Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Ein ActiveScriptEventConsumer-Anbieter (https://www.trojaner-board.de/137088-activescripteventconsumer-anbieter.html)

robili 23.06.2013 22:26

Ein ActiveScriptEventConsumer-Anbieter
 
Hallo,
Ich arbeite mit Windows 7
Hier ist mal wieder robili mit einer Sache die mir keine Ruhe lässt.
Seid längerem findet der Avira eine versteckte Datei oder Treiber.
War auch schon mal Thema hier, habe viele Dinge gelernt und auch geändert.
Da ich in letzter Zeit einige Abstürze zu verzeichnen hatte und nicht wußte wo der Fehler lag, bin ich nun mal auf diese Ereigniskontrolle gestoßen und habe diese durchgeblättert.
Da bin ich unter anderem auf eine Sache gestoßen mit der ich nichts anfangen kann, aber mich doch beängstigt.

"Ein ActiveScriptEventConsumer-Anbieter wurde im WMI-Namespace (Windows-Verwaltungsinstrumentation) root\default zur Verwendung des Kontos "LocalSystem" registriert. Dieses Konto ist ein privilegiertes Konto, d. h. der Anbieter kann Sicherheitsverletzungen verursachen, wenn der Identitätswechsel für Benutzeranforderungen nicht korrekt ausgeführt wird."

Ich hoffe, da kennt sich jemand aus und kann mir da helfen was es damit auf sich hat
mit freundlichen Grüßen
robili

schrauber 24.06.2013 07:14

HI,

zeig mal die Meldung von Avira.

Systemscan mit FRST
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Scan.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

robili 24.06.2013 12:48

Hallo schrauber,
mal ne Frage wie kann ich den einen sceenshot einfügen ??
gruß
robili

Hallo noch einmal,
hier die frst.txt

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2013
Ran by ..... (administrator) on 24-06-2013 13:25:30
Running from C:\Users\.....\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(PacketVideo) C:\Program Files (x86)\TwonkyMedia\twonkymediaserverwatchdog.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
() C:\Program Files (x86)\TwonkyMedia\TwonkyMediaServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieCtrl.exe
(TeamDrive Systems GmbH) C:\Program Files (x86)\TeamDrive 3\TeamDrive3.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe

==================== Registry (Whitelisted) ==================

HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-20] (Microsoft Corporation)
HKCU\...\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" [765200 2012-12-16] (SANDBOXIE L.T.D)
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM-x32\...\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide [205336 2011-11-11] (Logitech Inc.)
HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-06-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [162336 2009-07-22] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [162336 2009-07-22] ()
HKU\Gast\...\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c [x]
HKU\.....\...\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" [765200 2012-12-16] (SANDBOXIE L.T.D)
HKU\.....\...\Run: [Kalender] C:\Program Files (x86)\Kalender\Kalender.exe [x]
HKU\.....\...\Policies\system: [LogonHoursAction] 2
HKU\.....\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\.....\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TeamDrive starten.lnk
ShortcutTarget: TeamDrive starten.lnk -> C:\Program Files (x86)\TeamDrive 3\TeamDrive3.exe (TeamDrive Systems GmbH)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKCU - {091742E4-7D7D-4EEC-8CC3-4A10D50AFE63} URL = hxxp://go.web.de/suchbox/ebay?query={searchTerms}
SearchScopes: HKCU - {5CDCF058-64DF-4A6F-B9A2-D0C6EBF57ABD} URL = hxxp://go.1und1.de/suchbox/amazon?tag=1und1icon-21&field-keywords={searchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://go.web.de/suchbox/google?q={searchTerms}
SearchScopes: HKCU - {A2F3D9EA-46EA-4AC7-A8CC-B37DBEA1C7F8} URL = hxxp://go.1und1.de/suchbox/1und1suche?su={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -  No File
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} -  No File
BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
DPF: HKLM-x32 {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} file:///C:/Users/...../Videos/Weihnachten_2010/components/hidinputmonitorx.ocx
DPF: HKLM-x32 {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} file:///C:/Users/...../Videos/Weihnachten_2010/components/A9.ocx
DPF: HKLM-x32 {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} file:///C:/Users/...../Videos/Weihnachten_2010/components/wmvhdrating.ocx
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\.....\AppData\Roaming\Mozilla\Firefox\Profiles\5q0xfoi1.defaultextensions.ini
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @garmin.com/GpsControl - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pack.google.com/Google Updater;version=14 - C:\Program Files (x86)\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Extension: (Docs) - C:\Users\.....\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\.....\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\.....\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\.....\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Gmail) - C:\Users\.....\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 AntiVirFirewallService; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [654392 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [371768 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-06-24] (Avira Operations GmbH & Co. KG)
R2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [311592 2009-08-06] (Egis Technology Inc.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [123664 2012-12-16] (SANDBOXIE L.T.D)
R2 TwonkyMedia; C:\Program Files (x86)\TwonkyMedia\twonkymediaserverwatchdog.exe [493144 2010-09-18] (PacketVideo)

==================== Drivers (Whitelisted) ====================

R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [114608 2013-04-13] (Avira GmbH)
R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [141376 2013-04-13] (Avira GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-04-13] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-04-13] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-13] (Avira Operations GmbH & Co. KG)
S3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30304 2010-05-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30304 2010-05-07] ()
S3 rsvcdwdr; C:\Windows\System32\DRIVERS\rsvcdwdr.sys [45160 2012-01-03] (RapidSolution Software AG)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202632 2012-12-16] (SANDBOXIE L.T.D)
S3 cpuz132; \??\C:\Users\.....\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x]
S3 IAMTVE; \SystemRoot\system32\DRIVERS\IAMTVE.sys [x]
S3 IAMTXPE; \SystemRoot\system32\DRIVERS\IAMTXPE.sys [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [x]
S3 NAL; \??\C:\Windows\system32\Drivers\iqvw64e.sys [x]
S3 StarOpen; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-24 13:25 - 2013-06-24 13:25 - 00000000 ____D C:\FRST
2013-06-24 13:16 - 2013-06-24 13:17 - 01931364 ____A (Farbar) C:\Users\.....\Desktop\FRST64.exe
2013-06-24 13:13 - 2013-06-24 13:13 - 00000000 ___AD C:\Program Files (x86)\UtilityChest_49EI
2013-06-20 15:38 - 2013-06-20 15:38 - 00446432 ____A C:\Windows\Minidump\062013-41511-01.dmp
2013-06-20 15:37 - 2013-06-20 15:37 - 638652380 ____A C:\Windows\MEMORY.DMP
2013-06-19 18:17 - 2013-06-24 11:27 - 00001557 ____A C:\Windows\setupact.log
2013-06-19 18:17 - 2013-06-19 18:17 - 00000306 ____A C:\Windows\PFRO.log
2013-06-19 18:17 - 2013-06-19 18:17 - 00000000 ____A C:\Windows\setuperr.log
2013-06-18 20:32 - 2013-06-18 20:32 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_point64_01011.Wdf
2013-06-18 19:58 - 2013-06-18 20:32 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center
2013-06-12 09:28 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 09:28 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 09:28 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 09:28 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 09:28 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 09:28 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 09:28 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 09:28 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 09:28 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 09:28 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 09:28 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 09:28 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 09:28 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 09:28 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-12 09:28 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-12 09:28 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 09:28 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-12 09:28 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-12 09:28 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 09:27 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 09:27 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 09:27 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 09:27 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 09:27 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-12 09:27 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 09:27 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 09:27 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 09:27 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 09:27 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 09:27 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-12 09:27 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 09:26 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 09:26 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 09:26 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 09:26 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 09:26 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 09:26 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 09:26 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 09:26 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 09:26 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 09:26 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 09:26 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 09:26 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 09:26 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 09:26 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 09:26 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 09:26 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 09:26 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 09:26 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 09:26 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-07 09:57 - 2013-06-07 09:57 - 00001828 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-07 09:57 - 2013-06-07 09:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-07 09:57 - 2013-06-07 09:57 - 00000000 ____D C:\Program Files\iTunes
2013-06-07 09:57 - 2013-06-07 09:57 - 00000000 ____D C:\Program Files\iPod
2013-06-07 09:57 - 2013-06-07 09:57 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-06 09:42 - 2013-06-06 09:43 - 00001154 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-06-06 09:42 - 2013-06-06 09:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-06 09:42 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-05-31 09:59 - 2013-05-31 09:59 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-05-28 22:05 - 2013-05-28 22:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-28 20:22 - 2013-05-29 09:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-05-28 19:05 - 2013-04-12 16:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-05-28 19:05 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-28 19:05 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2013-05-28 19:05 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-05-28 19:05 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2013-05-28 19:05 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll
2013-05-28 19:05 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-28 19:05 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-28 19:05 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-28 19:05 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-05-28 19:05 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-28 19:05 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-28 19:05 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-28 19:05 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-05-28 19:05 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll
2013-05-28 19:01 - 2013-06-24 11:21 - 00083672 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys

==================== One Month Modified Files and Folders =======

2013-06-24 13:25 - 2013-06-24 13:25 - 00000000 ____D C:\FRST
2013-06-24 13:17 - 2013-06-24 13:16 - 01931364 ____A (Farbar) C:\Users\.....\Desktop\FRST64.exe
2013-06-24 13:13 - 2013-06-24 13:13 - 00000000 ___AD C:\Program Files (x86)\UtilityChest_49EI
2013-06-24 12:46 - 2012-12-21 09:53 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-24 12:30 - 2010-10-25 13:23 - 00000000 ____D C:\ProgramData\twonkymedia
2013-06-24 11:49 - 2009-09-03 18:02 - 00654150 ____A C:\Windows\System32\perfh007.dat
2013-06-24 11:49 - 2009-09-03 18:02 - 00130022 ____A C:\Windows\System32\perfc007.dat
2013-06-24 11:49 - 2009-07-14 07:13 - 01498742 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-24 11:37 - 2009-12-28 00:55 - 00000000 ___HD C:\Users\.....\AppData\Local\Corel
2013-06-24 11:37 - 2009-12-28 00:52 - 00000000 ____D C:\Users\.....\Documents\My PSP Files
2013-06-24 11:32 - 2009-07-14 06:45 - 00018736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-24 11:32 - 2009-07-14 06:45 - 00018736 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-24 11:30 - 2013-02-02 10:45 - 00000000 ____D C:\Users\.....\AppData\Roaming\TeamDrive3
2013-06-24 11:28 - 2010-10-25 13:23 - 00000000 ____D C:\Program Files (x86)\TwonkyMedia
2013-06-24 11:27 - 2013-06-19 18:17 - 00001557 ____A C:\Windows\setupact.log
2013-06-24 11:27 - 2013-01-11 22:52 - 00000000 ____D C:\ProgramData\NVIDIA
2013-06-24 11:27 - 2009-12-12 22:00 - 00000000 ____A C:\Windows\System32\Drivers\lvuvc.hs
2013-06-24 11:27 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-24 11:26 - 2009-09-19 01:41 - 01517034 ____A C:\Windows\WindowsUpdate.log
2013-06-24 11:21 - 2013-05-28 19:01 - 00083672 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys
2013-06-24 11:10 - 2009-12-13 02:39 - 00000000 ____D C:\Users\.....\AppData\Roaming\XnView
2013-06-24 10:01 - 2010-02-10 14:48 - 00001034 ____A C:\Windows\Tasks\Google Software Updater.job
2013-06-20 15:55 - 2012-03-09 09:43 - 00168104 ____A C:\Windows\System32\GDIPFONTCACHEV1.DAT
2013-06-20 15:38 - 2013-06-20 15:38 - 00446432 ____A C:\Windows\Minidump\062013-41511-01.dmp
2013-06-20 15:38 - 2013-01-11 22:40 - 00000000 ____D C:\Windows\Minidump
2013-06-20 15:37 - 2013-06-20 15:37 - 638652380 ____A C:\Windows\MEMORY.DMP
2013-06-19 20:43 - 2009-12-13 11:57 - 00000000 ____D C:\Users\.....\Documents\Turbo Lister Backup
2013-06-19 18:17 - 2013-06-19 18:17 - 00000306 ____A C:\Windows\PFRO.log
2013-06-19 18:17 - 2013-06-19 18:17 - 00000000 ____A C:\Windows\setuperr.log
2013-06-18 21:06 - 2011-10-23 17:21 - 00000000 ____D C:\Users\.....\Documents\Sicherung CC Cleaner
2013-06-18 21:02 - 2007-07-12 03:49 - 00000000 ___HD C:\Windows\Panther
2013-06-18 20:57 - 2011-07-11 19:55 - 00000827 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-06-18 20:57 - 2011-07-11 19:55 - 00000000 ____D C:\Program Files\CCleaner
2013-06-18 20:38 - 2010-03-08 00:52 - 00000000 ____D C:\ProgramData\Logishrd
2013-06-18 20:38 - 2009-12-12 22:00 - 00000000 ____D C:\Program Files\Common Files\logishrd
2013-06-18 20:32 - 2013-06-18 20:32 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_point64_01011.Wdf
2013-06-18 20:32 - 2013-06-18 19:58 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center
2013-06-18 20:28 - 2009-12-12 21:32 - 00000000 ____D C:\users\.....
2013-06-18 20:16 - 2012-08-07 10:44 - 00000000 ____D C:\users\.....
2013-06-18 20:16 - 2012-03-25 15:25 - 00000000 ____D C:\users\Gast
2013-06-18 20:16 - 2012-03-25 15:22 - 00000000 ____D C:\users\Internet
2013-06-18 20:16 - 2009-12-12 23:42 - 00000000 ____D C:\Software
2013-06-18 20:16 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-06-18 08:45 - 2012-08-15 23:39 - 00005642 ____A C:\Windows\Sandboxie.ini
2013-06-14 08:49 - 2012-07-28 11:03 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-14 08:49 - 2012-07-28 11:03 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 11:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-06-12 09:28 - 2009-12-13 00:55 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-08 16:08 - 2013-06-12 09:27 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-08 16:07 - 2013-06-12 09:27 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-08 16:06 - 2013-06-12 09:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-08 16:06 - 2013-06-12 09:27 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-08 16:06 - 2013-06-12 09:27 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-08 14:28 - 2013-06-12 09:27 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-08 13:42 - 2013-06-12 09:27 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-08 13:40 - 2013-06-12 09:27 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-08 13:40 - 2013-06-12 09:27 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-08 13:40 - 2013-06-12 09:27 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-08 13:40 - 2013-06-12 09:27 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-08 13:13 - 2013-06-12 09:27 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-07 09:57 - 2013-06-07 09:57 - 00001828 ____A C:\Users\Public\Desktop\iTunes.lnk
2013-06-07 09:57 - 2013-06-07 09:57 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-07 09:57 - 2013-06-07 09:57 - 00000000 ____D C:\Program Files\iTunes
2013-06-07 09:57 - 2013-06-07 09:57 - 00000000 ____D C:\Program Files\iPod
2013-06-07 09:57 - 2013-06-07 09:57 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-06 09:43 - 2013-06-06 09:42 - 00001154 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-06-06 09:43 - 2013-06-06 09:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-05-31 09:59 - 2013-05-31 09:59 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-05-31 09:59 - 2010-03-08 21:19 - 00000000 ____D C:\ProgramData\Apple Computer
2013-05-30 08:08 - 2012-07-17 19:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-05-29 09:28 - 2013-05-28 20:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-05-28 22:05 - 2013-05-28 22:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-05-28 19:21 - 2009-07-14 06:45 - 00542232 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-28 19:11 - 2009-08-15 06:20 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-05-28 19:03 - 2013-02-02 10:45 - 00000000 ____D C:\Program Files (x86)\TeamDrive 3
2013-05-28 19:02 - 2013-02-02 10:45 - 00001071 ____A C:\Users\Public\Desktop\TeamDrive 3.lnk

Files to move or delete:
====================
C:\ProgramData\FullRemove.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-23 09:46

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

nun die addition txt
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2013
Ran by ..... at 2013-06-24 13:26:05
Running from C:\Users\.....\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

