Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   gvu trojaner (https://www.trojaner-board.de/135365-gvu-trojaner.html)

Newson 22.05.2013 17:19

gvu trojaner
 
Guten Tag,

Erstmals, mein Deutsch ist nicht super, aber hoffentlich passt.

Zweitens, ich habe seit ein paar Stunde die GVU Trojaner, und kann nichts mehr mit mein Rechner machen. Ich habe die Rechner Runtergefahren und dann wieder hochgeahren aber ich habe um die 2 minute bevor die Sperrung wieder aufstellt.

Ich bin nicht die 'Technik-freak' aber vielleicht jemand könnte mich schrittweise begleitten.

Danke vielmals,

Gruß, Richie

markusg 22.05.2013 17:22

Hi,
kommst du an nen pc mit brenner?
download:
http://filepony.de/download-otlpe/
und brenne es mit ISOBurner auf eine CD.
ISO Burner - Download - Filepony
isoburner anleitung:
http://www.trojaner-board.de/83208-b...ei-cd-dvd.html
• Wenn der Download fertig ist mache ein doppel Klick auf die OTLPENet.exe, was ISOBurner öffnet um es auf die CD zu brennen.
Starte dein System neu und boote von der CD die du gerade erstellt hast.
Wenn du nicht weist wie du deinen Computer dazu bringst von der CD zu booten,
http://www.trojaner-board.de/81857-c...cd-booten.html

• Dein System sollte jetzt einen REATOGO-X-PE Desktop anzeigen.
• Mache einen doppel Klick auf das OTLPE Icon.
• Wenn du gefragt wirst "Do you wish to load the remote registry", dann wähle Yes.
• Wenn du gefragt wirst "Do you wish to load remote user profile(s) for scanning", dann wähle Yes.
• entferne den haken bei "Automatically Load All Remaining Users" wenn er gesetzt ist.

• OTL sollte nun starten.
Kopiere nun den Inhalt in die http://larusso.trojaner-board.de/Images/otlfix.jpg
Textbox.
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe

• Drücke Run Scan um den Scan zu starten.
• Wenn er fertig ist werden die Dateien in C:\otl.txt gesichert
• Kopiere diesen Ordner auf deinen USB-Stick wenn du keine Internetverbindung auf diesem System hast.
poste beide logs

Newson 22.05.2013 17:25

ok, ich melde mich wenn ich soweit bin. Danke

markusg 22.05.2013 17:43

bitte solche zwischenposts weg lassen, da die Nachfolgenen an diesen angehangen werden müsste ich dann immer reinsehen.

Newson 22.05.2013 19:25

Liste der Anhänge anzeigen (Anzahl: 1)
Hallo,

Ich habe jetz ein Problem. Ich habe das CD gebrannt, wie beschriben. Ich habe die Disk in die infizierte Laptop eingeliegt, F12 gedruckt, und selektiert CD-ROM. Dan hat die Computer versucht das REATOGO-X-PE Program hochzuladen, hat dann von allein Windows angefangen, und bevor Windows sich voll geöffnet hatte, die Rechner hat ein Blauebildschirm gezeigt.Anhang 54958

markusg 22.05.2013 19:27

Hi, gehe mal ins Bios, geht meist bei Neustart über entf.
dort musst du etwas suchen, das ide, bzw AHCI mode heißt, kann dir nicht genau sagen wo, da immer unterschiedlich, könnte aber unter advanced options sein.
konfiguriere jeweils den gegenteiligen Mode und versuche die CD erneut.

Newson 22.05.2013 20:29

Liste der Anhänge anzeigen (Anzahl: 1)
ok, ich habe es gefunden und AHCI auf IDE geändert.
Jetzt habe ich auf das OTLPE Icon geclickt, aber ich bekomme die folgenden fenster:

Anhang 54961

Wo muss ich hin?

Danke und Gruß

markusg 22.05.2013 23:56

alles aufklappen, ordner windows suchen und dann da draufklicken, dann gehts los

Newson 23.05.2013 06:16

OTL Logfile:
Code:

OTL logfile created on: 5/23/2013 11:56:23 AM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files
Drive C: | 12.15 Gb Total Space | 6.09 Gb Free Space | 50.11% Space Free | Partition Type: NTFS
Drive D: | 130.89 Gb Total Space | 127.98 Gb Free Space | 97.78% Space Free | Partition Type: NTFS
Drive E: | 155.00 Gb Total Space | 99.78 Gb Free Space | 64.37% Space Free | Partition Type: NTFS
Drive F: | 985.00 Mb Total Space | 585.69 Mb Free Space | 59.46% Space Free | Partition Type: FAT
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - [2013/05/16 01:04:44 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- E:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/23 03:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto] -- E:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2013/04/10 02:56:49 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand] -- E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/27 06:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/01/27 06:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/12/18 15:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/10/02 07:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto] -- E:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/06/07 13:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto] -- E:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/12/05 11:44:10 | 000,098,304 | ---- | M] (Multiplan Consultants Limited) [Auto] -- E:\SilentHerdsman\services\JavaService.exe -- (SilentHerdsman)
SRV - [2011/12/05 11:44:10 | 000,098,304 | ---- | M] (Multiplan Consultants Limited) [Auto] -- E:\SilentHerdsman\services\JavaService.exe -- (ETSWatchdog)
SRV - [2011/05/15 06:29:59 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/02/10 12:47:41 | 000,040,960 | ---- | M] (Dell Inc.) [Auto] -- E:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV - [2010/10/26 04:22:10 | 000,245,648 | ---- | M] () [Auto] -- E:\SilentHerdsman\resources\ntpServer\bin\ntpd.exe -- (NTP)
SRV - [2010/09/04 03:15:22 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto] -- E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010/09/04 03:14:26 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand] -- E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010/07/05 15:37:32 | 000,045,056 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe -- (svcGenericHost)
SRV - [2010/06/22 15:27:38 | 001,358,160 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe -- (tmlisten)
SRV - [2010/06/22 15:18:46 | 001,323,912 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe -- (ntrtscan)
SRV - [2010/05/14 08:11:08 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) [Auto] -- E:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe -- (postgresql-8.4)
SRV - [2010/04/07 08:35:04 | 000,229,458 | ---- | M] (IDT, Inc.) [Auto] -- E:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\stacsv.exe -- (STacSV)
SRV - [2009/12/01 13:13:12 | 000,345,352 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
SRV - [2009/11/04 17:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009/11/04 17:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009/10/20 11:11:58 | 000,595,232 | ---- | M] (Broadcom Corporation.) [Auto] -- E:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009/09/08 08:12:51 | 000,116,104 | ---- | M] () [Auto] -- E:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2009/07/15 19:39:06 | 000,497,008 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe -- (TmPfw)
SRV - [2009/07/15 19:37:18 | 000,689,416 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe -- (TmProxy)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/03/03 06:43:08 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) [Auto] -- E:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\AEstSrv.exe -- (AESTFilters)
SRV - [2009/01/26 09:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto] -- E:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2007/05/31 10:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 10:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (ALSysIO)
DRV - [2013/01/20 10:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto] -- E:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/05/11 01:34:06 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
DRV - [2011/02/10 12:47:40 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/09/29 12:38:00 | 000,043,888 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/08/30 23:15:56 | 000,247,808 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/08/20 13:04:38 | 000,017,648 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- E:\Windows\System32\drivers\stdcfltn.sys -- (stdcfltn)
DRV - [2010/08/12 12:50:20 | 000,146,528 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2010/07/19 13:03:10 | 000,059,472 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2010/07/19 13:03:00 | 000,051,792 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2010/07/19 13:02:54 | 000,163,408 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Windows\System32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2010/05/10 18:03:32 | 000,230,928 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmXPFlt.sys -- (TmFilter)
DRV - [2010/05/10 18:02:44 | 000,036,368 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\tmpreflt.sys -- (TmPreFilter)
DRV - [2010/05/10 17:41:54 | 001,322,808 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\vsapiNT.sys -- (VSApiNt)
DRV - [2010/04/07 08:35:04 | 000,423,936 | ---- | M] (IDT, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2010/02/27 11:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2009/09/17 16:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\HECI.sys -- (HECI) Intel(R)
DRV - [2009/08/10 15:06:08 | 000,171,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/07/15 19:38:14 | 000,283,152 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Windows\System32\drivers\tmwfp.sys -- (tmwfp)
DRV - [2009/07/15 19:38:04 | 000,146,448 | ---- | M] (Trend Micro Inc.) [Kernel | System] -- E:\Windows\System32\drivers\tmlwf.sys -- (tmlwf)
DRV - [2009/07/15 19:37:40 | 000,089,872 | ---- | M] (Trend Micro Inc.) [Kernel | System] -- E:\Windows\System32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2009/07/13 20:56:07 | 000,265,088 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BrSerIb.sys -- (BrSerIb) Brother MFC Serial Interface Driver(WDM)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 18:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BrUsbSIb.sys -- (BrUsbSIb) Brother MFC Serial USB Driver(WDM)
DRV - [2009/05/28 12:48:20 | 000,134,144 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\CtAudDrv.sys -- (CtAudDrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USSMB/8
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
 
 
IE - HKU\r.newson_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USSMB/8
IE - HKU\r.newson_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.semex-deutschland.de/
IE - HKU\r.newson_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\System32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: E:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: E:\Windows\System32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:  File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: E:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: E:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: E:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: E:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: c:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\FirefoxExtension [2012/04/19 06:23:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/11 02:56:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2013/05/11 02:56:27 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\extensions
[2013/04/10 02:57:39 | 000,263,064 | ---- | M] (Mozilla Foundation) -- E:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/10 04:18:46 | 000,001,392 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013/04/10 04:18:46 | 000,002,465 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/10 04:18:46 | 000,001,153 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013/04/10 04:18:46 | 000,006,805 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013/04/10 04:18:46 | 000,001,178 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013/04/10 04:18:46 | 000,001,105 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012/07/24 02:53:58 | 000,442,957 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1        autodiscover.tcom-it.de
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 15216 more lines...
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - E:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - E:\Program Files\Google\Chrome\Application\26.0.1410.64\npchrome_frame.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\c.proebsting_ON_E\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] E:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] E:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ControlCenter3] E:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DBRMTray] E:\dell\DBRM\Reminder\DbrmTrayicon.exe (Microsoft)
O4 - HKLM..\Run: [Dell Webcam Central] E:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] E:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [FreeFallProtection] E:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4 - HKLM..\Run: [IJNetworkScanUtility] E:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [MSC] E:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OfficeScanNT Monitor] E:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] E:\Program Files\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickSet] E:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [RemoteControl9] E:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] E:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\c.proebsting_ON_E..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\r.newson_ON_E..\Run: [DisplaySwitch] E:\ProgramData\DisplaySwitch.exe (Hilgraeve, Inc.)
O4 - HKU\r.newson_ON_E..\Run: [RESTART_STICKY_NOTES] E:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [DBRMTray] E:\dell\DBRM\Reminder\TrayApp.exe (Microsoft)
O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NTP_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\postgres_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: E:\Users\c.proebsting\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: An OneNote s&enden - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - E:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - E:\Program Files\Google\Chrome\Application\26.0.1410.64\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - E:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/05/23 11:49:59 | 000,000,000 | -HSD | C] -- E:\RECYCLER
[2013/05/22 13:57:41 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Client-Server Security Agent
[2013/05/22 10:35:13 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Byxew
[2013/05/22 10:23:00 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Liocgi
[2013/05/22 10:23:00 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Eqyx
[2013/05/22 10:22:04 | 000,095,744 | ---- | C] (Hilgraeve, Inc.) -- E:\ProgramData\DisplaySwitch.exe
[2013/05/16 01:09:29 | 000,420,864 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\vbscript.dll
[2013/05/16 01:09:28 | 000,065,024 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jsproxy.dll
[2013/05/16 01:09:27 | 000,607,744 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeeds.dll
[2013/05/16 01:09:27 | 000,176,640 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll
[2013/05/16 01:09:27 | 000,142,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieUnatt.exe
[2013/05/16 01:09:26 | 000,717,824 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript.dll
[2013/05/16 01:09:25 | 001,800,704 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript9.dll
[2013/05/16 01:09:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\url.dll
[2013/05/16 01:09:24 | 001,427,968 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\inetcpl.cpl
[2013/05/16 01:04:29 | 002,382,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb
[2013/05/15 01:26:17 | 000,040,960 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\wwanprotdim.dll
[2013/05/15 01:26:15 | 002,347,520 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\win32k.sys
[2013/05/15 01:19:58 | 000,218,984 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\dxgmms1.sys
[2013/05/15 01:19:54 | 001,796,096 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\authui.dll
[2013/05/15 01:19:54 | 000,101,720 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\consent.exe
[2013/05/11 03:06:17 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\{F3523132-0D6F-41A1-9CA2-F5C21E09DA5B}
[2013/05/11 03:06:17 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\{9FC7F15F-A688-4CE7-AE25-7D5914442510}
[2013/05/11 03:00:18 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\Macromedia
[2013/05/11 02:57:39 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Mozilla
[2013/05/11 02:57:39 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\Mozilla
[2011/02/10 14:18:24 | 000,004,096 | ---- | C] ( ) -- E:\Windows\System32\IGFXDEVLib.dll
[1 E:\Users\r.newson\Desktop\*.tmp files -> E:\Users\r.newson\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013/05/22 18:44:19 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat
[2013/05/22 18:42:28 | 000,001,098 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/22 18:42:13 | 2358,259,712 | -HS- | M] () -- E:\hiberfil.sys
[2013/05/22 16:25:00 | 000,000,506 | ---- | M] () -- E:\Windows\tasks\SystemToolsDailyTest.job
[2013/05/22 15:10:00 | 000,000,564 | ---- | M] () -- E:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/05/22 14:32:10 | 000,001,102 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/22 14:02:24 | 000,014,240 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/22 14:02:24 | 000,014,240 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/22 14:02:00 | 000,000,884 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/22 14:01:22 | 000,733,666 | ---- | M] () -- E:\Windows\System32\perfh007.dat
[2013/05/22 14:01:22 | 000,693,808 | ---- | M] () -- E:\Windows\System32\perfh009.dat
[2013/05/22 14:01:22 | 000,159,292 | ---- | M] () -- E:\Windows\System32\perfc007.dat
[2013/05/22 14:01:22 | 000,134,936 | ---- | M] () -- E:\Windows\System32\perfc009.dat
[2013/05/22 13:57:41 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Client-Server Security Agent
[2013/05/22 13:57:28 | 000,000,031 | ---- | M] () -- E:\tmuninst.ini
[2013/05/22 10:32:26 | 002,250,054 | ---- | M] () -- E:\ProgramData\1.bmp
[2013/05/22 10:32:12 | 000,465,655 | ---- | M] () -- E:\ProgramData\1.jpg
[2013/05/22 10:22:01 | 000,095,744 | ---- | M] (Hilgraeve, Inc.) -- E:\ProgramData\DisplaySwitch.exe
[2013/05/22 02:52:18 | 000,139,873 | ---- | M] () -- E:\Users\r.newson\Desktop\NF BHV1 freie bestande.pdf
[2013/05/18 01:06:05 | 000,492,184 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT
[2013/05/16 16:35:44 | 000,326,569 | ---- | M] () -- E:\Users\r.newson\Desktop\Carnival RZG.pdf
[2013/05/16 01:40:28 | 000,001,062 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2013/05/16 01:04:43 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerApp.exe
[2013/05/16 01:04:43 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/05/11 02:56:42 | 000,001,119 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/05/11 02:56:42 | 000,001,107 | ---- | M] () -- E:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/05/06 15:38:35 | 009,742,839 | ---- | M] () -- E:\Users\r.newson\Desktop\87nkIIlmUh7NiubCsfcT6e2Sw1367831810.pdf
[2013/05/05 15:12:55 | 002,382,848 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb
[2013/05/02 11:28:50 | 000,238,872 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\MpSigStub.exe
[2013/04/30 02:06:35 | 000,082,640 | ---- | M] () -- E:\Users\r.newson\Desktop\IB CAN 000102327659 _Picolo.pdf
[2013/04/30 02:06:06 | 000,725,866 | ---- | M] () -- E:\Users\r.newson\Desktop\karsten Heesch.pdf
[1 E:\Users\r.newson\Desktop\*.tmp files -> E:\Users\r.newson\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013/05/22 10:32:26 | 002,250,054 | ---- | C] () -- E:\ProgramData\1.bmp
[2013/05/22 10:32:07 | 000,465,655 | ---- | C] () -- E:\ProgramData\1.jpg
[2013/05/22 02:52:16 | 000,139,873 | ---- | C] () -- E:\Users\r.newson\Desktop\NF BHV1 freie bestande.pdf
[2013/05/16 16:35:43 | 000,326,569 | ---- | C] () -- E:\Users\r.newson\Desktop\Carnival RZG.pdf
[2013/05/16 15:57:49 | 000,165,239 | R--- | C] () -- E:\Users\r.newson\Desktop\facebook_-1277089541.jpg
[2013/05/11 02:56:42 | 000,001,107 | ---- | C] () -- E:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/05/06 15:38:33 | 009,742,839 | ---- | C] () -- E:\Users\r.newson\Desktop\87nkIIlmUh7NiubCsfcT6e2Sw1367831810.pdf
[2013/04/30 02:06:35 | 000,082,640 | ---- | C] () -- E:\Users\r.newson\Desktop\IB CAN 000102327659 _Picolo.pdf
[2013/04/30 02:06:05 | 000,725,866 | ---- | C] () -- E:\Users\r.newson\Desktop\karsten Heesch.pdf
[2012/07/08 04:49:11 | 000,000,848 | ---- | C] () -- E:\Windows\Brpfx04a.ini
[2012/07/08 04:49:11 | 000,000,163 | ---- | C] () -- E:\Windows\brpcfx.ini
[2012/07/08 04:48:55 | 000,106,496 | ---- | C] () -- E:\Windows\System32\BrMuSNMP.dll
[2012/07/08 04:48:55 | 000,000,066 | ---- | C] () -- E:\Windows\Brfaxrx.ini
[2012/07/08 04:48:55 | 000,000,000 | ---- | C] () -- E:\Windows\brdfxspd.dat
[2012/06/21 03:24:45 | 000,000,432 | ---- | C] () -- E:\Windows\BRWMARK.INI
[2012/06/21 03:24:45 | 000,000,065 | ---- | C] () -- E:\Windows\System32\BD7320.DAT
[2012/06/18 11:38:22 | 000,000,096 | ---- | C] () -- E:\Users\r.newson\AppData\Local\fusioncache.dat
[2011/08/02 08:40:58 | 000,252,928 | ---- | C] () -- E:\Windows\System32\DShowRdpFilter.dll
[2011/06/10 00:34:52 | 000,080,416 | ---- | C] () -- E:\Windows\System32\RtNicProp32.dll
[2011/04/23 08:22:01 | 000,000,100 | ---- | C] () -- E:\Users\c.proebsting\AppData\Local\fusioncache.dat
[2011/02/10 14:18:25 | 000,870,560 | ---- | C] () -- E:\Windows\System32\igkrng575.bin
[2011/02/10 14:18:25 | 000,208,896 | ---- | C] () -- E:\Windows\System32\iglhsip32.dll
[2011/02/10 14:18:25 | 000,143,360 | ---- | C] () -- E:\Windows\System32\iglhcp32.dll
[2011/02/10 14:18:24 | 000,104,796 | ---- | C] () -- E:\Windows\System32\igfcg575m.bin
[2011/02/10 14:18:22 | 000,127,868 | ---- | C] () -- E:\Windows\System32\igcompkrng575.bin
[2011/02/10 14:18:22 | 000,000,151 | ---- | C] () -- E:\Windows\System32\GfxUI.exe.config
[2011/02/10 12:48:01 | 000,006,656 | ---- | C] () -- E:\Windows\System32\bcmwlrc.dll
[2009/07/14 04:47:43 | 000,733,666 | ---- | C] () -- E:\Windows\System32\perfh007.dat
[2009/07/14 04:47:43 | 000,295,922 | ---- | C] () -- E:\Windows\System32\perfi007.dat
[2009/07/14 04:47:43 | 000,159,292 | ---- | C] () -- E:\Windows\System32\perfc007.dat
[2009/07/14 04:47:43 | 000,038,104 | ---- | C] () -- E:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,492,184 | ---- | C] () -- E:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,693,808 | ---- | C] () -- E:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- E:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,134,936 | ---- | C] () -- E:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- E:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- E:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- E:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- E:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\System32\mlang.dat
[2005/12/21 11:57:36 | 000,139,264 | ---- | C] () -- E:\Windows\System32\nsldap32v50.dll
[2005/12/21 11:57:04 | 000,024,576 | ---- | C] () -- E:\Windows\System32\nsldappr32v50.dll
[2005/12/21 11:54:34 | 000,040,960 | ---- | C] () -- E:\Windows\System32\nsldapssl32v50.dll
[2005/01/17 01:10:16 | 000,045,056 | ---- | C] () -- E:\Windows\System32\BRTCPCON.DLL
[2004/08/09 01:00:42 | 000,000,114 | ---- | C] () -- E:\Windows\System32\BRLMW03A.INI
 
========== LOP Check ==========
 
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2012/02/02 07:32:24 | 000,000,000 | ---D | M] -- E:\ProgramData\Ask
[2011/03/19 06:52:00 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonBJ
[2011/09/16 03:56:39 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonIJMyPrinter
[2013/05/06 05:49:39 | 000,000,000 | ---D | M] -- E:\ProgramData\CanonIJPLM
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2012/11/08 04:20:44 | 000,000,000 | ---D | M] -- E:\ProgramData\LSMilchkuh
[2011/12/19 05:50:06 | 000,000,000 | ---D | M] -- E:\ProgramData\PCDr
[2011/02/10 12:58:01 | 000,000,000 | ---D | M] -- E:\ProgramData\PhotoShow Shared Assets
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2011/02/10 12:51:16 | 000,000,000 | ---D | M] -- E:\ProgramData\Temp
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2011/02/10 12:59:21 | 000,000,000 | ---D | M] -- E:\ProgramData\Uninstall
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2013/05/22 15:10:00 | 000,000,564 | ---- | M] () -- E:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2013/03/18 10:16:35 | 000,032,632 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
[2013/05/22 16:25:00 | 000,000,506 | ---- | M] () -- E:\Windows\Tasks\SystemToolsDailyTest.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2012/06/18 11:27:22 | 000,000,000 | -HSD | M] -- E:\$Recycle.Bin
[2011/02/10 12:43:14 | 000,000,000 | ---D | M] -- E:\Apps
[2013/03/18 10:06:32 | 000,000,000 | ---D | M] -- E:\backup
[2013/05/16 01:10:25 | 000,000,000 | -HSD | M] -- E:\Config.Msi
[2011/03/01 04:50:30 | 000,000,000 | ---D | M] -- E:\dell
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\Documents and Settings
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\Dokumente und Einstellungen
[2011/02/10 14:18:51 | 000,000,000 | ---D | M] -- E:\Drivers
[2011/02/10 05:37:10 | 000,000,000 | ---D | M] -- E:\Intel
[2012/06/22 02:59:05 | 000,000,000 | ---D | M] -- E:\Logs
[2012/03/26 08:13:31 | 000,000,000 | RH-D | M] -- E:\MSOCache
[2012/12/17 16:26:37 | 000,000,000 | ---D | M] -- E:\NMP_Backup
[2009/07/13 22:37:05 | 000,000,000 | ---D | M] -- E:\PerfLogs
[2013/05/14 09:27:56 | 000,000,000 | R--D | M] -- E:\Program Files
[2013/05/22 10:32:26 | 000,000,000 | -H-D | M] -- E:\ProgramData
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\Programme
[2013/05/23 11:49:59 | 000,000,000 | -HSD | M] -- E:\RECYCLER
[2013/03/18 10:11:19 | 000,000,000 | ---D | M] -- E:\Ruby193
[2013/03/18 10:08:34 | 000,000,000 | ---D | M] -- E:\SilentHerdsman
[2013/03/18 10:11:53 | 000,000,000 | ---D | M] -- E:\SilentHerdsmanInstaller-2.7.7.0
[2013/05/20 06:31:06 | 000,000,000 | -HSD | M] -- E:\System Volume Information
[2013/03/18 10:11:50 | 000,000,000 | R--D | M] -- E:\Users
[2011/03/04 03:15:47 | 000,000,000 | ---D | M] -- E:\VIT
[2013/02/27 22:06:03 | 000,000,000 | ---D | M] -- E:\Windows
 
< %PROGRAMFILES%\*.exe >
 
Invalid Environment Variable: %LOCALAPPDATA%\*.exe
 
< %systemroot%\*. /mp /s >
 
 
< MD5 for: AGP440.SYS  >
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\System32\drivers\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\System32\drivers\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- E:\Windows\System32\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- E:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2011/02/26 01:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- E:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Drivers\storage\R271949\f6flpy-x86\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\drivers\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_e8a55be84650e755\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_c766b54545e4141f\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\System32\drivers\iaStorV.sys
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011/03/11 01:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2010/11/20 08:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- E:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 08:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010/11/20 08:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- E:\Windows\System32\netlogon.dll
[2010/11/20 08:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- E:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\System32\drivers\nvstor.sys
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011/03/11 01:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2010/11/20 08:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- E:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 08:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010/11/20 08:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- E:\Windows\System32\scecli.dll
[2010/11/20 08:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- E:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010/11/20 08:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- E:\Windows\System32\user32.dll
[2010/11/20 08:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- E:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- E:\Windows\System32\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- E:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- E:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- E:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- E:\Windows\System32\drivers\ws2ifsl.sys
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- E:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2010/11/20 08:19:02 | 000,828,928 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- E:\Windows\system32\fontext.dll
[2013/02/27 00:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- E:\Windows\system32\shell32.dll
 
Invalid Environment Variable: %USERPROFILE%\*.*
 
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.exe
 
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.dll
 
Invalid Environment Variable: %USERPROFILE%\Application Data\*.exe
< End of report >

--- --- ---

markusg 23.05.2013 10:50

komisch, wird erst mal nichts weiter im log angezeigt
auf deinem zweiten pc gehe auf start, programme zubehör editor, kopiere dort
rein:
Code:

:OTL
:Files
:Commands
[EMPTYFLASH]
[emptytemp]



dieses speicherst du auf nem usb stick als fix.txt
nutze nun wieder OTLPENet.exe (starte also von der erstellten cd) und hake alles an, wie es bereits im post zu OTLPENet.exe beschrieben ist.
• Klicke nun bitte auf den Fix Button.
es sollte nun eine meldung ähnlich dieser: "load fix from file" erscheinen, lade also die fix.txt von deinem stick.
wenn dies nicht funktioniert, bitte den fix manuell eintragen.
dann klicke erneut den fix buton. pc startet evtl. neu. wenn ja,
ins bios gehen, Modus umstellen
nimm die cd aus dem laufwerk, windows sollte nun normal starten und die otl.txt öffnen,
log posten bitte.

Newson 23.05.2013 18:20

Anbei ist Bericht:
pc hat sich von allein nicht wieder neu gestartet. Ich habe selbe es runtergefahren, modus umgestellt, aber kommt die BSI sperrbild wieder.

