 6120 FltMgr - ok 16:30:09.0589 6120 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 16:30:09.0604 6120 FontCache - ok 16:30:09.0682 6120 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 16:30:09.0682 6120 FontCache3.0.0.0 - ok 16:30:09.0713 6120 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 16:30:09.0713 6120 FsDepends - ok 16:30:09.0760 6120 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 16:30:09.0760 6120 Fs_Rec - ok 16:30:09.0823 6120 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 16:30:09.0838 6120 fvevol - ok 16:30:09.0916 6120 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 16:30:09.0916 6120 gagp30kx - ok 16:30:09.0963 6120 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 16:30:09.0963 6120 GEARAspiWDM - ok 16:30:10.0041 6120 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 16:30:10.0057 6120 gpsvc - ok 16:30:10.0103 6120 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 16:30:10.0103 6120 hcw85cir - ok 16:30:10.0181 6120 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 16:30:10.0197 6120 HdAudAddService - ok 16:30:10.0259 6120 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 16:30:10.0259 6120 HDAudBus - ok 16:30:10.0322 6120 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 16:30:10.0322 6120 HidBatt - ok 16:30:10.0384 6120 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys 16:30:10.0384 6120 HidBth - ok 16:30:10.0447 6120 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys 16:30:10.0447 6120 HidIr - ok 16:30:10.0509 6120 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 16:30:10.0509 6120 hidserv - ok 16:30:10.0634 6120 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 16:30:10.0634 6120 HidUsb - ok 16:30:10.0727 6120 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 16:30:10.0727 6120 hkmsvc - ok 16:30:10.0759 6120 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 16:30:10.0759 6120 HomeGroupListener - ok 16:30:10.0837 6120 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 16:30:10.0837 6120 HomeGroupProvider - ok 16:30:10.0868 6120 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 16:30:10.0868 6120 HpSAMD - ok 16:30:11.0117 6120 [ 447256D1C026654C5CD3CC17E7B20631 ] HsfXAudioService C:\Windows\SysWOW64\XAudio64.dll 16:30:11.0133 6120 HsfXAudioService - ok 16:30:11.0242 6120 [ F6AC1087A131FBB385400667BEA64FBE ] HSF_DPV C:\Windows\system32\DRIVERS\CAX_DPV.sys 16:30:11.0273 6120 HSF_DPV - ok 16:30:11.0383 6120 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 16:30:11.0398 6120 HTTP - ok 16:30:11.0414 6120 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 16:30:11.0414 6120 hwpolicy - ok 16:30:11.0601 6120 [ 9149907FF8681AD6475607EEBF62DD2F ] HyperW7Svc C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe 16:30:11.0601 6120 HyperW7Svc - ok 16:30:11.0695 6120 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 16:30:11.0695 6120 i8042prt - ok 16:30:11.0866 6120 [ D7921D5A870B11CC1ADAB198A519D50A ] iaStor C:\Windows\system32\drivers\iaStor.sys 16:30:11.0866 6120 iaStor - ok 16:30:11.0991 6120 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 16:30:12.0007 6120 iaStorV - ok 16:30:12.0069 6120 [ 29ED470689B7C597A9701D6A4C57A578 ] IBMPMDRV C:\Windows\system32\DRIVERS\ibmpmdrv.sys 16:30:12.0069 6120 IBMPMDRV - ok 16:30:12.0100 6120 [ BC7AF43EEC24E995D770EC92A441D5D8 ] IBMPMSVC C:\Windows\system32\ibmpmsvc.exe 16:30:12.0100 6120 IBMPMSVC - ok 16:30:12.0303 6120 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 16:30:12.0365 6120 idsvc - ok 16:30:12.0740 6120 [ 66DC0CE2D1867B8178EAA0E11930DBD7 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 16:30:12.0943 6120 igfx - ok 16:30:12.0989 6120 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys 16:30:12.0989 6120 iirsp - ok 16:30:13.0036 6120 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 16:30:13.0067 6120 IKEEXT - ok 16:30:13.0114 6120 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys 16:30:13.0114 6120 IntcDAud - ok 16:30:13.0145 6120 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 16:30:13.0145 6120 intelide - ok 16:30:13.0192 6120 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 16:30:13.0192 6120 intelppm - ok 16:30:13.0239 6120 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 16:30:13.0239 6120 IPBusEnum - ok 16:30:13.0270 6120 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 16:30:13.0270 6120 IpFilterDriver - ok 16:30:13.0364 6120 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 16:30:13.0379 6120 iphlpsvc - ok 16:30:13.0426 6120 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 16:30:13.0426 6120 IPMIDRV - ok 16:30:13.0457 6120 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 16:30:13.0457 6120 IPNAT - ok 16:30:13.0629 6120 [ B474C756C13960793C7583B766F904C4 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 16:30:13.0629 6120 iPod Service - ok 16:30:13.0676 6120 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 16:30:13.0676 6120 IRENUM - ok 16:30:13.0723 6120 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 16:30:13.0723 6120 isapnp - ok 16:30:13.0801 6120 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 16:30:13.0801 6120 iScsiPrt - ok 16:30:13.0941 6120 [ 6C85719A21B3F62C2C76280F4BD36C7B ] jhi_service C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe 16:30:13.0941 6120 jhi_service - ok 16:30:13.0972 6120 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 16:30:13.0988 6120 kbdclass - ok 16:30:14.0159 6120 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 16:30:14.0159 6120 kbdhid - ok 16:30:14.0191 6120 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 16:30:14.0191 6120 KeyIso - ok 16:30:14.0300 6120 [ E656FE10D6D27794AFA08136685A69E8 ] KL1 C:\Windows\system32\DRIVERS\kl1.sys 16:30:14.0315 6120 KL1 - ok 16:30:14.0362 6120 [ D865DD8B0448E3F963D68C04C532858F ] kl2 C:\Windows\system32\DRIVERS\kl2.sys 16:30:14.0362 6120 kl2 - ok 16:30:14.0503 6120 [ 8490798365236B6C8E54DEDD27A42D07 ] KLIF C:\Windows\system32\DRIVERS\klif.sys 16:30:14.0503 6120 KLIF - ok 16:30:14.0565 6120 [ 89FB5A33D7171B6D84F5EB721D5055E1 ] KLIM6 C:\Windows\system32\DRIVERS\klim6.sys 16:30:14.0565 6120 KLIM6 - ok 16:30:14.0581 6120 [ 9468D07E91BA136D82415F5DFC1FE168 ] klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys 16:30:14.0581 6120 klmouflt - ok 16:30:14.0612 6120 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 16:30:14.0612 6120 KSecDD - ok 16:30:14.0659 6120 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 16:30:14.0659 6120 KSecPkg - ok 16:30:14.0721 6120 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 16:30:14.0721 6120 ksthunk - ok 16:30:14.0799 6120 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 16:30:14.0815 6120 KtmRm - ok 16:30:14.0861 6120 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 16:30:14.0877 6120 LanmanServer - ok 16:30:14.0924 6120 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 16:30:14.0924 6120 LanmanWorkstation - ok 16:30:15.0049 6120 [ 1EF45F1BD62B8F4C19458326A3E91930 ] LENOVO.CAMMUTE C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe 16:30:15.0049 6120 