1&1 EasyLogin (x32)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Acer Arcade Deluxe (x32 Version: 3.1.6731)
Acer Backup Manager (x32 Version: 2.0.2.19)
Acer eRecovery Management (x32 Version: 4.05.3002)
Acer GameZone Console (x32 Version: 5.1.0.2)
Acer Registration (x32 Version: 1.02.3004)
Acer ScreenSaver (x32 Version: 1.1.0812)
Acer Updater (x32 Version: 1.01.3014)
Acronis*True*Image*Home 2012 (x32 Version: 15.0.7119)
Adobe Flash Player 11 ActiveX (x32 Version: 11.6.602.180)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
Audible Download Manager (x32 Version: 6.6.0.15)
Avira Internet Security (x32 Version: 13.0.0.3736)
Backup Manager Advance (x32 Version: 2.0.2.19)
Bonjour (Version: 3.0.0.10)
CameraHelperMsi (x32 Version: 13.31.1038.0)
Canon Easy-WebPrint EX (x32)
Canon IJ Network Scan Utility (x32)
Canon IJ Network Tool (x32)
Canon MP Navigator EX 3.0 (x32)
Canon MP640 series Benutzerregistrierung (x32)
Canon MP640 series MP Drivers
Canon Utilities CameraWindow (x32 Version: 7.0.0.8)
Canon Utilities Easy-PhotoPrint EX (x32)
Canon Utilities My Printer (x32)
Canon Utilities Solution Menu (x32)
CCleaner (Version: 4.02)
CDex - Open Source Digital Audio CD Extractor (x32 Version: 1.70.4.2009)
CD-LabelPrint (x32)
Corel Paint Shop Pro Photo X2 (x32 Version: 12.50.0001)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
DeLorme Street Atlas USA 2012 Plus (x32 Version: 12.110.34891)
DHTML Editing Component (x32 Version: 6.02.0001)
eBay Worldwide (x32 Version: 2.1.0703)
erLT (x32 Version: 1.20.0137)
erLT (x32 Version: 1.20.137.31)
eSobi v2 (x32 Version: 2.0.4.000274)
Exif-Viewer 2.50  (x32 Version: 2.50)
Firebird SQL Server - MAGIX Edition (x32 Version: 2.1.31.0)
Free Mp3 Wma Converter V 1.9 (x32 Version: 1.9.0.0)
Free YouTube to MP3 Converter version 3.12.0.128 (x32 Version: 3.12.0.128)
Garmin BaseCamp (x32 Version: 4.1.2)
Garmin City Navigator Europe NT 2011.32 Update (x32 Version: 14.30.0.0)
Garmin Communicator Plugin (x32 Version: 4.0.1)
Garmin Communicator Plugin x64 (Version: 4.0.1)
Garmin MapInstall (x32 Version: 4.0.3)
Garmin MapSource (x32 Version: 6.16.3)
Garmin TOPO U.S. 2008 (x32 Version: 4.0.0.0)
Garmin USB Drivers (x32 Version: 2.3.1.0)
Garmin WebUpdater (x32 Version: 2.5.6)
Google Earth (x32 Version: 5.2.1.1588)
Google Updater (x32 Version: 2.4.2432.1652)
Hotkey Utility (x32 Version: 1.00.3003)
Identity Card (x32 Version: 1.00.3001)
ImageMixer 3 SE for SD (x32 Version: 3.00.039)
ImagXpress (x32 Version: 7.0.74.0)
ImgBurn (x32 Version: 2.5.7.0)
Intel® Matrix Storage Manager
iTunes (Version: 11.0.4.4)
Java 7 Update 9 (64-bit) (Version: 7.0.90)
JMicron JMB36X Driver (x32 Version: 1.00.0000)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Logitech Webcam-Software (x32 Version: 2.30)
LWS Facebook (x32 Version: 13.31.1038.0)
LWS Gallery (x32 Version: 13.31.1038.0)
LWS Help_main (x32 Version: 13.31.1044.0)
LWS Launcher (x32 Version: 13.31.1038.0)
LWS Motion Detection (x32 Version: 13.30.1395.0)
LWS Pictures And Video (x32 Version: 13.31.1038.0)
LWS Twitter (x32 Version: 13.30.1346.0)
LWS Video Mask Maker (x32 Version: 13.30.1379.0)
LWS VideoEffects (Version: 13.30.1379.0)
LWS Webcam Software (x32 Version: 13.31.1038.0)
LWS WLM Plugin (x32 Version: 1.30.1201.0)
LWS YouTube Plugin (x32 Version: 13.31.1038.0)
MAGIX MP3 Maker 16 11.0.0.78 (D) (x32 Version: 11.0.0.78)
MAGIX Online Druck Service (x32 Version: 3.4.3.0)
MAGIX Screenshare (x32 Version: 4.3.6.1987)
MAGIX Speed 2 (MSI) (x32 Version: 6.0.1.4)
MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6)
MAGIX Speed burnR (x32 Version: 6.0.1.4)
MAGIX Video deluxe MX Plus (x32 Version: 11.0.3.0)
MAGIX Videoton Cleaning Lab (x32 Version: 1.0.0.0)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
MapSource - US Topo 24K National Parks, West v2 (x32)
MapSource - US Topo 24K National Parks, West v3 (x32 Version: 3.00)
MapSource (x32 Version: 6.3)
Mesh Runtime (x32 Version: 15.4.5722.2)
MICHELsoft 10.0 (x32 Version: 10.0.32)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Language Pack 2007 - German/Deutsch (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office O MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3) (x32)
Microsoft Office SharePoint Designer MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Suite Activation Assistant (x32 Version: 2.9)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office X MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Works (x32 Version: 9.7.0621)
Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0)
MozBackup 1.5.1 (x32)
Mozilla Firefox 21.0 (x86 de) (x32 Version: 21.0)
Mozilla Maintenance Service (x32 Version: 17.0.6)
Mozilla Thunderbird 17.0.6 (x86 de) (x32 Version: 17.0.6)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
MyWinLocker (x32 Version: 3.1.72.0)
neroxml (x32 Version: 1.0.0)
Nuance PDF Reader (x32 Version: 6.00.0041)
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19)
NVIDIA 3D Vision Treiber 311.06 (Version: 311.06)
NVIDIA Grafiktreiber 311.06 (Version: 311.06)
NVIDIA HD-Audiotreiber 1.3.12.0 (Version: 1.3.12.0)
NVIDIA Install Application (Version: 2.1002.108.688)
NVIDIA PhysX (x32 Version: 9.12.0209)
NVIDIA PhysX-Systemsoftware 9.12.0209 (Version: 9.12.0209)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106)
NVIDIA Systemsteuerung 311.06 (Version: 311.06)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
PicPick (x32 Version: 3.1.2)
Plus Pack für Acronis True Image Home 2012 (x32 Version: 15.0.6131)
QuickTime (x32 Version: 7.74.80.86)
Radiotracker (x32 Version: 6.2.13600.0)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30105)
Revo Uninstaller 1.94 (x32 Version: 1.94)
Sandboxie 3.76 (64-bit) (Version: 3.76)
Security Task Manager 1.8g (x32 Version: 1.8g)
shopping-preise.de - AddOn für Firefox (x32 Version: 2.81)
Skype Click to Call (x32 Version: 5.9.9216)
Skype™ 6.1 (x32 Version: 6.1.129)
Star Defender 4 (x32)
System Requirements Lab (x32)
TeamDrive 3 (x32 Version: 3.1.0.342)
Turbo Lister 2 (x32 Version: 2.00.0000)
TwonkyBeam for Internet Explorer (x32 Version: 1.2.19.0)
TwonkyMedia (x32 Version: 6.0.2.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2598242) 64-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 64-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 64-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678) (x32)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update für Microsoft Office Word 2007 Help (KB963665) (x32)
Vasco da Gama 4 (x32 Version: 4.00.0000)
Welcome Center (x32 Version: 1.00.3004)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (04/19/2012 2.3.1.0) (Version: 04/19/2012 2.3.1.0)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Sync (x32 Version: 14.0.8089.726)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinWein "de Pays" [Rel. 6.0] (x32 Version: 2.6.0.3)
XnView 1.99.6 (x32 Version: 1.99.6)

==================== Restore Points  =========================

22-04-2013 17:27:16 Removed iTunes
22-04-2013 17:33:04 Installed iTunes
22-04-2013 17:38:07 Removed iTunes
22-04-2013 17:41:28 Installed iTunes
28-05-2013 17:06:39 Windows Update
28-05-2013 19:17:56 Removed iTunes
28-05-2013 19:26:04 Installed iTunes
28-05-2013 19:29:13 Removed iTunes
03-06-2013 15:51:10 Windows Update
07-06-2013 06:40:33 Windows Update
11-06-2013 06:25:51 Windows Update
12-06-2013 07:26:44 Windows Update
18-06-2013 06:50:16 Windows Update
18-06-2013 17:57:39 DCInstallRestorePoint
18-06-2013 18:13:25 Wiederherstellungsvorgang
18-06-2013 18:21:24 Windows Update
18-06-2013 18:32:22 DCInstallRestorePoint

==================== Scheduled Tasks (whitelisted) =============

Task: {11437FED-0025-442C-8768-1987886CB643} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {17A7EA02-DCC2-42D6-B79D-59E0BC11396F} - System32\Tasks\{0363398C-31CA-4644-980C-6808BCEEEE1D} => C:\Program Files (x86)\iTunes\iTunes.exe [2013-05-31] (Apple Inc.)
Task: {2017E248-01EE-4A0C-86AC-33495593074C} - System32\Tasks\ASC4_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 4\PMonitor.exe No File
Task: {28FE0E90-A14F-4E54-99EC-285AE251FF1F} - System32\Tasks\{30EB0BB5-2B0F-4485-85B7-C337981EF38D} => C:\program files (x86)\mozilla firefox\firefox.exe [2013-05-28] (Mozilla Corporation)
Task: {2C3E5F59-88BA-4487-9F16-CFAC80AA1691} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {2E6502F5-E020-4239-BCDA-68FFCF0F5B68} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation)
Task: {39656657-9859-4035-A11D-2F50FBF68F46} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {50712161-7C3A-477B-B51D-D309DC59290C} - System32\Tasks\{56ED4D2F-9B0F-47FD-9100-BC95754C8D3D} => C:\Program Files (x86)\iTunes\iTunes.exe [2013-05-31] (Apple Inc.)
Task: {78E7E5EF-150F-4E2E-907E-9161D3A43556} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {7CE4B3DF-76CC-4128-9583-B2DC0B683666} - System32\Tasks\Google Software Updater => C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-09-07] (Google)
Task: {7F10B080-FA1C-45FB-97D9-DB8B2DAD23F7} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {84D0FD64-C3A0-4C24-8807-B0668F1E3C91} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {99343099-9549-4927-BD9E-0BFEF6DD8A57} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {9CF388D0-E1F4-49C0-9581-35039A593A69} - System32\Tasks\{DFDE255A-47DE-41F5-9E15-464295BBD28E} => C:\Program Files (x86)\iTunes\iTunes.exe [2013-05-31] (Apple Inc.)
Task: {AFAEFFA6-1981-4C78-92FD-C7B83876D9AF} - System32\Tasks\{7F529CE6-5238-4CF5-A0D3-D091204A7E79} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-01-08] (Skype Technologies S.A.)
Task: {B1405CDA-0F77-480A-B559-98963DD60018} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {BEADA6FD-DD9B-417A-A27B-D51B0812788D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd)
Task: {C186A8B2-8730-4F86-88F9-06CB5E12A8C1} - System32\Tasks\WPD\SqmUpload_S-1-5-21-3543778770-3754037758-82543695-1003 => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {E3DFFCE8-3970-41B5-8F48-002759AE0711} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-14] (Adobe Systems Incorporated)

==================== Faulty Device Manager Devices =============

Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Microsoft PS/2-Maus
Description: Microsoft PS/2-Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/21/2013 06:03:31 PM) (Source: MouseKeyboardCenter) (User: )
Description: Unknown Node:#text        -->

Error: (06/18/2013 08:57:25 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 21.0.0.4879, Zeitstempel: 0x518ec3cc
Name des fehlerhaften Moduls: xul.dll, Version: 21.0.0.4879, Zeitstempel: 0x518ec306
Ausnahmecode: 0xc0000005
Fehleroffset: 0x001c9789
ID des fehlerhaften Prozesses: 0xa80
Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0
Pfad der fehlerhaften Anwendung: firefox.exe1
Pfad des fehlerhaften Moduls: firefox.exe2
Berichtskennung: firefox.exe3

Error: (06/18/2013 08:40:54 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Während der Initialisierung der Suchengine trat ein unbekannter Fehler auf!
Fehlercode: 0x35

Error: (06/18/2013 08:40:30 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Während der Initialisierung der Suchengine trat ein unbekannter Fehler auf!
Fehlercode: 0x35

Error: (06/18/2013 08:40:21 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Während der Initialisierung der Suchengine trat ein unbekannter Fehler auf!
Fehlercode: 0x35

Error: (06/18/2013 08:40:01 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Während der Initialisierung der Suchengine trat ein unbekannter Fehler auf!
Fehlercode: 0x35

Error: (06/18/2013 08:33:23 PM) (Source: MouseKeyboardCenter) (User: )
Description: Unknown Node:#text        -->

Error: (06/18/2013 08:19:04 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: Während der Initialisierung der Suchengine trat ein unbekannter Fehler auf!
Fehlercode: 0x35

Error: (06/18/2013 08:19:04 PM) (Source: Avira FireWall) (User: )
Description: Ungültige Lizenz

Error: (06/18/2013 07:59:20 PM) (Source: MouseKeyboardCenter) (User: )
Description: Unknown Node:#text        -->


System errors:
=============
Error: (06/24/2013 01:26:08 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "Programme" den Befehl "chkdsk" aus.

Error: (06/24/2013 01:04:22 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "Programme" den Befehl "chkdsk" aus.

Error: (06/24/2013 00:58:15 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "Programme" den Befehl "chkdsk" aus.

Error: (06/24/2013 00:43:22 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "Programme" den Befehl "chkdsk" aus.

Error: (06/24/2013 11:30:28 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (06/24/2013 11:30:28 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535

Error: (06/24/2013 11:30:28 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535

Error: (06/24/2013 11:30:28 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (06/24/2013 11:30:28 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2140993535

Error: (06/24/2013 11:30:28 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet:
%%-2140993535


Microsoft Office Sessions:
=========================
Error: (06/21/2013 06:03:31 PM) (Source: MouseKeyboardCenter)(User: )
Description: Unknown Node:#text        -->

Error: (06/18/2013 08:57:25 PM) (Source: Application Error)(User: )
Description: firefox.exe21.0.0.4879518ec3ccxul.dll21.0.0.4879518ec306c0000005001c9789a8001ce6c55a4d7826dC:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dlle9f39ea2-d848-11e2-bf07-00016c6d67d0

Error: (06/18/2013 08:40:54 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x35

Error: (06/18/2013 08:40:30 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x35

Error: (06/18/2013 08:40:21 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x35

Error: (06/18/2013 08:40:01 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x35

Error: (06/18/2013 08:33:23 PM) (Source: MouseKeyboardCenter)(User: )
Description: Unknown Node:#text        -->

Error: (06/18/2013 08:19:04 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x35

Error: (06/18/2013 08:19:04 PM) (Source: Avira FireWall)(User: )
Description: Ungültige Lizenz

Error: (06/18/2013 07:59:20 PM) (Source: MouseKeyboardCenter)(User: )
Description: Unknown Node:#text        -->


CodeIntegrity Errors:
===================================
  Date: 2012-07-26 11:57:41.307
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2012-07-26 11:57:41.244
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2010-01-06 11:08:30.761
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Common Files\MAGIX Shared\Syscheck\SysCNTio.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2010-01-06 11:08:30.761
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\Common Files\MAGIX Shared\Syscheck\SysCNTio.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Percentage of memory in use: 48%
Total physical RAM: 4087.08 MB
Available physical RAM: 2089.93 MB
Total Pagefile: 8172.34 MB
Available Pagefile: 6124.72 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB

==================== Drives ================================

Drive c: (Programme) (Fixed) (Total:229.54 GB) (Free:74.5 GB) NTFS
Drive d: (Bilder Urlaub Musik Videos) (Fixed) (Total:458.46 GB) (Free:82.19 GB) NTFS
Drive p: (Private Dateien ) (Fixed) (Total:228.41 GB) (Free:214.5 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 9AF2C5BE)
Partition 1: (Not Active) - (Size=993 KB) - (Type=42)
Partition 2: (Not Active) - (Size=15 GB) - (Type=27)
Partition 3: (Active) - (Size=100 MB) - (Type=42)
Partition 4: (Not Active) - (Size=230 GB) - (Type=42)

==================== End Of Log ============================


schrauber 24.06.2013 12:52

Unten auf erweitert klicken und dann Anhänge verwalten, Bild anhängen oder aber per URL einfügen.

robili 24.06.2013 13:01

Liste der Anhänge anzeigen (Anzahl: 1)
Hallo,
müßte nun geklappt haben, die Nachricht vom Avira Anhang 56881
gruß
robili

schrauber 24.06.2013 13:48

Dann mach mal wie angegeben den kompletten Suchlauf mit Avira und poste das Logfile.

robili 24.06.2013 16:46

hallo,
hier nun der 2. Lauf vom Avira auf der Suche nach den Rootkits
Code:

Avira Internet Security
Erstellungsdatum der Reportdatei: Montag, 24. Juni 2013  17:04


Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  :
Seriennummer  :
Plattform      : Windows 7 Home Premium
Windowsversion : (Service Pack 1)  [6.1.7601]
Boot Modus    : Normal gebootet
Benutzername  : SYSTEM
Computername  : -PC