Anhang 55045

markusg 23.05.2013 18:26

OK stelle den Modus noch mal um, wähle im otl scan, den ich noch mal benötige auf jeden fall den betroffenen Nutzer aus, falls du mehrere Windows instalationen hast, auf verschiedenen Laufwerken zb musst du auch die richtige wählen. und poste das neue Log

Newson 23.05.2013 19:44

OTL Logfile:
Code:

OTL logfile created on: 5/23/2013 6:36:32 PM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files
Drive C: | 12.15 Gb Total Space | 6.09 Gb Free Space | 50.11% Space Free | Partition Type: NTFS
Drive D: | 130.89 Gb Total Space | 127.98 Gb Free Space | 97.78% Space Free | Partition Type: NTFS
Drive E: | 155.00 Gb Total Space | 99.78 Gb Free Space | 64.37% Space Free | Partition Type: NTFS
Drive F: | 985.00 Mb Total Space | 585.39 Mb Free Space | 59.43% Space Free | Partition Type: FAT
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - [2013/05/16 01:04:44 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- E:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/23 03:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto] -- E:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2013/04/10 02:56:49 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand] -- E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/27 06:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/01/27 06:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/12/18 15:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/10/02 07:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto] -- E:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/06/07 13:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto] -- E:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/12/05 11:44:10 | 000,098,304 | ---- | M] (Multiplan Consultants Limited) [Auto] -- E:\SilentHerdsman\services\JavaService.exe -- (SilentHerdsman)
SRV - [2011/12/05 11:44:10 | 000,098,304 | ---- | M] (Multiplan Consultants Limited) [Auto] -- E:\SilentHerdsman\services\JavaService.exe -- (ETSWatchdog)
SRV - [2011/05/15 06:29:59 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/02/10 12:47:41 | 000,040,960 | ---- | M] (Dell Inc.) [Auto] -- E:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV - [2010/10/26 04:22:10 | 000,245,648 | ---- | M] () [Auto] -- E:\SilentHerdsman\resources\ntpServer\bin\ntpd.exe -- (NTP)
SRV - [2010/09/04 03:15:22 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto] -- E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010/09/04 03:14:26 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand] -- E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010/07/05 15:37:32 | 000,045,056 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe -- (svcGenericHost)
SRV - [2010/06/22 15:27:38 | 001,358,160 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe -- (tmlisten)
SRV - [2010/06/22 15:18:46 | 001,323,912 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe -- (ntrtscan)
SRV - [2010/05/14 08:11:08 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) [Auto] -- E:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe -- (postgresql-8.4)
SRV - [2010/04/07 08:35:04 | 000,229,458 | ---- | M] (IDT, Inc.) [Auto] -- E:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\stacsv.exe -- (STacSV)
SRV - [2009/12/01 13:13:12 | 000,345,352 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
SRV - [2009/11/04 17:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009/11/04 17:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009/10/20 11:11:58 | 000,595,232 | ---- | M] (Broadcom Corporation.) [Auto] -- E:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009/09/08 08:12:51 | 000,116,104 | ---- | M] () [Auto] -- E:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2009/07/15 19:39:06 | 000,497,008 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe -- (TmPfw)
SRV - [2009/07/15 19:37:18 | 000,689,416 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe -- (TmProxy)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/03/03 06:43:08 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) [Auto] -- E:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\AEstSrv.exe -- (AESTFilters)
SRV - [2009/01/26 09:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto] -- E:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2007/05/31 10:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 10:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (ALSysIO)
DRV - [2013/01/20 10:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto] -- E:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/05/11 01:34:06 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
DRV - [2011/02/10 12:47:40 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/09/29 12:38:00 | 000,043,888 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/08/30 23:15:56 | 000,247,808 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/08/20 13:04:38 | 000,017,648 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- E:\Windows\System32\drivers\stdcfltn.sys -- (stdcfltn)
DRV - [2010/08/12 12:50:20 | 000,146,528 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2010/07/19 13:03:10 | 000,059,472 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2010/07/19 13:03:00 | 000,051,792 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2010/07/19 13:02:54 | 000,163,408 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Windows\System32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2010/05/10 18:03:32 | 000,230,928 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmXPFlt.sys -- (TmFilter)
DRV - [2010/05/10 18:02:44 | 000,036,368 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\tmpreflt.sys -- (TmPreFilter)
DRV - [2010/05/10 17:41:54 | 001,322,808 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\vsapiNT.sys -- (VSApiNt)
DRV - [2010/04/07 08:35:04 | 000,423,936 | ---- | M] (IDT, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2010/02/27 11:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2009/09/17 16:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\HECI.sys -- (HECI) Intel(R)
DRV - [2009/08/10 15:06:08 | 000,171,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/07/15 19:38:14 | 000,283,152 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Windows\System32\drivers\tmwfp.sys -- (tmwfp)
DRV - [2009/07/15 19:38:04 | 000,146,448 | ---- | M] (Trend Micro Inc.) [Kernel | System] -- E:\Windows\System32\drivers\tmlwf.sys -- (tmlwf)
DRV - [2009/07/15 19:37:40 | 000,089,872 | ---- | M] (Trend Micro Inc.) [Kernel | System] -- E:\Windows\System32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2009/07/13 20:56:07 | 000,265,088 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BrSerIb.sys -- (BrSerIb) Brother MFC Serial Interface Driver(WDM)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 18:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BrUsbSIb.sys -- (BrUsbSIb) Brother MFC Serial USB Driver(WDM)
DRV - [2009/05/28 12:48:20 | 000,134,144 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\CtAudDrv.sys -- (CtAudDrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
 
 
IE - HKU\r.newson_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
IE - HKU\r.newson_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = Semex-Deutschland
IE - HKU\r.newson_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\System32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: E:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: E:\Windows\System32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:  File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: E:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: E:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: E:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: E:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: c:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\FirefoxExtension [2012/04/19 06:23:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/11 02:56:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2013/05/11 02:57:46 | 000,000,000 | ---D | M] (No name found) -- E:\Users\r.newson\AppData\Roaming\Mozilla\Extensions
[2013/05/11 03:02:17 | 000,000,000 | ---D | M] (No name found) -- E:\Users\r.newson\AppData\Roaming\Mozilla\Firefox\Profiles\5vviftf1.default\extensions
[2013/05/11 03:02:17 | 000,000,000 | ---D | M] (DownloadHelper) -- E:\Users\r.newson\AppData\Roaming\Mozilla\Firefox\Profiles\5vviftf1.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013/05/11 02:56:27 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2013/04/10 02:57:39 | 000,263,064 | ---- | M] (Mozilla Foundation) -- E:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/10 04:18:46 | 000,001,392 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013/04/10 04:18:46 | 000,002,465 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/10 04:18:46 | 000,001,153 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013/04/10 04:18:46 | 000,006,805 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013/04/10 04:18:46 | 000,001,178 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013/04/10 04:18:46 | 000,001,105 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012/07/24 02:53:58 | 000,442,957 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1        autodiscover.tcom-it.de
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        ???,????,????cr67com,????,??????,?????112scg,tt???8bc8,?????
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        1001namen.com - Informationen zum Thema 1001namen.
O1 - Hosts: 127.0.0.1        ²©²Êͨ,²©²ÊÍø,½ð±¦²©188,²©²ÊͨÆÀ¼¶,°Ù¼ÒÀÖ,°ÂÃî°Ù¼ÒÀÖ
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        10sek.com - Informationen zum Thema 10sek.
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 15216 more lines...
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - E:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - E:\Program Files\Google\Chrome\Application\26.0.1410.64\npchrome_frame.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\c.proebsting_ON_E\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] E:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] E:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ControlCenter3] E:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DBRMTray] E:\dell\DBRM\Reminder\DbrmTrayicon.exe (Microsoft)
O4 - HKLM..\Run: [Dell Webcam Central] E:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] E:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [FreeFallProtection] E:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4 - HKLM..\Run: [IJNetworkScanUtility] E:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [MSC] E:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OfficeScanNT Monitor] E:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] E:\Program Files\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickSet] E:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [RemoteControl9] E:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] E:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\c.proebsting_ON_E..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\r.newson_ON_E..\Run: [DisplaySwitch] E:\ProgramData\DisplaySwitch.exe (Hilgraeve, Inc.)
O4 - HKU\r.newson_ON_E..\Run: [RESTART_STICKY_NOTES] E:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [DBRMTray] E:\dell\DBRM\Reminder\TrayApp.exe (Microsoft)
O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NTP_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\postgres_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: E:\Users\c.proebsting\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: An OneNote s&enden - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - E:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - E:\Program Files\Google\Chrome\Application\26.0.1410.64\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - E:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/05/23 11:49:59 | 000,000,000 | -HSD | C] -- E:\RECYCLER
[2013/05/22 13:57:41 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Client-Server Security Agent
[2013/05/22 10:35:13 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Byxew
[2013/05/22 10:23:00 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Liocgi
[2013/05/22 10:23:00 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Eqyx
[2013/05/22 10:22:04 | 000,095,744 | ---- | C] (Hilgraeve, Inc.) -- E:\ProgramData\DisplaySwitch.exe
[2013/05/16 01:09:29 | 000,420,864 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\vbscript.dll
[2013/05/16 01:09:28 | 000,065,024 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jsproxy.dll
[2013/05/16 01:09:27 | 000,607,744 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeeds.dll
[2013/05/16 01:09:27 | 000,176,640 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll
[2013/05/16 01:09:27 | 000,142,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieUnatt.exe
[2013/05/16 01:09:26 | 000,717,824 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript.dll
[2013/05/16 01:09:25 | 001,800,704 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript9.dll
[2013/05/16 01:09:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\url.dll
[2013/05/16 01:09:24 | 001,427,968 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\inetcpl.cpl
[2013/05/16 01:04:29 | 002,382,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb
[2013/05/15 01:26:17 | 000,040,960 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\wwanprotdim.dll
[2013/05/15 01:26:15 | 002,347,520 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\win32k.sys
[2013/05/15 01:19:58 | 000,218,984 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\dxgmms1.sys
[2013/05/15 01:19:54 | 001,796,096 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\authui.dll
[2013/05/15 01:19:54 | 000,101,720 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\consent.exe
[2013/05/11 03:06:17 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\{F3523132-0D6F-41A1-9CA2-F5C21E09DA5B}
[2013/05/11 03:06:17 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\{9FC7F15F-A688-4CE7-AE25-7D5914442510}
[2013/05/11 03:00:18 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\Macromedia
[2013/05/11 02:57:39 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Mozilla
[2013/05/11 02:57:39 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\Mozilla
[2011/02/10 14:18:24 | 000,004,096 | ---- | C] ( ) -- E:\Windows\System32\IGFXDEVLib.dll
[1 E:\Users\r.newson\Desktop\*.tmp files -> E:\Users\r.newson\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013/05/22 18:44:19 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat
[2013/05/22 18:42:28 | 000,001,098 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/22 18:42:13 | 2358,259,712 | -HS- | M] () -- E:\hiberfil.sys
[2013/05/22 16:25:00 | 000,000,506 | ---- | M] () -- E:\Windows\tasks\SystemToolsDailyTest.job
[2013/05/22 15:10:00 | 000,000,564 | ---- | M] () -- E:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/05/22 14:32:10 | 000,001,102 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/22 14:02:24 | 000,014,240 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/22 14:02:24 | 000,014,240 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/22 14:02:00 | 000,000,884 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/22 14:01:22 | 000,733,666 | ---- | M] () -- E:\Windows\System32\perfh007.dat
[2013/05/22 14:01:22 | 000,693,808 | ---- | M] () -- E:\Windows\System32\perfh009.dat
[2013/05/22 14:01:22 | 000,159,292 | ---- | M] () -- E:\Windows\System32\perfc007.dat
[2013/05/22 14:01:22 | 000,134,936 | ---- | M] () -- E:\Windows\System32\perfc009.dat
[2013/05/22 13:57:41 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Client-Server Security Agent
[2013/05/22 13:57:28 | 000,000,031 | ---- | M] () -- E:\tmuninst.ini
[2013/05/22 10:32:26 | 002,250,054 | ---- | M] () -- E:\ProgramData\1.bmp
[2013/05/22 10:32:12 | 000,465,655 | ---- | M] () -- E:\ProgramData\1.jpg
[2013/05/22 10:22:01 | 000,095,744 | ---- | M] (Hilgraeve, Inc.) -- E:\ProgramData\DisplaySwitch.exe
[2013/05/22 02:52:18 | 000,139,873 | ---- | M] () -- E:\Users\r.newson\Desktop\NF BHV1 freie bestande.pdf
[2013/05/18 01:06:05 | 000,492,184 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT
[2013/05/16 16:35:44 | 000,326,569 | ---- | M] () -- E:\Users\r.newson\Desktop\Carnival RZG.pdf
[2013/05/16 01:40:28 | 000,001,062 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2013/05/16 01:04:43 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerApp.exe
[2013/05/16 01:04:43 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/05/11 02:56:42 | 000,001,119 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/05/06 15:38:35 | 009,742,839 | ---- | M] () -- E:\Users\r.newson\Desktop\87nkIIlmUh7NiubCsfcT6e2Sw1367831810.pdf
[2013/05/05 15:12:55 | 002,382,848 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb
[2013/05/02 11:28:50 | 000,238,872 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\MpSigStub.exe
[2013/04/30 02:06:35 | 000,082,640 | ---- | M] () -- E:\Users\r.newson\Desktop\IB CAN 000102327659 _Picolo.pdf
[2013/04/30 02:06:06 | 000,725,866 | ---- | M] () -- E:\Users\r.newson\Desktop\karsten Heesch.pdf
[1 E:\Users\r.newson\Desktop\*.tmp files -> E:\Users\r.newson\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013/05/22 10:32:26 | 002,250,054 | ---- | C] () -- E:\ProgramData\1.bmp
[2013/05/22 10:32:07 | 000,465,655 | ---- | C] () -- E:\ProgramData\1.jpg
[2013/05/22 02:52:16 | 000,139,873 | ---- | C] () -- E:\Users\r.newson\Desktop\NF BHV1 freie bestande.pdf
[2013/05/16 16:35:43 | 000,326,569 | ---- | C] () -- E:\Users\r.newson\Desktop\Carnival RZG.pdf
[2013/05/16 15:57:49 | 000,165,239 | R--- | C] () -- E:\Users\r.newson\Desktop\facebook_-1277089541.jpg
[2013/05/06 15:38:33 | 009,742,839 | ---- | C] () -- E:\Users\r.newson\Desktop\87nkIIlmUh7NiubCsfcT6e2Sw1367831810.pdf
[2013/04/30 02:06:35 | 000,082,640 | ---- | C] () -- E:\Users\r.newson\Desktop\IB CAN 000102327659 _Picolo.pdf
[2013/04/30 02:06:05 | 000,725,866 | ---- | C] () -- E:\Users\r.newson\Desktop\karsten Heesch.pdf
[2012/07/08 04:49:11 | 000,000,848 | ---- | C] () -- E:\Windows\Brpfx04a.ini
[2012/07/08 04:49:11 | 000,000,163 | ---- | C] () -- E:\Windows\brpcfx.ini
[2012/07/08 04:48:55 | 000,106,496 | ---- | C] () -- E:\Windows\System32\BrMuSNMP.dll
[2012/07/08 04:48:55 | 000,000,066 | ---- | C] () -- E:\Windows\Brfaxrx.ini
[2012/07/08 04:48:55 | 000,000,000 | ---- | C] () -- E:\Windows\brdfxspd.dat
[2012/06/21 03:24:45 | 000,000,432 | ---- | C] () -- E:\Windows\BRWMARK.INI
[2012/06/21 03:24:45 | 000,000,065 | ---- | C] () -- E:\Windows\System32\BD7320.DAT
[2012/06/18 11:38:22 | 000,000,096 | ---- | C] () -- E:\Users\r.newson\AppData\Local\fusioncache.dat
[2011/08/02 08:40:58 | 000,252,928 | ---- | C] () -- E:\Windows\System32\DShowRdpFilter.dll
[2011/06/10 00:34:52 | 000,080,416 | ---- | C] () -- E:\Windows\System32\RtNicProp32.dll
[2011/04/23 08:22:01 | 000,000,100 | ---- | C] () -- E:\Users\c.proebsting\AppData\Local\fusioncache.dat
[2011/02/10 14:18:25 | 000,870,560 | ---- | C] () -- E:\Windows\System32\igkrng575.bin
[2011/02/10 14:18:25 | 000,208,896 | ---- | C] () -- E:\Windows\System32\iglhsip32.dll
[2011/02/10 14:18:25 | 000,143,360 | ---- | C] () -- E:\Windows\System32\iglhcp32.dll
[2011/02/10 14:18:24 | 000,104,796 | ---- | C] () -- E:\Windows\System32\igfcg575m.bin
[2011/02/10 14:18:22 | 000,127,868 | ---- | C] () -- E:\Windows\System32\igcompkrng575.bin
[2011/02/10 14:18:22 | 000,000,151 | ---- | C] () -- E:\Windows\System32\GfxUI.exe.config
[2011/02/10 12:48:01 | 000,006,656 | ---- | C] () -- E:\Windows\System32\bcmwlrc.dll
[2009/07/14 04:47:43 | 000,733,666 | ---- | C] () -- E:\Windows\System32\perfh007.dat
[2009/07/14 04:47:43 | 000,295,922 | ---- | C] () -- E:\Windows\System32\perfi007.dat
[2009/07/14 04:47:43 | 000,159,292 | ---- | C] () -- E:\Windows\System32\perfc007.dat
[2009/07/14 04:47:43 | 000,038,104 | ---- | C] () -- E:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,492,184 | ---- | C] () -- E:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,693,808 | ---- | C] () -- E:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- E:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,134,936 | ---- | C] () -- E:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- E:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- E:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- E:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- E:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\System32\mlang.dat
[2005/12/21 11:57:36 | 000,139,264 | ---- | C] () -- E:\Windows\System32\nsldap32v50.dll
[2005/12/21 11:57:04 | 000,024,576 | ---- | C] () -- E:\Windows\System32\nsldappr32v50.dll
[2005/12/21 11:54:34 | 000,040,960 | ---- | C] () -- E:\Windows\System32\nsldapssl32v50.dll
[2005/01/17 01:10:16 | 000,045,056 | ---- | C] () -- E:\Windows\System32\BRTCPCON.DLL
[2004/08/09 01:00:42 | 000,000,114 | ---- | C] () -- E:\Windows\System32\BRLMW03A.INI
 
========== LOP Check ==========
 
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2012/02/02 07:32:24 | 000,000,000 | ---D | M] -- E:\ProgramData\Ask
[2011/03/19 06:52:00 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonBJ
[2011/09/16 03:56:39 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonIJMyPrinter
[2013/05/06 05:49:39 | 000,000,000 | ---D | M] -- E:\ProgramData\CanonIJPLM
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2012/11/08 04:20:44 | 000,000,000 | ---D | M] -- E:\ProgramData\LSMilchkuh
[2011/12/19 05:50:06 | 000,000,000 | ---D | M] -- E:\ProgramData\PCDr
[2011/02/10 12:58:01 | 000,000,000 | ---D | M] -- E:\ProgramData\PhotoShow Shared Assets
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2011/02/10 12:51:16 | 000,000,000 | ---D | M] -- E:\ProgramData\Temp
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2011/02/10 12:59:21 | 000,000,000 | ---D | M] -- E:\ProgramData\Uninstall
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2013/05/22 15:10:00 | 000,000,564 | ---- | M] () -- E:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2013/03/18 10:16:35 | 000,032,632 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
[2013/05/22 16:25:00 | 000,000,506 | ---- | M] () -- E:\Windows\Tasks\SystemToolsDailyTest.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2012/06/18 11:27:22 | 000,000,000 | -HSD | M] -- E:\$Recycle.Bin
[2011/02/10 12:43:14 | 000,000,000 | ---D | M] -- E:\Apps
[2013/03/18 10:06:32 | 000,000,000 | ---D | M] -- E:\backup
[2013/05/16 01:10:25 | 000,000,000 | -HSD | M] -- E:\Config.Msi
[2011/03/01 04:50:30 | 000,000,000 | ---D | M] -- E:\dell
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\Documents and Settings
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\Dokumente und Einstellungen
[2011/02/10 14:18:51 | 000,000,000 | ---D | M] -- E:\Drivers
[2011/02/10 05:37:10 | 000,000,000 | ---D | M] -- E:\Intel
[2012/06/22 02:59:05 | 000,000,000 | ---D | M] -- E:\Logs
[2012/03/26 08:13:31 | 000,000,000 | RH-D | M] -- E:\MSOCache
[2012/12/17 16:26:37 | 000,000,000 | ---D | M] -- E:\NMP_Backup
[2009/07/13 22:37:05 | 000,000,000 | ---D | M] -- E:\PerfLogs
[2013/05/14 09:27:56 | 000,000,000 | R--D | M] -- E:\Program Files
[2013/05/22 10:32:26 | 000,000,000 | -H-D | M] -- E:\ProgramData
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\Programme
[2013/05/23 11:49:59 | 000,000,000 | -HSD | M] -- E:\RECYCLER
[2013/03/18 10:11:19 | 000,000,000 | ---D | M] -- E:\Ruby193
[2013/03/18 10:08:34 | 000,000,000 | ---D | M] -- E:\SilentHerdsman
[2013/03/18 10:11:53 | 000,000,000 | ---D | M] -- E:\SilentHerdsmanInstaller-2.7.7.0
[2013/05/20 06:31:06 | 000,000,000 | -HSD | M] -- E:\System Volume Information
[2013/03/18 10:11:50 | 000,000,000 | R--D | M] -- E:\Users
[2011/03/04 03:15:47 | 000,000,000 | ---D | M] -- E:\VIT
[2013/02/27 22:06:03 | 000,000,000 | ---D | M] -- E:\Windows
 
< %PROGRAMFILES%\*.exe >
 
Invalid Environment Variable: %LOCALAPPDATA%\*.exe
 
< %systemroot%\*. /mp /s >
 
 
< MD5 for: AGP440.SYS  >
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\System32\drivers\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\System32\drivers\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- E:\Windows\System32\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- E:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2011/02/26 01:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- E:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Drivers\storage\R271949\f6flpy-x86\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\drivers\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_e8a55be84650e755\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_c766b54545e4141f\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\System32\drivers\iaStorV.sys
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011/03/11 01:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2010/11/20 08:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- E:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 08:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010/11/20 08:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- E:\Windows\System32\netlogon.dll
[2010/11/20 08:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- E:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\System32\drivers\nvstor.sys
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011/03/11 01:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2010/11/20 08:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- E:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 08:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010/11/20 08:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- E:\Windows\System32\scecli.dll
[2010/11/20 08:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- E:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010/11/20 08:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- E:\Windows\System32\user32.dll
[2010/11/20 08:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- E:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- E:\Windows\System32\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- E:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- E:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- E:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- E:\Windows\System32\drivers\ws2ifsl.sys
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- E:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2010/11/20 08:19:02 | 000,828,928 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- E:\Windows\system32\fontext.dll
[2013/02/27 00:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- E:\Windows\system32\shell32.dll
 
Invalid Environment Variable: %USERPROFILE%\*.*
 
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.exe
 
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.dll
 
Invalid Environment Variable: %USERPROFILE%\Application Data\*.exe
< End of report >

--- --- ---

markusg 23.05.2013 20:33

auf deinem zweiten pc gehe auf start, programme zubehör editor, kopiere dort
rein:
Code:

:OTL
[2013/05/22 10:35:13 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Byxew
[2013/05/22 10:23:00 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Liocgi
[2013/05/22 10:22:04 | 000,095,744 | ---- | C] (Hilgraeve, Inc.) -- E:\ProgramData\DisplaySwitch.exe
O4 - HKU\r.newson_ON_E..\Run: [DisplaySwitch] E:\ProgramData\DisplaySwitch.exe (Hilgraeve, Inc.)
[2013/05/22 10:32:26 | 002,250,054 | ---- | M] () -- E:\ProgramData\1.bmp
[2013/05/22 10:32:12 | 000,465,655 | ---- | M] () -- E:\ProgramData\1.jpg
:Files
:Commands
[EMPTYFLASH]
[emptytemp]



dieses speicherst du auf nem usb stick als fix.txt
nutze nun wieder OTLPENet.exe (starte also von der erstellten cd) und hake alles an, wie es bereits im post zu OTLPENet.exe beschrieben ist.
• Klicke nun bitte auf den Fix Button.
es sollte nun eine meldung ähnlich dieser: "load fix from file" erscheinen, lade also die fix.txt von deinem stick.
wenn dies nicht funktioniert, bitte den fix manuell eintragen.
dann klicke erneut den fix buton. pc startet evtl. neu
wenn ja, nimm die cd aus dem laufwerk, Modus im Bios umstellen. windows sollte nun normal starten und die otl.txt öffnen,
log posten bitte.


falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

Hinweis: Die Datei bitte wie in der Anleitung zum UpChannel angegeben auch da hochladen. Bitte NICHT die ZIP-Datei hier als Anhang
in den Thread posten!




Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + E Taste.
  • Öffne dein Systemlaufwerk ( meistens C: )
  • Suche nun
    folgenden Ordner: _OTL und öffne diesen.
  • Mache einen Rechtsklick auf den Ordner Movedfiles --> Senden an --> Zip-Komprimierter Ordner

  • Dies wird eine Movedfiles.zip Datei in _OTL erstellen
  • Lade diese bitte in unseren Uploadchannel
    hoch. ( Durchsuchen --> C:\_OTL\Movedfiles.zip )
Teile mir mit ob der Upload problemlos geklappt hat. Danke im voraus :)

Newson 23.05.2013 21:45

Es scheint zu funktioniern. Hier ist die otl.txt beriecht. Ich lade gleich die reste über die Upchannel. An Desktop sind viele unbekannte Dokumente. Soll ich die auch als ZIP einpacken und über Upchannel dir schicken, oder einfach gleich losen?OTL Logfile:
Code:

OTL logfile created on: 5/23/2013 6:36:32 PM - Run
OTLPE by OldTimer - Version 3.1.48.0    Folder = X:\Programs\OTLPE
Windows 7 Home Premium Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = E: | %SystemRoot% = E:\Windows | %ProgramFiles% = E:\Program Files
Drive C: | 12.15 Gb Total Space | 6.09 Gb Free Space | 50.11% Space Free | Partition Type: NTFS
Drive D: | 130.89 Gb Total Space | 127.98 Gb Free Space | 97.78% Space Free | Partition Type: NTFS
Drive E: | 155.00 Gb Total Space | 99.78 Gb Free Space | 64.37% Space Free | Partition Type: NTFS
Drive F: | 985.00 Mb Total Space | 585.39 Mb Free Space | 59.43% Space Free | Partition Type: FAT
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
 
========== Win32 Services (SafeList) ==========
 
SRV - [2013/05/16 01:04:44 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- E:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/23 03:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto] -- E:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2013/04/10 02:56:49 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand] -- E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/27 06:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/01/27 06:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/12/18 15:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto] -- E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/10/02 07:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto] -- E:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/06/07 13:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto] -- E:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/12/05 11:44:10 | 000,098,304 | ---- | M] (Multiplan Consultants Limited) [Auto] -- E:\SilentHerdsman\services\JavaService.exe -- (SilentHerdsman)
SRV - [2011/12/05 11:44:10 | 000,098,304 | ---- | M] (Multiplan Consultants Limited) [Auto] -- E:\SilentHerdsman\services\JavaService.exe -- (ETSWatchdog)
SRV - [2011/05/15 06:29:59 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/02/10 12:47:41 | 000,040,960 | ---- | M] (Dell Inc.) [Auto] -- E:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV - [2010/10/26 04:22:10 | 000,245,648 | ---- | M] () [Auto] -- E:\SilentHerdsman\resources\ntpServer\bin\ntpd.exe -- (NTP)
SRV - [2010/09/04 03:15:22 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto] -- E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010/09/04 03:14:26 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand] -- E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010/07/05 15:37:32 | 000,045,056 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe -- (svcGenericHost)
SRV - [2010/06/22 15:27:38 | 001,358,160 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe -- (tmlisten)
SRV - [2010/06/22 15:18:46 | 001,323,912 | ---- | M] (Trend Micro Inc.) [Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe -- (ntrtscan)
SRV - [2010/05/14 08:11:08 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) [Auto] -- E:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe -- (postgresql-8.4)
SRV - [2010/04/07 08:35:04 | 000,229,458 | ---- | M] (IDT, Inc.) [Auto] -- E:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\stacsv.exe -- (STacSV)
SRV - [2009/12/01 13:13:12 | 000,345,352 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
SRV - [2009/11/04 17:45:46 | 002,320,920 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009/11/04 17:45:44 | 000,268,824 | ---- | M] (Intel Corporation) [Auto] -- E:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009/10/20 11:11:58 | 000,595,232 | ---- | M] (Broadcom Corporation.) [Auto] -- E:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009/09/08 08:12:51 | 000,116,104 | ---- | M] () [Auto] -- E:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2009/07/15 19:39:06 | 000,497,008 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe -- (TmPfw)
SRV - [2009/07/15 19:37:18 | 000,689,416 | ---- | M] (Trend Micro Inc.) [On_Demand] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe -- (TmProxy)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- E:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/03/03 06:43:08 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) [Auto] -- E:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\AEstSrv.exe -- (AESTFilters)
SRV - [2009/01/26 09:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto] -- E:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2007/05/31 10:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 10:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto] -- E:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand] --  -- (ALSysIO)
DRV - [2013/01/20 10:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto] -- E:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/05/11 01:34:06 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand] -- E:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
DRV - [2011/02/10 12:47:40 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/09/29 12:38:00 | 000,043,888 | ---- | M] (ST Microelectronics) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/08/30 23:15:56 | 000,247,808 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/08/20 13:04:38 | 000,017,648 | ---- | M] (ST Microelectronics) [Kernel | Boot] -- E:\Windows\System32\drivers\stdcfltn.sys -- (stdcfltn)
DRV - [2010/08/12 12:50:20 | 000,146,528 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2010/07/19 13:03:10 | 000,059,472 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2010/07/19 13:03:00 | 000,051,792 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2010/07/19 13:02:54 | 000,163,408 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Windows\System32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2010/05/10 18:03:32 | 000,230,928 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\TmXPFlt.sys -- (TmFilter)
DRV - [2010/05/10 18:02:44 | 000,036,368 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\tmpreflt.sys -- (TmPreFilter)
DRV - [2010/05/10 17:41:54 | 001,322,808 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Program Files\Trend Micro\Client Server Security Agent\vsapiNT.sys -- (VSApiNt)
DRV - [2010/04/07 08:35:04 | 000,423,936 | ---- | M] (IDT, Inc.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2010/02/27 11:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2009/09/17 16:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\HECI.sys -- (HECI) Intel(R)
DRV - [2009/08/10 15:06:08 | 000,171,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/07/15 19:38:14 | 000,283,152 | ---- | M] (Trend Micro Inc.) [Kernel | Auto] -- E:\Windows\System32\drivers\tmwfp.sys -- (tmwfp)
DRV - [2009/07/15 19:38:04 | 000,146,448 | ---- | M] (Trend Micro Inc.) [Kernel | System] -- E:\Windows\System32\drivers\tmlwf.sys -- (tmlwf)
DRV - [2009/07/15 19:37:40 | 000,089,872 | ---- | M] (Trend Micro Inc.) [Kernel | System] -- E:\Windows\System32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2009/07/13 20:56:07 | 000,265,088 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BrSerIb.sys -- (BrSerIb) Brother MFC Serial Interface Driver(WDM)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- E:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 18:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\BrUsbSIb.sys -- (BrUsbSIb) Brother MFC Serial USB Driver(WDM)
DRV - [2009/05/28 12:48:20 | 000,134,144 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand] -- E:\Windows\System32\drivers\CtAudDrv.sys -- (CtAudDrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USSMB/8
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\c.proebsting_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
 
 
IE - HKU\r.newson_ON_E\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USSMB/8
IE - HKU\r.newson_ON_E\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.semex-deutschland.de/
IE - HKU\r.newson_ON_E\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\Windows\System32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: E:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: E:\Windows\System32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE:  File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: E:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: E:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: E:\Program Files\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: E:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: E:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: E:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: E:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: c:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\FirefoxExtension [2012/04/19 06:23:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/11 02:56:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
 