LENOVO.CAMMUTE - ok 16:30:15.0095 6120 [ FCE735941DA27929DBFC1918F286FFD8 ] LENOVO.MICMUTE C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe 16:30:15.0095 6120 LENOVO.MICMUTE - ok 16:30:15.0142 6120 [ 2B9D8555DC004E240082D18E7725CE20 ] lenovo.smi C:\Windows\system32\DRIVERS\smiifx64.sys 16:30:15.0158 6120 lenovo.smi - ok 16:30:15.0189 6120 [ 448BE3E001004A55E8A959C57E17F6D8 ] LENOVO.TPKNRSVC C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe 16:30:15.0189 6120 LENOVO.TPKNRSVC - ok 16:30:15.0236 6120 [ 6F2CC57EB5836D2AC9BD37F3554D55F8 ] Lenovo.VIRTSCRLSVC C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe 16:30:15.0236 6120 Lenovo.VIRTSCRLSVC - ok 16:30:15.0283 6120 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 16:30:15.0283 6120 lltdio - ok 16:30:15.0361 6120 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 16:30:15.0376 6120 lltdsvc - ok 16:30:15.0423 6120 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 16:30:15.0423 6120 lmhosts - ok 16:30:15.0454 6120 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 16:30:15.0454 6120 LSI_FC - ok 16:30:15.0501 6120 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 16:30:15.0501 6120 LSI_SAS - ok 16:30:15.0517 6120 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 16:30:15.0517 6120 LSI_SAS2 - ok 16:30:15.0532 6120 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 16:30:15.0548 6120 LSI_SCSI - ok 16:30:15.0579 6120 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 16:30:15.0579 6120 luafv - ok 16:30:15.0641 6120 [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe 16:30:15.0641 6120 McComponentHostService - ok 16:30:15.0673 6120 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 16:30:15.0673 6120 Mcx2Svc - ok 16:30:15.0704 6120 [ E4F44EC214B3E381E1FC844A02926666 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys 16:30:15.0704 6120 mdmxsdk - ok 16:30:15.0751 6120 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys 16:30:15.0751 6120 megasas - ok 16:30:15.0829 6120 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 16:30:15.0829 6120 MegaSR - ok 16:30:15.0875 6120 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 16:30:15.0875 6120 MEIx64 - ok 16:30:15.0922 6120 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 16:30:15.0922 6120 MMCSS - ok 16:30:15.0953 6120 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 16:30:15.0953 6120 Modem - ok 16:30:15.0985 6120 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 16:30:15.0985 6120 monitor - ok 16:30:16.0047 6120 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 16:30:16.0047 6120 mouclass - ok 16:30:16.0078 6120 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 16:30:16.0078 6120 mouhid - ok 16:30:16.0109 6120 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 16:30:16.0109 6120 mountmgr - ok 16:30:16.0219 6120 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 16:30:16.0234 6120 MozillaMaintenance - ok 16:30:16.0297 6120 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 16:30:16.0312 6120 mpio - ok 16:30:16.0328 6120 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 16:30:16.0328 6120 mpsdrv - ok 16:30:16.0406 6120 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 16:30:16.0437 6120 MpsSvc - ok 16:30:16.0484 6120 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 16:30:16.0484 6120 MRxDAV - ok 16:30:16.0531 6120 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 16:30:16.0531 6120 mrxsmb - ok 16:30:16.0593 6120 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 16:30:16.0609 6120 mrxsmb10 - ok 16:30:16.0655 6120 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 16:30:16.0655 6120 mrxsmb20 - ok 16:30:16.0687 6120 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 16:30:16.0687 6120 msahci - ok 16:30:16.0733 6120 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 16:30:16.0733 6120 msdsm - ok 16:30:16.0780 6120 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 16:30:17.0170 6120 MSDTC - ok 16:30:17.0217 6120 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 16:30:17.0217 6120 Msfs - ok 16:30:17.0279 6120 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 16:30:17.0279 6120 mshidkmdf - ok 16:30:17.0311 6120 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 16:30:17.0311 6120 msisadrv - ok 16:30:17.0357 6120 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 16:30:17.0357 6120 MSiSCSI - ok 16:30:17.0373 6120 msiserver - ok 16:30:17.0420 6120 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 16:30:17.0420 6120 MSKSSRV - ok 16:30:17.0467 6120 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 16:30:17.0467 6120 MSPCLOCK - ok 16:30:17.0482 6120 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 16:30:17.0482 6120 MSPQM - ok 16:30:17.0498 6120 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 16:30:17.0513 6120 MsRPC - ok 16:30:17.0529 6120 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 16:30:17.0529 6120 mssmbios - ok 16:30:17.0545 6120 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 16:30:17.0545 6120 MSTEE - ok 16:30:17.0591 6120 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 16:30:17.0591 6120 MTConfig - ok 16:30:17.0607 6120 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 16:30:17.0607 6120 Mup - ok 16:30:17.0654 6120 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 16:30:17.0654 6120 napagent - ok 16:30:17.0716 6120 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 16:30:17.0716 6120 NativeWifiP - ok 16:30:17.0763 6120 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 16:30:17.0779 6120 NDIS - ok 16:30:17.0825 6120 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 16:30:17.0825 6120 NdisCap - ok 16:30:17.0857 6120 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 16:30:17.0857 6120 NdisTapi - ok 16:30:17.0888 6120 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 16:30:17.0888 6120 Ndisuio - ok 16:30:17.0903 6120 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 16:30:17.0903 6120 NdisWan - ok 16:30:17.0950 6120 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 16:30:17.0950 6120 NDProxy - ok 16:30:17.0997 6120 [ 6F4607E2333FE21E9E3FF8133A88B35B ] Netaapl C:\Windows\system32\DRIVERS\netaapl64.sys 16:30:17.0997 6120 Netaapl - ok 16:30:18.0044 6120 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 16:30:18.0044 6120 NetBIOS - ok 16:30:18.0075 6120 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 16:30:18.0075 6120 NetBT - ok 16:30:18.0091 6120 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 16:30:18.0091 6120 Netlogon - ok 16:30:18.0169 6120 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 16:30:18.0169 6120 Netman - ok 16:30:18.0184 6120 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 16:30:18.0184 6120 netprofm - ok 16:30:18.0215 6120 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 16:30:18.0231 6120 NetTcpPortSharing - ok 16:30:18.0481 6120 [ 5D262402B0634C998F8CBCEAD7DD8676 ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys 16:30:18.0637 6120 NETwNs64 - ok 16:30:18.0683 6120 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 