Versionsinformationen:
BUILD.DAT      : 13.0.0.3736    64555 Bytes  14.06.2013 14:38:00
AVSCAN.EXE    : 13.6.0.1722  634936 Bytes  24.06.2013 09:21:07
AVSCANRC.DLL  : 13.6.0.1550    62520 Bytes  24.06.2013 09:21:07
LUKE.DLL      : 13.6.0.1550    65080 Bytes  24.06.2013 09:21:20
AVSCPLR.DLL    : 13.6.0.1712    92216 Bytes  24.06.2013 09:21:08
AVREG.DLL      : 13.6.0.1550  247864 Bytes  24.06.2013 09:21:07
avlode.dll    : 13.6.2.1704  449592 Bytes  24.06.2013 09:21:05
avlode.rdf    : 13.0.1.18      26349 Bytes  21.06.2013 15:18:53
VBASE000.VDF  : 7.11.70.0  66736640 Bytes  04.04.2013 17:03:50
VBASE001.VDF  : 7.11.74.226  2201600 Bytes  30.04.2013 17:01:16
VBASE002.VDF  : 7.11.80.60  2751488 Bytes  28.05.2013 17:01:19
VBASE003.VDF  : 7.11.85.214  2162688 Bytes  21.06.2013 15:18:43
VBASE004.VDF  : 7.11.85.215    2048 Bytes  21.06.2013 15:18:43
VBASE005.VDF  : 7.11.85.216    2048 Bytes  21.06.2013 15:18:43
VBASE006.VDF  : 7.11.85.217    2048 Bytes  21.06.2013 15:18:43
VBASE007.VDF  : 7.11.85.218    2048 Bytes  21.06.2013 15:18:43
VBASE008.VDF  : 7.11.85.219    2048 Bytes  21.06.2013 15:18:43
VBASE009.VDF  : 7.11.85.220    2048 Bytes  21.06.2013 15:18:43
VBASE010.VDF  : 7.11.85.221    2048 Bytes  21.06.2013 15:18:43
VBASE011.VDF  : 7.11.85.222    2048 Bytes  21.06.2013 15:18:43
VBASE012.VDF  : 7.11.85.223    2048 Bytes  21.06.2013 15:18:43
VBASE013.VDF  : 7.11.85.224    2048 Bytes  21.06.2013 15:18:43
VBASE014.VDF  : 7.11.86.93    870400 Bytes  24.06.2013 09:21:01
VBASE015.VDF  : 7.11.86.94      2048 Bytes  24.06.2013 09:21:01
VBASE016.VDF  : 7.11.86.95      2048 Bytes  24.06.2013 09:21:01
VBASE017.VDF  : 7.11.86.96      2048 Bytes  24.06.2013 09:21:01
VBASE018.VDF  : 7.11.86.97      2048 Bytes  24.06.2013 09:21:01
VBASE019.VDF  : 7.11.86.98      2048 Bytes  24.06.2013 09:21:01
VBASE020.VDF  : 7.11.86.99      2048 Bytes  24.06.2013 09:21:01
VBASE021.VDF  : 7.11.86.100    2048 Bytes  24.06.2013 09:21:01
VBASE022.VDF  : 7.11.86.101    2048 Bytes  24.06.2013 09:21:01
VBASE023.VDF  : 7.11.86.102    2048 Bytes  24.06.2013 09:21:01
VBASE024.VDF  : 7.11.86.103    2048 Bytes  24.06.2013 09:21:02
VBASE025.VDF  : 7.11.86.104    2048 Bytes  24.06.2013 09:21:02
VBASE026.VDF  : 7.11.86.105    2048 Bytes  24.06.2013 09:21:02
VBASE027.VDF  : 7.11.86.106    2048 Bytes  24.06.2013 09:21:02
VBASE028.VDF  : 7.11.86.107    2048 Bytes  24.06.2013 09:21:02
VBASE029.VDF  : 7.11.86.108    2048 Bytes  24.06.2013 09:21:02
VBASE030.VDF  : 7.11.86.109    2048 Bytes  24.06.2013 09:21:02
VBASE031.VDF  : 7.11.86.154    9728 Bytes  24.06.2013 11:10:44
Engineversion  : 8.2.12.66
AEVDF.DLL      : 8.1.3.4      102774 Bytes  13.06.2013 14:44:44
AESCRIPT.DLL  : 8.1.4.124    487806 Bytes  20.06.2013 09:37:29
AESCN.DLL      : 8.1.10.4      131446 Bytes  13.04.2013 17:03:58
AESBX.DLL      : 8.2.5.12      606578 Bytes  13.04.2013 17:03:59
AERDL.DLL      : 8.2.0.128    688504 Bytes  13.06.2013 14:44:43
AEPACK.DLL    : 8.3.2.24      749945 Bytes  20.06.2013 09:37:29
AEOFFICE.DLL  : 8.1.2.60      205181 Bytes  18.06.2013 18:40:52
AEHEUR.DLL    : 8.1.4.426    5951866 Bytes  20.06.2013 09:37:29
AEHELP.DLL    : 8.1.27.2      266617 Bytes  04.06.2013 13:26:13
AEGEN.DLL      : 8.1.7.4      442741 Bytes  28.05.2013 17:01:21
AEEXP.DLL      : 8.4.0.34      201079 Bytes  04.06.2013 13:26:30
AEEMU.DLL      : 8.1.3.2      393587 Bytes  13.04.2013 17:03:54
AECORE.DLL    : 8.1.31.2      201080 Bytes  13.04.2013 17:03:53
AEBB.DLL      : 8.1.1.4        53619 Bytes  13.04.2013 17:03:53
AVWINLL.DLL    : 13.6.0.1550    23608 Bytes  24.06.2013 09:20:58
AVPREF.DLL    : 13.6.0.1550    48184 Bytes  24.06.2013 09:21:07
AVREP.DLL      : 13.6.0.1550  175672 Bytes  24.06.2013 09:21:07
AVARKT.DLL    : 13.6.0.1626  258104 Bytes  24.06.2013 09:21:02
AVEVTLOG.DLL  : 13.6.0.1550  164920 Bytes  24.06.2013 09:21:04
SQLITE3.DLL    : 3.7.0.1      397704 Bytes  13.04.2013 17:04:51
AVSMTP.DLL    : 13.6.0.1550    60472 Bytes  24.06.2013 09:21:08
NETNT.DLL      : 13.6.0.1550    13368 Bytes  24.06.2013 09:21:21
RCIMAGE.DLL    : 13.4.0.360  5154080 Bytes  13.04.2013 17:02:24
RCTEXT.DLL    : 13.6.0.1624    67128 Bytes  24.06.2013 09:20:58

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Suche nach Rootkits und aktiver Malware
Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\PROFILES\rootkit.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Durchsuche aktive Programme...........: ein
Laufende Programme erweitert..........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: ein
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: vollständig

Beginn des Suchlaufs: Montag, 24. Juni 2013  17:04

Der Suchlauf nach versteckten Objekten wird begonnen.
Versteckter Treiber
  [HINWEIS]  Eine Speicherveränderung wurde entdeckt, die möglicherweise zur versteckten Dateizugriffen missbraucht werden könnte.

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'svchost.exe' - '52' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvvsvc.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvSCPAPISvr.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '45' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '97' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '114' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '82' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '156' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'SbieSvc.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '73' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvxdsync.exe' - '50' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvvsvc.exe' - '47' Modul(e) wurden durchsucht
Durchsuche Prozess 'spoolsv.exe' - '95' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '48' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '76' Modul(e) wurden durchsucht
Durchsuche Prozess 'schedul2.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'armsvc.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'afcdpsrv.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'avfwsvc.exe' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '103' Modul(e) wurden durchsucht
Durchsuche Prozess 'AppleMobileDeviceService.exe' - '73' Modul(e) wurden durchsucht
Durchsuche Prozess 'mDNSResponder.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'MWLService.exe' - '49' Modul(e) wurden durchsucht
Durchsuche Prozess 'syncagentsrv.exe' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'twonkymediaserverwatchdog.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchIndexer.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'IAANTMon.exe' - '40' Modul(e) wurden durchsucht
Durchsuche Prozess 'TwonkyMediaServer.exe' - '50' Modul(e) wurden durchsucht
Durchsuche Prozess 'conhost.exe' - '14' Modul(e) wurden durchsucht
Durchsuche Prozess 'avshadow.exe' - '29' Modul(e) wurden durchsucht
Durchsuche Prozess 'avmailc.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'AVWEBGRD.EXE' - '72' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '60' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'Dwm.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskhost.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskeng.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'Explorer.EXE' - '177' Modul(e) wurden durchsucht
Durchsuche Prozess 'ipoint.exe' - '67' Modul(e) wurden durchsucht
Durchsuche Prozess 'itype.exe' - '68' Modul(e) wurden durchsucht
Durchsuche Prozess 'sidebar.exe' - '106' Modul(e) wurden durchsucht
Durchsuche Prozess 'SbieCtrl.exe' - '45' Modul(e) wurden durchsucht
Durchsuche Prozess 'TeamDrive3.exe' - '93' Modul(e) wurden durchsucht
Durchsuche Prozess 'LWS.exe' - '43' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvtray.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '108' Modul(e) wurden durchsucht
Durchsuche Prozess 'iTunesHelper.exe' - '79' Modul(e) wurden durchsucht
Durchsuche Prozess 'iPodService.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmpnetwk.exe' - '108' Modul(e) wurden durchsucht
Durchsuche Prozess 'FABS.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'daemonu.exe' - '75' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'OSPPSVC.EXE' - '32' Modul(e) wurden durchsucht
Durchsuche Prozess 'thunderbird.exe' - '126' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '126' Modul(e) wurden durchsucht
Durchsuche Prozess 'vssvc.exe' - '47' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'wininit.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'services.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsass.exe' - '70' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsm.exe' - '16' Modul(e) wurden durchsucht
Durchsuche Prozess 'winlogon.exe' - '32' Modul(e) wurden durchsucht

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '7123' Dateien ).



Ende des Suchlaufs: Montag, 24. Juni 2013  17:36
Benötigte Zeit: 32:24 Minute(n)

Der Suchlauf wurde vollständig durchgeführt.

      0 Verzeichnisse wurden überprüft
  11067 Dateien wurden geprüft
      0 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      0 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
  11067 Dateien ohne Befall
    68 Archive wurden durchsucht
      0 Warnungen
      1 Hinweise
 1499452 Objekte wurden beim Rootkitscan durchsucht
      1 Versteckte Objekte wurden gefunden

dieses ist der erste Lauf, habe die den Scan getrennt, da er immer nach der Suche von den Rootkits stehen bleibt und auf Antwort wartet, darum läuft diese Suche mittags zuerst und nachmittags der zweite.
Code:

Avira Internet Security
Erstellungsdatum der Reportdatei: Montag, 24. Juni 2013  15:03


Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer  :
Seriennummer  :
Plattform      : Windows 7 Home Premium
Windowsversion : (Service Pack 1)  [6.1.7601]
Boot Modus    : Normal gebootet
Benutzername  : SYSTEM
Computername  : -PC

Versionsinformationen:
BUILD.DAT      : 13.0.0.3736    64555 Bytes  14.06.2013 14:38:00
AVSCAN.EXE    : 13.6.0.1722  634936 Bytes  24.06.2013 09:21:07
AVSCANRC.DLL  : 13.6.0.1550    62520 Bytes  24.06.2013 09:21:07
LUKE.DLL      : 13.6.0.1550    65080 Bytes  24.06.2013 09:21:20
AVSCPLR.DLL    : 13.6.0.1712    92216 Bytes  24.06.2013 09:21:08
AVREG.DLL      : 13.6.0.1550  247864 Bytes  24.06.2013 09:21:07
avlode.dll    : 13.6.2.1704  449592 Bytes  24.06.2013 09:21:05
avlode.rdf    : 13.0.1.18      26349 Bytes  21.06.2013 15:18:53
VBASE000.VDF  : 7.11.70.0  66736640 Bytes  04.04.2013 17:03:50
VBASE001.VDF  : 7.11.74.226  2201600 Bytes  30.04.2013 17:01:16
VBASE002.VDF  : 7.11.80.60  2751488 Bytes  28.05.2013 17:01:19
VBASE003.VDF  : 7.11.85.214  2162688 Bytes  21.06.2013 15:18:43
VBASE004.VDF  : 7.11.85.215    2048 Bytes  21.06.2013 15:18:43
VBASE005.VDF  : 7.11.85.216    2048 Bytes  21.06.2013 15:18:43
VBASE006.VDF  : 7.11.85.217    2048 Bytes  21.06.2013 15:18:43
VBASE007.VDF  : 7.11.85.218    2048 Bytes  21.06.2013 15:18:43
VBASE008.VDF  : 7.11.85.219    2048 Bytes  21.06.2013 15:18:43
VBASE009.VDF  : 7.11.85.220    2048 Bytes  21.06.2013 15:18:43
VBASE010.VDF  : 7.11.85.221    2048 Bytes  21.06.2013 15:18:43
VBASE011.VDF  : 7.11.85.222    2048 Bytes  21.06.2013 15:18:43
VBASE012.VDF  : 7.11.85.223    2048 Bytes  21.06.2013 15:18:43
VBASE013.VDF  : 7.11.85.224    2048 Bytes  21.06.2013 15:18:43
VBASE014.VDF  : 7.11.86.93    870400 Bytes  24.06.2013 09:21:01
VBASE015.VDF  : 7.11.86.94      2048 Bytes  24.06.2013 09:21:01
VBASE016.VDF  : 7.11.86.95      2048 Bytes  24.06.2013 09:21:01
VBASE017.VDF  : 7.11.86.96      2048 Bytes  24.06.2013 09:21:01
VBASE018.VDF  : 7.11.86.97      2048 Bytes  24.06.2013 09:21:01
VBASE019.VDF  : 7.11.86.98      2048 Bytes  24.06.2013 09:21:01
VBASE020.VDF  : 7.11.86.99      2048 Bytes  24.06.2013 09:21:01
VBASE021.VDF  : 7.11.86.100    2048 Bytes  24.06.2013 09:21:01
VBASE022.VDF  : 7.11.86.101    2048 Bytes  24.06.2013 09:21:01
VBASE023.VDF  : 7.11.86.102    2048 Bytes  24.06.2013 09:21:01
VBASE024.VDF  : 7.11.86.103    2048 Bytes  24.06.2013 09:21:02
VBASE025.VDF  : 7.11.86.104    2048 Bytes  24.06.2013 09:21:02
VBASE026.VDF  : 7.11.86.105    2048 Bytes  24.06.2013 09:21:02
VBASE027.VDF  : 7.11.86.106    2048 Bytes  24.06.2013 09:21:02
VBASE028.VDF  : 7.11.86.107    2048 Bytes  24.06.2013 09:21:02
VBASE029.VDF  : 7.11.86.108    2048 Bytes  24.06.2013 09:21:02
VBASE030.VDF  : 7.11.86.109    2048 Bytes  24.06.2013 09:21:02
VBASE031.VDF  : 7.11.86.154    9728 Bytes  24.06.2013 11:10:44
Engineversion  : 8.2.12.66
AEVDF.DLL      : 8.1.3.4      102774 Bytes  13.06.2013 14:44:44
AESCRIPT.DLL  : 8.1.4.124    487806 Bytes  20.06.2013 09:37:29
AESCN.DLL      : 8.1.10.4      131446 Bytes  13.04.2013 17:03:58
AESBX.DLL      : 8.2.5.12      606578 Bytes  13.04.2013 17:03:59
AERDL.DLL      : 8.2.0.128    688504 Bytes  13.06.2013 14:44:43
AEPACK.DLL    : 8.3.2.24      749945 Bytes  20.06.2013 09:37:29
AEOFFICE.DLL  : 8.1.2.60      205181 Bytes  18.06.2013 18:40:52
AEHEUR.DLL    : 8.1.4.426    5951866 Bytes  20.06.2013 09:37:29
AEHELP.DLL    : 8.1.27.2      266617 Bytes  04.06.2013 13:26:13
AEGEN.DLL      : 8.1.7.4      442741 Bytes  28.05.2013 17:01:21
AEEXP.DLL      : 8.4.0.34      201079 Bytes  04.06.2013 13:26:30
AEEMU.DLL      : 8.1.3.2      393587 Bytes  13.04.2013 17:03:54
AECORE.DLL    : 8.1.31.2      201080 Bytes  13.04.2013 17:03:53
AEBB.DLL      : 8.1.1.4        53619 Bytes  13.04.2013 17:03:53
AVWINLL.DLL    : 13.6.0.1550    23608 Bytes  24.06.2013 09:20:58
AVPREF.DLL    : 13.6.0.1550    48184 Bytes  24.06.2013 09:21:07
AVREP.DLL      : 13.6.0.1550  175672 Bytes  24.06.2013 09:21:07
AVARKT.DLL    : 13.6.0.1626  258104 Bytes  24.06.2013 09:21:02
AVEVTLOG.DLL  : 13.6.0.1550  164920 Bytes  24.06.2013 09:21:04
SQLITE3.DLL    : 3.7.0.1      397704 Bytes  13.04.2013 17:04:51
AVSMTP.DLL    : 13.6.0.1550    60472 Bytes  24.06.2013 09:21:08
NETNT.DLL      : 13.6.0.1550    13368 Bytes  24.06.2013 09:21:21
RCIMAGE.DLL    : 13.4.0.360  5154080 Bytes  13.04.2013 17:02:24
RCTEXT.DLL    : 13.6.0.1624    67128 Bytes  24.06.2013 09:20:58

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Manuelle Auswahl
Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\PROFILES\folder.avp
Protokollierung.......................: standard
Primäre Aktion........................: interaktiv
Sekundäre Aktion......................: ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:, D:, P:,
Durchsuche aktive Programme...........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Datei Suchmodus.......................: Intelligente Dateiauswahl
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: erweitert

Beginn des Suchlaufs: Montag, 24. Juni 2013  15:03

Der Suchlauf über die Masterbootsektoren wird begonnen:
Masterbootsektor HD0
    [INFO]      Es wurde kein Virus gefunden!