[2013/05/11 02:57:46 | 000,000,000 | ---D | M] (No name found) -- E:\Users\r.newson\AppData\Roaming\Mozilla\Extensions
[2013/05/11 03:02:17 | 000,000,000 | ---D | M] (No name found) -- E:\Users\r.newson\AppData\Roaming\Mozilla\Firefox\Profiles\5vviftf1.default\extensions
[2013/05/11 03:02:17 | 000,000,000 | ---D | M] (DownloadHelper) -- E:\Users\r.newson\AppData\Roaming\Mozilla\Firefox\Profiles\5vviftf1.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2013/05/11 02:56:27 | 000,000,000 | ---D | M] (No name found) -- E:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2013/04/10 02:57:39 | 000,263,064 | ---- | M] (Mozilla Foundation) -- E:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/10 04:18:46 | 000,001,392 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2013/04/10 04:18:46 | 000,002,465 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/10 04:18:46 | 000,001,153 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2013/04/10 04:18:46 | 000,006,805 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2013/04/10 04:18:46 | 000,001,178 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2013/04/10 04:18:46 | 000,001,105 | ---- | M] () -- E:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2012/07/24 02:53:58 | 000,442,957 | ---- | M]) - E:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1        autodiscover.tcom-it.de
O1 - Hosts: 127.0.0.1        www.007guard.com
O1 - Hosts: 127.0.0.1        007guard.com
O1 - Hosts: 127.0.0.1        008i.com
O1 - Hosts: 127.0.0.1        www.008k.com
O1 - Hosts: 127.0.0.1        008k.com
O1 - Hosts: 127.0.0.1        www.00hq.com
O1 - Hosts: 127.0.0.1        00hq.com
O1 - Hosts: 127.0.0.1        010402.com
O1 - Hosts: 127.0.0.1        www.032439.com
O1 - Hosts: 127.0.0.1        032439.com
O1 - Hosts: 127.0.0.1        www.0scan.com
O1 - Hosts: 127.0.0.1        0scan.com
O1 - Hosts: 127.0.0.1        1000gratisproben.com
O1 - Hosts: 127.0.0.1        www.1000gratisproben.com
O1 - Hosts: 127.0.0.1        1001namen.com
O1 - Hosts: 127.0.0.1        www.1001namen.com
O1 - Hosts: 127.0.0.1        www.100888290cs.com
O1 - Hosts: 127.0.0.1        100888290cs.com
O1 - Hosts: 127.0.0.1        100sexlinks.com
O1 - Hosts: 127.0.0.1        www.100sexlinks.com
O1 - Hosts: 127.0.0.1        www.10sek.com
O1 - Hosts: 127.0.0.1        10sek.com
O1 - Hosts: 127.0.0.1        1-2005-search.com
O1 - Hosts: 127.0.0.1        www.1-2005-search.com
O1 - Hosts: 15216 more lines...
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - E:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - E:\Program Files\Google\Chrome\Application\26.0.1410.64\npchrome_frame.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\c.proebsting_ON_E\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - E:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] E:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] E:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ControlCenter3] E:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DBRMTray] E:\dell\DBRM\Reminder\DbrmTrayicon.exe (Microsoft)
O4 - HKLM..\Run: [Dell Webcam Central] E:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Desktop Disc Tool] E:\Program Files\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [FreeFallProtection] E:\Program Files\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4 - HKLM..\Run: [IJNetworkScanUtility] E:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [MSC] E:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OfficeScanNT Monitor] E:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] E:\Program Files\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickSet] E:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [RemoteControl9] E:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] E:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] E:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKU\c.proebsting_ON_E..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\r.newson_ON_E..\Run: [DisplaySwitch] E:\ProgramData\DisplaySwitch.exe (Hilgraeve, Inc.)
O4 - HKU\r.newson_ON_E..\Run: [RESTART_STICKY_NOTES] E:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [DBRMTray] E:\dell\DBRM\Reminder\TrayApp.exe (Microsoft)
O4 - HKU\LocalService_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NTP_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\postgres_ON_E..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: E:\Users\c.proebsting\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: An OneNote s&enden - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - E:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - E:\Program Files\Google\Chrome\Application\26.0.1410.64\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - E:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - E:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - E:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias -  File not found
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013/05/23 11:49:59 | 000,000,000 | -HSD | C] -- E:\RECYCLER
[2013/05/22 13:57:41 | 000,000,000 | ---D | C] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Client-Server Security Agent
[2013/05/22 10:35:13 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Byxew
[2013/05/22 10:23:00 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Liocgi
[2013/05/22 10:23:00 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Eqyx
[2013/05/22 10:22:04 | 000,095,744 | ---- | C] (Hilgraeve, Inc.) -- E:\ProgramData\DisplaySwitch.exe
[2013/05/16 01:09:29 | 000,420,864 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\vbscript.dll
[2013/05/16 01:09:28 | 000,065,024 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jsproxy.dll
[2013/05/16 01:09:27 | 000,607,744 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\msfeeds.dll
[2013/05/16 01:09:27 | 000,176,640 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieui.dll
[2013/05/16 01:09:27 | 000,142,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\ieUnatt.exe
[2013/05/16 01:09:26 | 000,717,824 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript.dll
[2013/05/16 01:09:25 | 001,800,704 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\jscript9.dll
[2013/05/16 01:09:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\url.dll
[2013/05/16 01:09:24 | 001,427,968 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\inetcpl.cpl
[2013/05/16 01:04:29 | 002,382,848 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb
[2013/05/15 01:26:17 | 000,040,960 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\wwanprotdim.dll
[2013/05/15 01:26:15 | 002,347,520 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\win32k.sys
[2013/05/15 01:19:58 | 000,218,984 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\drivers\dxgmms1.sys
[2013/05/15 01:19:54 | 001,796,096 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\authui.dll
[2013/05/15 01:19:54 | 000,101,720 | ---- | C] (Microsoft Corporation) -- E:\Windows\System32\consent.exe
[2013/05/11 03:06:17 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\{F3523132-0D6F-41A1-9CA2-F5C21E09DA5B}
[2013/05/11 03:06:17 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\{9FC7F15F-A688-4CE7-AE25-7D5914442510}
[2013/05/11 03:00:18 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\Macromedia
[2013/05/11 02:57:39 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Roaming\Mozilla
[2013/05/11 02:57:39 | 000,000,000 | ---D | C] -- E:\Users\r.newson\AppData\Local\Mozilla
[2011/02/10 14:18:24 | 000,004,096 | ---- | C] ( ) -- E:\Windows\System32\IGFXDEVLib.dll
[1 E:\Users\r.newson\Desktop\*.tmp files -> E:\Users\r.newson\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2013/05/22 18:44:19 | 000,067,584 | --S- | M] () -- E:\Windows\bootstat.dat
[2013/05/22 18:42:28 | 000,001,098 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/22 18:42:13 | 2358,259,712 | -HS- | M] () -- E:\hiberfil.sys
[2013/05/22 16:25:00 | 000,000,506 | ---- | M] () -- E:\Windows\tasks\SystemToolsDailyTest.job
[2013/05/22 15:10:00 | 000,000,564 | ---- | M] () -- E:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2013/05/22 14:32:10 | 000,001,102 | ---- | M] () -- E:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/22 14:02:24 | 000,014,240 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/22 14:02:24 | 000,014,240 | -H-- | M] () -- E:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/22 14:02:00 | 000,000,884 | ---- | M] () -- E:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/22 14:01:22 | 000,733,666 | ---- | M] () -- E:\Windows\System32\perfh007.dat
[2013/05/22 14:01:22 | 000,693,808 | ---- | M] () -- E:\Windows\System32\perfh009.dat
[2013/05/22 14:01:22 | 000,159,292 | ---- | M] () -- E:\Windows\System32\perfc007.dat
[2013/05/22 14:01:22 | 000,134,936 | ---- | M] () -- E:\Windows\System32\perfc009.dat
[2013/05/22 13:57:41 | 000,000,000 | ---D | M] -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Client-Server Security Agent
[2013/05/22 13:57:28 | 000,000,031 | ---- | M] () -- E:\tmuninst.ini
[2013/05/22 10:32:26 | 002,250,054 | ---- | M] () -- E:\ProgramData\1.bmp
[2013/05/22 10:32:12 | 000,465,655 | ---- | M] () -- E:\ProgramData\1.jpg
[2013/05/22 10:22:01 | 000,095,744 | ---- | M] (Hilgraeve, Inc.) -- E:\ProgramData\DisplaySwitch.exe
[2013/05/22 02:52:18 | 000,139,873 | ---- | M] () -- E:\Users\r.newson\Desktop\NF BHV1 freie bestande.pdf
[2013/05/18 01:06:05 | 000,492,184 | ---- | M] () -- E:\Windows\System32\FNTCACHE.DAT
[2013/05/16 16:35:44 | 000,326,569 | ---- | M] () -- E:\Users\r.newson\Desktop\Carnival RZG.pdf
[2013/05/16 01:40:28 | 000,001,062 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2013/05/16 01:04:43 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerApp.exe
[2013/05/16 01:04:43 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- E:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/05/11 02:56:42 | 000,001,119 | ---- | M] () -- E:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/05/06 15:38:35 | 009,742,839 | ---- | M] () -- E:\Users\r.newson\Desktop\87nkIIlmUh7NiubCsfcT6e2Sw1367831810.pdf
[2013/05/05 15:12:55 | 002,382,848 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\mshtml.tlb
[2013/05/02 11:28:50 | 000,238,872 | ---- | M] (Microsoft Corporation) -- E:\Windows\System32\MpSigStub.exe
[2013/04/30 02:06:35 | 000,082,640 | ---- | M] () -- E:\Users\r.newson\Desktop\IB CAN 000102327659 _Picolo.pdf
[2013/04/30 02:06:06 | 000,725,866 | ---- | M] () -- E:\Users\r.newson\Desktop\karsten Heesch.pdf
[1 E:\Users\r.newson\Desktop\*.tmp files -> E:\Users\r.newson\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2013/05/22 10:32:26 | 002,250,054 | ---- | C] () -- E:\ProgramData\1.bmp
[2013/05/22 10:32:07 | 000,465,655 | ---- | C] () -- E:\ProgramData\1.jpg
[2013/05/22 02:52:16 | 000,139,873 | ---- | C] () -- E:\Users\r.newson\Desktop\NF BHV1 freie bestande.pdf
[2013/05/16 16:35:43 | 000,326,569 | ---- | C] () -- E:\Users\r.newson\Desktop\Carnival RZG.pdf
[2013/05/16 15:57:49 | 000,165,239 | R--- | C] () -- E:\Users\r.newson\Desktop\facebook_-1277089541.jpg
[2013/05/06 15:38:33 | 009,742,839 | ---- | C] () -- E:\Users\r.newson\Desktop\87nkIIlmUh7NiubCsfcT6e2Sw1367831810.pdf
[2013/04/30 02:06:35 | 000,082,640 | ---- | C] () -- E:\Users\r.newson\Desktop\IB CAN 000102327659 _Picolo.pdf
[2013/04/30 02:06:05 | 000,725,866 | ---- | C] () -- E:\Users\r.newson\Desktop\karsten Heesch.pdf
[2012/07/08 04:49:11 | 000,000,848 | ---- | C] () -- E:\Windows\Brpfx04a.ini
[2012/07/08 04:49:11 | 000,000,163 | ---- | C] () -- E:\Windows\brpcfx.ini
[2012/07/08 04:48:55 | 000,106,496 | ---- | C] () -- E:\Windows\System32\BrMuSNMP.dll
[2012/07/08 04:48:55 | 000,000,066 | ---- | C] () -- E:\Windows\Brfaxrx.ini
[2012/07/08 04:48:55 | 000,000,000 | ---- | C] () -- E:\Windows\brdfxspd.dat
[2012/06/21 03:24:45 | 000,000,432 | ---- | C] () -- E:\Windows\BRWMARK.INI
[2012/06/21 03:24:45 | 000,000,065 | ---- | C] () -- E:\Windows\System32\BD7320.DAT
[2012/06/18 11:38:22 | 000,000,096 | ---- | C] () -- E:\Users\r.newson\AppData\Local\fusioncache.dat
[2011/08/02 08:40:58 | 000,252,928 | ---- | C] () -- E:\Windows\System32\DShowRdpFilter.dll
[2011/06/10 00:34:52 | 000,080,416 | ---- | C] () -- E:\Windows\System32\RtNicProp32.dll
[2011/04/23 08:22:01 | 000,000,100 | ---- | C] () -- E:\Users\c.proebsting\AppData\Local\fusioncache.dat
[2011/02/10 14:18:25 | 000,870,560 | ---- | C] () -- E:\Windows\System32\igkrng575.bin
[2011/02/10 14:18:25 | 000,208,896 | ---- | C] () -- E:\Windows\System32\iglhsip32.dll
[2011/02/10 14:18:25 | 000,143,360 | ---- | C] () -- E:\Windows\System32\iglhcp32.dll
[2011/02/10 14:18:24 | 000,104,796 | ---- | C] () -- E:\Windows\System32\igfcg575m.bin
[2011/02/10 14:18:22 | 000,127,868 | ---- | C] () -- E:\Windows\System32\igcompkrng575.bin
[2011/02/10 14:18:22 | 000,000,151 | ---- | C] () -- E:\Windows\System32\GfxUI.exe.config
[2011/02/10 12:48:01 | 000,006,656 | ---- | C] () -- E:\Windows\System32\bcmwlrc.dll
[2009/07/14 04:47:43 | 000,733,666 | ---- | C] () -- E:\Windows\System32\perfh007.dat
[2009/07/14 04:47:43 | 000,295,922 | ---- | C] () -- E:\Windows\System32\perfi007.dat
[2009/07/14 04:47:43 | 000,159,292 | ---- | C] () -- E:\Windows\System32\perfc007.dat
[2009/07/14 04:47:43 | 000,038,104 | ---- | C] () -- E:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- E:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,492,184 | ---- | C] () -- E:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,693,808 | ---- | C] () -- E:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- E:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,134,936 | ---- | C] () -- E:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- E:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- E:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- E:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- E:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- E:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- E:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- E:\Windows\System32\mlang.dat
[2005/12/21 11:57:36 | 000,139,264 | ---- | C] () -- E:\Windows\System32\nsldap32v50.dll
[2005/12/21 11:57:04 | 000,024,576 | ---- | C] () -- E:\Windows\System32\nsldappr32v50.dll
[2005/12/21 11:54:34 | 000,040,960 | ---- | C] () -- E:\Windows\System32\nsldapssl32v50.dll
[2005/01/17 01:10:16 | 000,045,056 | ---- | C] () -- E:\Windows\System32\BRTCPCON.DLL
[2004/08/09 01:00:42 | 000,000,114 | ---- | C] () -- E:\Windows\System32\BRLMW03A.INI
 
========== LOP Check ==========
 
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Application Data
[2012/02/02 07:32:24 | 000,000,000 | ---D | M] -- E:\ProgramData\Ask
[2011/03/19 06:52:00 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonBJ
[2011/09/16 03:56:39 | 000,000,000 | -H-D | M] -- E:\ProgramData\CanonIJMyPrinter
[2013/05/06 05:49:39 | 000,000,000 | ---D | M] -- E:\ProgramData\CanonIJPLM
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Documents
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Dokumente
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Favorites
[2012/11/08 04:20:44 | 000,000,000 | ---D | M] -- E:\ProgramData\LSMilchkuh
[2011/12/19 05:50:06 | 000,000,000 | ---D | M] -- E:\ProgramData\PCDr
[2011/02/10 12:58:01 | 000,000,000 | ---D | M] -- E:\ProgramData\PhotoShow Shared Assets
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Start Menu
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Startmenü
[2011/02/10 12:51:16 | 000,000,000 | ---D | M] -- E:\ProgramData\Temp
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\ProgramData\Templates
[2011/02/10 12:59:21 | 000,000,000 | ---D | M] -- E:\ProgramData\Uninstall
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\ProgramData\Vorlagen
[2013/05/22 15:10:00 | 000,000,564 | ---- | M] () -- E:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2013/03/18 10:16:35 | 000,032,632 | ---- | M] () -- E:\Windows\Tasks\SCHEDLGU.TXT
[2013/05/22 16:25:00 | 000,000,506 | ---- | M] () -- E:\Windows\Tasks\SystemToolsDailyTest.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2012/06/18 11:27:22 | 000,000,000 | -HSD | M] -- E:\$Recycle.Bin
[2011/02/10 12:43:14 | 000,000,000 | ---D | M] -- E:\Apps
[2013/03/18 10:06:32 | 000,000,000 | ---D | M] -- E:\backup
[2013/05/16 01:10:25 | 000,000,000 | -HSD | M] -- E:\Config.Msi
[2011/03/01 04:50:30 | 000,000,000 | ---D | M] -- E:\dell
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- E:\Documents and Settings
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\Dokumente und Einstellungen
[2011/02/10 14:18:51 | 000,000,000 | ---D | M] -- E:\Drivers
[2011/02/10 05:37:10 | 000,000,000 | ---D | M] -- E:\Intel
[2012/06/22 02:59:05 | 000,000,000 | ---D | M] -- E:\Logs
[2012/03/26 08:13:31 | 000,000,000 | RH-D | M] -- E:\MSOCache
[2012/12/17 16:26:37 | 000,000,000 | ---D | M] -- E:\NMP_Backup
[2009/07/13 22:37:05 | 000,000,000 | ---D | M] -- E:\PerfLogs
[2013/05/14 09:27:56 | 000,000,000 | R--D | M] -- E:\Program Files
[2013/05/22 10:32:26 | 000,000,000 | -H-D | M] -- E:\ProgramData
[2011/02/28 12:28:23 | 000,000,000 | -HSD | M] -- E:\Programme
[2013/05/23 11:49:59 | 000,000,000 | -HSD | M] -- E:\RECYCLER
[2013/03/18 10:11:19 | 000,000,000 | ---D | M] -- E:\Ruby193
[2013/03/18 10:08:34 | 000,000,000 | ---D | M] -- E:\SilentHerdsman
[2013/03/18 10:11:53 | 000,000,000 | ---D | M] -- E:\SilentHerdsmanInstaller-2.7.7.0
[2013/05/20 06:31:06 | 000,000,000 | -HSD | M] -- E:\System Volume Information
[2013/03/18 10:11:50 | 000,000,000 | R--D | M] -- E:\Users
[2011/03/04 03:15:47 | 000,000,000 | ---D | M] -- E:\VIT
[2013/02/27 22:06:03 | 000,000,000 | ---D | M] -- E:\Windows
 
< %PROGRAMFILES%\*.exe >
 
Invalid Environment Variable: %LOCALAPPDATA%\*.exe
 
< %systemroot%\*. /mp /s >
 
 
< MD5 for: AGP440.SYS  >
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\System32\drivers\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009/07/13 21:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- E:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\System32\drivers\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009/07/13 21:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- E:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- E:\Windows\System32\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- E:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
< MD5 for: EXPLORER.EXE  >
[2011/02/26 01:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- E:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- E:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
 
< MD5 for: IASTOR.SYS  >
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Drivers\storage\R271949\f6flpy-x86\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\drivers\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\DriverStore\FileRepository\iaahci.inf_x86_neutral_e8a55be84650e755\iaStor.sys
[2010/03/04 14:33:26 | 000,435,736 | ---- | M] (Intel Corporation) MD5=26541A068572F650A2FA490726FE81BE -- E:\Windows\System32\DriverStore\FileRepository\iastor.inf_x86_neutral_c766b54545e4141f\iaStor.sys
 
< MD5 for: IASTORV.SYS  >
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\System32\drivers\iaStorV.sys
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011/03/11 01:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011/03/11 01:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2010/11/20 08:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- E:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 08:29:54 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- E:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2010/11/20 08:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- E:\Windows\System32\netlogon.dll
[2010/11/20 08:20:28 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- E:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\System32\drivers\nvstor.sys
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/03/11 01:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011/03/11 01:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2010/11/20 08:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- E:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 08:30:06 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- E:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2010/11/20 08:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- E:\Windows\System32\scecli.dll
[2010/11/20 08:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- E:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
 
< MD5 for: USER32.DLL  >
[2010/11/20 08:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- E:\Windows\System32\user32.dll
[2010/11/20 08:21:33 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- E:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- E:\Windows\System32\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- E:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- E:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- E:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- E:\Windows\System32\drivers\ws2ifsl.sys
[2009/07/13 19:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- E:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
 
< %systemroot%\system32\*.dll /lockedfiles >
[2010/11/20 08:19:02 | 000,828,928 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- E:\Windows\system32\fontext.dll
[2013/02/27 00:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- E:\Windows\system32\shell32.dll
 
Invalid Environment Variable: %USERPROFILE%\*.*
 
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.exe
 
Invalid Environment Variable: %USERPROFILE%\Local Settings\Temp\*.dll
 
Invalid Environment Variable: %USERPROFILE%\Application Data\*.exe
< End of report >

--- --- ---

markusg 23.05.2013 21:51

bist du wieder im normalen Modus?
was für dokumente sind das denn, kannst du mir mal n namen posten, als text bitte?

Newson 23.05.2013 21:59

Ich bin wieder in normal modus.

Dokumente sind:

thumbs.ini (x2)
~WRL1477.tmp
~$nal text amrei 2.docx
~$llo Herr Gloy.docx
~$ex Acknowledgements.docx

Die erste 2 .docx Dokumenten sind endlich als zwei neulich verarbeitetet Word Dokumente. Der letzte kenne ich nicht.

markusg 23.05.2013 22:03

die kannst du löschen
Das sind zwishcengespeicherte word dokumente.
Upload hat geklappt, danke.
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