16:30:18.0683 6120 nfrd960 - ok 16:30:18.0730 6120 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 16:30:18.0730 6120 NlaSvc - ok 16:30:18.0746 6120 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 16:30:18.0746 6120 Npfs - ok 16:30:18.0777 6120 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 16:30:18.0777 6120 nsi - ok 16:30:18.0839 6120 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 16:30:18.0855 6120 nsiproxy - ok 16:30:19.0120 6120 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 16:30:19.0198 6120 Ntfs - ok 16:30:19.0292 6120 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 16:30:19.0307 6120 Null - ok 16:30:19.0401 6120 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 16:30:19.0401 6120 nvraid - ok 16:30:19.0495 6120 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 16:30:19.0495 6120 nvstor - ok 16:30:19.0541 6120 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 16:30:19.0557 6120 nv_agp - ok 16:30:19.0604 6120 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 16:30:19.0604 6120 ohci1394 - ok 16:30:19.0697 6120 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 16:30:19.0697 6120 ose - ok 16:30:20.0072 6120 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 16:30:20.0212 6120 osppsvc - ok 16:30:20.0259 6120 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 16:30:20.0259 6120 p2pimsvc - ok 16:30:20.0275 6120 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 16:30:20.0290 6120 p2psvc - ok 16:30:20.0306 6120 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys 16:30:20.0306 6120 Parport - ok 16:30:20.0353 6120 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 16:30:20.0353 6120 partmgr - ok 16:30:20.0384 6120 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 16:30:20.0384 6120 PcaSvc - ok 16:30:20.0415 6120 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 16:30:20.0415 6120 pci - ok 16:30:20.0431 6120 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 16:30:20.0431 6120 pciide - ok 16:30:20.0446 6120 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 16:30:20.0446 6120 pcmcia - ok 16:30:20.0462 6120 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 16:30:20.0462 6120 pcw - ok 16:30:20.0477 6120 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 16:30:20.0493 6120 PEAUTH - ok 16:30:20.0555 6120 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 16:30:20.0571 6120 PeerDistSvc - ok 16:30:20.0602 6120 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 16:30:20.0602 6120 PerfHost - ok 16:30:20.0618 6120 [ 18EEA095AF22AC5FA16FC27FB98C82D3 ] PHCORE C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS 16:30:20.0618 6120 PHCORE - ok 16:30:20.0696 6120 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 16:30:20.0711 6120 pla - ok 16:30:20.0789 6120 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 16:30:20.0805 6120 PlugPlay - ok 16:30:20.0836 6120 [ 0BEE791C7C7ACE453C134E73633C497D ] pmxdrv C:\Windows\system32\drivers\pmxdrv.sys 16:30:20.0836 6120 pmxdrv - ok 16:30:20.0867 6120 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 16:30:20.0867 6120 PNRPAutoReg - ok 16:30:20.0914 6120 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 16:30:20.0914 6120 PNRPsvc - ok 16:30:20.0945 6120 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 16:30:20.0961 6120 PolicyAgent - ok 16:30:20.0977 6120 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 16:30:20.0992 6120 Power - ok 16:30:21.0039 6120 [ AF7186CF9909BEF0D86097175175178F ] Power Manager DBC Service C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE 16:30:21.0055 6120 Power Manager DBC Service - ok 16:30:21.0086 6120 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 16:30:21.0101 6120 PptpMiniport - ok 16:30:21.0117 6120 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys 16:30:21.0117 6120 Processor - ok 16:30:21.0164 6120 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 16:30:21.0164 6120 ProfSvc - ok 16:30:21.0179 6120 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 16:30:21.0179 6120 ProtectedStorage - ok 16:30:21.0226 6120 [ A70AD30223866947E39BC221DF4C2306 ] psadd C:\Windows\system32\DRIVERS\psadd.sys 16:30:21.0226 6120 psadd - ok 16:30:21.0257 6120 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 16:30:21.0257 6120 Psched - ok 16:30:21.0289 6120 [ F036CFB275D0C55F4E45FBBF5F98B3C8 ] PSI_SVC_2 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe 16:30:21.0289 6120 PSI_SVC_2 - ok 16:30:21.0476 6120 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 16:30:21.0523 6120 ql2300 - ok 16:30:21.0538 6120 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 16:30:21.0554 6120 ql40xx - ok 16:30:21.0569 6120 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 16:30:21.0585 6120 QWAVE - ok 16:30:21.0585 6120 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 16:30:21.0585 6120 QWAVEdrv - ok 16:30:21.0601 6120 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 16:30:21.0601 6120 RasAcd - ok 16:30:21.0647 6120 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 16:30:21.0647 6120 RasAgileVpn - ok 16:30:21.0663 6120 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 16:30:21.0663 6120 RasAuto - ok 16:30:21.0679 6120 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 16:30:21.0679 6120 Rasl2tp - ok 16:30:21.0694 6120 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 16:30:21.0694 6120 RasMan - ok 16:30:21.0725 6120 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 16:30:21.0725 6120 RasPppoe - ok 16:30:21.0725 6120 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 16:30:21.0725 6120 RasSstp - ok 16:30:21.0772 6120 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 16:30:21.0772 6120 rdbss - ok 16:30:21.0788 6120 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 16:30:21.0788 6120 rdpbus - ok 16:30:21.0803 6120 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 16:30:21.0803 6120 RDPCDD - ok 16:30:21.0835 6120 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 16:30:21.0835 6120 RDPDR - ok 16:30:21.0850 6120 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 16:30:21.0850 6120 RDPENCDD - ok 16:30:21.0850 6120 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 16:30:21.0850 6120 RDPREFMP - ok 16:30:21.0897 6120 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 16:30:21.0897 6120 RDPWD - ok 16:30:21.0913 6120 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 16:30:21.0928 6120 rdyboost - ok 16:30:22.0037 6120 [ 189C5A8D2098E0AA14FD157A954B34FC ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 16:30:22.0053 6120 RegSrvc - ok 16:30:22.0069 6120 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 16:30:22.0084 6120 RemoteAccess - ok 16:30:22.0115 6120 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 16:30:22.0115 6120 RemoteRegistry - ok 16:30:22.0131 6120 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 16:30:22.0147 6120 RFCOMM - ok 16:30:22.0162 6120 [ 819FE65AE1C0312B535B7AA54D30CFDA ] risdxc C:\Windows\system32\DRIVERS\risdxc64.sys 16:30:22.0162 6120 risdxc - ok 16:30:22.0193 6120 