Der Suchlauf über die Bootsektoren wird begonnen:

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'svchost.exe' - '52' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvvsvc.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvSCPAPISvr.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '45' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '97' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '114' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '82' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '156' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'SbieSvc.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '73' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvxdsync.exe' - '50' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvvsvc.exe' - '47' Modul(e) wurden durchsucht
Durchsuche Prozess 'spoolsv.exe' - '94' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '48' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '75' Modul(e) wurden durchsucht
Durchsuche Prozess 'schedul2.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'armsvc.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'afcdpsrv.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'avfwsvc.exe' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '103' Modul(e) wurden durchsucht
Durchsuche Prozess 'AppleMobileDeviceService.exe' - '73' Modul(e) wurden durchsucht
Durchsuche Prozess 'mDNSResponder.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'MWLService.exe' - '49' Modul(e) wurden durchsucht
Durchsuche Prozess 'syncagentsrv.exe' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'twonkymediaserverwatchdog.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchIndexer.exe' - '70' Modul(e) wurden durchsucht
Durchsuche Prozess 'IAANTMon.exe' - '40' Modul(e) wurden durchsucht
Durchsuche Prozess 'TwonkyMediaServer.exe' - '50' Modul(e) wurden durchsucht
Durchsuche Prozess 'conhost.exe' - '14' Modul(e) wurden durchsucht
Durchsuche Prozess 'avshadow.exe' - '29' Modul(e) wurden durchsucht
Durchsuche Prozess 'avmailc.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'AVWEBGRD.EXE' - '72' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '60' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'Dwm.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskhost.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskeng.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'Explorer.EXE' - '179' Modul(e) wurden durchsucht
Durchsuche Prozess 'ipoint.exe' - '67' Modul(e) wurden durchsucht
Durchsuche Prozess 'itype.exe' - '68' Modul(e) wurden durchsucht
Durchsuche Prozess 'sidebar.exe' - '106' Modul(e) wurden durchsucht
Durchsuche Prozess 'SbieCtrl.exe' - '45' Modul(e) wurden durchsucht
Durchsuche Prozess 'TeamDrive3.exe' - '93' Modul(e) wurden durchsucht
Durchsuche Prozess 'LWS.exe' - '43' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvtray.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '108' Modul(e) wurden durchsucht
Durchsuche Prozess 'iTunesHelper.exe' - '79' Modul(e) wurden durchsucht
Durchsuche Prozess 'iPodService.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmpnetwk.exe' - '108' Modul(e) wurden durchsucht
Durchsuche Prozess 'FABS.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'daemonu.exe' - '75' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'OSPPSVC.EXE' - '32' Modul(e) wurden durchsucht
Durchsuche Prozess 'thunderbird.exe' - '126' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchProtocolHost.exe' - '43' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchFilterHost.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'avcenter.exe' - '125' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskhost.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '112' Modul(e) wurden durchsucht
Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'wininit.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'services.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsass.exe' - '70' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsm.exe' - '16' Modul(e) wurden durchsucht
Durchsuche Prozess 'winlogon.exe' - '32' Modul(e) wurden durchsucht

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '7123' Dateien ).


Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\' <Programme>
Beginne mit der Suche in 'D:\' <Bilder Urlaub Musik Videos>
Beginne mit der Suche in 'P:\' <Private Dateien >


Ende des Suchlaufs: Montag, 24. Juni 2013  16:56
Benötigte Zeit:  1:52:31 Stunde(n)

Der Suchlauf wurde vollständig durchgeführt.

  49516 Verzeichnisse wurden überprüft
 1220908 Dateien wurden geprüft
      0 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      0 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
 1220908 Dateien ohne Befall
  14182 Archive wurden durchsucht
      0 Warnungen
      0 Hinweise

gruß
robili

schrauber 24.06.2013 18:30

Ich seh keine Funde in dem Log von Avira. Komisch.
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

robili 24.06.2013 19:17

hallo schrauber
hier das log
Code:

ComboFix 13-06-24.01 - .... 24.06.2013  20:03:04.3.4 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.49.1031.18.4087.2033 [GMT 2:00]
ausgeführt von:: c:\users\....\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
FW: FireWall *Disabled* {CE40CCC0-8ADB-6D67-25A0-C5B6438E4B57}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-05-24 bis 2013-06-24  ))))))))))))))))))))))))))))))
.
.
2013-06-24 18:09 . 2013-06-24 18:09        --------        d-----w-        c:\users\....\AppData\Local\temp
2013-06-24 18:09 . 2013-06-24 18:09        --------        d-----w-        c:\users\UpdatusUser\AppData\Local\temp
2013-06-24 18:09 . 2013-06-24 18:09        --------        d-----w-        c:\users\Public\AppData\Local\temp
2013-06-24 18:09 . 2013-06-24 18:09        --------        d-----w-        c:\users\Internet\AppData\Local\temp
2013-06-24 18:09 . 2013-06-24 18:09        --------        d-----w-        c:\users\....\AppData\Local\temp
2013-06-24 18:09 . 2013-06-24 18:09        --------        d-----w-        c:\users\...Arbeit\AppData\Local\temp
2013-06-24 18:09 . 2013-06-24 18:09        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-06-24 11:25 . 2013-06-24 11:25        --------        d-----w-        C:\FRST
2013-06-24 11:13 . 2013-06-24 11:13        --------        d---a-w-        c:\program files (x86)\UtilityChest_49EI
2013-06-21 15:18 . 2013-06-17 00:10        9552976        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{12B37F29-541E-41EC-8492-C40A08B3BDD7}\mpengine.dll
2013-06-18 17:58 . 2013-06-18 18:32        --------        d-----w-        c:\program files\Microsoft Mouse and Keyboard Center
2013-06-12 07:27 . 2013-06-08 12:28        2706432        ----a-w-        c:\windows\system32\mshtml.tlb
2013-06-12 07:26 . 2013-05-13 05:51        184320        ----a-w-        c:\windows\system32\cryptsvc.dll
2013-06-07 07:57 . 2013-06-07 07:57        --------        d-----w-        c:\program files\iPod
2013-06-07 07:57 . 2013-06-07 07:57        --------        d-----w-        c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-07 07:57 . 2013-06-07 07:57        --------        d-----w-        c:\program files\iTunes
2013-06-07 07:57 . 2013-06-07 07:57        --------        d-----w-        c:\program files (x86)\iTunes
2013-06-06 07:42 . 2013-06-06 07:43        --------        d-----w-        c:\program files (x86)\Malwarebytes' Anti-Malware
2013-06-06 07:42 . 2013-04-04 12:50        25928        ----a-w-        c:\windows\system32\drivers\mbam.sys
2013-05-31 07:59 . 2013-05-31 07:59        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-05-31 07:59 . 2013-05-31 07:59        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-05-31 07:59 . 2013-05-31 07:59        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-05-31 07:59 . 2013-05-31 07:59        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-05-31 07:59 . 2013-05-31 07:59        159744        ----a-w-        c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-05-31 07:59 . 2013-05-31 07:59        --------        d-----w-        c:\program files (x86)\QuickTime
2013-05-28 18:22 . 2013-05-29 07:28        --------        d-----w-        c:\program files (x86)\Mozilla Thunderbird
2013-05-28 17:01 . 2013-06-24 09:21        83672        ----a-w-        c:\windows\system32\drivers\avnetflt.sys
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-14 06:49 . 2012-07-28 09:03        71048        ----a-w-        c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-14 06:49 . 2012-07-28 09:03        692104        ----a-w-        c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-12 07:28 . 2009-12-12 22:55        75825640        ----a-w-        c:\windows\system32\MRT.exe
2013-05-13 13:36 . 2013-05-13 13:36        862664        ----a-w-        c:\windows\SysWow64\msvcr110.dll
2013-05-13 13:36 . 2013-05-13 13:36        828872        ----a-w-        c:\windows\system32\msvcr110.dll
2013-05-13 13:36 . 2013-05-13 13:36        661448        ----a-w-        c:\windows\system32\msvcp110.dll
2013-05-13 13:36 . 2013-05-13 13:36        534480        ----a-w-        c:\windows\SysWow64\msvcp110.dll
2013-05-13 13:36 . 2013-05-13 13:36        354264        ----a-w-        c:\windows\system32\vccorlib110.dll
2013-05-13 13:36 . 2013-05-13 13:36        251864        ----a-w-        c:\windows\SysWow64\vccorlib110.dll
2013-05-13 13:36 . 2013-05-13 13:36        50864        ----a-w-        c:\windows\system32\drivers\point64.sys
2013-05-13 13:36 . 2013-05-13 13:36        1795952        ----a-w-        c:\windows\system32\WdfCoInstaller01011.dll
2013-05-02 08:22 . 2013-05-02 08:22        2274480        ----a-w-        c:\windows\system32\coin94.dll
2013-05-02 00:06 . 2009-12-12 22:26        278800        ------w-        c:\windows\system32\MpSigStub.exe
2013-05-01 01:59 . 2013-05-01 01:59        94208        ----a-w-        c:\windows\SysWow64\QuickTimeVR.qtx
2013-05-01 01:59 . 2013-05-01 01:59        69632        ----a-w-        c:\windows\SysWow64\QuickTime.qts
2013-04-13 17:05 . 2013-04-13 17:09        28600        ----a-w-        c:\windows\system32\drivers\avkmgr.sys
2013-04-13 17:05 . 2013-04-13 17:09        141376        ----a-w-        c:\windows\system32\drivers\avfwot.sys
2013-04-13 17:05 . 2013-04-13 17:09        130016        ----a-w-        c:\windows\system32\drivers\avipbb.sys
2013-04-13 17:05 . 2013-04-13 17:09        114608        ----a-w-        c:\windows\system32\drivers\avfwim.sys
2013-04-13 17:05 . 2013-04-13 17:09        100712        ----a-w-        c:\windows\system32\drivers\avgntflt.sys
2013-04-13 16:32 . 2013-04-13 15:48        181064        ----a-w-        c:\windows\PSEXESVC.EXE
2013-04-13 05:49 . 2013-05-28 17:05        135168        ----a-w-        c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-28 17:05        350208        ----a-w-        c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-28 17:05        308736        ----a-w-        c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-28 17:05        111104        ----a-w-        c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-28 17:05        474624        ----a-w-        c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-28 17:05        2176512        ----a-w-        c:\windows\apppatch\AcGenral.dll
2013-03-29 09:09 . 2013-03-29 09:09        97280        ----a-w-        c:\windows\system32\mshtmled.dll
2013-03-29 09:09 . 2013-03-29 09:09        905728        ----a-w-        c:\windows\system32\mshtmlmedia.dll
2013-03-29 09:09 . 2013-03-29 09:09        81408        ----a-w-        c:\windows\system32\icardie.dll
2013-03-29 09:09 . 2013-03-29 09:09        762368        ----a-w-        c:\windows\system32\ieapfltr.dll
2013-03-29 09:09 . 2013-03-29 09:09        73728        ----a-w-        c:\windows\SysWow64\SetIEInstalledDate.exe
2013-03-29 09:09 . 2013-03-29 09:09        719360        ----a-w-        c:\windows\SysWow64\mshtmlmedia.dll
2013-03-29 09:09 . 2013-03-29 09:09        61952        ----a-w-        c:\windows\SysWow64\tdc.ocx
2013-03-29 09:09 . 2013-03-29 09:09        599552        ----a-w-        c:\windows\system32\vbscript.dll
2013-03-29 09:09 . 2013-03-29 09:09        523264        ----a-w-        c:\windows\SysWow64\vbscript.dll
2013-03-29 09:09 . 2013-03-29 09:09        48640        ----a-w-        c:\windows\SysWow64\mshtmler.dll
2013-03-29 09:09 . 2013-03-29 09:09        452096        ----a-w-        c:\windows\system32\dxtmsft.dll
2013-03-29 09:09 . 2013-03-29 09:09        441856        ----a-w-        c:\windows\system32\html.iec
2013-03-29 09:09 . 2013-03-29 09:09        38400        ----a-w-        c:\windows\SysWow64\imgutil.dll
2013-03-29 09:09 . 2013-03-29 09:09        361984        ----a-w-        c:\windows\SysWow64\html.iec
2013-03-29 09:09 . 2013-03-29 09:09        281600        ----a-w-        c:\windows\system32\dxtrans.dll
2013-03-29 09:09 . 2013-03-29 09:09        27648        ----a-w-        c:\windows\system32\licmgr10.dll
2013-03-29 09:09 . 2013-03-29 09:09        270848        ----a-w-        c:\windows\system32\iedkcs32.dll
2013-03-29 09:09 . 2013-03-29 09:09        247296        ----a-w-        c:\windows\system32\webcheck.dll
2013-03-29 09:09 . 2013-03-29 09:09        235008        ----a-w-        c:\windows\system32\url.dll
2013-03-29 09:09 . 2013-03-29 09:09        23040        ----a-w-        c:\windows\SysWow64\licmgr10.dll
2013-03-29 09:09 . 2013-03-29 09:09        226304        ----a-w-        c:\windows\system32\elshyph.dll
2013-03-29 09:09 . 2013-03-29 09:09        216064        ----a-w-        c:\windows\system32\msls31.dll
2013-03-29 09:09 . 2013-03-29 09:09        197120        ----a-w-        c:\windows\system32\msrating.dll
2013-03-29 09:09 . 2013-03-29 09:09        185344        ----a-w-        c:\windows\SysWow64\elshyph.dll
2013-03-29 09:09 . 2013-03-29 09:09        167424        ----a-w-        c:\windows\system32\iexpress.exe
2013-03-29 09:09 . 2013-03-29 09:09        158720        ----a-w-        c:\windows\SysWow64\msls31.dll
2013-03-29 09:09 . 2013-03-29 09:09        1509376        ----a-w-        c:\windows\system32\inetcpl.cpl
2013-03-29 09:09 . 2013-03-29 09:09        150528        ----a-w-        c:\windows\SysWow64\iexpress.exe
2013-03-29 09:09 . 2013-03-29 09:09        144896        ----a-w-        c:\windows\system32\wextract.exe
2013-03-29 09:09 . 2013-03-29 09:09        1441280        ----a-w-        c:\windows\SysWow64\inetcpl.cpl
2013-03-29 09:09 . 2013-03-29 09:09        1400416        ----a-w-        c:\windows\system32\ieapfltr.dat
2013-03-29 09:09 . 2013-03-29 09:09        138752        ----a-w-        c:\windows\SysWow64\wextract.exe
2013-03-29 09:09 . 2013-03-29 09:09        137216        ----a-w-        c:\windows\SysWow64\ieUnatt.exe
2013-03-29 09:09 . 2013-03-29 09:09        12800        ----a-w-        c:\windows\SysWow64\mshta.exe
2013-03-29 09:09 . 2013-03-29 09:09        110592        ----a-w-        c:\windows\SysWow64\IEAdvpack.dll
2013-03-29 09:09 . 2013-03-29 09:09        1054720        ----a-w-        c:\windows\system32\MsSpellCheckingFacility.exe
2013-03-29 09:09 . 2013-03-29 09:09        102912        ----a-w-        c:\windows\system32\inseng.dll
2013-03-29 09:09 . 2013-03-29 09:09        92160        ----a-w-        c:\windows\system32\SetIEInstalledDate.exe
2013-03-29 09:09 . 2013-03-29 09:09        77312        ----a-w-        c:\windows\system32\tdc.ocx
2013-03-29 09:09 . 2013-03-29 09:09        62976        ----a-w-        c:\windows\system32\pngfilt.dll
2013-03-29 09:09 . 2013-03-29 09:09        52224        ----a-w-        c:\windows\system32\msfeedsbs.dll
2013-03-29 09:09 . 2013-03-29 09:09        51200        ----a-w-        c:\windows\system32\imgutil.dll
2013-03-29 09:09 . 2013-03-29 09:09        48640        ----a-w-        c:\windows\system32\mshtmler.dll
2013-03-29 09:09 . 2013-03-29 09:09        173568        ----a-w-        c:\windows\system32\ieUnatt.exe
2013-03-29 09:09 . 2013-03-29 09:09        149504        ----a-w-        c:\windows\system32\occache.dll
2013-03-29 09:09 . 2013-03-29 09:09        13824        ----a-w-        c:\windows\system32\mshta.exe
2013-03-29 09:09 . 2013-03-29 09:09        136192        ----a-w-        c:\windows\system32\iepeers.dll
2013-03-29 09:09 . 2013-03-29 09:09        135680        ----a-w-        c:\windows\system32\IEAdvpack.dll
2013-03-29 09:09 . 2013-03-29 09:09        12800        ----a-w-        c:\windows\system32\msfeedssync.exe
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-01-28 14:49        281760        ----a-w-        c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18        120104        ----a-w-        c:\program files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2012-12-16 765200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-06-24 345144]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392]
.
c:\users\....\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TeamDrive starten.lnk - c:\program files (x86)\TeamDrive 3\TeamDrive3.exe autostart [2013-2-2 11613216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [x]
R3 IAMTVE;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\DRIVERS\IAMTVE.sys;c:\windows\SYSNATIVE\DRIVERS\IAMTVE.sys [x]
R3 IAMTXPE;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\DRIVERS\IAMTXPE.sys;c:\windows\SYSNATIVE\DRIVERS\IAMTXPE.sys [x]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys;c:\windows\SYSNATIVE\Drivers\qd162x64.sys [x]
R3 ioatdma2;Intel(R) QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys;c:\windows\SYSNATIVE\Drivers\qd262x64.sys [x]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
R3 lvpopf64;Logitech POP Suppression Filter;c:\windows\system32\DRIVERS\lvpopf64.sys;c:\windows\SYSNATIVE\DRIVERS\lvpopf64.sys [x]
R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]
R3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 rsvcdwdr;rsvcdwdr;c:\windows\system32\DRIVERS\rsvcdwdr.sys;c:\windows\SYSNATIVE\DRIVERS\rsvcdwdr.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(1).sys [x]
R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(2).sys [x]
R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(3).sys [x]
R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(4).sys [x]
R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(5).sys [x]
R4 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe;c:\program files (x86)\Acer\Registration\GregHSRW.exe [x]
R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x]
R4 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
R4 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
R4 UPnPService;UPnPService;c:\program files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe;c:\program files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys;c:\windows\SYSNATIVE\DRIVERS\vididr.sys [x]
S0 vidsflt67;Acronis Disk Storage Filter (67);c:\windows\system32\DRIVERS\vsflt67.sys;c:\windows\SYSNATIVE\DRIVERS\vsflt67.sys [x]
S1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys;c:\windows\SYSNATIVE\DRIVERS\avfwot.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [x]
S2 AntiVirFirewallService;Avira FireWall;c:\program files (x86)\Avira\AntiVir Desktop\avfwsvc.exe;c:\program files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [x]
S2 AntiVirMailService;Avira Email Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [x]
S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 syncagentsrv;Acronis Sync Agent Service;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe;c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [x]
S2 TwonkyMedia;TwonkyMedia;c:\program files (x86)\TwonkyMedia\twonkymediaserverwatchdog.exe;c:\program files (x86)\TwonkyMedia\twonkymediaserverwatchdog.exe [x]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys;c:\windows\SYSNATIVE\DRIVERS\afcdp.sys [x]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys;c:\windows\SYSNATIVE\DRIVERS\avfwim.sys [x]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1k62x64.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech Webcam 200(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-06-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-28 06:49]
.
2013-06-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-15 16:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]
2013-01-28 14:49        342176        ----a-w-        c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:19        137512        ----a-w-        c:\program files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
uSearchURL,(Default) = hxxp://go.1und1.de/suchbox/1und1suche?su=%s
IE: Add to Playlist - c:\program files (x86)\PacketVideo\TwonkyBeam\Internet Explorer\TwonkyIEPlugin.dll/314
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: TwonkyBeam to - c:\program files (x86)\PacketVideo\TwonkyBeam\Internet Explorer\TwonkyIEPlugin.dll/231
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.1.1
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
FF - ProfilePath - c:\users\....\AppData\Roaming\Mozilla\Firefox\Profiles\637tdec4.default\
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers- - (no file)
ShellIconOverlayIdentifiers- - (no file)
ShellIconOverlayIdentifiers- - (no file)
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.alb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FotoManager10Deluxe.8.alb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\T*w*o*n*k*y*B*e*a*m*"!\Internet Explorer]
"Path"="c:\\Program Files (x86)\\PacketVideo\\TwonkyBeam\\Internet Explorer"
"Language"="1031"
.
Zeit der Fertigstellung: 2013-06-24  20:11:41
ComboFix-quarantined-files.txt  2013-06-24 18:11
ComboFix2.txt  2013-04-08 07:44
.
Vor Suchlauf: 30 Verzeichnis(se), 79.269.822.464 Bytes frei
Nach Suchlauf: 32 Verzeichnis(se), 79.230.124.032 Bytes frei
.
- - End Of File - - DEF138DB52863DCD3D280DB4D674389D
A36C5E4F47E84449FF07ED3517B43A31