Newson 23.05.2013 22:12

11:08:12.0058 6264 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
11:08:12.0308 6264 ============================================================
11:08:12.0308 6264 Current date / time: 2013/05/24 11:08:12.0308
11:08:12.0308 6264 SystemInfo:
11:08:12.0308 6264
11:08:12.0308 6264 OS Version: 6.1.7601 ServicePack: 1.0
11:08:12.0308 6264 Product type: Workstation
11:08:12.0323 6264 ComputerName: HWACKER-PC
11:08:12.0323 6264 UserName: r.newson
11:08:12.0323 6264 Windows directory: C:\Windows
11:08:12.0323 6264 System windows directory: C:\Windows
11:08:12.0323 6264 Processor architecture: Intel x86
11:08:12.0323 6264 Number of processors: 4
11:08:12.0323 6264 Page size: 0x1000
11:08:12.0323 6264 Boot type: Normal boot
11:08:12.0323 6264 ============================================================
11:08:13.0103 6264 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:08:13.0103 6264 ============================================================
11:08:13.0103 6264 \Device\Harddisk0\DR0:
11:08:13.0103 6264 MBR partitions:
11:08:13.0103 6264 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x15000, BlocksNum 0x184E000
11:08:13.0103 6264 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1863000, BlocksNum 0x13602000
11:08:13.0103 6264 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x14E65800, BlocksNum 0x105C8800
11:08:13.0103 6264 ============================================================
11:08:13.0103 6264 C: <-> \Device\Harddisk0\DR0\Partition2
11:08:13.0103 6264 D: <-> \Device\Harddisk0\DR0\Partition3
11:08:13.0103 6264 ============================================================
11:08:13.0103 6264 Initialize success
11:08:13.0103 6264 ============================================================
11:08:14.0866 4632 ============================================================
11:08:14.0866 4632 Scan started
11:08:14.0866 4632 Mode: Manual;
11:08:14.0866 4632 ============================================================
11:08:16.0535 4632 ================ Scan system memory ========================
11:08:16.0535 4632 System memory - ok
11:08:16.0535 4632 ================ Scan services =============================
11:08:16.0956 4632 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
11:08:16.0956 4632 1394ohci - ok
11:08:17.0112 4632 [ C351EB0DEB102D7EC67CDDEE6513DDF5 ] Acceler C:\Windows\system32\DRIVERS\Accelern.sys
11:08:17.0112 4632 Acceler - ok
11:08:17.0159 4632 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:08:17.0159 4632 ACPI - ok
11:08:17.0175 4632 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
11:08:17.0175 4632 AcpiPmi - ok
11:08:17.0300 4632 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
11:08:17.0300 4632 AdobeARMservice - ok
11:08:17.0393 4632 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
11:08:17.0393 4632 AdobeFlashPlayerUpdateSvc - ok
11:08:17.0565 4632 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
11:08:17.0580 4632 adp94xx - ok
11:08:17.0627 4632 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
11:08:17.0627 4632 adpahci - ok
11:08:17.0643 4632 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
11:08:17.0643 4632 adpu320 - ok
11:08:17.0752 4632 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:08:17.0752 4632 AeLookupSvc - ok
11:08:17.0892 4632 [ 827DBC22C96EECF6D36A13162FABAFD3 ] AESTFilters C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
11:08:17.0892 4632 AESTFilters - ok
11:08:17.0955 4632 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
11:08:17.0955 4632 AFD - ok
11:08:18.0002 4632 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
11:08:18.0002 4632 agp440 - ok
11:08:18.0017 4632 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
11:08:18.0017 4632 aic78xx - ok
11:08:18.0048 4632 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
11:08:18.0048 4632 ALG - ok
11:08:18.0095 4632 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
11:08:18.0095 4632 aliide - ok
11:08:18.0282 4632 ALSysIO - ok
11:08:18.0329 4632 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
11:08:18.0329 4632 amdagp - ok
11:08:18.0376 4632 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
11:08:18.0376 4632 amdide - ok
11:08:18.0423 4632 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
11:08:18.0423 4632 AmdK8 - ok
11:08:18.0438 4632 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
11:08:18.0438 4632 AmdPPM - ok
11:08:18.0516 4632 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:08:18.0516 4632 amdsata - ok
11:08:18.0766 4632 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
11:08:18.0769 4632 amdsbs - ok
11:08:18.0774 4632 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:08:18.0775 4632 amdxata - ok
11:08:18.0804 4632 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
11:08:18.0806 4632 AppID - ok
11:08:18.0853 4632 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:08:18.0855 4632 AppIDSvc - ok
11:08:18.0861 4632 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
11:08:18.0865 4632 Appinfo - ok
11:08:18.0878 4632 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
11:08:18.0881 4632 arc - ok
11:08:18.0888 4632 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
11:08:18.0890 4632 arcsas - ok
11:08:19.0001 4632 [ 39CDCB109BF200CC8A05B9C7E6272D11 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
11:08:19.0003 4632 aspnet_state - ok
11:08:19.0032 4632 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:08:19.0034 4632 AsyncMac - ok
11:08:19.0062 4632 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
11:08:19.0064 4632 atapi - ok
11:08:19.0093 4632 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:08:19.0100 4632 AudioEndpointBuilder - ok
11:08:19.0108 4632 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
11:08:19.0111 4632 Audiosrv - ok
11:08:19.0121 4632 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:08:19.0123 4632 AxInstSV - ok
11:08:19.0154 4632 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
11:08:19.0160 4632 b06bdrv - ok
11:08:19.0198 4632 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
11:08:19.0201 4632 b57nd60x - ok
11:08:19.0208 4632 [ 94F2DC372163D520D7B1DAD78AE40B5E ] BCM42RLY C:\Windows\system32\drivers\BCM42RLY.sys
11:08:19.0210 4632 BCM42RLY - ok
11:08:19.0355 4632 [ F689C5965CEFAD780A2948546703BD5D ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
11:08:19.0398 4632 BCM43XX - ok
11:08:19.0427 4632 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
11:08:19.0431 4632 BDESVC - ok
11:08:19.0446 4632 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
11:08:19.0449 4632 Beep - ok
11:08:19.0507 4632 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
11:08:19.0514 4632 BFE - ok
11:08:19.0533 4632 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
11:08:19.0544 4632 BITS - ok
11:08:19.0565 4632 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:08:19.0566 4632 blbdrive - ok
11:08:19.0573 4632 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:08:19.0574 4632 bowser - ok
11:08:19.0579 4632 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:08:19.0583 4632 BrFiltLo - ok
11:08:19.0587 4632 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:08:19.0589 4632 BrFiltUp - ok
11:08:19.0654 4632 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
11:08:19.0655 4632 Browser - ok
11:08:19.0678 4632 [ 08C7E41FF10F56E83B4F10B5E8B1E8B6 ] BrSerIb C:\Windows\system32\DRIVERS\BrSerIb.sys
11:08:19.0682 4632 BrSerIb - ok
11:08:19.0698 4632 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:08:19.0702 4632 Brserid - ok
11:08:19.0707 4632 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:08:19.0709 4632 BrSerWdm - ok
11:08:19.0715 4632 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:08:19.0716 4632 BrUsbMdm - ok
11:08:19.0720 4632 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:08:19.0722 4632 BrUsbSer - ok
11:08:19.0739 4632 [ 2132A117160F2A96A13C044AE9BCED91 ] BrUsbSIb C:\Windows\system32\DRIVERS\BrUsbSIb.sys
11:08:19.0740 4632 BrUsbSIb - ok
11:08:19.0762 4632 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
11:08:19.0763 4632 BthEnum - ok
11:08:19.0778 4632 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
11:08:19.0779 4632 BTHMODEM - ok
11:08:19.0786 4632 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
11:08:19.0788 4632 BthPan - ok
11:08:19.0801 4632 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
11:08:19.0809 4632 BTHPORT - ok
11:08:19.0848 4632 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
11:08:19.0850 4632 bthserv - ok
11:08:19.0855 4632 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
11:08:19.0856 4632 BTHUSB - ok
11:08:19.0873 4632 [ 7E826BE3B3558208D5C9B00034E51BE5 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
11:08:19.0874 4632 btwaudio - ok
11:08:19.0880 4632 [ AF9148C3E844131AC954CB53FF43D971 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
11:08:19.0881 4632 btwavdt - ok
11:08:19.0912 4632 [ 45F36763576B8AE91E809337DC7CE4E6 ] btwdins c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
11:08:19.0915 4632 btwdins - ok
11:08:19.0921 4632 [ AAFD7CB76BA61FBB08E302DA208C974A ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
11:08:19.0922 4632 btwl2cap - ok
11:08:19.0926 4632 [ 480B3D195854B2E55299CDDDDC50BCF9 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
11:08:19.0927 4632 btwrchid - ok
11:08:19.0932 4632 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:08:19.0936 4632 cdfs - ok
11:08:19.0997 4632 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
11:08:19.0999 4632 cdrom - ok
11:08:20.0022 4632 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
11:08:20.0024 4632 CertPropSvc - ok
11:08:20.0041 4632 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
11:08:20.0043 4632 circlass - ok
11:08:20.0053 4632 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
11:08:20.0056 4632 CLFS - ok
11:08:20.0063 4632 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:08:20.0065 4632 clr_optimization_v2.0.50727_32 - ok
11:08:20.0101 4632 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:08:20.0102 4632 clr_optimization_v4.0.30319_32 - ok
11:08:20.0106 4632 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:08:20.0108 4632 CmBatt - ok
11:08:20.0137 4632 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:08:20.0139 4632 cmdide - ok
11:08:20.0158 4632 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
11:08:20.0162 4632 CNG - ok
11:08:20.0167 4632 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
11:08:20.0168 4632 Compbatt - ok
11:08:20.0185 4632 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
11:08:20.0186 4632 CompositeBus - ok
11:08:20.0190 4632 COMSysApp - ok
11:08:20.0214 4632 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
11:08:20.0215 4632 crcdisk - ok
11:08:20.0228 4632 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:08:20.0231 4632 CryptSvc - ok
11:08:20.0244 4632 [ 0F538DF1673E5216F3BAACB6911D9D0F ] CtAudDrv C:\Windows\system32\Drivers\CtAudDrv.sys
11:08:20.0246 4632 CtAudDrv - ok
11:08:20.0254 4632 [ CEBA8413F9B2C73A4E9E16DBD127DC25 ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys
11:08:20.0257 4632 CtClsFlt - ok
11:08:20.0272 4632 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
11:08:20.0283 4632 DcomLaunch - ok
11:08:20.0329 4632 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
11:08:20.0335 4632 defragsvc - ok
11:08:20.0352 4632 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:08:20.0353 4632 DfsC - ok
11:08:20.0383 4632 [ F9F31A9F2A8C0DD0CEB6E380BF0985D4 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
11:08:20.0385 4632 dg_ssudbus - ok
11:08:20.0395 4632 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
11:08:20.0399 4632 Dhcp - ok
11:08:20.0407 4632 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
11:08:20.0408 4632 discache - ok
11:08:20.0477 4632 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
11:08:20.0478 4632 Disk - ok
11:08:20.0485 4632 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:08:20.0488 4632 Dnscache - ok
11:08:20.0506 4632 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
11:08:20.0509 4632 dot3svc - ok
11:08:20.0517 4632 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
11:08:20.0520 4632 DPS - ok
11:08:20.0539 4632 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:08:20.0541 4632 drmkaud - ok
11:08:20.0568 4632 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:08:20.0575 4632 DXGKrnl - ok
11:08:20.0592 4632 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
11:08:20.0595 4632 EapHost - ok
11:08:20.0657 4632 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
11:08:20.0716 4632 ebdrv - ok
11:08:20.0722 4632 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
11:08:20.0724 4632 EFS - ok
11:08:20.0788 4632 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
11:08:20.0795 4632 ehRecvr - ok
11:08:20.0801 4632 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
11:08:20.0803 4632 ehSched - ok
11:08:20.0821 4632 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
11:08:20.0826 4632 elxstor - ok
11:08:20.0847 4632 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:08:20.0849 4632 ErrDev - ok
11:08:20.0872 4632 [ C3075617DB699CDC9184A02AFD4D7928 ] ETSWatchdog c:\SilentHerdsman\services\JavaService.exe
11:08:20.0873 4632 ETSWatchdog - ok
11:08:20.0901 4632 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
11:08:20.0907 4632 EventSystem - ok
11:08:20.0914 4632 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
11:08:20.0917 4632 exfat - ok
11:08:20.0925 4632 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:08:20.0927 4632 fastfat - ok
11:08:20.0961 4632 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
11:08:20.0967 4632 Fax - ok
11:08:20.0976 4632 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
11:08:20.0977 4632 fdc - ok
11:08:20.0982 4632 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
11:08:20.0984 4632 fdPHost - ok
11:08:20.0989 4632 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
11:08:20.0991 4632 FDResPub - ok
11:08:21.0007 4632 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:08:21.0009 4632 FileInfo - ok
11:08:21.0014 4632 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:08:21.0016 4632 Filetrace - ok
11:08:21.0029 4632 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
11:08:21.0030 4632 flpydisk - ok
11:08:21.0038 4632 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:08:21.0041 4632 FltMgr - ok
11:08:21.0071 4632 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
11:08:21.0081 4632 FontCache - ok
11:08:21.0097 4632 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:08:21.0099 4632 FontCache3.0.0.0 - ok
11:08:21.0114 4632 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:08:21.0115 4632 FsDepends - ok
11:08:21.0121 4632 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:08:21.0122 4632 Fs_Rec - ok
11:08:21.0137 4632 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:08:21.0140 4632 fvevol - ok
11:08:21.0153 4632 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
11:08:21.0155 4632 gagp30kx - ok
11:08:21.0173 4632 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
11:08:21.0180 4632 gpsvc - ok
11:08:21.0225 4632 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
11:08:21.0226 4632 gupdate - ok
11:08:21.0235 4632 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
11:08:21.0237 4632 gupdatem - ok
11:08:21.0283 4632 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
11:08:21.0286 4632 gusvc - ok
11:08:21.0292 4632 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:08:21.0294 4632 hcw85cir - ok
11:08:21.0318 4632 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
11:08:21.0320 4632 HDAudBus - ok
11:08:21.0330 4632 [ A88485DC6A7136C10D9A6C7E38FDFE3C ] HECI C:\Windows\system32\DRIVERS\HECI.sys
11:08:21.0332 4632 HECI - ok
11:08:21.0342 4632 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
11:08:21.0344 4632 HidBatt - ok
11:08:21.0359 4632 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
11:08:21.0361 4632 HidBth - ok
11:08:21.0368 4632 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
11:08:21.0369 4632 HidIr - ok
11:08:21.0374 4632 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
11:08:21.0376 4632 hidserv - ok
11:08:21.0392 4632 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
11:08:21.0394 4632 HidUsb - ok
11:08:21.0400 4632 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:08:21.0403 4632 hkmsvc - ok
11:08:21.0412 4632 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:08:21.0415 4632 HomeGroupListener - ok
11:08:21.0424 4632 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:08:21.0430 4632 HomeGroupProvider - ok
11:08:21.0484 4632 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:08:21.0486 4632 HpSAMD - ok
11:08:21.0515 4632 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:08:21.0522 4632 HTTP - ok
11:08:21.0533 4632 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:08:21.0534 4632 hwpolicy - ok
11:08:21.0551 4632 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
11:08:21.0552 4632 i8042prt - ok
11:08:21.0570 4632 [ 26541A068572F650A2FA490726FE81BE ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
11:08:21.0573 4632 iaStor - ok
11:08:21.0647 4632 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:08:21.0652 4632 iaStorV - ok
11:08:21.0682 4632 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:08:21.0692 4632 idsvc - ok
11:08:21.0846 4632 [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
11:08:22.0030 4632 igfx - ok
11:08:22.0038 4632 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
11:08:22.0039 4632 iirsp - ok
11:08:22.0085 4632 [ C5B04409186A27409BD069580208A6D3 ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
11:08:22.0086 4632 IJPLMSVC - ok
11:08:22.0107 4632 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
11:08:22.0116 4632 IKEEXT - ok
11:08:22.0124 4632 [ E3C36AC5AE87EC970AE8EA2A93D59AE1 ] Impcd C:\Windows\system32\DRIVERS\Impcd.sys
11:08:22.0127 4632 Impcd - ok
11:08:22.0161 4632 [ 07D73EC613B1D3F177B914DC7F5E879B ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
11:08:22.0164 4632 IntcDAud - ok
11:08:22.0185 4632 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
11:08:22.0187 4632 intelide - ok
11:08:22.0203 4632 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:08:22.0204 4632 intelppm - ok
11:08:22.0218 4632 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:08:22.0220 4632 IPBusEnum - ok
11:08:22.0225 4632 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:08:22.0228 4632 IpFilterDriver - ok
11:08:22.0251 4632 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:08:22.0258 4632 iphlpsvc - ok
11:08:22.0263 4632 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
11:08:22.0265 4632 IPMIDRV - ok
11:08:22.0281 4632 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:08:22.0284 4632 IPNAT - ok
11:08:22.0288 4632 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:08:22.0290 4632 IRENUM - ok
11:08:22.0295 4632 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:08:22.0297 4632 isapnp - ok
11:08:22.0307 4632 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
11:08:22.0310 4632 iScsiPrt - ok
11:08:22.0316 4632 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
11:08:22.0318 4632 kbdclass - ok
11:08:22.0323 4632 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
11:08:22.0324 4632 kbdhid - ok
11:08:22.0328 4632 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
11:08:22.0330 4632 KeyIso - ok
11:08:22.0336 4632 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:08:22.0338 4632 KSecDD - ok
11:08:22.0346 4632 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:08:22.0348 4632 KSecPkg - ok
11:08:22.0359 4632 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
11:08:22.0365 4632 KtmRm - ok
11:08:22.0381 4632 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
11:08:22.0385 4632 LanmanServer - ok
11:08:22.0398 4632 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:08:22.0401 4632 LanmanWorkstation - ok
11:08:22.0424 4632 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:08:22.0425 4632 lltdio - ok
11:08:22.0447 4632 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:08:22.0451 4632 lltdsvc - ok
11:08:22.0455 4632 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
11:08:22.0458 4632 lmhosts - ok
11:08:22.0484 4632 [ 5460828F8951D310B42B442877603B8D ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:08:22.0486 4632 LMS - ok
11:08:22.0494 4632 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
11:08:22.0496 4632 LSI_FC - ok
11:08:22.0502 4632 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
11:08:22.0504 4632 LSI_SAS - ok
11:08:22.0520 4632 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:08:22.0521 4632 LSI_SAS2 - ok
11:08:22.0528 4632 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:08:22.0530 4632 LSI_SCSI - ok
11:08:22.0536 4632 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
11:08:22.0538 4632 luafv - ok
11:08:22.0565 4632 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
11:08:22.0567 4632 Mcx2Svc - ok
11:08:22.0583 4632 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
11:08:22.0584 4632 megasas - ok
11:08:22.0605 4632 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
11:08:22.0609 4632 MegaSR - ok
11:08:22.0621 4632 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
11:08:22.0624 4632 MMCSS - ok
11:08:22.0639 4632 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
11:08:22.0640 4632 Modem - ok
11:08:22.0645 4632 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:08:22.0646 4632 monitor - ok
11:08:22.0650 4632 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys
11:08:22.0652 4632 mouclass - ok
11:08:22.0667 4632 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:08:22.0669 4632 mouhid - ok
11:08:22.0675 4632 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:08:22.0677 4632 mountmgr - ok
11:08:22.0697 4632 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
11:08:22.0699 4632 MozillaMaintenance - ok
11:08:22.0720 4632 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
11:08:22.0723 4632 MpFilter - ok
11:08:22.0730 4632 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
11:08:22.0732 4632 mpio - ok
11:08:22.0747 4632 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:08:22.0749 4632 mpsdrv - ok
11:08:22.0768 4632 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
11:08:22.0776 4632 MpsSvc - ok
11:08:22.0785 4632 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:08:22.0788 4632 MRxDAV - ok
11:08:22.0795 4632 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:08:22.0797 4632 mrxsmb - ok
11:08:22.0807 4632 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:08:22.0810 4632 mrxsmb10 - ok
11:08:22.0816 4632 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:08:22.0818 4632 mrxsmb20 - ok
11:08:22.0829 4632 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
11:08:22.0831 4632 msahci - ok
11:08:22.0868 4632 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
11:08:22.0871 4632 msdsm - ok
11:08:22.0888 4632 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
11:08:22.0892 4632 MSDTC - ok
11:08:22.0902 4632 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:08:22.0903 4632 Msfs - ok
11:08:22.0907 4632 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:08:22.0909 4632 mshidkmdf - ok
11:08:22.0915 4632 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:08:22.0916 4632 msisadrv - ok
11:08:22.0928 4632 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:08:22.0931 4632 MSiSCSI - ok
11:08:22.0934 4632 msiserver - ok
11:08:22.0957 4632 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:08:22.0958 4632 MSKSSRV - ok
11:08:22.0968 4632 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
11:08:22.0969 4632 MsMpSvc - ok
11:08:22.0975 4632 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:08:22.0976 4632 MSPCLOCK - ok
11:08:22.0983 4632 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:08:22.0984 4632 MSPQM - ok
11:08:23.0003 4632 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:08:23.0006 4632 MsRPC - ok
11:08:23.0012 4632 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
11:08:23.0014 4632 mssmbios - ok
11:08:23.0056 4632 MSSQL$NMP - ok
11:08:23.0081 4632 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
11:08:23.0081 4632 MSSQLServerADHelper - ok
11:08:23.0097 4632 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:08:23.0097 4632 MSTEE - ok
11:08:23.0097 4632 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
11:08:23.0097 4632 MTConfig - ok
11:08:23.0113 4632 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
11:08:23.0113 4632 Mup - ok
11:08:23.0128 4632 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
11:08:23.0128 4632 napagent - ok
11:08:23.0144 4632 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:08:23.0144 4632 NativeWifiP - ok
11:08:23.0191 4632 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:08:23.0206 4632 NDIS - ok
11:08:23.0222 4632 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:08:23.0222 4632 NdisCap - ok
11:08:23.0222 4632 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:08:23.0237 4632 NdisTapi - ok
11:08:23.0237 4632 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:08:23.0237 4632 Ndisuio - ok
11:08:23.0253 4632 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:08:23.0269 4632 NdisWan - ok
11:08:23.0269 4632 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:08:23.0269 4632 NDProxy - ok
11:08:23.0284 4632 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:08:23.0284 4632 NetBIOS - ok
11:08:23.0300 4632 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:08:23.0300 4632 NetBT - ok
11:08:23.0318 4632 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
11:08:23.0320 4632 Netlogon - ok
11:08:23.0343 4632 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
11:08:23.0348 4632 Netman - ok
11:08:23.0366 4632 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
11:08:23.0374 4632 netprofm - ok
11:08:23.0388 4632 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:08:23.0390 4632 NetTcpPortSharing - ok
11:08:23.0410 4632 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
11:08:23.0412 4632 nfrd960 - ok
11:08:23.0419 4632 [ 832E098BCA8235436FE2D8AE50AC3718 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
11:08:23.0421 4632 NisDrv - ok
11:08:23.0433 4632 [ E570ECA850F30EB740C2E9699DF3D2BD ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
11:08:23.0437 4632 NisSrv - ok
11:08:23.0449 4632 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
11:08:23.0453 4632 NlaSvc - ok
11:08:23.0458 4632 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:08:23.0460 4632 Npfs - ok
11:08:23.0475 4632 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
11:08:23.0478 4632 nsi - ok
11:08:23.0483 4632 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:08:23.0484 4632 nsiproxy - ok
11:08:23.0540 4632 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:08:23.0554 4632 Ntfs - ok
11:08:23.0589 4632 NTP - ok
11:08:23.0655 4632 [ AFEFA4A7DAB65DA3FBEB6EC7B01E7D42 ] ntrtscan c:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
11:08:23.0664 4632 ntrtscan - ok
11:08:23.0669 4632 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
11:08:23.0671 4632 Null - ok
11:08:23.0694 4632 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:08:23.0697 4632 nvraid - ok
11:08:23.0714 4632 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:08:23.0717 4632 nvstor - ok
11:08:23.0739 4632 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:08:23.0742 4632 nv_agp - ok
11:08:23.0779 4632 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
11:08:23.0785 4632 odserv - ok
11:08:23.0818 4632 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
11:08:23.0820 4632 ohci1394 - ok
11:08:23.0843 4632 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:08:23.0846 4632 ose - ok
11:08:23.0947 4632 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:08:23.0972 4632 osppsvc - ok
11:08:24.0012 4632 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:08:24.0017 4632 p2pimsvc - ok
11:08:24.0029 4632 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
11:08:24.0035 4632 p2psvc - ok
11:08:24.0053 4632 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:08:24.0054 4632 Parport - ok
11:08:24.0071 4632 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:08:24.0072 4632 partmgr - ok
11:08:24.0089 4632 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
11:08:24.0091 4632 Parvdm - ok
11:08:24.0100 4632 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:08:24.0104 4632 PcaSvc - ok
11:08:24.0112 4632 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
11:08:24.0115 4632 pci - ok
11:08:24.0131 4632 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
11:08:24.0133 4632 pciide - ok
11:08:24.0139 4632 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
11:08:24.0143 4632 pcmcia - ok
11:08:24.0148 4632 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
11:08:24.0150 4632 pcw - ok
11:08:24.0175 4632 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:08:24.0182 4632 PEAUTH - ok
11:08:24.0226 4632 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
11:08:24.0260 4632 pla - ok
11:08:24.0295 4632 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:08:24.0301 4632 PlugPlay - ok
11:08:24.0305 4632 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:08:24.0308 4632 PNRPAutoReg - ok
11:08:24.0314 4632 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:08:24.0317 4632 PNRPsvc - ok
11:08:24.0328 4632 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:08:24.0335 4632 PolicyAgent - ok
11:08:24.0355 4632 postgresql-8.4 - ok
11:08:24.0361 4632 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
11:08:24.0365 4632 Power - ok
11:08:24.0370 4632 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:08:24.0372 4632 PptpMiniport - ok
11:08:24.0385 4632 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
11:08:24.0387 4632 Processor - ok
11:08:24.0406 4632 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
11:08:24.0409 4632 ProfSvc - ok
11:08:24.0414 4632 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:08:24.0416 4632 ProtectedStorage - ok
11:08:24.0423 4632 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:08:24.0425 4632 Psched - ok
11:08:24.0442 4632 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
11:08:24.0444 4632 PxHelp20 - ok
11:08:24.0474 4632 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
11:08:24.0501 4632 ql2300 - ok
11:08:24.0512 4632 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
11:08:24.0515 4632 ql40xx - ok
11:08:24.0524 4632 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
11:08:24.0529 4632 QWAVE - ok
11:08:24.0545 4632 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:08:24.0546 4632 QWAVEdrv - ok
11:08:24.0571 4632 [ 8F97D374AD1857E1EED85A79F29A1D3D ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
11:08:24.0573 4632 RapiMgr - ok
11:08:24.0578 4632 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:08:24.0580 4632 RasAcd - ok
11:08:24.0591 4632 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:08:24.0592 4632 RasAgileVpn - ok
11:08:24.0606 4632 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
11:08:24.0610 4632 RasAuto - ok
11:08:24.0616 4632 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:08:24.0617 4632 Rasl2tp - ok
11:08:24.0650 4632 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
11:08:24.0655 4632 RasMan - ok
11:08:24.0660 4632 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:08:24.0662 4632 RasPppoe - ok
11:08:24.0668 4632 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:08:24.0670 4632 RasSstp - ok
11:08:24.0680 4632 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:08:24.0683 4632 rdbss - ok
11:08:24.0688 4632 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:08:24.0690 4632 rdpbus - ok
11:08:24.0694 4632 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:08:24.0695 4632 RDPCDD - ok
11:08:24.0702 4632 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:08:24.0703 4632 RDPENCDD - ok
11:08:24.0709 4632 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:08:24.0710 4632 RDPREFMP - ok
11:08:24.0727 4632 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:08:24.0730 4632 RDPWD - ok
11:08:24.0740 4632 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:08:24.0742 4632 rdyboost - ok
11:08:24.0763 4632 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
11:08:24.0766 4632 RemoteAccess - ok
11:08:24.0772 4632 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:08:24.0776 4632 RemoteRegistry - ok
11:08:24.0784 4632 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
11:08:24.0786 4632 RFCOMM - ok
11:08:24.0791 4632 [ 0F6756EF8BDA6DFA7BE50465C83132BB ] RimUsb C:\Windows\system32\Drivers\RimUsb.sys
11:08:24.0792 4632 RimUsb - ok
11:08:24.0835 4632 [ BDDC447AB46625A54619808575D5CB46 ] RoxMediaDB12OEM C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
11:08:24.0847 4632 RoxMediaDB12OEM - ok
11:08:24.0857 4632 [ CE203243ADF512540249DF9C264F12DD ] RoxWatch12 C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
11:08:24.0859 4632 RoxWatch12 - ok
11:08:24.0864 4632 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:08:24.0868 4632 RpcEptMapper - ok
11:08:24.0886 4632 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
11:08:24.0889 4632 RpcLocator - ok
11:08:24.0902 4632 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
11:08:24.0906 4632 RpcSs - ok
11:08:24.0922 4632 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:08:24.0924 4632 rspndr - ok
11:08:24.0940 4632 [ 31D45ECA63884FF5F7AECC50F7D1BAE0 ] RSUSBSTOR C:\Windows\system32\Drivers\RtsUStor.sys
11:08:24.0943 4632 RSUSBSTOR - ok
11:08:24.0972 4632 [ 5283B9A27FF230F2FF70D92451FF409A ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
11:08:24.0977 4632 RTL8167 - ok
11:08:24.0982 4632 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
11:08:24.0985 4632 SamSs - ok
11:08:25.0010 4632 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:08:25.0012 4632 sbp2port - ok
11:08:25.0045 4632 [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
11:08:25.0058 4632 SBSDWSCService - ok
11:08:25.0076 4632 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:08:25.0080 4632 SCardSvr - ok
11:08:25.0085 4632 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:08:25.0087 4632 scfilter - ok
11:08:25.0109 4632 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
11:08:25.0119 4632 Schedule - ok
11:08:25.0125 4632 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
11:08:25.0126 4632 SCPolicySvc - ok
11:08:25.0149 4632 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:08:25.0153 4632 SDRSVC - ok
11:08:25.0158 4632 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:08:25.0159 4632 secdrv - ok
11:08:25.0164 4632 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
11:08:25.0168 4632 seclogon - ok
11:08:25.0173 4632 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
11:08:25.0176 4632 SENS - ok
11:08:25.0182 4632 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:08:25.0185 4632 SensrSvc - ok
11:08:25.0202 4632 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:08:25.0203 4632 Serenum - ok
11:08:25.0224 4632 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:08:25.0226 4632 Serial - ok
11:08:25.0246 4632 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:08:25.0248 4632 sermouse - ok
11:08:25.0261 4632 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
11:08:25.0265 4632 SessionEnv - ok
11:08:25.0272 4632 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:08:25.0273 4632 sffdisk - ok
11:08:25.0278 4632 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:08:25.0279 4632 sffp_mmc - ok
11:08:25.0289 4632 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:08:25.0290 4632 sffp_sd - ok
11:08:25.0309 4632 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:08:25.0311 4632 sfloppy - ok
11:08:25.0334 4632 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:08:25.0339 4632 SharedAccess - ok
11:08:25.0357 4632 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:08:25.0363 4632 ShellHWDetection - ok
11:08:25.0380 4632 [ C3075617DB699CDC9184A02AFD4D7928 ] SilentHerdsman c:\SilentHerdsman\services\JavaService.exe
11:08:25.0381 4632 SilentHerdsman - ok
11:08:25.0397 4632 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
11:08:25.0399 4632 sisagp - ok
11:08:25.0409 4632 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:08:25.0411 4632 SiSRaid2 - ok
11:08:25.0424 4632 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:08:25.0426 4632 SiSRaid4 - ok
11:08:25.0495 4632 [ 388AE59FE75F1B959DFA0900923C61BB ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
11:08:25.0511 4632 Skype C2C Service - ok
11:08:25.0561 4632 [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
11:08:25.0564 4632 SkypeUpdate - ok
11:08:25.0569 4632 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:08:25.0571 4632 Smb - ok
11:08:25.0585 4632 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:08:25.0588 4632 SNMPTRAP - ok
11:08:25.0592 4632 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
11:08:25.0594 4632 spldr - ok
11:08:25.0609 4632 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
11:08:25.0612 4632 Spooler - ok
11:08:25.0672 4632 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
11:08:25.0690 4632 sppsvc - ok
11:08:25.0696 4632 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:08:25.0700 4632 sppuinotify - ok
11:08:25.0708 4632 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
11:08:25.0711 4632 SQLBrowser - ok
11:08:25.0718 4632 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
11:08:25.0720 4632 SQLWriter - ok
11:08:25.0728 4632 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
11:08:25.0732 4632 srv - ok
11:08:25.0757 4632 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:08:25.0761 4632 srv2 - ok
11:08:25.0779 4632 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:08:25.0781 4632 srvnet - ok
11:08:25.0789 4632 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:08:25.0793 4632 SSDPSRV - ok
11:08:25.0801 4632 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:08:25.0804 4632 SstpSvc - ok
11:08:25.0875 4632 [ FBAA145C28074C853529050914D405C6 ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
11:08:25.0877 4632 STacSV - ok
11:08:25.0883 4632 [ 1E72739A30A0D3E3FC95EBB07F83912D ] stdcfltn C:\Windows\system32\DRIVERS\stdcfltn.sys
11:08:25.0885 4632 stdcfltn - ok
11:08:25.0903 4632 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:08:25.0905 4632 stexstor - ok
11:08:25.0931 4632 [ 06CBB271F42EF70FB6EF372C491BA9AA ] STHDA C:\Windows\system32\DRIVERS\stwrt.sys
11:08:25.0936 4632 STHDA - ok
11:08:25.0982 4632 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
11:08:25.0989 4632 StiSvc - ok
11:08:26.0013 4632 [ 9E182DD94496550A22A392CC1A8E0F52 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
11:08:26.0047 4632 stllssvr - ok
11:08:26.0061 4632 [ 01FBCC8F2C30EB1FAF9A477FA53C6655 ] svcGenericHost c:\Program Files\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe
11:08:26.0062 4632 svcGenericHost - ok
11:08:26.0075 4632 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
11:08:26.0076 4632 swenum - ok
11:08:26.0088 4632 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
11:08:26.0093 4632 swprv - ok
11:08:26.0124 4632 [ CF196A45FD61118C95585489FAD5B2AA ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
11:08:26.0127 4632 SynTP - ok
11:08:26.0158 4632 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
11:08:26.0172 4632 SysMain - ok
11:08:26.0177 4632 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:08:26.0181 4632 TabletInputService - ok
11:08:26.0190 4632 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
11:08:26.0195 4632 TapiSrv - ok
11:08:26.0202 4632 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
11:08:26.0204 4632 TBS - ok
11:08:26.0236 4632 [ 7C0507D2391AF5933600CBCED799F277 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:08:26.0262 4632 Tcpip - ok
11:08:26.0294 4632 [ 7C0507D2391AF5933600CBCED799F277 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:08:26.0301 4632 TCPIP6 - ok
11:08:26.0309 4632 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:08:26.0311 4632 tcpipreg - ok
11:08:26.0328 4632 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:08:26.0330 4632 TDPIPE - ok
11:08:26.0335 4632 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:08:26.0336 4632 TDTCP - ok
11:08:26.0348 4632 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:08:26.0350 4632 tdx - ok
11:08:26.0511 4632 [ 7C8DD5576695B3362202EF09B20C425E ] TeamViewer8 C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
11:08:26.0530 4632 TeamViewer8 - ok
11:08:26.0565 4632 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
11:08:26.0566 4632 TermDD - ok
11:08:26.0589 4632 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
11:08:26.0596 4632 TermService - ok
11:08:26.0603 4632 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
11:08:26.0606 4632 Themes - ok
11:08:26.0619 4632 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
11:08:26.0621 4632 THREADORDER - ok
11:08:26.0627 4632 [ CA9E9C2C04A198ED345C1752222A5F3E ] tmactmon C:\Windows\system32\DRIVERS\tmactmon.sys
11:08:26.0628 4632 tmactmon - ok
11:08:26.0646 4632 [ 4D69206E3A3E665221FDD7E397106405 ] TMBMServer c:\Program Files\Trend Micro\BM\TMBMSRV.exe
11:08:26.0650 4632 TMBMServer - ok
11:08:26.0667 4632 [ A3D20789B3FF0576A29462BEF25BCFCC ] tmcomm C:\Windows\system32\DRIVERS\tmcomm.sys
11:08:26.0670 4632 tmcomm - ok
11:08:26.0681 4632 [ 21F215E54770C4BF93EFAF63F58FE57E ] tmevtmgr C:\Windows\system32\DRIVERS\tmevtmgr.sys
11:08:26.0682 4632 tmevtmgr - ok
11:08:26.0692 4632 [ 1D84C335EB869BBE64543C6945A1F3C9 ] TmFilter c:\Program Files\Trend Micro\Client Server Security Agent\TmXPFlt.sys
11:08:26.0765 4632 TmFilter - ok
11:08:26.0813 4632 [ 3062BAB9C0F90577674BC2D006EB9EFA ] tmlisten c:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
11:08:26.0822 4632 tmlisten - ok
11:08:26.0848 4632 [ 4E87D02E56E9B1AF831C5D521597D629 ] tmlwf C:\Windows\system32\DRIVERS\tmlwf.sys
11:08:26.0851 4632 tmlwf - ok
11:08:26.0867 4632 [ 255328CF08D602368B69FF1F55EBD93E ] TmPfw c:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
11:08:26.0870 4632 TmPfw - ok
11:08:26.0885 4632 [ 7AAB3FEF8B19AE023EE05386F1B0A5DD ] TmPreFilter c:\Program Files\Trend Micro\Client Server Security Agent\TmPreFlt.sys
11:08:26.0912 4632 TmPreFilter - ok
11:08:26.0951 4632 [ 0FEC6C50B2BE07C57651573CDD1C721F ] TmProxy c:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe
11:08:26.0957 4632 TmProxy - ok
11:08:26.0970 4632 [ 44C262C1B2412DED35078B6166D2ACC2 ] tmtdi C:\Windows\system32\DRIVERS\tmtdi.sys
11:08:26.0972 4632 tmtdi - ok
11:08:26.0992 4632 [ D9882FD91B7C4C35ACAA8498D1F3CD68 ] tmwfp C:\Windows\system32\DRIVERS\tmwfp.sys
11:08:26.0996 4632 tmwfp - ok
11:08:27.0003 4632 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
11:08:27.0006 4632 TrkWks - ok
11:08:27.0015 4632 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:08:27.0018 4632 TrustedInstaller - ok
11:08:27.0026 4632 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:08:27.0027 4632 tssecsrv - ok
11:08:27.0054 4632 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:08:27.0056 4632 TsUsbFlt - ok
11:08:27.0075 4632 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:08:27.0077 4632 tunnel - ok
11:08:27.0084 4632 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:08:27.0085 4632 uagp35 - ok
11:08:27.0108 4632 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:08:27.0111 4632 udfs - ok
11:08:27.0122 4632 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:08:27.0125 4632 UI0Detect - ok
11:08:27.0137 4632 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:08:27.0138 4632 uliagpkx - ok
11:08:27.0164 4632 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
11:08:27.0166 4632 umbus - ok
11:08:27.0171 4632 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:08:27.0172 4632 UmPass - ok
11:08:27.0241 4632 [ 9E89C2D6945389270DE067CE51FF7425 ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
11:08:27.0254 4632 UNS - ok
11:08:27.0268 4632 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
11:08:27.0273 4632 upnphost - ok
11:08:27.0279 4632 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:08:27.0281 4632 usbccgp - ok
11:08:27.0296 4632 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:08:27.0298 4632 usbcir - ok
11:08:27.0303 4632 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\drivers\usbehci.sys
11:08:27.0305 4632 usbehci - ok
11:08:27.0314 4632 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:08:27.0318 4632 usbhub - ok
11:08:27.0322 4632 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
11:08:27.0324 4632 usbohci - ok
11:08:27.0329 4632 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:08:27.0331 4632 usbprint - ok
11:08:27.0337 4632 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
11:08:27.0338 4632 usbscan - ok
11:08:27.0354 4632 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:08:27.0356 4632 USBSTOR - ok
11:08:27.0371 4632 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
11:08:27.0372 4632 usbuhci - ok
11:08:27.0381 4632 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
11:08:27.0384 4632 usbvideo - ok
11:08:27.0390 4632 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
11:08:27.0393 4632 UxSms - ok
11:08:27.0398 4632 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
11:08:27.0400 4632 VaultSvc - ok
11:08:27.0405 4632 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:08:27.0407 4632 vdrvroot - ok
11:08:27.0429 4632 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
11:08:27.0436 4632 vds - ok
11:08:27.0453 4632 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:08:27.0454 4632 vga - ok
11:08:27.0459 4632 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
11:08:27.0461 4632 VgaSave - ok
11:08:27.0469 4632 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:08:27.0472 4632 vhdmp - ok
11:08:27.0497 4632 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
11:08:27.0499 4632 viaagp - ok
11:08:27.0504 4632 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
11:08:27.0506 4632 ViaC7 - ok
11:08:27.0520 4632 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
11:08:27.0522 4632 viaide - ok
11:08:27.0527 4632 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:08:27.0529 4632 volmgr - ok
11:08:27.0541 4632 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:08:27.0545 4632 volmgrx - ok
11:08:27.0554 4632 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:08:27.0558 4632 volsnap - ok
11:08:27.0593 4632 [ 8B9325C1D1167A703042986DF758D799 ] VSApiNt c:\Program Files\Trend Micro\Client Server Security Agent\VSApiNt.sys
11:08:27.0665 4632 VSApiNt - ok
11:08:27.0692 4632 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:08:27.0695 4632 vsmraid - ok
11:08:27.0723 4632 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
11:08:27.0736 4632 VSS - ok
11:08:27.0741 4632 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
11:08:27.0743 4632 vwifibus - ok
11:08:27.0749 4632 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
11:08:27.0751 4632 vwififlt - ok
11:08:27.0763 4632 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
11:08:27.0765 4632 vwifimp - ok
11:08:27.0778 4632 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
11:08:27.0785 4632 W32Time - ok
11:08:27.0800 4632 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:08:27.0801 4632 WacomPen - ok
11:08:27.0807 4632 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:08:27.0809 4632 WANARP - ok
11:08:27.0812 4632 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:08:27.0813 4632 Wanarpv6 - ok
11:08:27.0868 4632 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:08:27.0894 4632 WatAdminSvc - ok
11:08:27.0928 4632 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
11:08:27.0954 4632 wbengine - ok
11:08:27.0962 4632 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:08:27.0967 4632 WbioSrvc - ok
11:08:28.0003 4632 [ 59E19BD13C3BDB857646B9E436BA27F7 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
11:08:28.0007 4632 WcesComm - ok
11:08:28.0025 4632 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:08:28.0031 4632 wcncsvc - ok
11:08:28.0039 4632 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:08:28.0042 4632 WcsPlugInService - ok
11:08:28.0049 4632 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:08:28.0050 4632 Wd - ok
11:08:28.0097 4632 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:08:28.0104 4632 Wdf01000 - ok
11:08:28.0120 4632 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:08:28.0124 4632 WdiServiceHost - ok
11:08:28.0128 4632 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:08:28.0131 4632 WdiSystemHost - ok
11:08:28.0140 4632 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
11:08:28.0149 4632 WebClient - ok
11:08:28.0160 4632 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:08:28.0160 4632 Wecsvc - ok
11:08:28.0175 4632 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:08:28.0175 4632 wercplsupport - ok
11:08:28.0191 4632 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
11:08:28.0191 4632 WerSvc - ok
11:08:28.0191 4632 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:08:28.0191 4632 WfpLwf - ok
11:08:28.0207 4632 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:08:28.0207 4632 WIMMount - ok
11:08:28.0238 4632 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:08:28.0238 4632 WinDefend - ok
11:08:28.0253 4632 WinHttpAutoProxySvc - ok
11:08:28.0269 4632 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:08:28.0285 4632 Winmgmt - ok
11:08:28.0316 4632 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
11:08:28.0347 4632 WinRM - ok
11:08:28.0363 4632 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
11:08:28.0378 4632 WinUsb - ok
11:08:28.0394 4632 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:08:28.0413 4632 Wlansvc - ok
11:08:28.0431 4632 [ 6067ACEF367E79914AF628FA1E9B5330 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
11:08:28.0434 4632 wlcrasvc - ok
11:08:28.0480 4632 [ 0A70F4022EC2E14C159EFC4F69AA2477 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
11:08:28.0489 4632 wlidsvc - ok
11:08:28.0508 4632 [ 7FFF34AE69DFB80F7B190ABA31E00610 ] wltrysvc C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
11:08:28.0509 4632 wltrysvc - ok
11:08:28.0527 4632 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:08:28.0528 4632 WmiAcpi - ok
11:08:28.0548 4632 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:08:28.0551 4632 wmiApSrv - ok
11:08:28.0587 4632 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:08:28.0593 4632 WMPNetworkSvc - ok
11:08:28.0607 4632 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:08:28.0611 4632 WPCSvc - ok
11:08:28.0620 4632 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:08:28.0623 4632 WPDBusEnum - ok
11:08:28.0628 4632 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:08:28.0630 4632 ws2ifsl - ok
11:08:28.0644 4632 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
11:08:28.0653 4632 wscsvc - ok
11:08:28.0657 4632 WSearch - ok
11:08:28.0714 4632 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
11:08:28.0757 4632 wuauserv - ok
11:08:28.0790 4632 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:08:28.0791 4632 WudfPf - ok
11:08:28.0813 4632 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:08:28.0815 4632 WUDFRd - ok
11:08:28.0822 4632 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:08:28.0826 4632 wudfsvc - ok
11:08:28.0835 4632 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
11:08:28.0840 4632 WwanSvc - ok
11:08:28.0852 4632 ================ Scan global ===============================
11:08:28.0861 4632 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
11:08:28.0885 4632 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
11:08:28.0893 4632 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
11:08:28.0901 4632 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
11:08:28.0926 4632 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
11:08:28.0930 4632 [Global] - ok
11:08:28.0931 4632 ================ Scan MBR ==================================
11:08:28.0947 4632 [ CDB4DE4BBD714F152979DA2DCBEF57EB ] \Device\Harddisk0\DR0
11:08:29.0204 4632 \Device\Harddisk0\DR0 - ok
11:08:29.0205 4632 ================ Scan VBR ==================================
11:08:29.0207 4632 [ 45FD117738263C35344EBD657EBF809A ] \Device\Harddisk0\DR0\Partition1
11:08:29.0208 4632 \Device\Harddisk0\DR0\Partition1 - ok
11:08:29.0213 4632 [ 1A7CCBAF7849D00F720F22AFF41F240E ] \Device\Harddisk0\DR0\Partition2
11:08:29.0214 4632 \Device\Harddisk0\DR0\Partition2 - ok
11:08:29.0217 4632 [ 598D13034BF0D21259BF25EFD891BFD8 ] \Device\Harddisk0\DR0\Partition3
11:08:29.0219 4632 \Device\Harddisk0\DR0\Partition3 - ok
11:08:29.0219 4632 ============================================================
11:08:29.0219 4632 Scan finished
11:08:29.0219 4632 ============================================================
11:08:29.0229 6884 Detected object count: 0
11:08:29.0229 6884 Actual detected object count: 0