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 16:30:22.0209 6120 RpcEptMapper - ok 16:30:22.0225 6120 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 16:30:22.0225 6120 RpcLocator - ok 16:30:22.0256 6120 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 16:30:22.0271 6120 RpcSs - ok 16:30:22.0303 6120 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 16:30:22.0303 6120 rspndr - ok 16:30:22.0318 6120 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys 16:30:22.0318 6120 s3cap - ok 16:30:22.0334 6120 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 16:30:22.0334 6120 SamSs - ok 16:30:22.0334 6120 SAService - ok 16:30:22.0349 6120 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 16:30:22.0349 6120 sbp2port - ok 16:30:22.0396 6120 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 16:30:22.0396 6120 SCardSvr - ok 16:30:22.0443 6120 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 16:30:22.0443 6120 scfilter - ok 16:30:22.0474 6120 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 16:30:22.0490 6120 Schedule - ok 16:30:22.0505 6120 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 16:30:22.0505 6120 SCPolicySvc - ok 16:30:22.0568 6120 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 16:30:22.0568 6120 SDRSVC - ok 16:30:22.0630 6120 [ CC781378E7EDA615D2CDCA3B17829FA4 ] SeaPort C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE 16:30:22.0630 6120 SeaPort - ok 16:30:22.0661 6120 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 16:30:22.0661 6120 secdrv - ok 16:30:22.0693 6120 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 16:30:22.0693 6120 seclogon - ok 16:30:22.0693 6120 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 16:30:22.0693 6120 SENS - ok 16:30:22.0724 6120 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 16:30:22.0724 6120 SensrSvc - ok 16:30:22.0739 6120 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys 16:30:22.0739 6120 Serenum - ok 16:30:22.0771 6120 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys 16:30:22.0771 6120 Serial - ok 16:30:22.0786 6120 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys 16:30:22.0786 6120 sermouse - ok 16:30:22.0817 6120 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 16:30:22.0817 6120 SessionEnv - ok 16:30:22.0817 6120 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 16:30:22.0817 6120 sffdisk - ok 16:30:22.0833 6120 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 16:30:22.0833 6120 sffp_mmc - ok 16:30:22.0849 6120 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 16:30:22.0849 6120 sffp_sd - ok 16:30:22.0849 6120 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 16:30:22.0849 6120 sfloppy - ok 16:30:22.0864 6120 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 16:30:22.0864 6120 SharedAccess - ok 16:30:22.0911 6120 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 16:30:22.0927 6120 ShellHWDetection - ok 16:30:22.0958 6120 [ E2FC046D4EDABFE3B5EF7DA06406277D ] Shockprf C:\Windows\system32\DRIVERS\Apsx64.sys 16:30:22.0958 6120 Shockprf - ok 16:30:22.0973 6120 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 16:30:22.0973 6120 SiSRaid2 - ok 16:30:22.0989 6120 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 16:30:22.0989 6120 SiSRaid4 - ok 16:30:23.0083 6120 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 16:30:23.0083 6120 SkypeUpdate - ok 16:30:23.0114 6120 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 16:30:23.0114 6120 Smb - ok 16:30:23.0161 6120 [ C5B1A19B14F19B08AE72FCB20A3075B6 ] smihlp C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys 16:30:23.0161 6120 smihlp - ok 16:30:23.0207 6120 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 16:30:23.0207 6120 SNMPTRAP - ok 16:30:23.0223 6120 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 16:30:23.0223 6120 spldr - ok 16:30:23.0254 6120 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 16:30:23.0254 6120 Spooler - ok 16:30:23.0363 6120 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 16:30:23.0441 6120 sppsvc - ok 16:30:23.0473 6120 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 16:30:23.0473 6120 sppuinotify - ok 16:30:23.0504 6120 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 16:30:23.0519 6120 srv - ok 16:30:23.0535 6120 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 16:30:23.0551 6120 srv2 - ok 16:30:23.0566 6120 [ 0C4540311E11664B245A263E1154CEF8 ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL6.SYS 16:30:23.0582 6120 SrvHsfHDA - ok 16:30:23.0613 6120 [ 02071D207A9858FBE3A48CBFD59C4A04 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV6.SYS 16:30:23.0644 6120 SrvHsfV92 - ok 16:30:23.0800 6120 [ 18E40C245DBFAF36FD0134A7EF2DF396 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT6.SYS 16:30:23.0800 6120 SrvHsfWinac - ok 16:30:23.0831 6120 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 16:30:23.0831 6120 srvnet - ok 16:30:23.0878 6120 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 16:30:23.0894 6120 SSDPSRV - ok 16:30:23.0894 6120 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 16:30:23.0894 6120 SstpSvc - ok 16:30:23.0925 6120 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys 16:30:23.0925 6120 stexstor - ok 16:30:23.0956 6120 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 16:30:23.0972 6120 stisvc - ok 16:30:23.0987 6120 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 16:30:23.0987 6120 storflt - ok 16:30:24.0050 6120 [ C40841817EF57D491F22EB103DA587CC ] StorSvc C:\Windows\system32\storsvc.dll 16:30:24.0050 6120 StorSvc - ok 16:30:24.0081 6120 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys 16:30:24.0081 6120 storvsc - ok 16:30:24.0128 6120 [ 6EA2F517373771CAC5188E82617C9C0B ] SUService C:\Program Files (x86)\Lenovo\System Update\SUService.exe 16:30:24.0143 6120 SUService - ok 16:30:24.0143 6120 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 16:30:24.0143 6120 swenum - ok 16:30:24.0175 6120 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 16:30:24.0175 6120 swprv - ok 16:30:24.0253 6120 [ 06D602A637E171E151853F1D8ECD34F1 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 16:30:24.0253 6120 SynTP - ok 16:30:24.0315 6120 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 16:30:24.0346 6120 SysMain - ok 16:30:24.0377 6120 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 16:30:24.0377 6120 TabletInputService - ok 16:30:24.0393 6120 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 16:30:24.0393 6120 TapiSrv - ok 16:30:24.0424 6120 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 16:30:24.0424 6120 TBS - ok 16:30:24.0471 6120 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 16:30:24.0502 6120 Tcpip - ok 16:30:24.0596 6120 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 16:30:24.0611 6120 TCPIP6 - ok 16:30:24.0674 6120 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 16:30:24.0674 6120 tcpipreg - ok 16:30:24.0705 6120 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 16:30:24.0705 6120 TDPIPE - ok 16:30:24.0767 6120 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 16:30:24.0767 6120 TDTCP - ok 16:30:24.0799 6120 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 16:30:24.0799 6120 tdx - ok 16:30:24.0830 6120 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 16:30:24.0830 6120 TermDD - ok 16:30:24.0861 6120 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 16:30:24.0877 6120 TermService - ok 16:30:24.0892 6120 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 16:30:24.0892 6120 Themes - ok 16:30:24.0923 6120 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 16:30:24.0923 6120 THREADORDER - ok 16:30:24.0970 6120 [ 55B7FE3E1D3B616BDC4E9EA48D92D6E6 ] TPDIGIMN C:\Windows\system32\DRIVERS\ApsHM64.sys 16:30:24.0970 6120 TPDIGIMN - ok 16:30:24.0986 6120 [ F0684C62ED8FD3061CD488ECFC851022 ] TPHDEXLGSVC C:\Windows\system32\TPHDEXLG64.exe 16:30:24.0986 6120 TPHDEXLGSVC - ok 16:30:25.0033 6120 [ 63626012E44CAAA162677B57B6DCB542 ] TPHKLOAD C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe 16:30:25.0033 6120 TPHKLOAD - ok 16:30:25.0048 6120 [ 9E6E4A9789F76593CC5A6A5AF8FC5929 ] TPHKSVC C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe 16:30:25.0064 6120 TPHKSVC - ok 16:30:25.0095 6120 [ DBCC20C02E8A3E43B03C304A4E40A84F ] TPM C:\Windows\system32\drivers\tpm.sys 16:30:25.0095 6120 TPM - ok 16:30:25.0126 6120 [ 7165B5A9B4867F64A6D6935F57D4196B ] TPPWRIF C:\Windows\system32\drivers\Tppwr64v.sys 16:30:25.0126 6120 TPPWRIF - ok 16:30:25.0157 6120 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 16:30:25.0157 6120 TrkWks - ok 16:30:25.0220 6120 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 16:30:25.0235 6120 TrustedInstaller - ok 16:30:25.0282 6120 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 16:30:25.0282 6120 tssecsrv - ok 16:30:25.0313 6120 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 16:30:25.0329 6120 TsUsbFlt - ok 16:30:25.0345 6120 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 16:30:25.0345 6120 TsUsbGD - ok 16:30:25.0360 6120 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 16:30:25.0360 6120 tunnel - ok 16:30:25.0391 6120 [ 4DAAE0413CD4E816258838E2FAFB3147 ] TVTI2C C:\Windows\system32\DRIVERS\Tvti2c.sys 16:30:25.0391 6120 TVTI2C - ok 16:30:25.0391 6120 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 16:30:25.0407 6120 uagp35 - ok 16:30:25.0423 6120 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 16:30:25.0423 6120 udfs - ok 16:30:25.0469 6120 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 16:30:25.0469 6120 UI0Detect - ok 16:30:25.0469 6120 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 16:30:25.0469 6120 uliagpkx - ok 16:30:25.0485 6120 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 16:30:25.0501 6120 umbus - ok 16:30:25.0501 6120 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys 16:30:25.0501 6120 UmPass - ok 16:30:25.0547 6120 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll 16:30:25.0547 6120 UmRdpService - ok 16:30:25.0563 6120 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 16:30:25.0563 6120 upnphost - ok 16:30:25.0610 6120 [ 43228F8EDD1B0BCDD3145AD246E63D39 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 16:30:25.0610 6120 USBAAPL64 - ok 16:30:25.0641 6120 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 16:30:25.0641 6120 usbccgp - ok 16:30:25.0672 6120 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 16:30:25.0672 6120 usbcir - ok 16:30:25.0703 6120 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys 16:30:25.0703 6120 usbehci - ok 16:30:25.0735 6120 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 16:30:25.0735 6120 usbhub - ok 16:30:25.0781 6120 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 16:30:25.0781 6120 usbohci - ok 16:30:25.0813 6120 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 16:30:25.0813 6120 usbprint - ok 16:30:25.0859 6120 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 16:30:25.0859 6120 USBSTOR - ok 16:30:25.0875 6120 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 16:30:25.0875 6120 usbuhci - ok 16:30:25.0906 6120 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 16:30:25.0906 6120 usbvideo - ok 16:30:25.0937 6120 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 16:30:25.0937 6120 UxSms - ok 16:30:25.0953 6120 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 16:30:25.0953 6120 VaultSvc - ok 16:30:25.0969 6120 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 16:30:25.0969 6120 vdrvroot - ok 16:30:25.0984 6120 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 16:30:26.0000 6120 vds - ok 16:30:26.0031 6120 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 16:30:26.0031 6120 vga - ok 16:30:26.0047 6120 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 16:30:26.0047 6120 VgaSave - ok 16:30:26.0062 6120 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 16:30:26.0062 6120 vhdmp - ok 16:30:26.0062 6120 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 16:30:26.0062 6120 viaide - ok 16:30:26.0140 6120 [ 6AD85F32EA4AA65BB2EA652F2B9D4005 ] VIPAppService C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe 16:30:26.0140 6120 VIPAppService - ok 16:30:26.0171 6120 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys 16:30:26.0171 6120 vmbus - ok 16:30:26.0171 6120 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 16:30:26.0171 6120 VMBusHID - ok 16:30:26.0187 6120 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 16:30:26.0187 6120 volmgr - ok 16:30:26.0218 6120 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 16:30:26.0234 6120 volmgrx - ok 16:30:26.0281 6120 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 16:30:26.0281 6120 volsnap - ok 16:30:26.0312 6120 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 16:30:26.0312 6120 vsmraid - ok 16:30:26.0390 6120 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 16:30:26.0468 6120 VSS - ok 16:30:26.0499 6120 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 16:30:26.0499 6120 vwifibus - ok 16:30:26.0530 6120 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 16:30:26.0546 6120 vwififlt - ok 16:30:26.0561 6120 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 16:30:26.0577 6120 W32Time - ok 16:30:26.0593 6120 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys 16:30:26.0593 6120 WacomPen - ok 16:30:26.0608 6120 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 16:30:26.0624 6120 WANARP - ok 16:30:26.0624 6120 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 16:30:26.0624 6120 Wanarpv6 - ok 16:30:26.0780 6120 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 16:30:26.0811 6120 WatAdminSvc - ok 16:30:26.0873 6120 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 16:30:26.0905 6120 wbengine - ok 16:30:26.0936 6120 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 16:30:26.0951 6120 WbioSrvc - ok 16:30:26.0967 6120 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 16:30:26.0967 6120 wcncsvc - ok 16:30:26.0998 6120 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 16:30:26.0998 6120 WcsPlugInService - ok 16:30:27.0029 6120 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys 16:30:27.0029 6120 Wd - ok 16:30:27.0076 