schrauber 25.06.2013 07:38

Meckert Antivir immer noch?

robili 25.06.2013 08:49

hallo,
ja, leider und zwar immer nach dem Lauf mit der Suche nach den Rootkits
gruß
robili

schrauber 25.06.2013 14:02

Antivir is dumm, da is nix :)

ESET Online Scanner
Bitte während der Online-Scans evtl. vorhandene externe Festplatten einschalten! Bitte während der Scans alle Hintergrundwächter (Anti-Virus-Programm, Firewall, Skriptblocking und ähnliches) abstellen und nicht vergessen, alles hinterher wieder einzuschalten.
  • Anmerkung für Vista und Win7 User: Bitte den Browser unbedingt als Administrator starten.
  • Dein Anti-Virus-Programm während des Scans deaktivieren.

    Button http://larusso.trojaner-board.de/Images/eset.jpg (<< klick) drücken.
    • Firefox-User:
      Bitte esetsmartinstaller_enu.exe downloaden.Das Firefox-Addon auf dem Desktop speichern und dann installieren.
    • IE-User:
      müssen das Installieren eines ActiveX Elements erlauben.
  • Setze den einen Hacken bei Yes, i accept the Terms of Use.
  • Drücke den http://img707.imageshack.us/img707/687/starteg.jpg Button.
  • Warte bis die Komponenten herunter geladen wurden.
  • Setze einen Haken bei "Scan archives".
  • Gehe sicher, dass bei Remove Found Threads kein Haken gesetzt ist.
  • http://img707.imageshack.us/img707/687/starteg.jpg drücken.
  • Die Signaturen werden herunter geladen.Der Scan beginnt automatisch.
Wenn der Scan beendet wurdeBitte poste die Logfile hier.

robili 26.06.2013 09:55

Hallo,
habe das Programm laufen lassen, habe bis nach 01,30 Uhr morgens gewartet, als er noch immer nicht fertig war bin ichg ins Bett.
Morgens um 7,30 Uhr bin ich auf da war es fertig
allerdings habe ich die unteren Butten list of found threats und export to text file nicht gefunden, habe dann auf finish gedrückt, das wars. ???
gruß
robili

schrauber 26.06.2013 10:34

Also wurde nix gefunden?

robili 26.06.2013 13:00

hallo schrauber,
also ich habe auch die zwei externen Festplatten laufen lassen, bis zur ersten habe ich noch geschaut, da war noch alles im grünen Bereich, bis zur zweiten habe ich es nicht mehr geschafft, war einfach zu spät, da aber keine Meldung da war, gehe ich davon aus das auch auf der zweiten nichts zu finden war.
Die externen sind auch normalerweise nicht an, nur einmal im Monat zur Sicherung der Daten, das heist der Avira sieht sie normalerweise nicht und trotzdem kommt diese blöde Meldung.????
gruß
robili

schrauber 26.06.2013 14:22

Deinstalliere Avira und installier Avast, Avira is Müll und installiert Adware mit.

robili 26.06.2013 16:22

hallo schrauber,
habe ich mir auch schon überlegt, aber ich wuste nie für welches ich mich entscheiden sollte. Meinst du die freie oder die kostenpflichtige Version von Avast ?
Da gibt es auch noch Trend Micro Titanium Internet Security 2013 steht ganz oben, soll wohl das beste sein ??????
gruß
robili

schrauber 26.06.2013 17:16

Wenn Du Freeware willst, Avast free, wenn Du bissl Geld ausgeben willst, Emsisoft :)

robili 26.06.2013 22:42

hallo schrauber,
es geht hier nicht darum ob ich etwas bezahlen will, sondern darum welches Programm das sicherste ist.
gruß
robili

schrauber 27.06.2013 08:08

Guckst Du :)

AV-Comparatives - Independent Tests of Anti-Virus Software - Real World Protection Test Overview

robili 27.06.2013 19:44

hallo schrauber,
ich habe geschaut, habe mir von " AVAST " internet security herunterladen wollen.
Hat nicht gefunzt, hat mein PC gestreikt, konnte fast nichts mehr machen, und das nachdem ich den " avira " gelöscht hatte.
Allerdings ist der Download vom avast in meiner Sandboxi gelandet, die hat sich total geweigert bestimmte Dateien von avast zu installieren. ???????
gruß
robili

schrauber 28.06.2013 06:14

In der Sandbox wird das auch nicht funktionieren :)

robili 29.06.2013 09:02

hallo schrauber,
werde es später noch einmal versuchen, natürlich außerhalb der Sandbox.
Nun muss ich mal etwas anderes tun.
Was ich nur nicht verstehe, sind die Meldungen zum einen vom Avira bei der Suche nach den Rootkits und die Meldung in der Ereigniskontrolle die sich ja inhaltlich gleichen ?????
gruß
robili

schrauber 29.06.2013 09:05

Welche? :)

robili 29.06.2013 10:19

hallo schrauber,
in der Ereigniskontrolle vom Windows steht,
Ein ActiveScriptEventConsumer-Anbieter wurde im WMI-Namespace (Windows-Verwaltungsinstrumentation) root\default zur Verwendung des Kontos "LocalSystem" registriert. Dieses Konto ist ein privilegiertes Konto, d. h. der Anbieter kann Sicherheitsverletzungen verursachen, wenn der Identitätswechsel für Benutzeranforderungen nicht korrekt ausgeführt wird."
und der Avira meldet bei der Rootkitsuche,
" Es wurden verstekte Objekte gefunden, die auf ein unerwünschtes Programm oder einem verstekten Virus hinweisen".
Beide Meldungen weisen doch darauf hin das in der Systemsteuerung etwas faul ist oder war ?????
gruß
robili

schrauber 29.06.2013 11:43

Alle Scans sind sauber, selbst Avira zeigt nix im Logfile, was es vorher anmeckert.

Machen wir noch einen letzten Kontrollscan:

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

robili 29.06.2013 13:32

Liste der Anhänge anzeigen (Anzahl: 1)
Hallo schrauber,
allerdings kommt auch eine Fehlermeldung



Code:

Malwarebytes Anti-Rootkit BETA 1.06.0.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 10.0.9200.16618

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, P:\ DRIVE_FIXED
CPU speed: 2.660000 GHz
Memory total: 4285612032, free: 2353192960

Downloaded database version: v2013.06.29.01
Initializing...
------------ Kernel report ------------
    06/29/2013 14:07:35
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\DRIVERS\vsflt67.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\DRIVERS\jraid.sys
\SystemRoot\system32\DRIVERS\SCSIPORT.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\vididr.sys
\SystemRoot\system32\DRIVERS\timntr.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\system32\DRIVERS\tdrpman.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\system32\DRIVERS\snapman.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\system32\DRIVERS\fltsrv.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\mwlPSDFilter.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\avfwot.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mwlPSDVDisk.sys
\SystemRoot\system32\DRIVERS\mwlPSDNServ.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\avkmgr.sys
\SystemRoot\system32\DRIVERS\avipbb.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\System32\Drivers\nvBridge.kmd
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\e1k62x64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\drivers\1394ohci.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\avfwim.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\nvhda64v.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\lvuvc64.sys
\SystemRoot\system32\drivers\usbaudio.sys
\SystemRoot\system32\DRIVERS\lvrs64.sys
\SystemRoot\System32\Drivers\RtsUStor.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\avgntflt.sys
\??\C:\Program Files\Sandboxie\SbieDrv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\system32\DRIVERS\afcdp.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\mbamswissarmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\setupapi.dll
\Windows\System32\urlmon.dll
\Windows\System32\difxapi.dll
\Windows\System32\comdlg32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\gdi32.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\iertutil.dll
\Windows\System32\ws2_32.dll
\Windows\System32\ole32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\normaliz.dll
\Windows\System32\kernel32.dll
\Windows\System32\shell32.dll
\Windows\System32\imm32.dll
\Windows\System32\lpk.dll
\Windows\System32\msvcrt.dll
\Windows\System32\msctf.dll
\Windows\System32\psapi.dll
\Windows\System32\wininet.dll
\Windows\System32\advapi32.dll
\Windows\System32\user32.dll
\Windows\System32\clbcatq.dll
\Windows\System32\sechost.dll
\Windows\System32\imagehlp.dll
\Windows\System32\oleaut32.dll
\Windows\System32\usp10.dll
\Windows\System32\nsi.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\devobj.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\wintrust.dll
\Windows\System32\crypt32.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\comctl32.dll
\Windows\System32\msasn1.dll
\Windows\SysWOW64\normaliz.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8005923060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xfffffa8004aa5050
Lower Device Driver Name: \Driver\iaStor\
<<<2>>>
Can't get device number
Can't access volume using primary device, the volume might be encrypted.
<<<2>>>
Can't get device number
The system volume seems inaccessible or encrypted. Scan can't continue.
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8005923060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xfffffa8004aa5050
Lower Device Driver Name: \Driver\iaStor\
<<<2>>>
Can't get device number
Can't access volume using primary device, the volume might be encrypted.
<<<2>>>
Can't get device number
The system volume seems inaccessible or encrypted. Scan can't continue.
=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.06.0.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 10.0.9200.16618

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, P:\ DRIVE_FIXED
CPU speed: 2.660000 GHz
Memory total: 4285612032, free: 2390736896

Initializing...
------------ Kernel report ------------
    06/29/2013 14:13:29
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\DRIVERS\vsflt67.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\DRIVERS\jraid.sys
\SystemRoot\system32\DRIVERS\SCSIPORT.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\vididr.sys
\SystemRoot\system32\DRIVERS\timntr.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\system32\DRIVERS\tdrpman.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\system32\DRIVERS\snapman.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\system32\DRIVERS\fltsrv.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\mwlPSDFilter.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\avfwot.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mwlPSDVDisk.sys
\SystemRoot\system32\DRIVERS\mwlPSDNServ.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\avkmgr.sys
\SystemRoot\system32\DRIVERS\avipbb.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\System32\Drivers\nvBridge.kmd
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\e1k62x64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\drivers\1394ohci.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\avfwim.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\nvhda64v.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\lvuvc64.sys
\SystemRoot\system32\drivers\usbaudio.sys
\SystemRoot\system32\DRIVERS\lvrs64.sys
\SystemRoot\System32\Drivers\RtsUStor.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\avgntflt.sys
\??\C:\Program Files\Sandboxie\SbieDrv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\system32\DRIVERS\afcdp.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\mbamswissarmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\setupapi.dll
\Windows\System32\urlmon.dll
\Windows\System32\difxapi.dll
\Windows\System32\comdlg32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\gdi32.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\iertutil.dll
\Windows\System32\ws2_32.dll
\Windows\System32\ole32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\normaliz.dll
\Windows\System32\kernel32.dll
\Windows\System32\shell32.dll
\Windows\System32\imm32.dll
\Windows\System32\lpk.dll
\Windows\System32\msvcrt.dll
\Windows\System32\msctf.dll
\Windows\System32\psapi.dll
\Windows\System32\wininet.dll
\Windows\System32\advapi32.dll
\Windows\System32\user32.dll
\Windows\System32\clbcatq.dll
\Windows\System32\sechost.dll
\Windows\System32\imagehlp.dll
\Windows\System32\oleaut32.dll
\Windows\System32\usp10.dll
\Windows\System32\nsi.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\devobj.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\wintrust.dll
\Windows\System32\crypt32.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\comctl32.dll
\Windows\System32\msasn1.dll
\Windows\SysWOW64\normaliz.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8005923060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xfffffa8004aa5050
Lower Device Driver Name: \Driver\iaStor\
<<<2>>>
Can't get device number
Can't access volume using primary device, the volume might be encrypted.
<<<2>>>
Can't get device number
The system volume seems inaccessible or encrypted. Scan can't continue.
=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.06.0.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 10.0.9200.16618

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, P:\ DRIVE_FIXED
CPU speed: 2.660000 GHz
Memory total: 4285612032, free: 2261839872

Downloaded database version: v2013.06.29.01
Initializing...
------------ Kernel report ------------
    06/29/2013 14:27:15
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\DRIVERS\vsflt67.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\DRIVERS\jraid.sys
\SystemRoot\system32\DRIVERS\SCSIPORT.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\vididr.sys
\SystemRoot\system32\DRIVERS\timntr.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\system32\DRIVERS\tdrpman.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\system32\DRIVERS\snapman.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\system32\DRIVERS\fltsrv.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\mwlPSDFilter.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\avfwot.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mwlPSDVDisk.sys
\SystemRoot\system32\DRIVERS\mwlPSDNServ.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\avkmgr.sys
\SystemRoot\system32\DRIVERS\avipbb.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\System32\Drivers\nvBridge.kmd
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\e1k62x64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\drivers\1394ohci.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\avfwim.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\nvhda64v.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\lvuvc64.sys
\SystemRoot\system32\drivers\usbaudio.sys
\SystemRoot\system32\DRIVERS\lvrs64.sys
\SystemRoot\System32\Drivers\RtsUStor.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\avgntflt.sys
\??\C:\Program Files\Sandboxie\SbieDrv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\system32\DRIVERS\afcdp.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\mbamswissarmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\setupapi.dll
\Windows\System32\urlmon.dll
\Windows\System32\difxapi.dll
\Windows\System32\comdlg32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\gdi32.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\iertutil.dll
\Windows\System32\ws2_32.dll
\Windows\System32\ole32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\normaliz.dll
\Windows\System32\kernel32.dll
\Windows\System32\shell32.dll
\Windows\System32\imm32.dll
\Windows\System32\lpk.dll
\Windows\System32\msvcrt.dll
\Windows\System32\msctf.dll
\Windows\System32\psapi.dll
\Windows\System32\wininet.dll
\Windows\System32\advapi32.dll
\Windows\System32\user32.dll
\Windows\System32\clbcatq.dll
\Windows\System32\sechost.dll
\Windows\System32\imagehlp.dll
\Windows\System32\oleaut32.dll
\Windows\System32\usp10.dll
\Windows\System32\nsi.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\devobj.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\wintrust.dll
\Windows\System32\crypt32.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\comctl32.dll
\Windows\System32\msasn1.dll
\Windows\SysWOW64\normaliz.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8005923060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xfffffa8004aa5050
Lower Device Driver Name: \Driver\iaStor\
<<<2>>>
Can't get device number
Can't access volume using primary device, the volume might be encrypted.
<<<2>>>
Can't get device number
The system volume seems inaccessible or encrypted. Scan can't continue.
=======================================

gruß
robili

schrauber 29.06.2013 14:34

Benutzt Du irgend ne Verschlüsselungssoftware?

robili 29.06.2013 15:17

nein !!

schrauber 29.06.2013 18:57

Komisch.