markusg 23.05.2013 22:13

bitte noch mal, nach Anleitung konfigurieren und scannen

Newson 23.05.2013 22:25

der text hat zu viele Zeichen. Soll ich über Upchannel hochladen?

markusg 24.05.2013 11:56

nein, teilen bitte
oder anhängenb

Newson 25.05.2013 08:35

E$rste Halfte:


11:08:12.0058 6264 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
11:08:12.0308 6264 ============================================================
11:08:12.0308 6264 Current date / time: 2013/05/24 11:08:12.0308
11:08:12.0308 6264 SystemInfo:
11:08:12.0308 6264
11:08:12.0308 6264 OS Version: 6.1.7601 ServicePack: 1.0
11:08:12.0308 6264 Product type: Workstation
11:08:12.0323 6264 ComputerName: HWACKER-PC
11:08:12.0323 6264 UserName: r.newson
11:08:12.0323 6264 Windows directory: C:\Windows
11:08:12.0323 6264 System windows directory: C:\Windows
11:08:12.0323 6264 Processor architecture: Intel x86
11:08:12.0323 6264 Number of processors: 4
11:08:12.0323 6264 Page size: 0x1000
11:08:12.0323 6264 Boot type: Normal boot
11:08:12.0323 6264 ============================================================
11:08:13.0103 6264 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:08:13.0103 6264 ============================================================
11:08:13.0103 6264 \Device\Harddisk0\DR0:
11:08:13.0103 6264 MBR partitions:
11:08:13.0103 6264 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x15000, BlocksNum 0x184E000
11:08:13.0103 6264 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1863000, BlocksNum 0x13602000
11:08:13.0103 6264 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x14E65800, BlocksNum 0x105C8800
11:08:13.0103 6264 ============================================================
11:08:13.0103 6264 C: <-> \Device\Harddisk0\DR0\Partition2
11:08:13.0103 6264 D: <-> \Device\Harddisk0\DR0\Partition3
11:08:13.0103 6264 ============================================================
11:08:13.0103 6264 Initialize success
11:08:13.0103 6264 ============================================================
11:08:14.0866 4632 ============================================================
11:08:14.0866 4632 Scan started
11:08:14.0866 4632 Mode: Manual;
11:08:14.0866 4632 ============================================================
11:08:16.0535 4632 ================ Scan system memory ========================
11:08:16.0535 4632 System memory - ok
11:08:16.0535 4632 ================ Scan services =============================
11:08:16.0956 4632 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
11:08:16.0956 4632 1394ohci - ok
11:08:17.0112 4632 [ C351EB0DEB102D7EC67CDDEE6513DDF5 ] Acceler C:\Windows\system32\DRIVERS\Accelern.sys
11:08:17.0112 4632 Acceler - ok
11:08:17.0159 4632 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:08:17.0159 4632 ACPI - ok
11:08:17.0175 4632 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
11:08:17.0175 4632 AcpiPmi - ok
11:08:17.0300 4632 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
11:08:17.0300 4632 AdobeARMservice - ok
11:08:17.0393 4632 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
11:08:17.0393 4632 AdobeFlashPlayerUpdateSvc - ok
11:08:17.0565 4632 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
11:08:17.0580 4632 adp94xx - ok
11:08:17.0627 4632 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
11:08:17.0627 4632 adpahci - ok
11:08:17.0643 4632 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
11:08:17.0643 4632 adpu320 - ok
11:08:17.0752 4632 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:08:17.0752 4632 AeLookupSvc - ok
11:08:17.0892 4632 [ 827DBC22C96EECF6D36A13162FABAFD3 ] AESTFilters C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
11:08:17.0892 4632 AESTFilters - ok
11:08:17.0955 4632 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
11:08:17.0955 4632 AFD - ok
11:08:18.0002 4632 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
11:08:18.0002 4632 agp440 - ok
11:08:18.0017 4632 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
11:08:18.0017 4632 aic78xx - ok
11:08:18.0048 4632 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
11:08:18.0048 4632 ALG - ok
11:08:18.0095 4632 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
11:08:18.0095 4632 aliide - ok
11:08:18.0282 4632 ALSysIO - ok
11:08:18.0329 4632 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
11:08:18.0329 4632 amdagp - ok
11:08:18.0376 4632 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
11:08:18.0376 4632 amdide - ok
11:08:18.0423 4632 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
11:08:18.0423 4632 AmdK8 - ok
11:08:18.0438 4632 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
11:08:18.0438 4632 AmdPPM - ok
11:08:18.0516 4632 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:08:18.0516 4632 amdsata - ok
11:08:18.0766 4632 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
11:08:18.0769 4632 amdsbs - ok
11:08:18.0774 4632 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:08:18.0775 4632 amdxata - ok
11:08:18.0804 4632 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
11:08:18.0806 4632 AppID - ok
11:08:18.0853 4632 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:08:18.0855 4632 AppIDSvc - ok
11:08:18.0861 4632 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
11:08:18.0865 4632 Appinfo - ok
11:08:18.0878 4632 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
11:08:18.0881 4632 arc - ok
11:08:18.0888 4632 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
11:08:18.0890 4632 arcsas - ok
11:08:19.0001 4632 [ 39CDCB109BF200CC8A05B9C7E6272D11 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
11:08:19.0003 4632 aspnet_state - ok
11:08:19.0032 4632 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:08:19.0034 4632 AsyncMac - ok
11:08:19.0062 4632 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
11:08:19.0064 4632 atapi - ok
11:08:19.0093 4632 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:08:19.0100 4632 AudioEndpointBuilder - ok
11:08:19.0108 4632 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
11:08:19.0111 4632 Audiosrv - ok
11:08:19.0121 4632 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:08:19.0123 4632 AxInstSV - ok
11:08:19.0154 4632 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
11:08:19.0160 4632 b06bdrv - ok
11:08:19.0198 4632 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
11:08:19.0201 4632 b57nd60x - ok
11:08:19.0208 4632 [ 94F2DC372163D520D7B1DAD78AE40B5E ] BCM42RLY C:\Windows\system32\drivers\BCM42RLY.sys
11:08:19.0210 4632 BCM42RLY - ok
11:08:19.0355 4632 [ F689C5965CEFAD780A2948546703BD5D ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
11:08:19.0398 4632 BCM43XX - ok
11:08:19.0427 4632 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
11:08:19.0431 4632 BDESVC - ok
11:08:19.0446 4632 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
11:08:19.0449 4632 Beep - ok
11:08:19.0507 4632 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
11:08:19.0514 4632 BFE - ok
11:08:19.0533 4632 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
11:08:19.0544 4632 BITS - ok
11:08:19.0565 4632 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:08:19.0566 4632 blbdrive - ok
11:08:19.0573 4632 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:08:19.0574 4632 bowser - ok
11:08:19.0579 4632 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:08:19.0583 4632 BrFiltLo - ok
11:08:19.0587 4632 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:08:19.0589 4632 BrFiltUp - ok
11:08:19.0654 4632 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
11:08:19.0655 4632 Browser - ok
11:08:19.0678 4632 [ 08C7E41FF10F56E83B4F10B5E8B1E8B6 ] BrSerIb C:\Windows\system32\DRIVERS\BrSerIb.sys
11:08:19.0682 4632 BrSerIb - ok
11:08:19.0698 4632 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:08:19.0702 4632 Brserid - ok
11:08:19.0707 4632 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:08:19.0709 4632 BrSerWdm - ok
11:08:19.0715 4632 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:08:19.0716 4632 BrUsbMdm - ok
11:08:19.0720 4632 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:08:19.0722 4632 BrUsbSer - ok
11:08:19.0739 4632 [ 2132A117160F2A96A13C044AE9BCED91 ] BrUsbSIb C:\Windows\system32\DRIVERS\BrUsbSIb.sys
11:08:19.0740 4632 BrUsbSIb - ok
11:08:19.0762 4632 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
11:08:19.0763 4632 BthEnum - ok
11:08:19.0778 4632 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
11:08:19.0779 4632 BTHMODEM - ok
11:08:19.0786 4632 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
11:08:19.0788 4632 BthPan - ok
11:08:19.0801 4632 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
11:08:19.0809 4632 BTHPORT - ok
11:08:19.0848 4632 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
11:08:19.0850 4632 bthserv - ok
11:08:19.0855 4632 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
11:08:19.0856 4632 BTHUSB - ok
11:08:19.0873 4632 [ 7E826BE3B3558208D5C9B00034E51BE5 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
11:08:19.0874 4632 btwaudio - ok
11:08:19.0880 4632 [ AF9148C3E844131AC954CB53FF43D971 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
11:08:19.0881 4632 btwavdt - ok
11:08:19.0912 4632 [ 45F36763576B8AE91E809337DC7CE4E6 ] btwdins c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
11:08:19.0915 4632 btwdins - ok
11:08:19.0921 4632 [ AAFD7CB76BA61FBB08E302DA208C974A ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
11:08:19.0922 4632 btwl2cap - ok
11:08:19.0926 4632 [ 480B3D195854B2E55299CDDDDC50BCF9 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
11:08:19.0927 4632 btwrchid - ok
11:08:19.0932 4632 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:08:19.0936 4632 cdfs - ok
11:08:19.0997 4632 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
11:08:19.0999 4632 cdrom - ok
11:08:20.0022 4632 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
11:08:20.0024 4632 CertPropSvc - ok
11:08:20.0041 4632 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
11:08:20.0043 4632 circlass - ok
11:08:20.0053 4632 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
11:08:20.0056 4632 CLFS - ok
11:08:20.0063 4632 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:08:20.0065 4632 clr_optimization_v2.0.50727_32 - ok
11:08:20.0101 4632 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:08:20.0102 4632 clr_optimization_v4.0.30319_32 - ok
11:08:20.0106 4632 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:08:20.0108 4632 CmBatt - ok
11:08:20.0137 4632 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:08:20.0139 4632 cmdide - ok
11:08:20.0158 4632 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
11:08:20.0162 4632 CNG - ok
11:08:20.0167 4632 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
11:08:20.0168 4632 Compbatt - ok
11:08:20.0185 4632 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
11:08:20.0186 4632 CompositeBus - ok
11:08:20.0190 4632 COMSysApp - ok
11:08:20.0214 4632 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
11:08:20.0215 4632 crcdisk - ok
11:08:20.0228 4632 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:08:20.0231 4632 CryptSvc - ok
11:08:20.0244 4632 [ 0F538DF1673E5216F3BAACB6911D9D0F ] CtAudDrv C:\Windows\system32\Drivers\CtAudDrv.sys
11:08:20.0246 4632 CtAudDrv - ok
11:08:20.0254 4632 [ CEBA8413F9B2C73A4E9E16DBD127DC25 ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys
11:08:20.0257 4632 CtClsFlt - ok
11:08:20.0272 4632 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
11:08:20.0283 4632 DcomLaunch - ok
11:08:20.0329 4632 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
11:08:20.0335 4632 defragsvc - ok
11:08:20.0352 4632 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:08:20.0353 4632 DfsC - ok
11:08:20.0383 4632 [ F9F31A9F2A8C0DD0CEB6E380BF0985D4 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
11:08:20.0385 4632 dg_ssudbus - ok
11:08:20.0395 4632 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
11:08:20.0399 4632 Dhcp - ok
11:08:20.0407 4632 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
11:08:20.0408 4632 discache - ok
11:08:20.0477 4632 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
11:08:20.0478 4632 Disk - ok
11:08:20.0485 4632 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:08:20.0488 4632 Dnscache - ok
11:08:20.0506 4632 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
11:08:20.0509 4632 dot3svc - ok
11:08:20.0517 4632 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
11:08:20.0520 4632 DPS - ok
11:08:20.0539 4632 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:08:20.0541 4632 drmkaud - ok
11:08:20.0568 4632 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:08:20.0575 4632 DXGKrnl - ok
11:08:20.0592 4632 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
11:08:20.0595 4632 EapHost - ok
11:08:20.0657 4632 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
11:08:20.0716 4632 ebdrv - ok
11:08:20.0722 4632 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
11:08:20.0724 4632 EFS - ok
11:08:20.0788 4632 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
11:08:20.0795 4632 ehRecvr - ok
11:08:20.0801 4632 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
11:08:20.0803 4632 ehSched - ok
11:08:20.0821 4632 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
11:08:20.0826 4632 elxstor - ok
11:08:20.0847 4632 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:08:20.0849 4632 ErrDev - ok
11:08:20.0872 4632 [ C3075617DB699CDC9184A02AFD4D7928 ] ETSWatchdog c:\SilentHerdsman\services\JavaService.exe
11:08:20.0873 4632 ETSWatchdog - ok
11:08:20.0901 4632 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
11:08:20.0907 4632 EventSystem - ok
11:08:20.0914 4632 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
11:08:20.0917 4632 exfat - ok
11:08:20.0925 4632 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:08:20.0927 4632 fastfat - ok
11:08:20.0961 4632 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
11:08:20.0967 4632 Fax - ok
11:08:20.0976 4632 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
11:08:20.0977 4632 fdc - ok
11:08:20.0982 4632 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
11:08:20.0984 4632 fdPHost - ok
11:08:20.0989 4632 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
11:08:20.0991 4632 FDResPub - ok
11:08:21.0007 4632 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:08:21.0009 4632 FileInfo - ok
11:08:21.0014 4632 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:08:21.0016 4632 Filetrace - ok
11:08:21.0029 4632 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
11:08:21.0030 4632 flpydisk - ok
11:08:21.0038 4632 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:08:21.0041 4632 FltMgr - ok
11:08:21.0071 4632 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
11:08:21.0081 4632 FontCache - ok
11:08:21.0097 4632 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:08:21.0099 4632 FontCache3.0.0.0 - ok
11:08:21.0114 4632 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:08:21.0115 4632 FsDepends - ok
11:08:21.0121 4632 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:08:21.0122 4632 Fs_Rec - ok
11:08:21.0137 4632 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:08:21.0140 4632 fvevol - ok
11:08:21.0153 4632 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
11:08:21.0155 4632 gagp30kx - ok
11:08:21.0173 4632 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
11:08:21.0180 4632 gpsvc - ok
11:08:21.0225 4632 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
11:08:21.0226 4632 gupdate - ok
11:08:21.0235 4632 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
11:08:21.0237 4632 gupdatem - ok
11:08:21.0283 4632 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
11:08:21.0286 4632 gusvc - ok
11:08:21.0292 4632 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:08:21.0294 4632 hcw85cir - ok
11:08:21.0318 4632 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
11:08:21.0320 4632 HDAudBus - ok
11:08:21.0330 4632 [ A88485DC6A7136C10D9A6C7E38FDFE3C ] HECI C:\Windows\system32\DRIVERS\HECI.sys
11:08:21.0332 4632 HECI - ok
11:08:21.0342 4632 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
11:08:21.0344 4632 HidBatt - ok
11:08:21.0359 4632 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
11:08:21.0361 4632 HidBth - ok
11:08:21.0368 4632 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
11:08:21.0369 4632 HidIr - ok
11:08:21.0374 4632 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
11:08:21.0376 4632 hidserv - ok
11:08:21.0392 4632 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
11:08:21.0394 4632 HidUsb - ok
11:08:21.0400 4632 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:08:21.0403 4632 hkmsvc - ok
11:08:21.0412 4632 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:08:21.0415 4632 HomeGroupListener - ok
11:08:21.0424 4632 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:08:21.0430 4632 HomeGroupProvider - ok
11:08:21.0484 4632 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:08:21.0486 4632 HpSAMD - ok
11:08:21.0515 4632 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:08:21.0522 4632 HTTP - ok
11:08:21.0533 4632 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:08:21.0534 4632 hwpolicy - ok
11:08:21.0551 4632 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
11:08:21.0552 4632 i8042prt - ok
11:08:21.0570 4632 [ 26541A068572F650A2FA490726FE81BE ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
11:08:21.0573 4632 iaStor - ok
11:08:21.0647 4632 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:08:21.0652 4632 iaStorV - ok
11:08:21.0682 4632 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:08:21.0692 4632 idsvc - ok
11:08:21.0846 4632 [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
11:08:22.0030 4632 igfx - ok
11:08:22.0038 4632 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
11:08:22.0039 4632 iirsp - ok
11:08:22.0085 4632 [ C5B04409186A27409BD069580208A6D3 ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
11:08:22.0086 4632 IJPLMSVC - ok
11:08:22.0107 4632 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
11:08:22.0116 4632 IKEEXT - ok
11:08:22.0124 4632 [ E3C36AC5AE87EC970AE8EA2A93D59AE1 ] Impcd C:\Windows\system32\DRIVERS\Impcd.sys
11:08:22.0127 4632 Impcd - ok
11:08:22.0161 4632 [ 07D73EC613B1D3F177B914DC7F5E879B ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
11:08:22.0164 4632 IntcDAud - ok
11:08:22.0185 4632 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
11:08:22.0187 4632 intelide - ok
11:08:22.0203 4632 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:08:22.0204 4632 intelppm - ok
11:08:22.0218 4632 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:08:22.0220 4632 IPBusEnum - ok
11:08:22.0225 4632 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:08:22.0228 4632 IpFilterDriver - ok
11:08:22.0251 4632 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:08:22.0258 4632 iphlpsvc - ok
11:08:22.0263 4632 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
11:08:22.0265 4632 IPMIDRV - ok
11:08:22.0281 4632 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:08:22.0284 4632 IPNAT - ok
11:08:22.0288 4632 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:08:22.0290 4632 IRENUM - ok
11:08:22.0295 4632 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:08:22.0297 4632 isapnp - ok
11:08:22.0307 4632 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
11:08:22.0310 4632 iScsiPrt - ok
11:08:22.0316 4632 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
11:08:22.0318 4632 kbdclass - ok
11:08:22.0323 4632 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
11:08:22.0324 4632 kbdhid - ok
11:08:22.0328 4632 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
11:08:22.0330 4632 KeyIso - ok
11:08:22.0336 4632 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:08:22.0338 4632 KSecDD - ok
11:08:22.0346 4632 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:08:22.0348 4632 KSecPkg - ok
11:08:22.0359 4632 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
11:08:22.0365 4632 KtmRm - ok
11:08:22.0381 4632 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
11:08:22.0385 4632 LanmanServer - ok
11:08:22.0398 4632 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:08:22.0401 4632 LanmanWorkstation - ok
11:08:22.0424 4632 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:08:22.0425 4632 lltdio - ok
11:08:22.0447 4632 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:08:22.0451 4632 lltdsvc - ok
11:08:22.0455 4632 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
11:08:22.0458 4632 lmhosts - ok
11:08:22.0484 4632 [ 5460828F8951D310B42B442877603B8D ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:08:22.0486 4632 LMS - ok
11:08:22.0494 4632 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
11:08:22.0496 4632 LSI_FC - ok
11:08:22.0502 4632 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
11:08:22.0504 4632 LSI_SAS - ok
11:08:22.0520 4632 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:08:22.0521 4632 LSI_SAS2 - ok
11:08:22.0528 4632 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:08:22.0530 4632 LSI_SCSI - ok
11:08:22.0536 4632 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
11:08:22.0538 4632 luafv - ok
11:08:22.0565 4632 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
11:08:22.0567 4632 Mcx2Svc - ok
11:08:22.0583 4632 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
11:08:22.0584 4632 megasas - ok
11:08:22.0605 4632 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
11:08:22.0609 4632 MegaSR - ok
11:08:22.0621 4632 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
11:08:22.0624 4632 MMCSS - ok
11:08:22.0639 4632 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
11:08:22.0640 4632 Modem - ok
11:08:22.0645 4632 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:08:22.0646 4632 monitor - ok
11:08:22.0650 4632 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys
11:08:22.0652 4632 mouclass - ok
11:08:22.0667 4632 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:08:22.0669 4632 mouhid - ok
11:08:22.0675 4632 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:08:22.0677 4632 mountmgr - ok
11:08:22.0697 4632 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
11:08:22.0699 4632 MozillaMaintenance - ok
11:08:22.0720 4632 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
11:08:22.0723 4632 MpFilter - ok
11:08:22.0730 4632 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
11:08:22.0732 4632 mpio - ok
11:08:22.0747 4632 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:08:22.0749 4632 mpsdrv - ok
11:08:22.0768 4632 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
11:08:22.0776 4632 MpsSvc - ok
11:08:22.0785 4632 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:08:22.0788 4632 MRxDAV - ok
11:08:22.0795 4632 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:08:22.0797 4632 mrxsmb - ok
11:08:22.0807 4632 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:08:22.0810 4632 mrxsmb10 - ok
11:08:22.0816 4632 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:08:22.0818 4632 mrxsmb20 - ok
11:08:22.0829 4632 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
11:08:22.0831 4632 msahci - ok
11:08:22.0868 4632 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
11:08:22.0871 4632 msdsm - ok
11:08:22.0888 4632 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
11:08:22.0892 4632 MSDTC - ok
11:08:22.0902 4632 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:08:22.0903 4632 Msfs - ok
11:08:22.0907 4632 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:08:22.0909 4632 mshidkmdf - ok
11:08:22.0915 4632 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:08:22.0916 4632 msisadrv - ok
11:08:22.0928 4632 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:08:22.0931 4632 MSiSCSI - ok
11:08:22.0934 4632 msiserver - ok
11:08:22.0957 4632 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:08:22.0958 4632 MSKSSRV - ok
11:08:22.0968 4632 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
11:08:22.0969 4632 MsMpSvc - ok
11:08:22.0975 4632 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:08:22.0976 4632 MSPCLOCK - ok
11:08:22.0983 4632 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:08:22.0984 4632 MSPQM - ok
11:08:23.0003 4632 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:08:23.0006 4632 MsRPC - ok
11:08:23.0012 4632 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
11:08:23.0014 4632 mssmbios - ok
11:08:23.0056 4632 MSSQL$NMP - ok
11:08:23.0081 4632 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
11:08:23.0081 4632 MSSQLServerADHelper - ok
11:08:23.0097 4632 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:08:23.0097 4632 MSTEE - ok
11:08:23.0097 4632 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
11:08:23.0097 4632 MTConfig - ok
11:08:23.0113 4632 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
11:08:23.0113 4632 Mup - ok
11:08:23.0128 4632 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
11:08:23.0128 4632 napagent - ok
11:08:23.0144 4632 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:08:23.0144 4632 NativeWifiP - ok
11:08:23.0191 4632 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:08:23.0206 4632 NDIS - ok
11:08:23.0222 4632 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:08:23.0222 4632 NdisCap - ok
11:08:23.0222 4632 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:08:23.0237 4632 NdisTapi - ok
11:08:23.0237 4632 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:08:23.0237 4632 Ndisuio - ok
11:08:23.0253 4632 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:08:23.0269 4632 NdisWan - ok
11:08:23.0269 4632 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:08:23.0269 4632 NDProxy - ok
11:08:23.0284 4632 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:08:23.0284 4632 NetBIOS - ok
11:08:23.0300 4632 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:08:23.0300 4632 NetBT - ok
11:08:23.0318 4632 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
11:08:23.0320 4632 Netlogon - ok
11:08:23.0343 4632 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
11:08:23.0348 4632 Netman - ok
11:08:23.0366 4632 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
11:08:23.0374 4632 netprofm - ok
11:08:23.0388 4632 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:08:23.0390 4632 NetTcpPortSharing - ok
11:08:23.0410 4632 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
11:08:23.0412 4632 nfrd960 - ok
11:08:23.0419 4632 [ 832E098BCA8235436FE2D8AE50AC3718 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
11:08:23.0421 4632 NisDrv - ok
11:08:23.0433 4632 [ E570ECA850F30EB740C2E9699DF3D2BD ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
11:08:23.0437 4632 NisSrv - ok
11:08:23.0449 4632 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
11:08:23.0453 4632 NlaSvc - ok
11:08:23.0458 4632 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:08:23.0460 4632 Npfs - ok
11:08:23.0475 4632 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
11:08:23.0478 4632 nsi - ok
11:08:23.0483 4632 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:08:23.0484 4632 nsiproxy - ok
11:08:23.0540 4632 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:08:23.0554 4632 Ntfs - ok
11:08:23.0589 4632 NTP - ok
11:08:23.0655 4632 [ AFEFA4A7DAB65DA3FBEB6EC7B01E7D42 ] ntrtscan c:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
11:08:23.0664 4632 ntrtscan - ok
11:08:23.0669 4632 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
11:08:23.0671 4632 Null - ok
11:08:23.0694 4632 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:08:23.0697 4632 nvraid - ok
11:08:23.0714 4632 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:08:23.0717 4632 nvstor - ok
11:08:23.0739 4632 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:08:23.0742 4632 nv_agp - ok
11:08:23.0779 4632 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
11:08:23.0785 4632 odserv - ok
11:08:23.0818 4632 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
11:08:23.0820 4632 ohci1394 - ok
11:08:23.0843 4632 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:08:23.0846 4632 ose - ok
11:08:23.0947 4632 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:08:23.0972 4632 osppsvc - ok
11:08:24.0012 4632 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:08:24.0017 4632 p2pimsvc - ok
11:08:24.0029 4632 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
11:08:24.0035 4632 p2psvc - ok
11:08:24.0053 4632 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:08:24.0054 4632 Parport - ok
11:08:24.0071 4632 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:08:24.0072 4632 partmgr - ok
11:08:24.0089 4632 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
11:08:24.0091 4632 Parvdm - ok
11:08:24.0100 4632 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:08:24.0104 4632 PcaSvc - ok
11:08:24.0112 4632 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
11:08:24.0115 4632 pci - ok
11:08:24.0131 4632 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
11:08:24.0133 4632 pciide - ok
11:08:24.0139 4632 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
11:08:24.0143 4632 pcmcia - ok
11:08:24.0148 4632 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
11:08:24.0150 4632 pcw - ok
11:08:24.0175 4632 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:08:24.0182 4632 PEAUTH - ok
11:08:24.0226 4632 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
11:08:24.0260 4632 pla - ok
11:08:24.0295 4632 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:08:24.0301 4632 PlugPlay - ok
11:08:24.0305 4632 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:08:24.0308 4632 PNRPAutoReg - ok
11:08:24.0314 4632 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:08:24.0317 4632 PNRPsvc - ok
11:08:24.0328 4632 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:08:24.0335 4632 PolicyAgent - ok
11:08:24.0355 4632 postgresql-8.4 - ok
11:08:24.0361 4632 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
11:08:24.0365 4632 Power - ok
11:08:24.0370 4632 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:08:24.0372 4632 PptpMiniport - ok
11:08:24.0385 4632 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
11:08:24.0387 4632 Processor - ok
11:08:24.0406 4632 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
11:08:24.0409 4632 ProfSvc - ok
11:08:24.0414 4632 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:08:24.0416 4632 ProtectedStorage - ok
11:08:24.0423 4632 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:08:24.0425 4632 Psched - ok
11:08:24.0442 4632 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
11:08:24.0444 4632 PxHelp20 - ok
11:08:24.0474 4632 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
11:08:24.0501 4632 ql2300 - ok
11:08:24.0512 4632 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
11:08:24.0515 4632 ql40xx - ok
11:08:24.0524 4632 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
11:08:24.0529 4632 QWAVE - ok
11:08:24.0545 4632 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:08:24.0546 4632 QWAVEdrv - ok
11:08:24.0571 4632 [ 8F97D374AD1857E1EED85A79F29A1D3D ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
11:08:24.0573 4632 RapiMgr - ok
11:08:24.0578 4632 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:08:24.0580 4632 RasAcd - ok
11:08:24.0591 4632 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:08:24.0592 4632 RasAgileVpn - ok
11:08:24.0606 4632 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
11:08:24.0610 4632 RasAuto - ok
11:08:24.0616 4632 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:08:24.0617 4632 Rasl2tp - ok
11:08:24.0650 4632 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
11:08:24.0655 4632 RasMan - ok
11:08:24.0660 4632 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:08:24.0662 4632 RasPppoe - ok
11:08:24.0668 4632 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:08:24.0670 4632 RasSstp - ok
11:08:24.0680 4632 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:08:24.0683 4632 rdbss - ok
11:08:24.0688 4632 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:08:24.0690 4632 rdpbus - ok
11:08:24.0694 4632 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:08:24.0695 4632 RDPCDD - ok
11:08:24.0702 4632 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:08:24.0703 4632 RDPENCDD - ok
11:08:24.0709 4632 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:08:24.0710 4632 RDPREFMP - ok
11:08:24.0727 4632 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:08:24.0730 4632 RDPWD - ok
11:08:24.0740 4632 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:08:24.0742 4632 rdyboost - ok
11:08:24.0763 4632 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
11:08:24.0766 4632 RemoteAccess - ok
11:08:24.0772 4632 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:08:24.0776 4632 RemoteRegistry - ok
11:08:24.0784 4632 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
11:08:24.0786 4632 RFCOMM - ok
11:08:24.0791 4632 [ 0F6756EF8BDA6DFA7BE50465C83132BB ] RimUsb C:\Windows\system32\Drivers\RimUsb.sys
11:08:24.0792 4632 RimUsb - ok
11:08:24.0835 4632 [ BDDC447AB46625A54619808575D5CB46 ] RoxMediaDB12OEM C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
11:08:24.0847 4632 RoxMediaDB12OEM - ok
11:08:24.0857 4632 [ CE203243ADF512540249DF9C264F12DD ] RoxWatch12 C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
11:08:24.0859 4632 RoxWatch12 - ok
11:08:24.0864 4632 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:08:24.0868 4632 RpcEptMapper - ok
11:08:24.0886 4632 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
11:08:24.0889 4632 RpcLocator - ok
11:08:24.0902 4632 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
11:08:24.0906 4632 RpcSs - ok
11:08:24.0922 4632 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:08:24.0924 4632 rspndr - ok
11:08:24.0940 4632 [ 31D45ECA63884FF5F7AECC50F7D1BAE0 ] RSUSBSTOR C:\Windows\system32\Drivers\RtsUStor.sys
11:08:24.0943 4632 RSUSBSTOR - ok
11:08:24.0972 4632 [ 5283B9A27FF230F2FF70D92451FF409A ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
11:08:24.0977 4632 RTL8167 - ok
11:08:24.0982 4632 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
11:08:24.0985 4632 SamSs - ok
11:08:25.0010 4632 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:08:25.0012 4632 sbp2port - ok
11:08:25.0045 4632 [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
11:08:25.0058 4632 SBSDWSCService - ok
11:08:25.0076 4632 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:08:25.0080 4632 SCardSvr - ok
11:08:25.0085 4632 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:08:25.0087 4632 scfilter - ok
11:08:25.0109 4632 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
11:08:25.0119 4632 Schedule - ok
11:08:25.0125 4632 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
11:08:25.0126 4632 SCPolicySvc - ok
11:08:25.0149 4632 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:08:25.0153 4632 SDRSVC - ok
11:08:25.0158 4632 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:08:25.0159 4632 secdrv - ok
11:08:25.0164 4632 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
11:08:25.0168 4632 seclogon - ok
11:08:25.0173 4632 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
11:08:25.0176 4632 SENS - ok
11:08:25.0182 4632 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:08:25.0185 4632 SensrSvc - ok
11:08:25.0202 4632 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:08:25.0203 4632 Serenum - ok
11:08:25.0224 4632 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:08:25.0226 4632 Serial - ok
11:08:25.0246 4632 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:08:25.0248 4632 sermouse - ok
11:08:25.0261 4632 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
11:08:25.0265 4632 SessionEnv - ok
11:08:25.0272 4632 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:08:25.0273 4632 sffdisk - ok
11:08:25.0278 4632 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:08:25.0279 4632 sffp_mmc - ok
11:08:25.0289 4632 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:08:25.0290 4632 sffp_sd - ok
11:08:25.0309 4632 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:08:25.0311 4632 sfloppy - ok
11:08:25.0334 4632 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:08:25.0339 4632 SharedAccess - ok
11:08:25.0357 4632 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:08:25.0363 4632 ShellHWDetection - ok
11:08:25.0380 4632 [ C3075617DB699CDC9184A02AFD4D7928 ] SilentHerdsman c:\SilentHerdsman\services\JavaService.exe
11:08:25.0381 4632 SilentHerdsman - ok
11:08:25.0397 4632 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
11:08:25.0399 4632 sisagp - ok
11:08:25.0409 4632 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:08:25.0411 4632 SiSRaid2 - ok
11:08:25.0424 4632 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:08:25.0426 4632 SiSRaid4 - ok
11:08:25.0495 4632 [ 388AE59FE75F1B959DFA0900923C61BB ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
11:08:25.0511 4632 Skype C2C Service - ok
11:08:25.0561 4632 [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
11:08:25.0564 4632 SkypeUpdate - ok
11:08:25.0569 4632 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:08:25.0571 4632 Smb - ok
11:08:25.0585 4632 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:08:25.0588 4632 SNMPTRAP - ok
11:08:25.0592 4632 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
11:08:25.0594 4632 spldr - ok
11:08:25.0609 4632 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
11:08:25.0612 4632 Spooler - ok
11:08:25.0672 4632 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
11:08:25.0690 4632 sppsvc - ok
11:08:25.0696 4632 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:08:25.0700 4632 sppuinotify - ok
11:08:25.0708 4632 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
11:08:25.0711 4632 SQLBrowser - ok
11:08:25.0718 4632 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
11:08:25.0720 4632 SQLWriter - ok
11:08:25.0728 4632 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
11:08:25.0732 4632 srv - ok
11:08:25.0757 4632 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:08:25.0761 4632 srv2 - ok
11:08:25.0779 4632 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:08:25.0781 4632 srvnet - ok
11:08:25.0789 4632 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:08:25.0793 4632 SSDPSRV - ok
11:08:25.0801 4632 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:08:25.0804 4632 SstpSvc - ok
11:08:25.0875 4632 [ FBAA145C28074C853529050914D405C6 ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
11:08:25.0877 4632 STacSV - ok
11:08:25.0883 4632 [ 1E72739A30A0D3E3FC95EBB07F83912D ] stdcfltn C:\Windows\system32\DRIVERS\stdcfltn.sys
11:08:25.0885 4632 stdcfltn - ok
11:08:25.0903 4632 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:08:25.0905 4632 stexstor - ok
11:08:25.0931 4632 [ 06CBB271F42EF70FB6EF372C491BA9AA ] STHDA C:\Windows\system32\DRIVERS\stwrt.sys
11:08:25.0936 4632 STHDA - ok
11:08:25.0982 4632 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
11:08:25.0989 4632 StiSvc - ok
11:08:26.0013 4632 [ 9E182DD94496550A22A392CC1A8E0F52 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
11:08:26.0047 4632 stllssvr - ok
11:08:26.0061 4632 [ 01FBCC8F2C30EB1FAF9A477FA53C6655 ] svcGenericHost c:\Program Files\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe
11:08:26.0062 4632 svcGenericHost - ok
11:08:26.0075 4632 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
11:08:26.0076 4632 swenum - ok
11:08:26.0088 4632 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
11:08:26.0093 4632 swprv - ok
11:08:26.0124 4632 [ CF196A45FD61118C95585489FAD5B2AA ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
11:08:26.0127 4632 SynTP - ok
11:08:26.0158 4632 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
11:08:26.0172 4632 SysMain - ok
11:08:26.0177 4632 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:08:26.0181 4632 TabletInputService - ok
11:08:26.0190 4632 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
11:08:26.0195 4632 TapiSrv - ok
11:08:26.0202 4632 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
11:08:26.0204 4632 TBS - ok
11:08:26.0236 4632 [ 7C0507D2391AF5933600CBCED799F277 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:08:26.0262 4632 Tcpip - ok
11:08:26.0294 4632 [ 7C0507D2391AF5933600CBCED799F277 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:08:26.0301 4632 TCPIP6 - ok
11:08:26.0309 4632 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:08:26.0311 4632 tcpipreg - ok
11:08:26.0328 4632 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:08:26.0330 4632 TDPIPE - ok
11:08:26.0335 4632 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:08:26.0336 4632 TDTCP - ok
11:08:26.0348 4632 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:08:26.0350 4632 tdx - ok
11:08:26.0511 4632 [ 7C8DD5576695B3362202EF09B20C425E ] TeamViewer8 C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
11:08:26.0530 4632 TeamViewer8 - ok
11:08:26.0565 4632 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
11:08:26.0566 4632 TermDD - ok
11:08:26.0589 4632 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
11:08:26.0596 4632 TermService - ok
11:08:26.0603 4632 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
11:08:26.0606 4632 Themes - ok
11:08:26.0619 4632 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
11:08:26.0621 4632 THREADORDER - ok
11:08:26.0627 4632 [ CA9E9C2C04A198ED345C1752222A5F3E ] tmactmon C:\Windows\system32\DRIVERS\tmactmon.sys
11:08:26.0628 4632 tmactmon - ok
11:08:26.0646 4632 [ 4D69206E3A3E665221FDD7E397106405 ] TMBMServer c:\Program Files\Trend Micro\BM\TMBMSRV.exe
11:08:26.0650 4632 TMBMServer - ok
11:08:26.0667 4632 [ A3D20789B3FF0576A29462BEF25BCFCC ] tmcomm C:\Windows\system32\DRIVERS\tmcomm.sys
11:08:26.0670 4632 tmcomm - ok
11:08:26.0681 4632 [ 21F215E54770C4BF93EFAF63F58FE57E ] tmevtmgr C:\Windows\system32\DRIVERS\tmevtmgr.sys
11:08:26.0682 4632 tmevtmgr - ok
11:08:26.0692 4632 [ 1D84C335EB869BBE64543C6945A1F3C9 ] TmFilter c:\Program Files\Trend Micro\Client Server Security Agent\TmXPFlt.sys
11:08:26.0765 4632 TmFilter - ok
11:08:26.0813 4632 [ 3062BAB9C0F90577674BC2D006EB9EFA ] tmlisten c:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
11:08:26.0822 4632 tmlisten - ok
11:08:26.0848 4632 [ 4E87D02E56E9B1AF831C5D521597D629 ] tmlwf C:\Windows\system32\DRIVERS\tmlwf.sys
11:08:26.0851 4632 tmlwf - ok
11:08:26.0867 4632 [ 255328CF08D602368B69FF1F55EBD93E ] TmPfw c:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
11:08:26.0870 4632 TmPfw - ok
11:08:26.0885 4632 [ 7AAB3FEF8B19AE023EE05386F1B0A5DD ] TmPreFilter c:\Program Files\Trend Micro\Client Server Security Agent\TmPreFlt.sys
11:08:26.0912 4632 TmPreFilter - ok
11:08:26.0951 4632 [ 0FEC6C50B2BE07C57651573CDD1C721F ] TmProxy c:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe
11:08:26.0957 4632 TmProxy - ok
11:08:26.0970 4632 [ 44C262C1B2412DED35078B6166D2ACC2 ] tmtdi C:\Windows\system32\DRIVERS\tmtdi.sys
11:08:26.0972 4632 tmtdi - ok
11:08:26.0992 4632 [ D9882FD91B7C4C35ACAA8498D1F3CD68 ] tmwfp C:\Windows\system32\DRIVERS\tmwfp.sys
11:08:26.0996 4632 tmwfp - ok
11:08:27.0003 4632 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
11:08:27.0006 4632 TrkWks - ok
11:08:27.0015 4632 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:08:27.0018 4632 TrustedInstaller - ok
11:08:27.0026 4632 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:08:27.0027 4632 tssecsrv - ok
11:08:27.0054 4632 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:08:27.0056 4632 TsUsbFlt - ok
11:08:27.0075 4632 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:08:27.0077 4632 tunnel - ok
11:08:27.0084 4632 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:08:27.0085 4632 uagp35 - ok
11:08:27.0108 4632 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:08:27.0111 4632 udfs - ok
11:08:27.0122 4632 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:08:27.0125 4632 UI0Detect - ok
11:08:27.0137 4632 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:08:27.0138 4632 uliagpkx - ok
11:08:27.0164 4632 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
11:08:27.0166 4632 umbus - ok
11:08:27.0171 4632 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:08:27.0172 4632 UmPass - ok
11:08:27.0241 4632 [ 9E89C2D6945389270DE067CE51FF7425 ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
11:08:27.0254 4632 UNS - ok
11:08:27.0268 4632 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
11:08:27.0273 4632 upnphost - ok
11:08:27.0279 4632 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:08:27.0281 4632 usbccgp - ok
11:08:27.0296 4632 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:08:27.0298 4632 usbcir - ok
11:08:27.0303 4632 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\drivers\usbehci.sys
11:08:27.0305 4632 usbehci - ok
11:08:27.0314 4632 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:08:27.0318 4632 usbhub - ok
11:08:27.0322 4632 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
11:08:27.0324 4632 usbohci - ok
11:08:27.0329 4632 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:08:27.0331 4632 usbprint - ok
11:08:27.0337 4632 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
11:08:27.0338 4632 usbscan - ok
11:08:27.0354 4632 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:08:27.0356 4632 USBSTOR - ok
11:08:27.0371 4632 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
11:08:27.0372 4632 usbuhci - ok
11:08:27.0381 4632 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
11:08:27.0384 4632 usbvideo - ok
11:08:27.0390 4632 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
11:08:27.0393 4632 UxSms - ok
11:08:27.0398 4632 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
11:08:27.0400 4632 VaultSvc - ok
11:08:27.0405 4632 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:08:27.0407 4632 vdrvroot - ok
11:08:27.0429 4632 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
11:08:27.0436 4632 vds - ok
11:08:27.0453 4632 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:08:27.0454 4632 vga - ok
11:08:27.0459 4632 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
11:08:27.0461 4632 VgaSave - ok
11:08:27.0469 4632 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:08:27.0472 4632 vhdmp - ok
11:08:27.0497 4632 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
11:08:27.0499 4632 viaagp - ok
11:08:27.0504 4632 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
11:08:27.0506 4632 ViaC7 - ok
11:08:27.0520 4632 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
11:08:27.0522 4632 viaide - ok
11:08:27.0527 4632 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:08:27.0529 4632 volmgr - ok
11:08:27.0541 4632 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:08:27.0545 4632 volmgrx - ok
11:08:27.0554 4632 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:08:27.0558 4632 volsnap - ok
11:08:27.0593 4632 [ 8B9325C1D1167A703042986DF758D799 ] VSApiNt c:\Program Files\Trend Micro\Client Server Security Agent\VSApiNt.sys
11:08:27.0665 4632 VSApiNt - ok
11:08:27.0692 4632 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:08:27.0695 4632 vsmraid - ok
11:08:27.0723 4632 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
11:08:27.0736 4632 VSS - ok
11:08:27.0741 4632 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
11:08:27.0743 4632 vwifibus - ok
11:08:27.0749 4632 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
11:08:27.0751 4632 vwififlt - ok
11:08:27.0763 4632 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
11:08:27.0765 4632 vwifimp - ok
11:08:27.0778 4632 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
11:08:27.0785 4632 W32Time - ok
11:08:27.0800 4632 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:08:27.0801 4632 WacomPen - ok
11:08:27.0807 4632 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:08:27.0809 4632 WANARP - ok
11:08:27.0812 4632 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:08:27.0813 4632 Wanarpv6 - ok
11:08:27.0868 4632 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:08:27.0894 4632 WatAdminSvc - ok
11:08:27.0928 4632 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
11:08:27.0954 4632 wbengine - ok
11:08:27.0962 4632 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:08:27.0967 4632 WbioSrvc - ok
11:08:28.0003 4632 [ 59E19BD13C3BDB857646B9E436BA27F7 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
11:08:28.0007 4632 WcesComm - ok
11:08:28.0025 4632 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:08:28.0031 4632 wcncsvc - ok
11:08:28.0039 4632 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:08:28.0042 4632 WcsPlugInService - ok
11:08:28.0049 4632 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:08:28.0050 4632 Wd - ok
11:08:28.0097 4632 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:08:28.0104 4632 Wdf01000 - ok
11:08:28.0120 4632 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:08:28.0124 4632 WdiServiceHost - ok
11:08:28.0128 4632 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:08:28.0131 4632 WdiSystemHost - ok
11:08:28.0140 4632 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
11:08:28.0149 4632 WebClient - ok
11:08:28.0160 4632 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:08:28.0160 4632 Wecsvc - ok
11:08:28.0175 4632 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:08:28.0175 4632 wercplsupport - ok
11:08:28.0191 4632 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
11:08:28.0191 4632 WerSvc - ok
11:08:28.0191 4632 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:08:28.0191 4632 WfpLwf - ok
11:08:28.0207 4632 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:08:28.0207 4632 WIMMount - ok
11:08:28.0238 4632 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:08:28.0238 4632 WinDefend - ok
11:08:28.0253 4632 WinHttpAutoProxySvc - ok
11:08:28.0269 4632 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:08:28.0285 4632 Winmgmt - ok
11:08:28.0316 4632 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
11:08:28.0347 4632 WinRM - ok
11:08:28.0363 4632 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
11:08:28.0378 4632 WinUsb - ok
11:08:28.0394 4632 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:08:28.0413 4632 Wlansvc - ok
11:08:28.0431 4632 [ 6067ACEF367E79914AF628FA1E9B5330 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
11:08:28.0434 4632 wlcrasvc - ok
11:08:28.0480 4632 [ 0A70F4022EC2E14C159EFC4F69AA2477 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
11:08:28.0489 4632 wlidsvc - ok
11:08:28.0508 4632 [ 7FFF34AE69DFB80F7B190ABA31E00610 ] wltrysvc C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
11:08:28.0509 4632 wltrysvc - ok
11:08:28.0527 4632 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:08:28.0528 4632 WmiAcpi - ok
11:08:28.0548 4632 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:08:28.0551 4632 wmiApSrv - ok
11:08:28.0587 4632 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:08:28.0593 4632 WMPNetworkSvc - ok
11:08:28.0607 4632 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:08:28.0611 4632 WPCSvc - ok
11:08:28.0620 4632 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:08:28.0623 4632 WPDBusEnum - ok
11:08:28.0628 4632 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:08:28.0630 4632 ws2ifsl - ok
11:08:28.0644 4632 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
11:08:28.0653 4632 wscsvc - ok
11:08:28.0657 4632 WSearch - ok
11:08:28.0714 4632 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
11:08:28.0757 4632 wuauserv - ok
11:08:28.0790 4632 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:08:28.0791 4632 WudfPf - ok
11:08:28.0813 4632 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:08:28.0815 4632 WUDFRd - ok
11:08:28.0822 4632 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:08:28.0826 4632 wudfsvc - ok
11:08:28.0835 4632 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
11:08:28.0840 4632 WwanSvc - ok
11:08:28.0852 4632 ================ Scan global ===============================
11:08:28.0861 4632 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
11:08:28.0885 4632 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
11:08:28.0893 4632 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
11:08:28.0901 4632 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
11:08:28.0926 4632 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
11:08:28.0930 4632 [Global] - ok
11:08:28.0931 4632 ================ Scan MBR ==================================
11:08:28.0947 4632 [ CDB4DE4BBD714F152979DA2DCBEF57EB ] \Device\Harddisk0\DR0
11:08:29.0204 4632 \Device\Harddisk0\DR0 - ok
11:08:29.0205 4632 ================ Scan VBR ==================================

Newson 25.05.2013 08:36

Zweite Halfte:


11:08:29.0207 4632 [ 45FD117738263C35344EBD657EBF809A ] \Device\Harddisk0\DR0\Partition1
11:08:29.0208 4632 \Device\Harddisk0\DR0\Partition1 - ok
11:08:29.0213 4632 [ 1A7CCBAF7849D00F720F22AFF41F240E ] \Device\Harddisk0\DR0\Partition2
11:08:29.0214 4632 \Device\Harddisk0\DR0\Partition2 - ok
11:08:29.0217 4632 [ 598D13034BF0D21259BF25EFD891BFD8 ] \Device\Harddisk0\DR0\Partition3
11:08:29.0219 4632 \Device\Harddisk0\DR0\Partition3 - ok
11:08:29.0219 4632 ============================================================
11:08:29.0219 4632 Scan finished
11:08:29.0219 4632 ============================================================
11:08:29.0229 6884 Detected object count: 0
11:08:29.0229 6884 Actual detected object count: 0
11:20:07.0920 6920 ============================================================
11:20:07.0920 6920 Scan started
11:20:07.0920 6920 Mode: Manual; SigCheck; TDLFS;
11:20:07.0920 6920 ============================================================
11:20:08.0232 6920 ================ Scan system memory ========================
11:20:08.0232 6920 System memory - ok
11:20:08.0232 6920 ================ Scan services =============================
11:20:08.0450 6920 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
11:20:08.0528 6920 1394ohci - ok
11:20:08.0544 6920 [ C351EB0DEB102D7EC67CDDEE6513DDF5 ] Acceler C:\Windows\system32\DRIVERS\Accelern.sys
11:20:08.0575 6920 Acceler - ok
11:20:08.0590 6920 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:20:08.0637 6920 ACPI - ok
11:20:08.0653 6920 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
11:20:08.0700 6920 AcpiPmi - ok
11:20:08.0715 6920 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
11:20:08.0746 6920 AdobeARMservice - ok
11:20:08.0762 6920 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
11:20:08.0809 6920 AdobeFlashPlayerUpdateSvc - ok
11:20:08.0840 6920 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
11:20:08.0902 6920 adp94xx - ok
11:20:08.0934 6920 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
11:20:08.0980 6920 adpahci - ok
11:20:08.0996 6920 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
11:20:09.0043 6920 adpu320 - ok
11:20:09.0058 6920 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:20:09.0136 6920 AeLookupSvc - ok
11:20:09.0199 6920 [ 827DBC22C96EECF6D36A13162FABAFD3 ] AESTFilters C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\aestsrv.exe
11:20:09.0230 6920 AESTFilters - ok
11:20:09.0261 6920 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
11:20:09.0308 6920 AFD - ok
11:20:09.0324 6920 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
11:20:09.0355 6920 agp440 - ok
11:20:09.0370 6920 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
11:20:09.0402 6920 aic78xx - ok
11:20:09.0417 6920 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
11:20:09.0464 6920 ALG - ok
11:20:09.0464 6920 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
11:20:09.0495 6920 aliide - ok
11:20:09.0573 6920 ALSysIO - ok
11:20:09.0573 6920 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
11:20:09.0604 6920 amdagp - ok
11:20:09.0620 6920 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
11:20:09.0651 6920 amdide - ok
11:20:09.0667 6920 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
11:20:09.0714 6920 AmdK8 - ok
11:20:09.0714 6920 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
11:20:09.0760 6920 AmdPPM - ok
11:20:09.0776 6920 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:20:09.0807 6920 amdsata - ok
11:20:09.0823 6920 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
11:20:09.0870 6920 amdsbs - ok
11:20:09.0870 6920 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:20:09.0901 6920 amdxata - ok
11:20:09.0916 6920 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
11:20:09.0994 6920 AppID - ok
11:20:10.0010 6920 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:20:10.0088 6920 AppIDSvc - ok
11:20:10.0088 6920 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
11:20:10.0135 6920 Appinfo - ok
11:20:10.0150 6920 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
11:20:10.0182 6920 arc - ok
11:20:10.0197 6920 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
11:20:10.0228 6920 arcsas - ok
11:20:10.0260 6920 [ 39CDCB109BF200CC8A05B9C7E6272D11 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
11:20:10.0291 6920 aspnet_state - ok
11:20:10.0291 6920 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:20:10.0384 6920 AsyncMac - ok
11:20:10.0384 6920 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
11:20:10.0431 6920 atapi - ok
11:20:10.0447 6920 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:20:10.0540 6920 AudioEndpointBuilder - ok
11:20:10.0572 6920 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
11:20:10.0665 6920 Audiosrv - ok
11:20:10.0681 6920 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:20:10.0743 6920 AxInstSV - ok
11:20:10.0759 6920 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
11:20:10.0821 6920 b06bdrv - ok
11:20:10.0837 6920 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
11:20:10.0884 6920 b57nd60x - ok
11:20:10.0899 6920 [ 94F2DC372163D520D7B1DAD78AE40B5E ] BCM42RLY C:\Windows\system32\drivers\BCM42RLY.sys
11:20:10.0930 6920 BCM42RLY - ok
11:20:11.0008 6920 [ F689C5965CEFAD780A2948546703BD5D ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
11:20:11.0164 6920 BCM43XX - ok
11:20:11.0180 6920 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
11:20:11.0227 6920 BDESVC - ok
11:20:11.0227 6920 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
11:20:11.0305 6920 Beep - ok
11:20:11.0336 6920 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
11:20:11.0445 6920 BFE - ok
11:20:11.0461 6920 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
11:20:11.0570 6920 BITS - ok
11:20:11.0586 6920 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:20:11.0648 6920 blbdrive - ok
11:20:11.0648 6920 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:20:11.0695 6920 bowser - ok
11:20:11.0710 6920 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:20:11.0757 6920 BrFiltLo - ok
11:20:11.0773 6920 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:20:11.0820 6920 BrFiltUp - ok
11:20:11.0835 6920 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
11:20:11.0882 6920 Browser - ok
11:20:11.0913 6920 [ 08C7E41FF10F56E83B4F10B5E8B1E8B6 ] BrSerIb C:\Windows\system32\DRIVERS\BrSerIb.sys
11:20:11.0960 6920 BrSerIb - ok
11:20:11.0991 6920 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:20:12.0038 6920 Brserid - ok
11:20:12.0054 6920 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:20:12.0116 6920 BrSerWdm - ok
11:20:12.0116 6920 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:20:12.0163 6920 BrUsbMdm - ok
11:20:12.0178 6920 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:20:12.0210 6920 BrUsbSer - ok
11:20:12.0225 6920 [ 2132A117160F2A96A13C044AE9BCED91 ] BrUsbSIb C:\Windows\system32\DRIVERS\BrUsbSIb.sys
11:20:12.0272 6920 BrUsbSIb - ok
11:20:12.0288 6920 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
11:20:12.0334 6920 BthEnum - ok
11:20:12.0334 6920 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
11:20:12.0381 6920 BTHMODEM - ok
11:20:12.0397 6920 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
11:20:12.0444 6920 BthPan - ok
11:20:12.0475 6920 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
11:20:12.0522 6920 BTHPORT - ok
11:20:12.0537 6920 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
11:20:12.0631 6920 bthserv - ok
11:20:12.0631 6920 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
11:20:12.0678 6920 BTHUSB - ok
11:20:12.0693 6920 [ 7E826BE3B3558208D5C9B00034E51BE5 ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
11:20:12.0724 6920 btwaudio - ok
11:20:12.0724 6920 [ AF9148C3E844131AC954CB53FF43D971 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
11:20:12.0771 6920 btwavdt - ok
11:20:12.0802 6920 [ 45F36763576B8AE91E809337DC7CE4E6 ] btwdins c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
11:20:12.0849 6920 btwdins - ok
11:20:12.0865 6920 [ AAFD7CB76BA61FBB08E302DA208C974A ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
11:20:12.0896 6920 btwl2cap - ok
11:20:12.0896 6920 [ 480B3D195854B2E55299CDDDDC50BCF9 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
11:20:12.0927 6920 btwrchid - ok
11:20:12.0943 6920 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:20:13.0021 6920 cdfs - ok
11:20:13.0036 6920 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
11:20:13.0083 6920 cdrom - ok
11:20:13.0099 6920 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
11:20:13.0177 6920 CertPropSvc - ok
11:20:13.0192 6920 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
11:20:13.0239 6920 circlass - ok
11:20:13.0255 6920 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
11:20:13.0302 6920 CLFS - ok
11:20:13.0317 6920 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:20:13.0348 6920 clr_optimization_v2.0.50727_32 - ok
11:20:13.0364 6920 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:20:13.0411 6920 clr_optimization_v4.0.30319_32 - ok
11:20:13.0411 6920 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:20:13.0458 6920 CmBatt - ok
11:20:13.0473 6920 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:20:13.0504 6920 cmdide - ok
11:20:13.0536 6920 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
11:20:13.0598 6920 CNG - ok
11:20:13.0614 6920 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
11:20:13.0645 6920 Compbatt - ok
11:20:13.0660 6920 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
11:20:13.0707 6920 CompositeBus - ok
11:20:13.0707 6920 COMSysApp - ok
11:20:13.0723 6920 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
11:20:13.0770 6920 crcdisk - ok
11:20:13.0785 6920 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:20:13.0832 6920 CryptSvc - ok
11:20:13.0848 6920 [ 0F538DF1673E5216F3BAACB6911D9D0F ] CtAudDrv C:\Windows\system32\Drivers\CtAudDrv.sys
11:20:13.0879 6920 CtAudDrv - ok
11:20:13.0894 6920 [ CEBA8413F9B2C73A4E9E16DBD127DC25 ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys
11:20:13.0941 6920 CtClsFlt - ok
11:20:13.0957 6920 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
11:20:14.0050 6920 DcomLaunch - ok
11:20:14.0066 6920 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
11:20:14.0160 6920 defragsvc - ok
11:20:14.0175 6920 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:20:14.0269 6920 DfsC - ok
11:20:14.0269 6920 [ F9F31A9F2A8C0DD0CEB6E380BF0985D4 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys
11:20:14.0316 6920 dg_ssudbus - ok
11:20:14.0331 6920 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
11:20:14.0378 6920 Dhcp - ok
11:20:14.0378 6920 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
11:20:14.0472 6920 discache - ok
11:20:14.0487 6920 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
11:20:14.0518 6920 Disk - ok
11:20:14.0534 6920 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:20:14.0581 6920 Dnscache - ok
11:20:14.0612 6920 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
11:20:14.0706 6920 dot3svc - ok
11:20:14.0721 6920 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
11:20:14.0799 6920 DPS - ok
11:20:14.0815 6920 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:20:14.0846 6920 drmkaud - ok
11:20:14.0893 6920 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:20:14.0955 6920 DXGKrnl - ok
11:20:14.0971 6920 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
11:20:15.0080 6920 EapHost - ok
11:20:15.0174 6920 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
11:20:15.0314 6920 ebdrv - ok
11:20:15.0330 6920 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
11:20:15.0376 6920 EFS - ok
11:20:15.0408 6920 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
11:20:15.0470 6920 ehRecvr - ok
11:20:15.0486 6920 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
11:20:15.0532 6920 ehSched - ok
11:20:15.0564 6920 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
11:20:15.0610 6920 elxstor - ok
11:20:15.0626 6920 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:20:15.0657 6920 ErrDev - ok
11:20:15.0688 6920 [ C3075617DB699CDC9184A02AFD4D7928 ] ETSWatchdog c:\SilentHerdsman\services\JavaService.exe
11:20:15.0704 6920 ETSWatchdog ( UnsignedFile.Multi.Generic ) - warning
11:20:15.0704 6920 ETSWatchdog - detected UnsignedFile.Multi.Generic (1)
11:20:15.0720 6920 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
11:20:15.0829 6920 EventSystem - ok
11:20:15.0829 6920 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
11:20:15.0938 6920 exfat - ok
11:20:15.0954 6920 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:20:16.0047 6920 fastfat - ok
11:20:16.0078 6920 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
11:20:16.0141 6920 Fax - ok
11:20:16.0156 6920 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
11:20:16.0203 6920 fdc - ok
11:20:16.0203 6920 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
11:20:16.0297 6920 fdPHost - ok
11:20:16.0312 6920 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
11:20:16.0390 6920 FDResPub - ok
11:20:16.0406 6920 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:20:16.0437 6920 FileInfo - ok
11:20:16.0453 6920 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:20:16.0546 6920 Filetrace - ok
11:20:16.0562 6920 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
11:20:16.0609 6920 flpydisk - ok
11:20:16.0624 6920 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:20:16.0671 6920 FltMgr - ok
11:20:16.0718 6920 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
11:20:16.0796 6920 FontCache - ok
11:20:16.0812 6920 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:20:16.0843 6920 FontCache3.0.0.0 - ok
11:20:16.0858 6920 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:20:16.0890 6920 FsDepends - ok
11:20:16.0905 6920 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:20:16.0936 6920 Fs_Rec - ok
11:20:16.0952 6920 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:20:16.0999 6920 fvevol - ok
11:20:17.0014 6920 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
11:20:17.0046 6920 gagp30kx - ok
11:20:17.0077 6920 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
11:20:17.0186 6920 gpsvc - ok
11:20:17.0202 6920 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
11:20:17.0233 6920 gupdate - ok
11:20:17.0248 6920 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
11:20:17.0280 6920 gupdatem - ok
11:20:17.0295 6920 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
11:20:17.0326 6920 gusvc - ok
11:20:17.0342 6920 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:20:17.0389 6920 hcw85cir - ok
11:20:17.0404 6920 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
11:20:17.0451 6920 HDAudBus - ok
11:20:17.0451 6920 [ A88485DC6A7136C10D9A6C7E38FDFE3C ] HECI C:\Windows\system32\DRIVERS\HECI.sys
11:20:17.0498 6920 HECI - ok
11:20:17.0498 6920 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
11:20:17.0545 6920 HidBatt - ok
11:20:17.0560 6920 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
11:20:17.0607 6920 HidBth - ok
11:20:17.0607 6920 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
11:20:17.0670 6920 HidIr - ok
11:20:17.0670 6920 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
11:20:17.0763 6920 hidserv - ok
11:20:17.0763 6920 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
11:20:17.0810 6920 HidUsb - ok
11:20:17.0810 6920 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:20:17.0888 6920 hkmsvc - ok
11:20:17.0904 6920 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:20:17.0950 6920 HomeGroupListener - ok
11:20:17.0966 6920 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:20:18.0028 6920 HomeGroupProvider - ok
11:20:18.0028 6920 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:20:18.0075 6920 HpSAMD - ok
11:20:18.0106 6920 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:20:18.0200 6920 HTTP - ok
11:20:18.0216 6920 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:20:18.0262 6920 hwpolicy - ok
11:20:18.0262 6920 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
11:20:18.0309 6920 i8042prt - ok
11:20:18.0340 6920 [ 26541A068572F650A2FA490726FE81BE ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
11:20:18.0387 6920 iaStor - ok
11:20:18.0418 6920 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:20:18.0465 6920 iaStorV - ok
11:20:18.0512 6920 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:20:18.0574 6920 idsvc - ok
11:20:18.0808 6920 [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
11:20:19.0120 6920 igfx - ok
11:20:19.0136 6920 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
11:20:19.0167 6920 iirsp - ok
11:20:19.0198 6920 [ C5B04409186A27409BD069580208A6D3 ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
11:20:19.0230 6920 IJPLMSVC - ok
11:20:19.0261 6920 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
11:20:19.0370 6920 IKEEXT - ok
11:20:19.0386 6920 [ E3C36AC5AE87EC970AE8EA2A93D59AE1 ] Impcd C:\Windows\system32\DRIVERS\Impcd.sys
11:20:19.0417 6920 Impcd - ok
11:20:19.0432 6920 [ 07D73EC613B1D3F177B914DC7F5E879B ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
11:20:19.0479 6920 IntcDAud - ok
11:20:19.0495 6920 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
11:20:19.0526 6920 intelide - ok
11:20:19.0542 6920 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:20:19.0573 6920 intelppm - ok
11:20:19.0588 6920 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:20:19.0682 6920 IPBusEnum - ok
11:20:19.0698 6920 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:20:19.0791 6920 IpFilterDriver - ok
11:20:19.0822 6920 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:20:19.0885 6920 iphlpsvc - ok
11:20:19.0900 6920 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
11:20:19.0932 6920 IPMIDRV - ok
11:20:19.0947 6920 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:20:20.0025 6920 IPNAT - ok
11:20:20.0041 6920 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:20:20.0088 6920 IRENUM - ok
11:20:20.0088 6920 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:20:20.0134 6920 isapnp - ok
11:20:20.0150 6920 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
11:20:20.0197 6920 iScsiPrt - ok
11:20:20.0212 6920 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
11:20:20.0244 6920 kbdclass - ok
11:20:20.0259 6920 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
11:20:20.0306 6920 kbdhid - ok
11:20:20.0306 6920 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
11:20:20.0353 6920 KeyIso - ok
11:20:20.0368 6920 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:20:20.0400 6920 KSecDD - ok
11:20:20.0415 6920 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:20:20.0446 6920 KSecPkg - ok
11:20:20.0478 6920 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
11:20:20.0571 6920 KtmRm - ok
11:20:20.0587 6920 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
11:20:20.0665 6920 LanmanServer - ok
11:20:20.0680 6920 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:20:20.0774 6920 LanmanWorkstation - ok
11:20:20.0790 6920 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:20:20.0883 6920 lltdio - ok
11:20:20.0899 6920 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:20:20.0992 6920 lltdsvc - ok
11:20:20.0992 6920 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
11:20:21.0070 6920 lmhosts - ok
11:20:21.0102 6920 [ 5460828F8951D310B42B442877603B8D ] LMS C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:20:21.0133 6920 LMS - ok
11:20:21.0148 6920 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
11:20:21.0195 6920 LSI_FC - ok
11:20:21.0211 6920 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
11:20:21.0242 6920 LSI_SAS - ok
11:20:21.0242 6920 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:20:21.0289 6920 LSI_SAS2 - ok
11:20:21.0304 6920 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:20:21.0336 6920 LSI_SCSI - ok
11:20:21.0351 6920 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
11:20:21.0429 6920 luafv - ok
11:20:21.0445 6920 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
11:20:21.0492 6920 Mcx2Svc - ok
11:20:21.0507 6920 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
11:20:21.0538 6920 megasas - ok
11:20:21.0554 6920 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
11:20:21.0601 6920 MegaSR - ok
11:20:21.0616 6920 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
11:20:21.0726 6920 MMCSS - ok
11:20:21.0741 6920 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
11:20:21.0850 6920 Modem - ok
11:20:21.0850 6920 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:20:21.0897 6920 monitor - ok
11:20:21.0913 6920 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys
11:20:21.0944 6920 mouclass - ok
11:20:21.0960 6920 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:20:22.0006 6920 mouhid - ok
11:20:22.0038 6920 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:20:22.0069 6920 mountmgr - ok
11:20:22.0084 6920 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
11:20:22.0131 6920 MozillaMaintenance - ok
11:20:22.0162 6920 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
11:20:22.0209 6920 MpFilter - ok
11:20:22.0225 6920 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
11:20:22.0256 6920 mpio - ok
11:20:22.0272 6920 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:20:22.0350 6920 mpsdrv - ok
11:20:22.0381 6920 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
11:20:22.0490 6920 MpsSvc - ok
11:20:22.0506 6920 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:20:22.0568 6920 MRxDAV - ok
11:20:22.0584 6920 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:20:22.0615 6920 mrxsmb - ok
11:20:22.0646 6920 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:20:22.0693 6920 mrxsmb10 - ok
11:20:22.0693 6920 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:20:22.0740 6920 mrxsmb20 - ok
11:20:22.0755 6920 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
11:20:22.0786 6920 msahci - ok
11:20:22.0802 6920 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
11:20:22.0833 6920 msdsm - ok
11:20:22.0849 6920 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
11:20:22.0896 6920 MSDTC - ok
11:20:22.0927 6920 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:20:23.0020 6920 Msfs - ok
11:20:23.0036 6920 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:20:23.0130 6920 mshidkmdf - ok
11:20:23.0145 6920 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:20:23.0208 6920 msisadrv - ok
11:20:23.0208 6920 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:20:23.0317 6920 MSiSCSI - ok
11:20:23.0317 6920 msiserver - ok
11:20:23.0332 6920 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:20:23.0426 6920 MSKSSRV - ok
11:20:23.0457 6920 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
11:20:23.0504 6920 MsMpSvc - ok
11:20:23.0504 6920 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:20:23.0598 6920 MSPCLOCK - ok
11:20:23.0598 6920 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:20:23.0707 6920 MSPQM - ok
11:20:23.0722 6920 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:20:23.0754 6920 MsRPC - ok
11:20:23.0785 6920 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
11:20:23.0816 6920 mssmbios - ok
11:20:23.0832 6920 MSSQL$NMP - ok
11:20:23.0832 6920 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
11:20:23.0863 6920 MSSQLServerADHelper - ok
11:20:23.0878 6920 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:20:23.0972 6920 MSTEE - ok
11:20:23.0988 6920 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
11:20:24.0019 6920 MTConfig - ok
11:20:24.0034 6920 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
11:20:24.0081 6920 Mup - ok
11:20:24.0097 6920 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
11:20:24.0190 6920 napagent - ok
11:20:24.0206 6920 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:20:24.0268 6920 NativeWifiP - ok
11:20:24.0300 6920 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:20:24.0378 6920 NDIS - ok
11:20:24.0378 6920 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:20:24.0456 6920 NdisCap - ok
11:20:24.0471 6920 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:20:24.0549 6920 NdisTapi - ok
11:20:24.0565 6920 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:20:24.0658 6920 Ndisuio - ok
11:20:24.0674 6920 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:20:24.0752 6920 NdisWan - ok
11:20:24.0768 6920 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:20:24.0846 6920 NDProxy - ok
11:20:24.0861 6920 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:20:24.0939 6920 NetBIOS - ok
11:20:24.0955 6920 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:20:25.0048 6920 NetBT - ok
11:20:25.0064 6920 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
11:20:25.0095 6920 Netlogon - ok
11:20:25.0126 6920 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
11:20:25.0220 6920 Netman - ok
11:20:25.0251 6920 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
11:20:25.0345 6920 netprofm - ok
11:20:25.0360 6920 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:20:25.0392 6920 NetTcpPortSharing - ok
11:20:25.0407 6920 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
11:20:25.0454 6920 nfrd960 - ok
11:20:25.0470 6920 [ 832E098BCA8235436FE2D8AE50AC3718 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
11:20:25.0501 6920 NisDrv - ok
11:20:25.0516 6920 [ E570ECA850F30EB740C2E9699DF3D2BD ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
11:20:25.0579 6920 NisSrv - ok
11:20:25.0594 6920 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
11:20:25.0641 6920 NlaSvc - ok
11:20:25.0657 6920 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:20:25.0735 6920 Npfs - ok
11:20:25.0750 6920 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
11:20:25.0844 6920 nsi - ok
11:20:25.0844 6920 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:20:25.0938 6920 nsiproxy - ok
11:20:25.0984 6920 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:20:26.0078 6920 Ntfs - ok
11:20:26.0094 6920 NTP - ok
11:20:26.0203 6920 [ AFEFA4A7DAB65DA3FBEB6EC7B01E7D42 ] ntrtscan c:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
11:20:26.0296 6920 ntrtscan - ok
11:20:26.0312 6920 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
11:20:26.0406 6920 Null - ok
11:20:26.0406 6920 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:20:26.0452 6920 nvraid - ok
11:20:26.0468 6920 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:20:26.0499 6920 nvstor - ok
11:20:26.0515 6920 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:20:26.0562 6920 nv_agp - ok