6120 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 16:30:27.0107 6120 Wdf01000 - ok 16:30:27.0154 6120 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 16:30:27.0170 6120 WdiServiceHost - ok 16:30:27.0170 6120 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 16:30:27.0185 6120 WdiSystemHost - ok 16:30:27.0185 6120 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 16:30:27.0201 6120 WebClient - ok 16:30:27.0201 6120 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 16:30:27.0217 6120 Wecsvc - ok 16:30:27.0232 6120 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 16:30:27.0232 6120 wercplsupport - ok 16:30:27.0263 6120 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 16:30:27.0263 6120 WerSvc - ok 16:30:27.0295 6120 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 16:30:27.0295 6120 WfpLwf - ok 16:30:27.0326 6120 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 16:30:27.0341 6120 WIMMount - ok 16:30:27.0388 6120 [ 1EDBBF412A382550AF6EB35F5E46928E ] winachsf C:\Windows\system32\DRIVERS\CAX_CNXT.sys 16:30:27.0419 6120 winachsf - ok 16:30:27.0451 6120 WinDefend - ok 16:30:27.0451 6120 WinHttpAutoProxySvc - ok 16:30:27.0513 6120 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 16:30:27.0529 6120 Winmgmt - ok 16:30:27.0591 6120 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 16:30:27.0638 6120 WinRM - ok 16:30:27.0700 6120 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUSB.sys 16:30:27.0700 6120 WinUsb - ok 16:30:27.0731 6120 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 16:30:27.0731 6120 Wlansvc - ok 16:30:27.0794 6120 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 16:30:27.0794 6120 wlcrasvc - ok 16:30:27.0950 6120 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 16:30:27.0981 6120 wlidsvc - ok 16:30:28.0012 6120 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 16:30:28.0012 6120 WmiAcpi - ok 16:30:28.0059 6120 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 16:30:28.0059 6120 wmiApSrv - ok 16:30:28.0090 6120 WMPNetworkSvc - ok 16:30:28.0121 6120 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 16:30:28.0121 6120 WPCSvc - ok 16:30:28.0153 6120 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 16:30:28.0153 6120 WPDBusEnum - ok 16:30:28.0168 6120 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 16:30:28.0168 6120 ws2ifsl - ok 16:30:28.0184 6120 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 16:30:28.0184 6120 wscsvc - ok 16:30:28.0184 6120 WSearch - ok 16:30:28.0324 6120 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 16:30:28.0387 6120 wuauserv - ok 16:30:28.0418 6120 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 16:30:28.0418 6120 WudfPf - ok 16:30:28.0465 6120 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 16:30:28.0465 6120 WUDFRd - ok 16:30:28.0496 6120 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 16:30:28.0496 6120 wudfsvc - ok 16:30:28.0543 6120 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 16:30:28.0558 6120 WwanSvc - ok 16:30:28.0605 6120 [ E8F3FA126A06F8E7088F63757112A186 ] XAudio C:\Windows\system32\DRIVERS\XAudio64.sys 16:30:28.0605 6120 XAudio - ok 16:30:28.0636 6120 ================ Scan global =============================== 16:30:28.0683 6120 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 16:30:28.0777 6120 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll 16:30:28.0792 6120 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll 16:30:28.0808 6120 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 16:30:28.0839 6120 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 16:30:28.0855 6120 [Global] - ok 16:30:28.0855 6120 ================ Scan MBR ================================== 16:30:28.0870 6120 [ 5F5A918DA24C481814079F26143FCAAE ] \Device\Harddisk0\DR0 16:30:29.0447 6120 \Device\Harddisk0\DR0 - ok 16:30:29.0447 6120 ================ Scan VBR ================================== 16:30:29.0479 6120 [ F256128F3056AF6FF17D161EB5A32972 ] \Device\Harddisk0\DR0\Partition1 16:30:29.0479 6120 \Device\Harddisk0\DR0\Partition1 - ok 16:30:29.0494 6120 [ 4247623A29E1F01AA60A3CF5D43E15DC ] \Device\Harddisk0\DR0\Partition2 16:30:29.0494 6120 \Device\Harddisk0\DR0\Partition2 - ok 16:30:29.0525 6120 [ 530420C0EA06AB63AED2C88C314A86CE ] \Device\Harddisk0\DR0\Partition3 16:30:29.0525 6120 \Device\Harddisk0\DR0\Partition3 - ok 16:30:29.0525 6120 ============================================================ 16:30:29.0525 6120 Scan finished 16:30:29.0525 6120 ============================================================ 16:30:29.0541 3276 Detected object count: 0 16:30:29.0541 3276 Actual detected object count: 0 ok, Schritt 3 hat doch noch geklappt. Hier das log: aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software Run date: 2012-12-01 16:36:36 ----------------------------- 16:36:36.704 OS Version: Windows x64 6.1.7601 Service Pack 1 16:36:36.704 Number of processors: 4 586 0x2A07 16:36:36.704 ComputerName: MMEPRI-THINKP UserName: Mme Pri 16:36:37.375 Initialize success 16:36:46.002 AVAST engine defs: 12120100 16:37:22.740 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 16:37:22.740 Disk 0 Vendor: WDC_WD32 02.0 Size: 305245MB BusType: 3 16:37:22.771 Disk 0 MBR read successfully 16:37:22.771 Disk 0 MBR scan 16:37:22.786 Disk 0 unknown MBR code 16:37:22.786 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1200 MB offset 2048 16:37:22.802 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 288043 MB offset 2459648 16:37:22.833 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 16000 MB offset 592371712 16:37:22.880 Disk 0 scanning C:\Windows\system32\drivers 16:37:30.836 Service scanning 16:37:54.922 Modules scanning 16:37:54.938 Disk 0 trace - called modules: 16:37:54.954 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 16:37:54.969 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005ff4060] 16:37:54.969 3 CLASSPNP.SYS[fffff8800205143f] -> nt!IofCallDriver -> [0xfffffa80044908c0] 16:37:54.985 5 ACPI.sys[fffff88000f8d7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004498050] 16:37:54.985 Scan finished successfully 16:38:06.466 Disk 0 MBR has been saved successfully to "C:\Users\Mme Pri\Desktop\MBR.dat" 16:38:06.466 The log file has been saved successfully to "C:\Users\Mme Pri\Desktop\aswMBR.txt" |
Servus, Als erstes möchte ich, dass du diese Datei C:\Users\Mme Pri\Downloads\SoftonicDownloader_fuer_photo-card-maker.exe hier hochlädst: http://www.bleepingcomputer.com/subm...hp?channel=147 Auf Durchsuchen klicken, zu der genannten Datei navigieren, auf Öffnen klicken und abschließend auf Send File klicken. Gib mir Bescheid, wenn es geklappt hat. Finger weg von Softonic! Damit hast du dir diesen Müll eingehandelt! Lade dir Software direkt beim Hersteller! Dann geht es so weiter: Schritt 1 Downloade Dir bitte den Revo Uninstaller
Starte den Rechner abschließend neu auf. Schritt 2 Downloade Dir bitte ![]()
Schritt 3 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden. http://imageshack.us/a/img841/7292/thisisujrt.gif Bitte lade Junkware Removal Tool auf Deinen Desktop.