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.


mach entgegen der Anleitung noch nen Haken bei Loaded Modules und lass beim Neustart scannen.

robili 30.06.2013 16:17

hallo schrauber
Das Ergebnis ist zu lang, ich soll das Log als Archiv anhängen
aber wie ??
gruß
robili
[

schrauber 30.06.2013 16:18

Teile das Log in Häppchen :)

robili 30.06.2013 16:29

hallo schrauber
hier nun die erste Hälfte
Code:

16:53:38.0006 4756  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
16:53:40.0018 4756  ============================================================
16:53:40.0018 4756  Current date / time: 2013/06/30 16:53:40.0018
16:53:40.0018 4756  SystemInfo:
16:53:40.0018 4756 
16:53:40.0018 4756  OS Version: 6.1.7601 ServicePack: 1.0
16:53:40.0018 4756  Product type: Workstation
16:53:40.0018 4756  ComputerName: ....
16:53:40.0018 4756  UserName: ....
16:53:40.0018 4756  Windows directory: C:\Windows
16:53:40.0018 4756  System windows directory: C:\Windows
16:53:40.0018 4756  Running under WOW64
16:53:40.0018 4756  Processor architecture: Intel x64
16:53:40.0018 4756  Number of processors: 4
16:53:40.0018 4756  Page size: 0x1000
16:53:40.0018 4756  Boot type: Normal boot
16:53:40.0018 4756  ============================================================
16:53:59.0846 4756  BG loaded
16:54:02.0248 4756  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:54:02.0248 4756  ============================================================
16:54:02.0248 4756  \Device\Harddisk0\DR0:
16:54:02.0248 4756  MBR partitions:
16:54:02.0248 4756  Initialize success
16:54:02.0248 4756  ============================================================
16:54:33.0869 4268  ============================================================
16:54:33.0869 4268  Scan started
16:54:33.0869 4268  Mode: Manual; SigCheck; TDLFS;
16:54:33.0869 4268  ============================================================
16:54:33.0947 4268  ================ Scan system memory ========================
16:54:33.0947 4268  System memory - ok
16:54:33.0947 4268  ================ Scan services =============================
16:54:34.0025 4268  1394ohci - ok
16:54:34.0041 4268  ACPI - ok
16:54:34.0057 4268  AcpiPmi - ok
16:54:34.0057 4268  AcrSch2Svc - ok
16:54:34.0088 4268  AdobeARMservice - ok
16:54:34.0119 4268  AdobeFlashPlayerUpdateSvc - ok
16:54:34.0119 4268  adp94xx - ok
16:54:34.0119 4268  adpahci - ok
16:54:34.0119 4268  adpu320 - ok
16:54:34.0135 4268  AeLookupSvc - ok
16:54:34.0135 4268  afcdp - ok
16:54:34.0135 4268  afcdpsrv - ok
16:54:34.0135 4268  AFD - ok
16:54:34.0150 4268  agp440 - ok
16:54:34.0150 4268  ALG - ok
16:54:34.0150 4268  aliide - ok
16:54:34.0166 4268  amdide - ok
16:54:34.0166 4268  AmdK8 - ok
16:54:34.0166 4268  AmdPPM - ok
16:54:34.0181 4268  amdsata - ok
16:54:34.0181 4268  amdsbs - ok
16:54:34.0181 4268  amdxata - ok
16:54:34.0197 4268  AntiVirFirewallService - ok
16:54:34.0213 4268  AntiVirMailService - ok
16:54:34.0228 4268  AntiVirSchedulerService - ok
16:54:34.0228 4268  AntiVirService - ok
16:54:34.0244 4268  AntiVirWebService - ok
16:54:34.0259 4268  AppID - ok
16:54:34.0259 4268  AppIDSvc - ok
16:54:34.0259 4268  Appinfo - ok
16:54:34.0291 4268  Apple Mobile Device - ok
16:54:34.0306 4268  arc - ok
16:54:34.0306 4268  arcsas - ok
16:54:34.0306 4268  AsyncMac - ok
16:54:34.0306 4268  atapi - ok
16:54:34.0337 4268  atikmdag - ok
16:54:34.0337 4268  AudioEndpointBuilder - ok
16:54:34.0337 4268  AudioSrv - ok
16:54:34.0337 4268  avfwim - ok
16:54:34.0353 4268  avfwot - ok
16:54:34.0353 4268  avgntflt - ok
16:54:34.0353 4268  avipbb - ok
16:54:34.0353 4268  avkmgr - ok
16:54:34.0384 4268  AxInstSV - ok
16:54:34.0384 4268  b06bdrv - ok
16:54:34.0384 4268  b57nd60a - ok
16:54:34.0384 4268  BDESVC - ok
16:54:34.0384 4268  Beep - ok
16:54:34.0415 4268  BFE - ok
16:54:34.0415 4268  BITS - ok
16:54:34.0415 4268  blbdrive - ok
16:54:34.0415 4268  Bonjour Service - ok
16:54:34.0431 4268  bowser - ok
16:54:34.0431 4268  BrFiltLo - ok
16:54:34.0431 4268  BrFiltUp - ok
16:54:34.0447 4268  BridgeMP - ok
16:54:34.0447 4268  Browser - ok
16:54:34.0447 4268  Brserid - ok
16:54:34.0447 4268  BrSerWdm - ok
16:54:34.0462 4268  BrUsbMdm - ok
16:54:34.0462 4268  BrUsbSer - ok
16:54:34.0462 4268  BTHMODEM - ok
16:54:34.0462 4268  bthserv - ok
16:54:34.0462 4268  cdfs - ok
16:54:34.0478 4268  cdrom - ok
16:54:34.0478 4268  CertPropSvc - ok
16:54:34.0478 4268  circlass - ok
16:54:34.0493 4268  CLFS - ok
16:54:34.0493 4268  clr_optimization_v2.0.50727_32 - ok
16:54:34.0493 4268  clr_optimization_v2.0.50727_64 - ok
16:54:34.0493 4268  clr_optimization_v4.0.30319_32 - ok
16:54:34.0493 4268  clr_optimization_v4.0.30319_64 - ok
16:54:34.0509 4268  CmBatt - ok
16:54:34.0509 4268  cmdide - ok
16:54:34.0509 4268  CNG - ok
16:54:34.0509 4268  Compbatt - ok
16:54:34.0509 4268  CompositeBus - ok
16:54:34.0525 4268  COMSysApp - ok
16:54:34.0525 4268  cpuz132 - ok
16:54:34.0525 4268  crcdisk - ok
16:54:34.0540 4268  CryptSvc - ok
16:54:34.0540 4268  DcomLaunch - ok
16:54:34.0540 4268  defragsvc - ok
16:54:34.0540 4268  DfsC - ok
16:54:34.0540 4268  Dhcp - ok
16:54:34.0556 4268  discache - ok
16:54:34.0556 4268  Disk - ok
16:54:34.0556 4268  Dnscache - ok
16:54:34.0556 4268  dot3svc - ok
16:54:34.0556 4268  DPS - ok
16:54:34.0571 4268  drmkaud - ok
16:54:34.0571 4268  DXGKrnl - ok
16:54:34.0571 4268  e1kexpress - ok
16:54:34.0571 4268  EapHost - ok
16:54:34.0587 4268  ebdrv - ok
16:54:34.0587 4268  EFS - ok
16:54:34.0587 4268  ehRecvr - ok
16:54:34.0587 4268  ehSched - ok
16:54:34.0587 4268  elxstor - ok
16:54:34.0587 4268  ErrDev - ok
16:54:34.0603 4268  EventSystem - ok
16:54:34.0603 4268  exfat - ok
16:54:34.0634 4268  Fabs - ok
16:54:34.0634 4268  fastfat - ok
16:54:34.0634 4268  Fax - ok
16:54:34.0649 4268  fdc - ok
16:54:34.0649 4268  fdPHost - ok
16:54:34.0649 4268  FDResPub - ok
16:54:34.0649 4268  FileInfo - ok
16:54:34.0649 4268  Filetrace - ok
16:54:34.0665 4268  FirebirdServerMAGIXInstance - ok
16:54:34.0665 4268  flpydisk - ok
16:54:34.0681 4268  FltMgr - ok
16:54:34.0681 4268  fltsrv - ok
16:54:34.0681 4268  FontCache - ok
16:54:34.0681 4268  FontCache3.0.0.0 - ok
16:54:34.0681 4268  FsDepends - ok
16:54:34.0681 4268  Fs_Rec - ok
16:54:34.0696 4268  fvevol - ok
16:54:34.0696 4268  gagp30kx - ok
16:54:34.0696 4268  GEARAspiWDM - ok
16:54:34.0696 4268  gpsvc - ok
16:54:34.0696 4268  Greg_Service - ok
16:54:34.0696 4268  grmnusb - ok
16:54:34.0712 4268  gusvc - ok
16:54:34.0712 4268  hcw85cir - ok
16:54:34.0712 4268  HdAudAddService - ok
16:54:34.0712 4268  HDAudBus - ok
16:54:34.0712 4268  HidBatt - ok
16:54:34.0712 4268  HidBth - ok
16:54:34.0727 4268  HidIr - ok
16:54:34.0727 4268  hidserv - ok
16:54:34.0727 4268  HidUsb - ok
16:54:34.0727 4268  hkmsvc - ok
16:54:34.0727 4268  HomeGroupListener - ok
16:54:34.0727 4268  HomeGroupProvider - ok
16:54:34.0743 4268  HpSAMD - ok
16:54:34.0759 4268  HTTP - ok
16:54:34.0759 4268  hwpolicy - ok
16:54:34.0759 4268  i8042prt - ok
16:54:34.0759 4268  IAANTMON - ok
16:54:34.0759 4268  IAMTVE - ok
16:54:34.0759 4268  IAMTXPE - ok
16:54:34.0774 4268  iaStor - ok
16:54:34.0774 4268  iaStorV - ok
16:54:34.0774 4268  idsvc - ok
16:54:34.0774 4268  iirsp - ok
16:54:34.0774 4268  IKEEXT - ok
16:54:34.0774 4268  IntcAzAudAddService - ok
16:54:34.0790 4268  intelide - ok
16:54:34.0790 4268  intelppm - ok
16:54:34.0790 4268  ioatdma1 - ok
16:54:34.0837 4268  ioatdma2 - ok
16:54:34.0837 4268  IPBusEnum - ok
16:54:34.0837 4268  IpFilterDriver - ok
16:54:34.0852 4268  iphlpsvc - ok
16:54:34.0852 4268  IPMIDRV - ok
16:54:34.0852 4268  IPNAT - ok
16:54:34.0868 4268  iPod Service - ok
16:54:34.0868 4268  IRENUM - ok
16:54:34.0883 4268  isapnp - ok
16:54:34.0883 4268  iScsiPrt - ok
16:54:34.0883 4268  JRAID - ok
16:54:34.0883 4268  kbdclass - ok
16:54:34.0883 4268  kbdhid - ok
16:54:34.0899 4268  KeyIso - ok
16:54:34.0899 4268  KSecDD - ok
16:54:34.0899 4268  KSecPkg - ok
16:54:34.0899 4268  ksthunk - ok
16:54:34.0899 4268  KtmRm - ok
16:54:34.0915 4268  L8042Kbd - ok
16:54:34.0915 4268  L8042mou - ok
16:54:34.0915 4268  LanmanServer - ok
16:54:34.0915 4268  LanmanWorkstation - ok
16:54:34.0930 4268  LEqdUsb - ok
16:54:34.0946 4268  LHidEqd - ok
16:54:34.0961 4268  LHidFilt - ok
16:54:34.0961 4268  lltdio - ok
16:54:34.0961 4268  lltdsvc - ok
16:54:34.0961 4268  lmhosts - ok
16:54:34.0961 4268  LMouFilt - ok
16:54:34.0977 4268  LMouKE - ok
16:54:34.0977 4268  LSI_FC - ok
16:54:34.0977 4268  LSI_SAS - ok
16:54:34.0977 4268  LSI_SAS2 - ok
16:54:34.0977 4268  LSI_SCSI - ok
16:54:34.0993 4268  luafv - ok
16:54:35.0024 4268  lvpopf64 - ok
16:54:35.0024 4268  LVPr2M64 - ok
16:54:35.0024 4268  LVPr2Mon - ok
16:54:35.0024 4268  LVRS64 - ok
16:54:35.0024 4268  LVUVC64 - ok
16:54:35.0039 4268  Mcx2Svc - ok
16:54:35.0039 4268  megasas - ok
16:54:35.0039 4268  MegaSR - ok
16:54:35.0039 4268  MMCSS - ok
16:54:35.0039 4268  Modem - ok
16:54:35.0039 4268  monitor - ok
16:54:35.0055 4268  mouclass - ok
16:54:35.0055 4268  mouhid - ok
16:54:35.0055 4268  mountmgr - ok
16:54:35.0055 4268  MozillaMaintenance - ok
16:54:35.0055 4268  mpio - ok
16:54:35.0071 4268  mpsdrv - ok
16:54:35.0071 4268  MpsSvc - ok
16:54:35.0071 4268  MRxDAV - ok
16:54:35.0071 4268  mrxsmb - ok
16:54:35.0071 4268  mrxsmb10 - ok
16:54:35.0071 4268  mrxsmb20 - ok
16:54:35.0086 4268  msahci - ok
16:54:35.0086 4268  msdsm - ok
16:54:35.0086 4268  MSDTC - ok
16:54:35.0086 4268  Msfs - ok
16:54:35.0086 4268  mshidkmdf - ok
16:54:35.0086 4268  msisadrv - ok
16:54:35.0102 4268  MSiSCSI - ok
16:54:35.0102 4268  msiserver - ok
16:54:35.0102 4268  MSKSSRV - ok
16:54:35.0102 4268  MSPCLOCK - ok
16:54:35.0102 4268  MSPQM - ok
16:54:35.0102 4268  MsRPC - ok
16:54:35.0117 4268  mssmbios - ok
16:54:35.0117 4268  MSTEE - ok
16:54:35.0117 4268  MTConfig - ok
16:54:35.0117 4268  Mup - ok
16:54:35.0117 4268  mwlPSDFilter - ok
16:54:35.0117 4268  mwlPSDNServ - ok
16:54:35.0133 4268  mwlPSDVDisk - ok
16:54:35.0133 4268  MWLService - ok
16:54:35.0133 4268  NAL - ok
16:54:35.0133 4268  napagent - ok
16:54:35.0133 4268  NativeWifiP - ok
16:54:35.0133 4268  NDIS - ok
16:54:35.0149 4268  NdisCap - ok
16:54:35.0149 4268  NdisTapi - ok
16:54:35.0149 4268  Ndisuio - ok
16:54:35.0149 4268  NdisWan - ok
16:54:35.0149 4268  NDProxy - ok
16:54:35.0149 4268  NetBIOS - ok
16:54:35.0164 4268  NetBT - ok
16:54:35.0164 4268  Netlogon - ok
16:54:35.0164 4268  Netman - ok
16:54:35.0164 4268  netprofm - ok
16:54:35.0164 4268  netr28x - ok
16:54:35.0164 4268  NetTcpPortSharing - ok
16:54:35.0180 4268  nfrd960 - ok
16:54:35.0195 4268  NlaSvc - ok
16:54:35.0195 4268  Npfs - ok
16:54:35.0195 4268  nsi - ok
16:54:35.0195 4268  nsiproxy - ok
16:54:35.0195 4268  Ntfs - ok
16:54:35.0195 4268  NTI IScheduleSvc - ok
16:54:35.0211 4268  NTIDrvr - ok
16:54:35.0211 4268  Null - ok
16:54:35.0227 4268  NVHDA - ok
16:54:35.0227 4268  nvlddmkm - ok
16:54:35.0227 4268  nvraid - ok
16:54:35.0227 4268  nvstor - ok
16:54:35.0227 4268  nvsvc - ok
16:54:35.0227 4268  nvUpdatusService - ok
16:54:35.0242 4268  nv_agp - ok
16:54:35.0242 4268  ohci1394 - ok
16:54:35.0242 4268  ose - ok
16:54:35.0242 4268  ose64 - ok
16:54:35.0242 4268  osppsvc - ok
16:54:35.0258 4268  p2pimsvc - ok
16:54:35.0258 4268  p2psvc - ok
16:54:35.0258 4268  Parport - ok
16:54:35.0258 4268  partmgr - ok
16:54:35.0258 4268  PcaSvc - ok
16:54:35.0273 4268  pci - ok
16:54:35.0273 4268  pciide - ok
16:54:35.0273 4268  pcmcia - ok
16:54:35.0273 4268  pcw - ok
16:54:35.0273 4268  PEAUTH - ok
16:54:35.0273 4268  PerfHost - ok
16:54:35.0289 4268  pla - ok
16:54:35.0289 4268  PlugPlay - ok
16:54:35.0289 4268  PNRPAutoReg - ok
16:54:35.0289 4268  PNRPsvc - ok
16:54:35.0305 4268  Point64 - ok
16:54:35.0305 4268  PolicyAgent - ok