11:20:26.0624 6920 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
11:20:26.0671 6920 odserv - ok
11:20:26.0686 6920 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
11:20:26.0733 6920 ohci1394 - ok
11:20:26.0749 6920 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:20:26.0796 6920 ose - ok
11:20:26.0936 6920 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:20:27.0154 6920 osppsvc - ok
11:20:27.0186 6920 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:20:27.0248 6920 p2pimsvc - ok
11:20:27.0264 6920 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
11:20:27.0326 6920 p2psvc - ok
11:20:27.0326 6920 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:20:27.0373 6920 Parport - ok
11:20:27.0388 6920 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:20:27.0420 6920 partmgr - ok
11:20:27.0435 6920 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
11:20:27.0482 6920 Parvdm - ok
11:20:27.0498 6920 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:20:27.0544 6920 PcaSvc - ok
11:20:27.0560 6920 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
11:20:27.0607 6920 pci - ok
11:20:27.0622 6920 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
11:20:27.0654 6920 pciide - ok
11:20:27.0669 6920 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
11:20:27.0716 6920 pcmcia - ok
11:20:27.0716 6920 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
11:20:27.0763 6920 pcw - ok
11:20:27.0778 6920 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:20:27.0888 6920 PEAUTH - ok
11:20:27.0966 6920 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
11:20:28.0106 6920 pla - ok
11:20:28.0122 6920 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:20:28.0184 6920 PlugPlay - ok
11:20:28.0200 6920 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:20:28.0231 6920 PNRPAutoReg - ok
11:20:28.0246 6920 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:20:28.0309 6920 PNRPsvc - ok
11:20:28.0324 6920 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:20:28.0418 6920 PolicyAgent - ok
11:20:28.0434 6920 postgresql-8.4 - ok
11:20:28.0449 6920 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
11:20:28.0558 6920 Power - ok
11:20:28.0558 6920 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:20:28.0652 6920 PptpMiniport - ok
11:20:28.0652 6920 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
11:20:28.0699 6920 Processor - ok
11:20:28.0714 6920 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
11:20:28.0761 6920 ProfSvc - ok
11:20:28.0777 6920 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:20:28.0808 6920 ProtectedStorage - ok
11:20:28.0824 6920 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:20:28.0917 6920 Psched - ok
11:20:28.0933 6920 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
11:20:28.0964 6920 PxHelp20 - ok
11:20:29.0011 6920 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
11:20:29.0104 6920 ql2300 - ok
11:20:29.0120 6920 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
11:20:29.0167 6920 ql40xx - ok
11:20:29.0182 6920 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
11:20:29.0245 6920 QWAVE - ok
11:20:29.0260 6920 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:20:29.0307 6920 QWAVEdrv - ok
11:20:29.0338 6920 [ 8F97D374AD1857E1EED85A79F29A1D3D ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
11:20:29.0370 6920 RapiMgr - ok
11:20:29.0385 6920 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:20:29.0479 6920 RasAcd - ok
11:20:29.0494 6920 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:20:29.0572 6920 RasAgileVpn - ok
11:20:29.0588 6920 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
11:20:29.0697 6920 RasAuto - ok
11:20:29.0697 6920 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:20:29.0775 6920 Rasl2tp - ok
11:20:29.0806 6920 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
11:20:29.0900 6920 RasMan - ok
11:20:29.0900 6920 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:20:29.0994 6920 RasPppoe - ok
11:20:29.0994 6920 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:20:30.0087 6920 RasSstp - ok
11:20:30.0103 6920 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:20:30.0196 6920 rdbss - ok
11:20:30.0196 6920 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:20:30.0243 6920 rdpbus - ok
11:20:30.0259 6920 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:20:30.0337 6920 RDPCDD - ok
11:20:30.0352 6920 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:20:30.0430 6920 RDPENCDD - ok
11:20:30.0446 6920 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:20:30.0524 6920 RDPREFMP - ok
11:20:30.0540 6920 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:20:30.0586 6920 RDPWD - ok
11:20:30.0618 6920 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:20:30.0649 6920 rdyboost - ok
11:20:30.0664 6920 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
11:20:30.0758 6920 RemoteAccess - ok
11:20:30.0774 6920 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:20:30.0867 6920 RemoteRegistry - ok
11:20:30.0883 6920 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
11:20:30.0930 6920 RFCOMM - ok
11:20:30.0930 6920 [ 0F6756EF8BDA6DFA7BE50465C83132BB ] RimUsb C:\Windows\system32\Drivers\RimUsb.sys
11:20:30.0976 6920 RimUsb - ok
11:20:31.0039 6920 [ BDDC447AB46625A54619808575D5CB46 ] RoxMediaDB12OEM C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
11:20:31.0117 6920 RoxMediaDB12OEM - ok
11:20:31.0132 6920 [ CE203243ADF512540249DF9C264F12DD ] RoxWatch12 C:\Program Files\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
11:20:31.0179 6920 RoxWatch12 - ok
11:20:31.0179 6920 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:20:31.0288 6920 RpcEptMapper - ok
11:20:31.0288 6920 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
11:20:31.0335 6920 RpcLocator - ok
11:20:31.0351 6920 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
11:20:31.0460 6920 RpcSs - ok
11:20:31.0476 6920 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:20:31.0554 6920 rspndr - ok
11:20:31.0569 6920 [ 31D45ECA63884FF5F7AECC50F7D1BAE0 ] RSUSBSTOR C:\Windows\system32\Drivers\RtsUStor.sys
11:20:31.0616 6920 RSUSBSTOR - ok
11:20:31.0647 6920 [ 5283B9A27FF230F2FF70D92451FF409A ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
11:20:31.0694 6920 RTL8167 - ok
11:20:31.0710 6920 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
11:20:31.0756 6920 SamSs - ok
11:20:31.0772 6920 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:20:31.0819 6920 sbp2port - ok
11:20:31.0866 6920 [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
11:20:31.0944 6920 SBSDWSCService - ok
11:20:31.0959 6920 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:20:32.0053 6920 SCardSvr - ok
11:20:32.0068 6920 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:20:32.0146 6920 scfilter - ok
11:20:32.0178 6920 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
11:20:32.0287 6920 Schedule - ok
11:20:32.0287 6920 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
11:20:32.0365 6920 SCPolicySvc - ok
11:20:32.0380 6920 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:20:32.0427 6920 SDRSVC - ok
11:20:32.0443 6920 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:20:32.0521 6920 secdrv - ok
11:20:32.0536 6920 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
11:20:32.0630 6920 seclogon - ok
11:20:32.0646 6920 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
11:20:32.0739 6920 SENS - ok
11:20:32.0755 6920 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:20:32.0802 6920 SensrSvc - ok
11:20:32.0802 6920 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:20:32.0848 6920 Serenum - ok
11:20:32.0864 6920 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:20:32.0895 6920 Serial - ok
11:20:32.0911 6920 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:20:32.0958 6920 sermouse - ok
11:20:32.0973 6920 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
11:20:33.0082 6920 SessionEnv - ok
11:20:33.0082 6920 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:20:33.0129 6920 sffdisk - ok
11:20:33.0145 6920 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:20:33.0192 6920 sffp_mmc - ok
11:20:33.0207 6920 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:20:33.0254 6920 sffp_sd - ok
11:20:33.0254 6920 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:20:33.0301 6920 sfloppy - ok
11:20:33.0332 6920 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:20:33.0441 6920 SharedAccess - ok
11:20:33.0472 6920 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:20:33.0566 6920 ShellHWDetection - ok
11:20:33.0566 6920 [ C3075617DB699CDC9184A02AFD4D7928 ] SilentHerdsman c:\SilentHerdsman\services\JavaService.exe
11:20:33.0582 6920 SilentHerdsman ( UnsignedFile.Multi.Generic ) - warning
11:20:33.0582 6920 SilentHerdsman - detected UnsignedFile.Multi.Generic (1)
11:20:33.0597 6920 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
11:20:33.0644 6920 sisagp - ok
11:20:33.0644 6920 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:20:33.0691 6920 SiSRaid2 - ok
11:20:33.0691 6920 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:20:33.0738 6920 SiSRaid4 - ok
11:20:33.0831 6920 [ 388AE59FE75F1B959DFA0900923C61BB ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
11:20:34.0003 6920 Skype C2C Service - ok
11:20:34.0034 6920 [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
11:20:34.0065 6920 SkypeUpdate - ok
11:20:34.0065 6920 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:20:34.0159 6920 Smb - ok
11:20:34.0174 6920 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:20:34.0221 6920 SNMPTRAP - ok
11:20:34.0237 6920 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
11:20:34.0268 6920 spldr - ok
11:20:34.0299 6920 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
11:20:34.0346 6920 Spooler - ok
11:20:34.0440 6920 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
11:20:34.0611 6920 sppsvc - ok
11:20:34.0627 6920 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:20:34.0720 6920 sppuinotify - ok
11:20:34.0736 6920 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
11:20:34.0767 6920 SQLBrowser - ok
11:20:34.0783 6920 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
11:20:34.0814 6920 SQLWriter - ok
11:20:34.0845 6920 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
11:20:34.0892 6920 srv - ok
11:20:34.0908 6920 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:20:34.0954 6920 srv2 - ok
11:20:34.0970 6920 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:20:35.0017 6920 srvnet - ok
11:20:35.0032 6920 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:20:35.0126 6920 SSDPSRV - ok
11:20:35.0126 6920 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:20:35.0235 6920 SstpSvc - ok
11:20:35.0313 6920 [ FBAA145C28074C853529050914D405C6 ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_f39a6924a795ad94\STacSV.exe
11:20:35.0344 6920 STacSV - ok
11:20:35.0360 6920 [ 1E72739A30A0D3E3FC95EBB07F83912D ] stdcfltn C:\Windows\system32\DRIVERS\stdcfltn.sys
11:20:35.0376 6920 stdcfltn - ok
11:20:35.0391 6920 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:20:35.0438 6920 stexstor - ok
11:20:35.0454 6920 [ 06CBB271F42EF70FB6EF372C491BA9AA ] STHDA C:\Windows\system32\DRIVERS\stwrt.sys
11:20:35.0500 6920 STHDA - ok
11:20:35.0547 6920 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
11:20:35.0610 6920 StiSvc - ok
11:20:35.0625 6920 [ 9E182DD94496550A22A392CC1A8E0F52 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
11:20:35.0656 6920 stllssvr - ok
11:20:35.0688 6920 [ 01FBCC8F2C30EB1FAF9A477FA53C6655 ] svcGenericHost c:\Program Files\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe
11:20:35.0703 6920 svcGenericHost ( UnsignedFile.Multi.Generic ) - warning
11:20:35.0703 6920 svcGenericHost - detected UnsignedFile.Multi.Generic (1)
11:20:35.0719 6920 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
11:20:35.0750 6920 swenum - ok
11:20:35.0766 6920 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
11:20:35.0875 6920 swprv - ok
11:20:35.0890 6920 [ CF196A45FD61118C95585489FAD5B2AA ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
11:20:35.0937 6920 SynTP - ok
11:20:35.0984 6920 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
11:20:36.0078 6920 SysMain - ok
11:20:36.0093 6920 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:20:36.0140 6920 TabletInputService - ok
11:20:36.0171 6920 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
11:20:36.0265 6920 TapiSrv - ok
11:20:36.0280 6920 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
11:20:36.0374 6920 TBS - ok
11:20:36.0421 6920 [ 7C0507D2391AF5933600CBCED799F277 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:20:36.0514 6920 Tcpip - ok
11:20:36.0561 6920 [ 7C0507D2391AF5933600CBCED799F277 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:20:36.0670 6920 TCPIP6 - ok
11:20:36.0686 6920 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:20:36.0733 6920 tcpipreg - ok
11:20:36.0748 6920 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:20:36.0795 6920 TDPIPE - ok
11:20:36.0811 6920 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:20:36.0858 6920 TDTCP - ok
11:20:36.0858 6920 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:20:36.0951 6920 tdx - ok
11:20:37.0123 6920 [ 7C8DD5576695B3362202EF09B20C425E ] TeamViewer8 C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
11:20:37.0326 6920 TeamViewer8 - ok
11:20:37.0341 6920 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
11:20:37.0372 6920 TermDD - ok
11:20:37.0404 6920 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
11:20:37.0513 6920 TermService - ok
11:20:37.0513 6920 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
11:20:37.0575 6920 Themes - ok
11:20:37.0591 6920 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
11:20:37.0684 6920 THREADORDER - ok
11:20:37.0700 6920 [ CA9E9C2C04A198ED345C1752222A5F3E ] tmactmon C:\Windows\system32\DRIVERS\tmactmon.sys
11:20:37.0731 6920 tmactmon - ok
11:20:37.0747 6920 [ 4D69206E3A3E665221FDD7E397106405 ] TMBMServer c:\Program Files\Trend Micro\BM\TMBMSRV.exe
11:20:37.0778 6920 TMBMServer - ok
11:20:37.0794 6920 [ A3D20789B3FF0576A29462BEF25BCFCC ] tmcomm C:\Windows\system32\DRIVERS\tmcomm.sys
11:20:37.0825 6920 tmcomm - ok
11:20:37.0840 6920 [ 21F215E54770C4BF93EFAF63F58FE57E ] tmevtmgr C:\Windows\system32\DRIVERS\tmevtmgr.sys
11:20:37.0872 6920 tmevtmgr - ok
11:20:37.0887 6920 [ 1D84C335EB869BBE64543C6945A1F3C9 ] TmFilter c:\Program Files\Trend Micro\Client Server Security Agent\TmXPFlt.sys
11:20:37.0918 6920 TmFilter - ok
11:20:37.0996 6920 [ 3062BAB9C0F90577674BC2D006EB9EFA ] tmlisten c:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
11:20:38.0074 6920 tmlisten - ok
11:20:38.0090 6920 [ 4E87D02E56E9B1AF831C5D521597D629 ] tmlwf C:\Windows\system32\DRIVERS\tmlwf.sys
11:20:38.0121 6920 tmlwf - ok
11:20:38.0137 6920 [ 255328CF08D602368B69FF1F55EBD93E ] TmPfw c:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
11:20:38.0199 6920 TmPfw - ok
11:20:38.0199 6920 [ 7AAB3FEF8B19AE023EE05386F1B0A5DD ] TmPreFilter c:\Program Files\Trend Micro\Client Server Security Agent\TmPreFlt.sys
11:20:38.0230 6920 TmPreFilter - ok
11:20:38.0277 6920 [ 0FEC6C50B2BE07C57651573CDD1C721F ] TmProxy c:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe
11:20:38.0324 6920 TmProxy - ok
11:20:38.0340 6920 [ 44C262C1B2412DED35078B6166D2ACC2 ] tmtdi C:\Windows\system32\DRIVERS\tmtdi.sys
11:20:38.0371 6920 tmtdi - ok
11:20:38.0402 6920 [ D9882FD91B7C4C35ACAA8498D1F3CD68 ] tmwfp C:\Windows\system32\DRIVERS\tmwfp.sys
11:20:38.0433 6920 tmwfp - ok
11:20:38.0449 6920 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
11:20:38.0542 6920 TrkWks - ok
11:20:38.0558 6920 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:20:38.0652 6920 TrustedInstaller - ok
11:20:38.0667 6920 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:20:38.0745 6920 tssecsrv - ok
11:20:38.0761 6920 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:20:38.0808 6920 TsUsbFlt - ok
11:20:38.0823 6920 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:20:38.0901 6920 tunnel - ok
11:20:38.0917 6920 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:20:38.0948 6920 uagp35 - ok
11:20:38.0964 6920 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:20:39.0042 6920 udfs - ok
11:20:39.0073 6920 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:20:39.0120 6920 UI0Detect - ok
11:20:39.0135 6920 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:20:39.0166 6920 uliagpkx - ok
11:20:39.0182 6920 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
11:20:39.0229 6920 umbus - ok
11:20:39.0229 6920 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:20:39.0276 6920 UmPass - ok
11:20:39.0369 6920 [ 9E89C2D6945389270DE067CE51FF7425 ] UNS C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
11:20:39.0510 6920 UNS - ok
11:20:39.0525 6920 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
11:20:39.0619 6920 upnphost - ok
11:20:39.0634 6920 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:20:39.0681 6920 usbccgp - ok
11:20:39.0681 6920 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:20:39.0744 6920 usbcir - ok
11:20:39.0744 6920 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\drivers\usbehci.sys
11:20:39.0790 6920 usbehci - ok
11:20:39.0806 6920 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:20:39.0853 6920 usbhub - ok
11:20:39.0868 6920 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
11:20:39.0915 6920 usbohci - ok
11:20:39.0915 6920 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:20:39.0962 6920 usbprint - ok
11:20:39.0978 6920 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
11:20:40.0024 6920 usbscan - ok
11:20:40.0040 6920 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:20:40.0087 6920 USBSTOR - ok
11:20:40.0087 6920 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
11:20:40.0134 6920 usbuhci - ok
11:20:40.0149 6920 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
11:20:40.0196 6920 usbvideo - ok
11:20:40.0212 6920 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
11:20:40.0305 6920 UxSms - ok
11:20:40.0321 6920 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
11:20:40.0352 6920 VaultSvc - ok
11:20:40.0368 6920 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:20:40.0399 6920 vdrvroot - ok
11:20:40.0430 6920 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
11:20:40.0539 6920 vds - ok
11:20:40.0555 6920 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:20:40.0602 6920 vga - ok
11:20:40.0617 6920 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
11:20:40.0695 6920 VgaSave - ok
11:20:40.0711 6920 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:20:40.0758 6920 vhdmp - ok
11:20:40.0773 6920 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
11:20:40.0804 6920 viaagp - ok
11:20:40.0820 6920 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
11:20:40.0867 6920 ViaC7 - ok
11:20:40.0867 6920 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
11:20:40.0914 6920 viaide - ok
11:20:40.0914 6920 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:20:40.0960 6920 volmgr - ok
11:20:40.0976 6920 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:20:41.0023 6920 volmgrx - ok
11:20:41.0038 6920 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:20:41.0085 6920 volsnap - ok
11:20:41.0148 6920 [ 8B9325C1D1167A703042986DF758D799 ] VSApiNt c:\Program Files\Trend Micro\Client Server Security Agent\VSApiNt.sys
11:20:41.0226 6920 VSApiNt - ok
11:20:41.0241 6920 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:20:41.0288 6920 vsmraid - ok
11:20:41.0335 6920 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
11:20:41.0444 6920 VSS - ok
11:20:41.0460 6920 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
11:20:41.0506 6920 vwifibus - ok
11:20:41.0522 6920 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
11:20:41.0584 6920 vwififlt - ok
11:20:41.0584 6920 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
11:20:41.0647 6920 vwifimp - ok
11:20:41.0678 6920 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
11:20:41.0787 6920 W32Time - ok
11:20:41.0803 6920 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:20:41.0865 6920 WacomPen - ok
11:20:41.0881 6920 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:20:41.0959 6920 WANARP - ok
11:20:41.0959 6920 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:20:42.0052 6920 Wanarpv6 - ok
11:20:42.0099 6920 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:20:42.0193 6920 WatAdminSvc - ok
11:20:42.0240 6920 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
11:20:42.0333 6920 wbengine - ok
11:20:42.0349 6920 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:20:42.0411 6920 WbioSrvc - ok
11:20:42.0427 6920 [ 59E19BD13C3BDB857646B9E436BA27F7 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
11:20:42.0474 6920 WcesComm - ok
11:20:42.0505 6920 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:20:42.0567 6920 wcncsvc - ok
11:20:42.0583 6920 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:20:42.0614 6920 WcsPlugInService - ok
11:20:42.0630 6920 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:20:42.0661 6920 Wd - ok
11:20:42.0692 6920 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:20:42.0754 6920 Wdf01000 - ok
11:20:42.0754 6920 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:20:42.0817 6920 WdiServiceHost - ok
11:20:42.0832 6920 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:20:42.0879 6920 WdiSystemHost - ok
11:20:42.0895 6920 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
11:20:42.0973 6920 WebClient - ok
11:20:42.0973 6920 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:20:43.0066 6920 Wecsvc - ok
11:20:43.0098 6920 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:20:43.0191 6920 wercplsupport - ok
11:20:43.0207 6920 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
11:20:43.0285 6920 WerSvc - ok
11:20:43.0300 6920 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:20:43.0394 6920 WfpLwf - ok
11:20:43.0410 6920 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:20:43.0441 6920 WIMMount - ok
11:20:43.0472 6920 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:20:43.0550 6920 WinDefend - ok
11:20:43.0566 6920 WinHttpAutoProxySvc - ok
11:20:43.0597 6920 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:20:43.0690 6920 Winmgmt - ok
11:20:43.0737 6920 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
11:20:43.0846 6920 WinRM - ok
11:20:43.0862 6920 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
11:20:43.0924 6920 WinUsb - ok
11:20:43.0956 6920 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:20:44.0034 6920 Wlansvc - ok
11:20:44.0065 6920 [ 6067ACEF367E79914AF628FA1E9B5330 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
11:20:44.0096 6920 wlcrasvc - ok
11:20:44.0158 6920 [ 0A70F4022EC2E14C159EFC4F69AA2477 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
11:20:44.0252 6920 wlidsvc - ok
11:20:44.0268 6920 [ 7FFF34AE69DFB80F7B190ABA31E00610 ] wltrysvc C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
11:20:44.0283 6920 wltrysvc ( UnsignedFile.Multi.Generic ) - warning
11:20:44.0283 6920 wltrysvc - detected UnsignedFile.Multi.Generic (1)
11:20:44.0299 6920 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:20:44.0346 6920 WmiAcpi - ok
11:20:44.0361 6920 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:20:44.0408 6920 wmiApSrv - ok
11:20:44.0470 6920 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:20:44.0533 6920 WMPNetworkSvc - ok
11:20:44.0548 6920 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:20:44.0595 6920 WPCSvc - ok
11:20:44.0611 6920 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:20:44.0658 6920 WPDBusEnum - ok
11:20:44.0673 6920 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:20:44.0767 6920 ws2ifsl - ok
11:20:44.0767 6920 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
11:20:44.0845 6920 wscsvc - ok
11:20:44.0845 6920 WSearch - ok
11:20:44.0923 6920 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
11:20:45.0048 6920 wuauserv - ok
11:20:45.0063 6920 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:20:45.0094 6920 WudfPf - ok
11:20:45.0110 6920 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:20:45.0157 6920 WUDFRd - ok
11:20:45.0172 6920 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:20:45.0219 6920 wudfsvc - ok
11:20:45.0250 6920 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
11:20:45.0313 6920 WwanSvc - ok
11:20:45.0328 6920 ================ Scan global ===============================
11:20:45.0328 6920 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
11:20:45.0344 6920 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
11:20:45.0344 6920 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
11:20:45.0360 6920 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
11:20:45.0375 6920 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
11:20:45.0375 6920 [Global] - ok
11:20:45.0375 6920 ================ Scan MBR ==================================
11:20:45.0375 6920 [ CDB4DE4BBD714F152979DA2DCBEF57EB ] \Device\Harddisk0\DR0
11:20:45.0703 6920 \Device\Harddisk0\DR0 - ok
11:20:45.0703 6920 ================ Scan VBR ==================================
11:20:45.0718 6920 [ 45FD117738263C35344EBD657EBF809A ] \Device\Harddisk0\DR0\Partition1
11:20:45.0718 6920 \Device\Harddisk0\DR0\Partition1 - ok
11:20:45.0718 6920 [ 1A7CCBAF7849D00F720F22AFF41F240E ] \Device\Harddisk0\DR0\Partition2
11:20:45.0718 6920 \Device\Harddisk0\DR0\Partition2 - ok
11:20:45.0718 6920 [ 598D13034BF0D21259BF25EFD891BFD8 ] \Device\Harddisk0\DR0\Partition3
11:20:45.0734 6920 \Device\Harddisk0\DR0\Partition3 - ok
11:20:45.0734 6920 ============================================================
11:20:45.0734 6920 Scan finished
11:20:45.0734 6920 ============================================================
11:20:45.0734 1208 Detected object count: 4
11:20:45.0734 1208 Actual detected object count: 4
11:20:50.0679 1208 ETSWatchdog ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:50.0679 1208 ETSWatchdog ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:50.0679 1208 SilentHerdsman ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:50.0679 1208 SilentHerdsman ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:50.0679 1208 svcGenericHost ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:50.0679 1208 svcGenericHost ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:50.0679 1208 wltrysvc ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:50.0679 1208 wltrysvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:17:56.0011 7476 Deinitialize success