Schritt 3 Scan mit Combofix
Bitte poste mit deiner nächsten Antwort
|
Okidok! Werd mich dran halten! Versprochen! Datei habe ich hochgeladen. # AdwCleaner v2.010 - Datei am 01/12/2012 um 17:48:55 erstellt # Aktualisiert am 29/11/2012 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : Mme Pri - MMEPRI-THINKP # Bootmodus : Normal # Ausgeführt unter : C:\Users\Mme Pri\Downloads\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Users\Mme Pri\AppData\Roaming\DataMgr Ordner Gelöscht : C:\Users\Mme Pri\AppData\Roaming\HMN Ordner Gelöscht : C:\Users\Mme Pri\AppData\Roaming\SDIV 2.0 ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Softonic Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DataMgr] Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Protector] Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [TU] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v16.0.2 (de) Profilname : default Datei : C:\Users\Mme Pri\AppData\Roaming\Mozilla\Firefox\Profiles\689eorrd.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [1214 octets] - [01/12/2012 17:48:55] ########## EOF - C:\AdwCleaner[S1].txt - [1274 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 3.7.0 (11.30.2012:3) OS: Windows 7 Professional x64 Ran by Mme Pri on 01.12.2012 at 17:57:22.16 Blog: hxxp://thisisudax.blogspot.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page Successfully repaired: [Registry Value] hkey_users\S-1-5-21-1184588185-1753179807-1908705451-1001\software\microsoft\internet explorer\main\\Start Page ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Mme Pri\AppData\Roaming\dvdvideosoft" ~~~ FireFox Successfully deleted the following from C:\Users\Mme Pri\AppData\Roaming\mozilla\firefox\profiles\689eorrd.default\prefs.js user_pref("browser.newtab.url", "hxxp://search.fbdownloader.com/?channel=sfch203fbdgy18"); user_pref("browser.search.defaultenginename", "FBDownloader"); user_pref("browser.startup.homepage", "https://www.google.ch/search?q=hollywood+trinken+antiage&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:de:official&client=firefox-a#hl=de&client=firefox-a&hs=M7s&tbo=d&rls=org.mozilla:de%3Aofficial&sclient=psy-ab&q=trinkkur&oq=trinkkur&gs_l=serp.3..0l4.27790.28879.0.29107.8.7.0.0.0.0.258.462.2-2.2.0...0.0...1c.1.FcbtXXzRAJY&pbx=1&bav=on.2,or.r_gc.r_pw.r_qf.&fp=d5879f63d7b2892a&bpcl=39314241&biw=1366&bih=638|hxxp://www.gofeminin.de/stars-beauty/anti-age-tricks-der-stars-d15992c233479.html|hxxp://www.flickr.com/photos/richardchisholm/sets/72157601695828573/|hxxp://www.fitundgesund.at/diaeten/zitronensaft-kur.85.htm|https://www.google.ch/search?q=zitat+brunnenkur&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:de:official&client=firefox-a#q=hollywood+star+detox&hl=de&client=firefox-a&hs=gYY&tbo=d&rls=org.mozilla:de:official&ei=LuG3UJaND8On4gTt-IHwDQ&start=10&sa=N&bav=on.2,or.r_gc.r_pw.r_qf.&fp=d5879f63d7b2892a&bpcl=39314241&biw=1366&bih=638|hxxp://www.wortpfau.de/autoren/Johann-Wolfgang-von-Goethe-41.html|hxxp://madonna.oe24.at/Diaet/Gwyneth-Paltrow-Schlank-mit-Wasser-Kur/1245839#textBegin|hxxp://lifestyle.t-online.de/aerzte-warnen-vor-selbstbehandlung-mit-tipps-aus-dem-internet/id_19951218/index|hxxp://de.wikipedia.org/wiki/Brunnenkur|hxxp://de.wikipedia.org/wiki/Dyspepsie|hxxp://www.paradisi.de/Wellness/Kuren_und_Anwendungen/Trinkkur/|hxxp://www.fangomed.com/shop/shop-549-fango-magen-darm-trinkkur.html|hxxp://de.wikipedia.org/wiki/Moderne#Anfang_der_Moderne|hxxp://de.wikipedia.org/wiki/Kult|hxxp://search.fbdownloader.com/?channel=sfch203fbdgy18|https://www.google.ch/"); user_pref("extensions.fbdownloader.issearch", true); user_pref("keyword.URL", "hxxp://search.fbdownloader.com/search.php?channel=sfch203fbdgy18&q="); ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 01.12.2012 at 18:02:07.55 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Combofix Logfile: Code: ComboFix 12-12-01.01 - Mme Pri 01.12.2012 18:06:38.1.4 - x64 |
Servus, gibt es noch Probleme mit fbDownoader? Wenn ja, in welchem Browser? Starte bitte OTL.exe und drücke den Quick Scan Button. Poste die OTL.txt hier in deinen Thread. |
Hallo Matthias! Danke für Deine Rückmeldung! So weit ich das beurteilen kann, macht der fbDownloader keine Probleme mehr!OTL Logfile: Code: OTL logfile created on: 02.12.2012 13:18:11 - Run 2 |
Servus, hört sich doch schon mal gut an! Nachfolgend noch ein paar Kontrollsuchläufe: Schritt 1 Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop. Download Mirror # 1
Schritt 2
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte SecurityCheck
Bitte poste mit deiner nächsten Antwort
|
Ok! Shaiiit, ich glaub, da is noch was... :-S Los gehts: SystemLook 30.07.11 by jpshortstuff Log created at 14:30 on 02/12/2012 by Mme Pri Administrator - Elevation successful ========== filefind ========== Searching for "*fbdownloader*" No files found. ========== folderfind ========== Searching for "*fbdownloader*" No folders found. ========== regfind ========== Searching for "fbdownloader" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}] @="FBDownloader" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}] "ButtonText"="FBDownloader" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}] "Hot Icon"="C:\Users\Mme Pri\AppData\Local\fbDownloader\Extensions\FBDownloader.dll,1000" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}] "Icon"="C:\Users\Mme Pri\AppData\Local\fbDownloader\Extensions\FBDownloader.dll,1000" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDownloader.BHO] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDownloader.BHO] @="FBDownloader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDownloader.BHO\CurVer] @="FBDownloader.BHO.