16:54:35.0305 4268  Power - ok
16:54:35.0305 4268  PptpMiniport - ok
16:54:35.0305 4268  Processor - ok
16:54:35.0305 4268  ProfSvc - ok
16:54:35.0320 4268  ProtectedStorage - ok
16:54:35.0320 4268  Psched - ok
16:54:35.0320 4268  PSI_SVC_2 - ok
16:54:35.0320 4268  ql2300 - ok
16:54:35.0320 4268  ql40xx - ok
16:54:35.0320 4268  QWAVE - ok
16:54:35.0336 4268  QWAVEdrv - ok
16:54:35.0336 4268  RasAcd - ok
16:54:35.0336 4268  RasAgileVpn - ok
16:54:35.0336 4268  RasAuto - ok
16:54:35.0336 4268  Rasl2tp - ok
16:54:35.0336 4268  RasMan - ok
16:54:35.0351 4268  RasPppoe - ok
16:54:35.0351 4268  RasSstp - ok
16:54:35.0351 4268  rdbss - ok
16:54:35.0351 4268  rdpbus - ok
16:54:35.0351 4268  RDPCDD - ok
16:54:35.0351 4268  RDPENCDD - ok
16:54:35.0367 4268  RDPREFMP - ok
16:54:35.0367 4268  RdpVideoMiniport - ok
16:54:35.0367 4268  RDPWD - ok
16:54:35.0367 4268  rdyboost - ok
16:54:35.0367 4268  RemoteAccess - ok
16:54:35.0383 4268  RemoteRegistry - ok
16:54:35.0383 4268  RpcEptMapper - ok
16:54:35.0383 4268  RpcLocator - ok
16:54:35.0383 4268  RpcSs - ok
16:54:35.0383 4268  rspndr - ok
16:54:35.0398 4268  RSUSBSTOR - ok
16:54:35.0398 4268  rsvcdwdr - ok
16:54:35.0398 4268  SamSs - ok
16:54:35.0398 4268  SbieDrv - ok
16:54:35.0414 4268  SbieSvc - ok
16:54:35.0414 4268  sbp2port - ok
16:54:35.0414 4268  SCardSvr - ok
16:54:35.0414 4268  scfilter - ok
16:54:35.0414 4268  Schedule - ok
16:54:35.0414 4268  SCPolicySvc - ok
16:54:35.0414 4268  SDRSVC - ok
16:54:35.0429 4268  secdrv - ok
16:54:35.0429 4268  seclogon - ok
16:54:35.0429 4268  SENS - ok
16:54:35.0429 4268  SensrSvc - ok
16:54:35.0429 4268  Serenum - ok
16:54:35.0429 4268  Serial - ok
16:54:35.0445 4268  sermouse - ok
16:54:35.0445 4268  SessionEnv - ok
16:54:35.0445 4268  sffdisk - ok
16:54:35.0445 4268  sffp_mmc - ok
16:54:35.0445 4268  sffp_sd - ok
16:54:35.0461 4268  sfloppy - ok
16:54:35.0461 4268  SharedAccess - ok
16:54:35.0461 4268  ShellHWDetection - ok
16:54:35.0461 4268  SiSRaid2 - ok
16:54:35.0461 4268  SiSRaid4 - ok
16:54:35.0476 4268  SkypeUpdate - ok
16:54:35.0476 4268  Smb - ok
16:54:35.0476 4268  snapman - ok
16:54:35.0476 4268  SNMPTRAP - ok
16:54:35.0476 4268  spldr - ok
16:54:35.0476 4268  Spooler - ok
16:54:35.0492 4268  sppsvc - ok
16:54:35.0492 4268  sppuinotify - ok
16:54:35.0492 4268  srv - ok
16:54:35.0492 4268  srv2 - ok
16:54:35.0492 4268  srvnet - ok
16:54:35.0492 4268  SSDPSRV - ok
16:54:35.0507 4268  SstpSvc - ok
16:54:35.0507 4268  StarOpen - ok
16:54:35.0507 4268  Stereo Service - ok
16:54:35.0507 4268  stexstor - ok
16:54:35.0507 4268  stisvc - ok
16:54:35.0507 4268  swenum - ok
16:54:35.0523 4268  swprv - ok
16:54:35.0523 4268  syncagentsrv - ok
16:54:35.0523 4268  SysMain - ok
16:54:35.0523 4268  TabletInputService - ok
16:54:35.0523 4268  TapiSrv - ok
16:54:35.0523 4268  tbhsd - ok
16:54:35.0539 4268  TBS - ok
16:54:35.0539 4268  Tcpip - ok
16:54:35.0539 4268  TCPIP6 - ok
16:54:35.0539 4268  tcpipreg - ok
16:54:35.0539 4268  TDPIPE - ok
16:54:35.0554 4268  tdrpman - ok
16:54:35.0554 4268  TDTCP - ok
16:54:35.0554 4268  tdx - ok
16:54:35.0554 4268  TermDD - ok
16:54:35.0554 4268  TermService - ok
16:54:35.0554 4268  Themes - ok
16:54:35.0554 4268  THREADORDER - ok
16:54:35.0570 4268  timounter - ok
16:54:35.0570 4268  TrkWks - ok
16:54:35.0570 4268  TrustedInstaller - ok
16:54:35.0570 4268  tssecsrv - ok
16:54:35.0570 4268  TsUsbFlt - ok
16:54:35.0570 4268  tunnel - ok
16:54:35.0585 4268  TwonkyMedia - ok
16:54:35.0585 4268  uagp35 - ok
16:54:35.0585 4268  UBHelper - ok
16:54:35.0585 4268  udfs - ok
16:54:35.0585 4268  UI0Detect - ok
16:54:35.0601 4268  uliagpkx - ok
16:54:35.0601 4268  umbus - ok
16:54:35.0601 4268  UmPass - ok
16:54:35.0601 4268  UMVPFSrv - ok
16:54:35.0601 4268  Updater Service - ok
16:54:35.0617 4268  upnphost - ok
16:54:35.0617 4268  UPnPService - ok
16:54:35.0617 4268  USBAAPL64 - ok
16:54:35.0617 4268  usbaudio - ok
16:54:35.0617 4268  usbccgp - ok
16:54:35.0617 4268  usbcir - ok
16:54:35.0632 4268  usbehci - ok
16:54:35.0632 4268  usbhub - ok
16:54:35.0632 4268  usbohci - ok
16:54:35.0632 4268  usbprint - ok
16:54:35.0632 4268  USBSTOR - ok
16:54:35.0632 4268  usbuhci - ok
16:54:35.0648 4268  usbvideo - ok
16:54:35.0648 4268  UxSms - ok
16:54:35.0648 4268  VaultSvc - ok
16:54:35.0648 4268  vdrvroot - ok
16:54:35.0648 4268  vds - ok
16:54:35.0648 4268  vga - ok
16:54:35.0648 4268  VgaSave - ok
16:54:35.0663 4268  vhdmp - ok
16:54:35.0663 4268  viaide - ok
16:54:35.0663 4268  vididr - ok
16:54:35.0663 4268  vidsflt67 - ok
16:54:35.0663 4268  volmgr - ok
16:54:35.0663 4268  volmgrx - ok
16:54:35.0679 4268  volsnap - ok
16:54:35.0679 4268  vsmraid - ok
16:54:35.0679 4268  VSS - ok
16:54:35.0679 4268  vwifibus - ok
16:54:35.0679 4268  vwififlt - ok
16:54:35.0679 4268  W32Time - ok
16:54:35.0695 4268  WacomPen - ok
16:54:35.0695 4268  WANARP - ok
16:54:35.0695 4268  Wanarpv6 - ok
16:54:35.0695 4268  WatAdminSvc - ok
16:54:35.0695 4268  wbengine - ok
16:54:35.0695 4268  WbioSrvc - ok
16:54:35.0710 4268  wcncsvc - ok
16:54:35.0710 4268  WcsPlugInService - ok
16:54:35.0710 4268  Wd - ok
16:54:35.0710 4268  Wdf01000 - ok
16:54:35.0710 4268  WdiServiceHost - ok
16:54:35.0710 4268  WdiSystemHost - ok
16:54:35.0726 4268  WebClient - ok
16:54:35.0726 4268  Wecsvc - ok
16:54:35.0726 4268  wercplsupport - ok
16:54:35.0726 4268  WerSvc - ok
16:54:35.0726 4268  WfpLwf - ok
16:54:35.0726 4268  WIMMount - ok
16:54:35.0741 4268  WinDefend - ok
16:54:35.0741 4268  WinHttpAutoProxySvc - ok
16:54:35.0741 4268  Winmgmt - ok
16:54:35.0741 4268  WinRM - ok
16:54:35.0757 4268  WinUsb - ok
16:54:35.0757 4268  Wlansvc - ok
16:54:35.0757 4268  wlcrasvc - ok
16:54:35.0757 4268  wlidsvc - ok
16:54:35.0773 4268  WmiAcpi - ok
16:54:35.0773 4268  wmiApSrv - ok
16:54:35.0773 4268  WMPNetworkSvc - ok
16:54:35.0773 4268  WPCSvc - ok
16:54:35.0773 4268  WPDBusEnum - ok
16:54:35.0773 4268  ws2ifsl - ok
16:54:35.0788 4268  WsAudio_DeviceS(1) - ok
16:54:35.0788 4268  WsAudio_DeviceS(2) - ok
16:54:35.0788 4268  WsAudio_DeviceS(3) - ok
16:54:35.0788 4268  WsAudio_DeviceS(4) - ok
16:54:35.0788 4268  WsAudio_DeviceS(5) - ok
16:54:35.0804 4268  wscsvc - ok
16:54:35.0804 4268  WSearch - ok
16:54:35.0804 4268  wuauserv - ok
16:54:35.0804 4268  WudfPf - ok
16:54:35.0804 4268  WUDFRd - ok
16:54:35.0804 4268  wudfsvc - ok
16:54:35.0819 4268  WwanSvc - ok
16:54:35.0819 4268  ================ Scan global ===============================
16:54:35.0819 4268  [Global] - ok
16:54:35.0819 4268  ================ Scan MBR ==================================
16:54:35.0835 4268  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
16:54:36.0131 4268  \Device\Harddisk0\DR0 - ok
16:54:36.0131 4268  ================ Scan VBR ==================================
16:54:36.0131 4268  ================ Scan active images ========================
16:54:36.0131 4268  [ 3E588B60EC061686BA05D33574A344C6 ] C:\Windows\System32\drivers\crashdmp.sys
16:54:36.0131 4268  C:\Windows\System32\drivers\crashdmp.sys - ok
16:54:36.0147 4268  [ 814DB88F2641691575A455CF25354098 ] C:\Windows\System32\drivers\dumpfve.sys
16:54:36.0147 4268  C:\Windows\System32\drivers\dumpfve.sys - ok
16:54:36.0147 4268  [ 1D004CB1DA6323B1F55CAEF7F94B61D9 ] C:\Windows\System32\drivers\iaStor.sys
16:54:36.0147 4268  C:\Windows\System32\drivers\iaStor.sys - ok
16:54:36.0147 4268  [ F036CE71586E93D94DAB220D7BDF4416 ] C:\Windows\System32\drivers\cdrom.sys
16:54:36.0147 4268  C:\Windows\System32\drivers\cdrom.sys - ok
16:54:36.0163 4268  [ 6FFECC25B39DC7652A0CEC0ADA9DB589 ] C:\Windows\System32\drivers\mwlPSDFilter.sys
16:54:36.0163 4268  C:\Windows\System32\drivers\mwlPSDFilter.sys - ok
16:54:36.0163 4268  [ 16A47CE2DECC9B099349A5F840654746 ] C:\Windows\System32\drivers\beep.sys
16:54:36.0163 4268  C:\Windows\System32\drivers\beep.sys - ok
16:54:36.0163 4268  [ 9899284589F75FA8724FF3D16AED75C1 ] C:\Windows\System32\drivers\null.sys
16:54:36.0163 4268  C:\Windows\System32\drivers\null.sys - ok
16:54:36.0178 4268  [ CEA6CC257FC9B7715F1C2B4849286D24 ] C:\Windows\System32\drivers\RDPCDD.sys
16:54:36.0178 4268  C:\Windows\System32\drivers\RDPCDD.sys - ok
16:54:36.0178 4268  [ BB5971A4F00659529A5C44831AF22365 ] C:\Windows\System32\drivers\RDPENCDD.sys
16:54:36.0178 4268  C:\Windows\System32\drivers\RDPENCDD.sys - ok
16:54:36.0178 4268  [ 216F3FA57533D98E1F74DED70113177A ] C:\Windows\System32\drivers\RDPREFMP.sys
16:54:36.0178 4268  C:\Windows\System32\drivers\RDPREFMP.sys - ok
16:54:36.0178 4268  [ 53E92A310193CB3C03BEA963DE7D9CFC ] C:\Windows\System32\drivers\vga.sys
16:54:36.0178 4268  C:\Windows\System32\drivers\vga.sys - ok
16:54:36.0178 4268  [ E7353D59C9842BC7299FAEB7E7E09340 ] C:\Windows\System32\drivers\videoprt.sys
16:54:36.0178 4268  C:\Windows\System32\drivers\videoprt.sys - ok
16:54:36.0178 4268  [ FC438D1430B28618E2D0C7C332A710AD ] C:\Windows\System32\drivers\watchdog.sys
16:54:36.0178 4268  C:\Windows\System32\drivers\watchdog.sys - ok
16:54:36.0194 4268  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] C:\Windows\System32\drivers\msfs.sys
16:54:36.0194 4268  C:\Windows\System32\drivers\msfs.sys - ok
16:54:36.0194 4268  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] C:\Windows\System32\drivers\npfs.sys
16:54:36.0194 4268  C:\Windows\System32\drivers\npfs.sys - ok
16:54:36.0194 4268  [ 6F020A220388ECA0AB6062DC27BD16B6 ] C:\Windows\System32\drivers\tdi.sys
16:54:36.0194 4268  C:\Windows\System32\drivers\tdi.sys - ok
16:54:36.0194 4268  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] C:\Windows\System32\drivers\tdx.sys
16:54:36.0194 4268  C:\Windows\System32\drivers\tdx.sys - ok
16:54:36.0194 4268  [ 2427ABF5319463B9B7DF062C79967E9E ] C:\Windows\System32\drivers\avfwot.sys
16:54:36.0194 4268  C:\Windows\System32\drivers\avfwot.sys - ok
16:54:36.0194 4268  [ 1C7857B62DE5994A75B054A9FD4C3825 ] C:\Windows\System32\drivers\afd.sys
16:54:36.0194 4268  C:\Windows\System32\drivers\afd.sys - ok
16:54:36.0209 4268  [ 09594D1089C523423B32A4229263F068 ] C:\Windows\System32\drivers\netbt.sys
16:54:36.0209 4268  C:\Windows\System32\drivers\netbt.sys - ok
16:54:36.0209 4268  [ 611B23304BF067451A9FDEE01FBDD725 ] C:\Windows\System32\drivers\wfplwf.sys
16:54:36.0209 4268  C:\Windows\System32\drivers\wfplwf.sys - ok
16:54:36.0209 4268  [ 6BCC1D7D2FD2453957C5479A32364E52 ] C:\Windows\System32\drivers\ws2ifsl.sys
16:54:36.0209 4268  C:\Windows\System32\drivers\ws2ifsl.sys - ok
16:54:36.0209 4268  [ 86743D9F5D2B1048062B14B1D84501C4 ] C:\Windows\System32\drivers\netbios.sys
16:54:36.0209 4268  C:\Windows\System32\drivers\netbios.sys - ok
16:54:36.0209 4268  [ 0557CF5A2556BD58E26384169D72438D ] C:\Windows\System32\drivers\pacer.sys
16:54:36.0209 4268  C:\Windows\System32\drivers\pacer.sys - ok
16:54:36.0209 4268  [ 6A3D66263414FF0D6FA754C646612F3F ] C:\Windows\System32\drivers\vwififlt.sys
16:54:36.0209 4268  C:\Windows\System32\drivers\vwififlt.sys - ok
16:54:36.0225 4268  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] C:\Windows\System32\drivers\termdd.sys
16:54:36.0225 4268  C:\Windows\System32\drivers\termdd.sys - ok
16:54:36.0225 4268  [ 356AFD78A6ED4457169241AC3965230C ] C:\Windows\System32\drivers\wanarp.sys
16:54:36.0225 4268  C:\Windows\System32\drivers\wanarp.sys - ok
16:54:36.0225 4268  [ E7F5AE18AF4168178A642A9247C63001 ] C:\Windows\System32\drivers\nsiproxy.sys
16:54:36.0225 4268  C:\Windows\System32\drivers\nsiproxy.sys - ok
16:54:36.0225 4268  [ 77F665941019A1594D887A74F301FA2F ] C:\Windows\System32\drivers\rdbss.sys
16:54:36.0225 4268  C:\Windows\System32\drivers\rdbss.sys - ok
16:54:36.0225 4268  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] C:\Windows\System32\drivers\dfsc.sys
16:54:36.0225 4268  C:\Windows\System32\drivers\dfsc.sys - ok