Die paar 'Bedrohungen' sind mir bekannt. 'Silent Herdsman' ist meine Kuh management Program, 'ETS' ist die Hersteller davon. Ich frage mich ob die andere zwei auch irgendwie damit verbunden sind:

markusg 25.05.2013 11:30

Passt alles.
Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Newson 25.05.2013 13:52

Hallo,

Ich habe Combifix runtergeladen und durchgeführt. Durchführen hat um 15 Minute gedauert.

Ich finde keine C:\Combofix.txt Bericht. Ich habe versucht die Rechner wieder neuzustarten, und noch einmal durchlaufen lassen. Aber finde ich es trotzdem nichts.

markusg 25.05.2013 15:45

dann eben log.txt direkt auf c: sollten ja nicht so viele liegen. evtl. auch im ordner qoobox schauen

Newson 26.05.2013 19:37

Sollte es so aussehen??

In qoobox/Quarantine und heißt: catchme.log, sonst is keine.


-------- 2013-05-25 - 13:29:51 -------------


-------- 2013-05-25 - 13:45:28 -------------


-------- 2013-05-25 - 14:08:21 -------------

Sonst habe ich keine Ahnung. Ich habe auch ein Suche durchgemacht für alles die gestern geändert / neu sind. Kein andere Ergebnisse

markusg 28.05.2013 09:23

ok dann erst mal:
malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

Newson 29.05.2013 11:15

Anhang 55402

markusg 29.05.2013 11:16

Hi,

lade den CCleaner standard:
CCleaner - Download - Filepony
falls der CCleaner
bereits instaliert, überspringen.
öffnen, Tools (extras),uninstall Llist, als txt speichern. öffnen.
hinter, jedes von dir benötigte programm, schreibe notwendig.
hinter, jedes, von dir nicht benötigte, unnötig.
hinter, dir unbekannte, unbekannt.
liste posten.

Newson 29.05.2013 15:21

Anhang 55428

markusg 29.05.2013 15:52

deinstaliere:
Adobe Flash Player alle
Adobe - Adobe Flash Player installieren
neueste version laden, instalieren.
bitte auch mal den adobe reader wie folgt konfigurieren:
adobe reader öffnen, bearbeiten, voreinstellungen.
allgemein:
nur zertifizierte zusatz module verwenden, anhaken.
Sicherheit (erweitert)
Erweiterte Sicherheit anhaken
und alle Dateien auswählen.
internet:
hier sollte alles deaktiviert werden, es ist sehr unsicher pdfs automatisch zu öffnen, zu downloaden etc.
es ist immer besser diese direkt abzuspeichern da man nur so die kontrolle hat was auf dem pc vor geht.
bei javascript den haken bei java script verwenden raus nehmen
bei updater, automatisch instalieren wählen.
übernehmen /ok

deinstaliere:
Core Temp
Google : unnötige
Java
downloade Java jre:
Java-Downloads für alle Betriebssysteme
klicke:
Download der Java-Software für Windows Offline
laden, und instalieren
deinstaliere:
Spelling
Spybot

Öffne CCleaner, analysieren, starten, PC neustarten.
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Newson 29.05.2013 17:56

Schlechte Nachricht. Ich habe zwischen durch die Rechner neu gestartet. Es fährt wie normal hoch, bis zum die blaue Windows " Willkommen" Bild. Danach geht es auf ein schwarze Bildschirm mit ein bewegliche Maus Pointer. was mache ich jetzt. Ich habe ein Bauch Gefühl, das könnte mit die Core Temp Programm zusammen hängen.

markusg 29.05.2013 19:05

Core Temp ist eigendlich nur ein programm zur überwachung nichts wichtitges.
Starte mal neu, drücke f8 letzte funktionierene Konfiguration.

Newson 29.05.2013 21:23

AdwCleaner Logfile:
Code:

# AdwCleaner v2.301 - Datei am 29/05/2013 um 21:56:37 erstellt
# Aktualisiert am 16/05/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzer : r.newson - HWACKER-PC
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\r.newson\Downloads\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\Users\c.proebsting\AppData\LocalLow\AskToolbar

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com

***** [Internet Browser] *****

-\\ Internet Explorer v9.0.8112.16483

[OK] Die Registrierungsdatenbank ist sauber.

-\\ Google Chrome v [Version kann nicht ermittelt werden]

Datei : C:\Users\r.newson\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[R1].txt - [1241 octets] - [29/05/2013 21:55:54]
AdwCleaner[S1].txt - [1174 octets] - [29/05/2013 21:56:37]

########## EOF - C:\AdwCleaner[S1].txt - [1234 octets] ##########

--- --- ---

markusg 29.05.2013 21:46

Hi,
neustarten bitte.
Hitman Pro - Download - Filepony
Hitmanpro laden, doppelklicken, scan.
Nichts löschen.
auf weiter.
Log speichern, bzw als xml exportieren, dann posten, bzw packen und anhängenb

Newson 29.05.2013 22:25

Anhang 55451

markusg 30.05.2013 12:16

Hi,

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

activex
netsvcs
msconfig
%SYSTEMDRIVE%\*.
%PROGRAMFILES%\*.exe
%LOCALAPPDATA%\*.exe
%systemroot%\*. /mp /s
C:\Windows\system32\*.tsp
/md5start
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
explorer.exe
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs
CREATERESTOREPOINT

  • Schliesse bitte nun alle Programme. (Wichtig)
  • Klicke nun bitte auf den Quick Scan Button.
  • Kopiere
    nun den Inhalt aus OTL.txt und Extra.txt hier in Deinen Thread

Newson 30.05.2013 13:00

beide datein sind in die Zip
Anhang 55482

markusg 30.05.2013 14:04

Hi,


otl fix

Fixen mit OTL

  • Starte bitte die OTL.exe.
  • Kopiere nun den Inhalt aus der Codebox in die Textbox.

Code:

:OTL
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKU\S-1-5-21-4103434952-271241770-3750179241-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe File not found
:files
:Commands
[emptytemp]

  • Solltest du deinen Benutzernamen z. B. durch "*****" unkenntlich gemacht haben, so füge an entsprechender Stelle deinen richtigen Benutzernamen ein. Andernfalls wird der Fix nicht funktionieren.
  • Schließe bitte nun alle Programme.
  • Klicke nun bitte auf den Fix Button.
  • OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
  • Nach dem Neustart findest Du ein Textdokument auf deinem Desktop.
    ( Auch zu finden unter C:\_OTL\MovedFiles\<Uhrzeit_Datum>.txt)
    Kopiere nun den Inhalt hier in Deinen Thread



bitte teste, ob es im Firefox, internet explorer, und sonstigen
evtl. instalierte Browser, irgendwelche ungewollten toolbars, umleitungen oder sonstigen Probleme gibt.
Teste wie pc und programme allgemein laufen.

Newson 30.05.2013 15:12

ok. ich habe die Fix Scan am laufen. sie läuft seit Nähe an 45 min. an Bild schirm ist nur Hintergrund Bild und die otl. die maus zeige ist permanent am Arbeiten . soll ich die Rechner ausschalten und wieder von Anfang machen?

markusg 30.05.2013 16:27

ja, diesmal aber versuchen im abgesicherten modus mit Netzwerk zu starten, sollte via f8 beim neustarten klappen

Newson 30.05.2013 16:58

In gesamt, funktioniert die Computer schneller als bevor die Trojaner. Ausser die ein oder andere Störung, die Du schon davon weiß, bin ich zu frieden mit Internet, Start up, und Programm nutzen. Da ist kein neue toolbarszu finden.



All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry key HKEY_USERS\S-1-5-21-4103434952-271241770-3750179241-1000\Software\Microsoft\Windows\CurrentVersion\Run not found.
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: c.proebsting
->Temp folder emptied: 5004885 bytes
->Temporary Internet Files folder emptied: 1080458490 bytes
->Java cache emptied: 1131277 bytes
->Flash cache emptied: 32503 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NTP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: postgres
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Public

User: r.newson
->Temp folder emptied: 442840 bytes
->Temporary Internet Files folder emptied: 40028232 bytes
->Java cache emptied: 939558 bytes
->Google Chrome cache emptied: 6718132 bytes
->Flash cache emptied: 506 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2191751 bytes
RecycleBin emptied: 4022 bytes

Total Files Cleaned = 1.084,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 05302013_174710

Files\Folders moved on Reboot...
File\Folder C:\Users\c.proebsting\AppData\Local\Temp\OICE_5EB00DBD-9311-48AB-81FE-4F43A78C0FE9.0\1B9A0EB2. not found!
File\Folder C:\Users\c.proebsting\AppData\Local\Temp\OICE_38B0D7AA-585B-49B9-8096-60BD6F08B5C0.0\2AE615E5. not found!
C:\Users\r.newson\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

markusg 30.05.2013 17:09

welche Störung?

Newson 30.05.2013 17:14

die zwei berichtete Störungen. die eine bei otl fix, und die frühere wo ich vermutet hatte, von core Temp gekommen wäre.

markusg 30.05.2013 17:16

na du kannst doch aber wieder normal starten oder nicht?

Newson 30.05.2013 17:29

einwandfrei

markusg 30.05.2013 17:44

kann ich das also als "ja" auffassen?

Newson 30.05.2013 17:45

ja.

markusg 30.05.2013 17:54

otl öffnen bereinigen, pc startet neu, remover werden gelöscht.
Lösche von uns verwendete Tools logs, setups.
pc absichern:
als antimalware programm würde ich emsisoft empfehlen.
diese haben für mich den besten schutz kostet aber etwas.
Computeractive Software Store - Emsisoft Anti-Malware 7 [1-PC] - 63% off RRP
testversion:
Meine Antivirus-Empfehlung: Emsisoft Anti-Malware
insbesondere wenn du onlinebanking, einkäufe, sonstige zahlungsabwicklungen oder ähnlich wichtiges, wie zb berufliches machst, also sensible daten zu schützen sind, solltest du in sicherheitssoftware investieren.
vor dem aktivieren der lizenz die 30 tage testzeitraum ausnutzen.

kostenlos, aber eben nicht ganz so gut währe avast zu empfehlen.
http://www.trojaner-board.de/110895-...antivirus.html

sag mir welches du nutzt, dann gebe ich konfigurationshinweise.
bitte dein bisheriges av deinstalieren
die folgende anleitung ist umfangreich, dass ist mir klar, sie sollte aber umgesetzt werden, da nur dann dein pc sicher ist. stelle so viele fragen wie nötig, ich arbeite gern alles mit dir durch!

http://www.trojaner-board.de/96344-a...-rechners.html
Starte bitte mit der Passage, Windows Vista und Windows 7
Bitte beginne damit, Windows Updates zu instalieren.
Am besten geht dies, wenn du über Start, Suchen gehst, und dort Windows Updates eingibst.
Prüfe unter "Einstellungen ändern" dass folgendes ausgewählt ist:
- Updates automatisch Instalieren,
- Täglich
- Uhrzeit wählen
- Bitte den gesammten rest anhaken, außer:
- detailierte benachichtungen anzeigen, wenn neue Microsoft software verfügbar ist.
Klicke jetzt die Schaltfläche "OK"
Klicke jetzt "nach Updates suchen".
Bitte instaliere zunächst wichtige Updates.
Es wird nötig sein, den PC zwischendurch neu zu starten. falls dies der Fall ist, musst du erneut über Start, Suchen, Windows Update aufrufen, auf Updates suchen klicken und die nächsten instalieren.
Mache das selbe bitte mit den optionalen Updates.
Bitte übernimm den rest so, wie es im Abschnitt windows 7 / Vista zu lesen ist.
aus dem Abschnitt xp, bitte den punkt "datenausführungsverhinderung, dep" übernehmen.
als browser rate ich dir zu chrome:
http://support.google.com/chrome/bin...&answer=118663
anleitung lesen bitte
falls du nen andern nutzen willst, sags mir dann muss ich teile der nun folgenden anleitung anpassen.


Sandboxie
Die devinition einer Sandbox ist hier nachzulesen:
Sandbox
Kurz gesagt, man kann Programme fast 100 %ig isuliert vom System ausführen.

Der Vorteil liegt klar auf der Hand, wenn über den Browser Schadcode eingeschläust wird, kann dieser nicht nach außen dringen.
Download Link:
Sandboxie - Download - Filepony

anleitung:
http://www.trojaner-board.de/71542-a...sandboxie.html
ausführliche anleitung als pdf, auch abarbeiten:
Sandbox Einstellungen |

bitte folgende zusatz konfiguration machen:
sandboxie control öffnen, menü sandbox anklicken, defauldbox wählen.
dort klicke auf sandbox einstellungen.
beschrenkungen, bei programm start und internet zugriff schreibe:
chrome.exe
dann gehe auf anwendungen, webbrowser, chrome.
dort aktiviere alles außer gesammten profil ordner freigeben.
Wie du evtl. schon gesehen hast, kannst du einige Funktionen nicht nutzen.
Dies ist nur in der Vollversion nötig, zu deren Kauf ich dir rate.
Du kannst zb unter "Erzwungene Programmstarts" festlegen, dass alle Browser in der Sandbox starten.
Ansonsten musst du immer auf "Sandboxed webbrowser" klicken bzw Rechtsklick, in Sandboxie starten.
Eine lebenslange Lizenz kostet 30 €, und ist auf allen deinen PC's nutzbar.

Weiter mit:
Maßnahmen für ALLE Windows-Versionen
alles komplett durcharbeiten
anmerkung zu file hippo.
in den settings zusätzlich auswählen:
hide beta updates.
Run updateChecker when Windows starts

Backup Programm:
in meiner Anleitung ist bereits ein Backup Programm verlinkt, als Alternative bietet sich auch das Windows eigene Backup Programm an:
http://www.trojaner-board.de/82962-w...en-backup.html
Dies ist aber leider nur für Windows 7 Nutzer vernünftig nutzbar.
Alle Anderen sollten sich aber auf jeden fall auch ein Backup Programm instalieren, denn dies kann unter Umständen sehr wichtig sein, zum Beispiel, wenn die Festplatte einmal kaputt ist.

Zum Schluss, die allgemeinen sicherheitstipps beachten, wenn es dich betrifft, den Tipp zum Onlinebanking beachten und alle Passwörter ändern
bitte auch lesen, wie mache ich programme für alle sichtbar:
Programme für alle Konten nutzbar machen - PCtipp.ch - Praxis & Hilfe
surfe jetzt also nur noch im standard nutzer konto und dort in der sandbox.
wenn du die kostenlose version nutzt, dann mit klick auf sandboxed web browser, wenn du die bezahlversion hast, kannst du erzwungene programm starts festlegen, dann wird sandboxie immer gestartet wenn du nen browser aufrufst.
wenn du mit der maus über den browser fährst sollte der eingerahmt sein, dann bist du im sandboxed web browser

passwort sicherheit:
jeder dienst benötigt ein eigenes, mindestens 12-stelliges passwort
bei der passwort verwaltung und erstellung hilft roboform
Passwort Manager, Formular Ausfueller, Passwort Management | RoboForm Passwort Manager
anleitung:
RoboForm-Bedienungsanleitung: Passwort-Manager, Verwalten von Passwörtern und persönlichen Daten


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:33 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131