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDownloader.DownloadPhoto] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDownloader.DownloadPhoto\CurVer] @="FBDownloader.DownloadPhoto.1" [HKEY_USERS\S-1-5-21-1184588185-1753179807-1908705451-1001\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}] @="FBDownloader" [HKEY_USERS\S-1-5-21-1184588185-1753179807-1908705451-1001\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}] "ButtonText"="FBDownloader" [HKEY_USERS\S-1-5-21-1184588185-1753179807-1908705451-1001\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}] "Hot Icon"="C:\Users\Mme Pri\AppData\Local\fbDownloader\Extensions\FBDownloader.dll,1000" [HKEY_USERS\S-1-5-21-1184588185-1753179807-1908705451-1001\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}] "Icon"="C:\Users\Mme Pri\AppData\Local\fbDownloader\Extensions\FBDownloader.dll,1000" Searching for " " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\Mme Pri\Desktop\gimp-2.8.0-setup.exe"="GIMP Setup " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_#11032603004530&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_#12032778000459&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_8.07#12053112032636&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.70#000A270022FD9 2CE&0#] "DeviceDesc"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_#11032603004530&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_#12032778000459&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_8.07#12053112032636&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.70#000A270022FD9 2CE&0#] "DeviceDesc"="iPod " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_#11032603004530&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_#12032778000459&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_&PROD_&REV_8.07#12053112032636&0#] "DeviceDesc"=" " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.70#000A27002 2FD92CE&0#] "DeviceDesc"="iPod " [HKEY_USERS\S-1-5-21-1184588185-1753179807-1908705451-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\Mme Pri\Desktop\gimp-2.8.0-setup.exe"="GIMP Setup " [HKEY_USERS\S-1-5-21-1184588185-1753179807-1908705451-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\Mme Pri\Desktop\gimp-2.8.0-setup.exe"="GIMP Setup " -= EOF =- Malwarebytes Anti-Malware 1.65.1.1000 Malwarebytes : Free anti-malware download Datenbank Version: v2012.12.02.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Mme Pri :: MMEPRI-THINKP [Administrator] 02.12.2012 14:34:38 mbam-log-2012-12-02 (14-34-38).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 250454 Laufzeit: 1 Minute(n), 40 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=8cade0acb43d5e4885bb71a9d0f66faf # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-12-02 02:59:16 # local_time=2012-12-02 03:59:16 (+0100, Mitteleuropäische Zeit) # country="Switzerland" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1280 16777215 100 0 22612251 22612251 0 0 # compatibility_mode=5893 16776574 100 94 169023 106085678 0 0 # compatibility_mode=8192 67108863 100 0 3794 3794 0 0 # scanned=169115 # found=1 # cleaned=0 # scan_time=4528 C:\Users\Mme Pri\Downloads\SoftonicDownloader_fuer_photo-card-maker.exe a variant of Win32/SoftonicDownloader.E application (unable to clean) 00000000000000000000000000000000 I Results of screen317's Security Check version 0.99.56 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Internet Security Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.65.1.1000 Java(TM) SE Runtime Environment 6 Java version out of Date! Adobe Flash Player 10 Flash Player out of Date! Adobe Flash Player 11.5.502.110 Adobe Reader 10.1.4 Adobe Reader out of Date! Mozilla Firefox 16.0.2 Firefox out of Date! ````````Process Check: objlist.exe by Laurent```````` Kaspersky Lab Kaspersky Internet Security 2012 avp.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Danke! |
Servus, ein paar Reste müssen wir noch entfernen: Fixen mit OTL
Code: :files
|
========== FILES ========== C:\Users\Mme Pri\Downloads\SoftonicDownloader_fuer_photo-card-maker.exe moved successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{553318DA-D010-469E-84B1-496563CAE1BF}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDownloader.BHO\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDownloader.DownloadPhoto\ deleted successfully. Registry key HKEY_USERS\S-1-5-21-1184588185-1753179807-1908705451-1001\Software\Microsoft\Internet Explorer\Extensions\{553318DA-D010-469E-84B1-496563CAE1BF}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{553318DA-D010-469E-84B1-496563CAE1BF}\ not found. ========== COMMANDS ========== OTL by OldTimer - Version 3.2.69.0 log created on 12022012_193708 und wieder ein riesiges Dankeschön! Bin gespannt wies weitergeht! Die miese kleine Ratte steckt jetzt in einem Ordner, oder? brrrr... :-) |
Servus, Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. :daumenhoc Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Schritt 2 Deine Version von Adobe Flash Player ist veraltet. Bitte folge diesen Schritte, um Adobe Flash zu aktualisieren:
Schritt 3 Deinstalliere bitte deine aktuelle Version von Adobe Reader Start--> Systemsteuerung--> Software / Programme deinstallieren--> Adobe Reader und lade dir die neue Version von Hier herunter- Entferne den Hacken für den McAfee SecurityScan bzw. Google Chrome. Schritt 4
Prüfe bitte auch (regelmässig) ob folgende Links fehlende Updates bei deinen Plugins zeigen: Schritt 5 Starte DeFogger und klicke auf Re-enable. Gegebenenfalls muss dein Rechner neu gestartet werden. Schritt 6 Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren. Windows-Taste + R drücke. Kopiere nun folgende Zeile in die Kommandozeile und klicke OK. Code: Combofix /Uninstall Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch aus dieser die Schädlinge verschwinden. Nun die eben deaktivierten Programme wieder aktivieren. Schritt 7 Downloade dir bitte delfix auf deinen Desktop.
Schritt 8 Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
Lieber Matthias Habe alles wie beschrieben ausgeführt. Es bleibt mir also nur noch, mich bei Dir herzlich zu bedanken! Jetzt gehts ab zum Spenden! Ihr seid grossartig und Du insbesondere! Danke Danke Danke für alle Hilfe! :-* Dicker Schmatz von der Ninja Katz' |
Ich bin froh, dass wir helfen konnten :abklatsch: Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 15:16 Uhr. |
Copyright ©2000-2025, Trojaner-Board