16:54:36.0225 4268  [ 13096B05847EC78F0977F2C0F79E9AB3 ] C:\Windows\System32\drivers\discache.sys
16:54:36.0225 4268  C:\Windows\System32\drivers\discache.sys - ok
16:54:36.0241 4268  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] C:\Windows\System32\drivers\mssmbios.sys
16:54:36.0241 4268  C:\Windows\System32\drivers\mssmbios.sys - ok
16:54:36.0241 4268  [ 0BEFE32CA56D6EE89D58175725596A85 ] C:\Windows\System32\drivers\mwlPSDNserv.sys
16:54:36.0241 4268  C:\Windows\System32\drivers\mwlPSDNserv.sys - ok
16:54:36.0241 4268  [ D43BC633B8660463E446E28E14A51262 ] C:\Windows\System32\drivers\mwlPSDVDisk.sys
16:54:36.0241 4268  C:\Windows\System32\drivers\mwlPSDVDisk.sys - ok
16:54:36.0241 4268  [ 61583EE3C3A17003C4ACD0475646B4D3 ] C:\Windows\System32\drivers\blbdrive.sys
16:54:36.0241 4268  C:\Windows\System32\drivers\blbdrive.sys - ok
16:54:36.0241 4268  [ 490FA25161BF3E51993EB724ECF0ACEB ] C:\Windows\System32\drivers\avkmgr.sys
16:54:36.0241 4268  C:\Windows\System32\drivers\avkmgr.sys - ok
16:54:36.0241 4268  [ 488486DAD09A5B6C6DBB8B990A8B2307 ] C:\Windows\System32\drivers\avipbb.sys
16:54:36.0241 4268  C:\Windows\System32\drivers\avipbb.sys - ok
16:54:36.0241 4268  [ ADA036632C664CAA754079041CF1F8C1 ] C:\Windows\System32\drivers\intelppm.sys
16:54:36.0241 4268  C:\Windows\System32\drivers\intelppm.sys - ok
16:54:36.0256 4268  [ 3566A8DAAFA27AF944F5D705EAA64894 ] C:\Windows\System32\drivers\tunnel.sys
16:54:36.0256 4268  C:\Windows\System32\drivers\tunnel.sys - ok
16:54:36.0256 4268  [ CF95B85FF8D128385ABD411C8CA74DED ] C:\Windows\System32\ntdll.dll
16:54:36.0256 4268  C:\Windows\System32\ntdll.dll - ok
16:54:36.0256 4268  [ F0371DE302FFFF8F086661611BE60848 ] C:\Windows\System32\smss.exe
16:54:36.0256 4268  C:\Windows\System32\smss.exe - ok
16:54:36.0256 4268  [ 3B536A8BEC3B4F23FFDFD78B11A2AB93 ] C:\Windows\System32\autochk.exe
16:54:36.0256 4268  C:\Windows\System32\autochk.exe - ok
16:54:36.0256 4268  [ FCBA1C22727939E7CFF9EB08FE9692AB ] C:\Windows\System32\drivers\nvlddmkm.sys
16:54:36.0256 4268  C:\Windows\System32\drivers\nvlddmkm.sys - ok
16:54:36.0256 4268  [ 115BE147638F62321DFE754D3193099C ] C:\Windows\System32\drivers\nvBridge.kmd
16:54:36.0256 4268  C:\Windows\System32\drivers\nvBridge.kmd - ok
16:54:36.0272 4268  [ AF2E16242AA723F68F461B6EAE2EAD3D ] C:\Windows\System32\drivers\dxgkrnl.sys
16:54:36.0272 4268  C:\Windows\System32\drivers\dxgkrnl.sys - ok
16:54:36.0272 4268  [ 1F04CFB79DD5FB7694468CE3FB3DCC31 ] C:\Windows\System32\drivers\dxgmms1.sys
16:54:36.0272 4268  C:\Windows\System32\drivers\dxgmms1.sys - ok
16:54:36.0272 4268  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] C:\Windows\System32\drivers\hdaudbus.sys
16:54:36.0272 4268  C:\Windows\System32\drivers\hdaudbus.sys - ok
16:54:36.0272 4268  [ 04DDDEA79B9E616F50B9132752F656FC ] C:\Windows\System32\drivers\e1k62x64.sys
16:54:36.0272 4268  C:\Windows\System32\drivers\e1k62x64.sys - ok
16:54:36.0272 4268  [ D87E1E59C73C1F98D5DED5B3850C40F5 ] C:\Windows\System32\psapi.dll
16:54:36.0272 4268  C:\Windows\System32\psapi.dll - ok
16:54:36.0272 4268  [ C025055FE7B87701EB042095DF1A2D7B ] C:\Windows\System32\drivers\usbehci.sys
16:54:36.0272 4268  C:\Windows\System32\drivers\usbehci.sys - ok
16:54:36.0287 4268  [ AE259C75F9A0B057B6BF9E9695632B09 ] C:\Windows\System32\drivers\usbport.sys
16:54:36.0287 4268  C:\Windows\System32\drivers\usbport.sys - ok
16:54:36.0287 4268  [ A87D604AEA360176311474C87A63BB88 ] C:\Windows\System32\drivers\1394ohci.sys
16:54:36.0287 4268  C:\Windows\System32\drivers\1394ohci.sys - ok
16:54:36.0287 4268  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] C:\Windows\System32\drivers\i8042prt.sys
16:54:36.0287 4268  C:\Windows\System32\drivers\i8042prt.sys - ok
16:54:36.0287 4268  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] C:\Windows\System32\drivers\kbdclass.sys
16:54:36.0287 4268  C:\Windows\System32\drivers\kbdclass.sys - ok
16:54:36.0287 4268  [ 7D27EA49F3C1F687D357E77A470AEA99 ] C:\Windows\System32\drivers\mouclass.sys
16:54:36.0287 4268  C:\Windows\System32\drivers\mouclass.sys - ok
16:54:36.0287 4268  [ F6FF8944478594D0E414D3F048F0D778 ] C:\Windows\System32\drivers\wmiacpi.sys
16:54:36.0287 4268  C:\Windows\System32\drivers\wmiacpi.sys - ok
16:54:36.0287 4268  [ AA63DDD55F620BF96F1114F3BE3691C0 ] C:\Windows\System32\drivers\avfwim.sys
16:54:36.0287 4268  C:\Windows\System32\drivers\avfwim.sys - ok
16:54:36.0303 4268  [ 03EDB043586CCEBA243D689BDDA370A8 ] C:\Windows\System32\drivers\CompositeBus.sys
16:54:36.0303 4268  C:\Windows\System32\drivers\CompositeBus.sys - ok
16:54:36.0303 4268  [ 7ECFF9B22276B73F43A99A15A6094E90 ] C:\Windows\System32\drivers\agilevpn.sys
16:54:36.0303 4268  C:\Windows\System32\drivers\agilevpn.sys - ok
16:54:36.0303 4268  [ 30639C932D9FEF22B31268FE25A1B6E5 ] C:\Windows\System32\drivers\ndistapi.sys
16:54:36.0303 4268  C:\Windows\System32\drivers\ndistapi.sys - ok
16:54:36.0303 4268  [ 53F7305169863F0A2BDDC49E116C2E11 ] C:\Windows\System32\drivers\ndiswan.sys
16:54:36.0303 4268  C:\Windows\System32\drivers\ndiswan.sys - ok
16:54:36.0303 4268  [ 471815800AE33E6F1C32FB1B97C490CA ] C:\Windows\System32\drivers\rasl2tp.sys
16:54:36.0303 4268  C:\Windows\System32\drivers\rasl2tp.sys - ok
16:54:36.0303 4268  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] C:\Windows\System32\drivers\raspppoe.sys
16:54:36.0303 4268  C:\Windows\System32\drivers\raspppoe.sys - ok
16:54:36.0319 4268  [ 24FBF5CC5C04150073C315A7C83521EE ] C:\Windows\System32\drivers\ks.sys
16:54:36.0319 4268  C:\Windows\System32\drivers\ks.sys - ok
16:54:36.0319 4268  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] C:\Windows\System32\drivers\raspptp.sys
16:54:36.0319 4268  C:\Windows\System32\drivers\raspptp.sys - ok
16:54:36.0319 4268  [ E8B1E447B008D07FF47D016C2B0EEECB ] C:\Windows\System32\drivers\rassstp.sys
16:54:36.0319 4268  C:\Windows\System32\drivers\rassstp.sys - ok
16:54:36.0319 4268  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] C:\Windows\System32\drivers\swenum.sys
16:54:36.0319 4268  C:\Windows\System32\drivers\swenum.sys - ok
16:54:36.0319 4268  [ DC54A574663A895C8763AF0FA1FF7561 ] C:\Windows\System32\drivers\umbus.sys
16:54:36.0319 4268  C:\Windows\System32\drivers\umbus.sys - ok
16:54:36.0319 4268  [ F7CE0C81C545364020ED8203CF0A633E ] C:\Windows\System32\difxapi.dll
16:54:36.0319 4268  C:\Windows\System32\difxapi.dll - ok
16:54:36.0334 4268  [ 0611473C1AD9E2D991CD9482068417F7 ] C:\Windows\System32\rpcrt4.dll
16:54:36.0334 4268  C:\Windows\System32\rpcrt4.dll - ok
16:54:36.0334 4268  [ 4E4FFB09D895AA000DD56D1404F69A7E ] C:\Windows\System32\Wldap32.dll
16:54:36.0334 4268  C:\Windows\System32\Wldap32.dll - ok
16:54:36.0334 4268  [ C9152A497D0CA33CE9D729F1179DDB01 ] C:\Windows\System32\urlmon.dll
16:54:36.0334 4268  C:\Windows\System32\urlmon.dll - ok
16:54:36.0334 4268  [ 6C60B5ACA7442EFB794082CDACFC001C ] C:\Windows\System32\ole32.dll
16:54:36.0334 4268  C:\Windows\System32\ole32.dll - ok
16:54:36.0334 4268  [ 65C113214F7B05820F6D8A65B1485196 ] C:\Windows\System32\kernel32.dll
16:54:36.0334 4268  C:\Windows\System32\kernel32.dll - ok
16:54:36.0334 4268  [ 4BBFA57F594F7E8A8EDC8F377184C3F0 ] C:\Windows\System32\ws2_32.dll
16:54:36.0334 4268  C:\Windows\System32\ws2_32.dll - ok
16:54:36.0350 4268  [ FE70103391A64039A921DBFFF9C7AB1B ] C:\Windows\System32\user32.dll
16:54:36.0350 4268  C:\Windows\System32\user32.dll - ok
16:54:36.0350 4268  [ 6DF46D2BD74E3DA1B45F08F10D172732 ] C:\Windows\System32\advapi32.dll
16:54:36.0350 4268  C:\Windows\System32\advapi32.dll - ok
16:54:36.0350 4268  [ 25983DE69B57142039AC8D95E71CD9C9 ] C:\Windows\System32\clbcatq.dll
16:54:36.0350 4268  C:\Windows\System32\clbcatq.dll - ok
16:54:36.0350 4268  [ A1BE6A720D02E37F72E9CD89AE9CB3CF ] C:\Windows\System32\imagehlp.dll
16:54:36.0350 4268  C:\Windows\System32\imagehlp.dll - ok
16:54:36.0350 4268  [ C431EAF5CAA1C82CAC2534A2EAB348A3 ] C:\Windows\System32\msctf.dll
16:54:36.0350 4268  C:\Windows\System32\msctf.dll - ok
16:54:36.0350 4268  [ 044FE45FFD6AD40E3BBBE60B7F41BABE ] C:\Windows\System32\nsi.dll
16:54:36.0350 4268  C:\Windows\System32\nsi.dll - ok
16:54:36.0350 4268  [ 5D8E6C95156ED1F79A63D1EADE6F9ED5 ] C:\Windows\System32\setupapi.dll
16:54:36.0350 4268  C:\Windows\System32\setupapi.dll - ok
16:54:36.0365 4268  [ 9835E63E09F824D22B689D2BB789BAB9 ] C:\Windows\System32\comdlg32.dll
16:54:36.0365 4268  C:\Windows\System32\comdlg32.dll - ok
16:54:36.0365 4268  [ C06B32165E23A72A898B7A89679AD754 ] C:\Windows\System32\oleaut32.dll
16:54:36.0365 4268  C:\Windows\System32\oleaut32.dll - ok
16:54:36.0365 4268  [ 1084AA52CCC324EA54C7121FA24C2221 ] C:\Windows\System32\gdi32.dll
16:54:36.0365 4268  C:\Windows\System32\gdi32.dll - ok
16:54:36.0365 4268  [ AA2C08CE85653B1A0D2E4AB407FA176C ] C:\Windows\System32\imm32.dll
16:54:36.0365 4268  C:\Windows\System32\imm32.dll - ok
16:54:36.0365 4268  [ 1BFC94665BCA35F9001ADC7BFB167C63 ] C:\Windows\System32\shell32.dll
16:54:36.0365 4268  C:\Windows\System32\shell32.dll - ok
16:54:36.0365 4268  [ DBF99FD9CAF75CA66D042BD8D050FF71 ] C:\Windows\System32\usp10.dll
16:54:36.0365 4268  C:\Windows\System32\usp10.dll - ok
16:54:36.0381 4268  [ C391FC68282A000CDF953F8B6B55D2EF ] C:\Windows\System32\msvcrt.dll
16:54:36.0381 4268  C:\Windows\System32\msvcrt.dll - ok
16:54:36.0381 4268  [ 12716D987D475B051F35895659159705 ] C:\Windows\System32\wininet.dll
16:54:36.0381 4268  C:\Windows\System32\wininet.dll - ok
16:54:36.0381 4268  [ 1BDF694C5BA91A1576DA907DA3077EF8 ] C:\Windows\System32\iertutil.dll
16:54:36.0381 4268  C:\Windows\System32\iertutil.dll - ok
16:54:36.0381 4268  [ D202223587518B13D72D68937B7E3F70 ] C:\Windows\System32\lpk.dll
16:54:36.0381 4268  C:\Windows\System32\lpk.dll - ok
16:54:36.0381 4268  [ 83404DCBCE4925B6A5A77C5170F46D86 ] C:\Windows\System32\sechost.dll
16:54:36.0381 4268  C:\Windows\System32\sechost.dll - ok
16:54:36.0381 4268  [ 28C0B5024F5C5A438E78B188CFC81B7F ] C:\Windows\System32\normaliz.dll
16:54:36.0381 4268  C:\Windows\System32\normaliz.dll - ok
16:54:36.0397 4268  [ EAF32CB8C1F810E4715B4DFBE785C7FF ] C:\Windows\System32\shlwapi.dll
16:54:36.0397 4268  C:\Windows\System32\shlwapi.dll - ok
16:54:36.0397 4268  [ 2477A28081BDAEE622CF045ACF8EE124 ] C:\Windows\System32\cfgmgr32.dll
16:54:36.0397 4268  C:\Windows\System32\cfgmgr32.dll - ok
16:54:36.0397 4268  [ 14DFDEAF4E589ED3F1FF187A86B9408C ] C:\Windows\System32\comctl32.dll
16:54:36.0397 4268  C:\Windows\System32\comctl32.dll - ok
16:54:36.0397 4268  [ 06FEC9E8117103BB1141A560E98077DA ] C:\Windows\System32\devobj.dll
16:54:36.0397 4268  C:\Windows\System32\devobj.dll - ok
16:54:36.0397 4268  [ 64A4AB126E24FD3F58EBE64852773DB5 ] C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
16:54:36.0397 4268  C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll - ok
16:54:36.0397 4268  [ 0E6FBF19D9DFBB77316C23DF91F8A101 ] C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
16:54:36.0397 4268  C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll - ok
16:54:36.0397 4268  [ AFC3DB5C6EB8CA8017DDB81D6C0AD02A ] C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
16:54:36.0397 4268  C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll - ok
16:54:36.0412 4268  [ 9094039A00485F71C4DE64BF51F64C46 ] C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
16:54:36.0412 4268  C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll - ok
16:54:36.0412 4268  [ A96D5ECA5742603E0E345C4F6B801F5E ] C:\Windows\System32\crypt32.dll
16:54:36.0412 4268  C:\Windows\System32\crypt32.dll - ok
16:54:36.0412 4268  [ 1F56F209585F350A5666E3CC7931FD67 ] C:\Windows\System32\KernelBase.dll
16:54:36.0412 4268  C:\Windows\System32\KernelBase.dll - ok
16:54:36.0412 4268  [ F49E92B50CED5C9F1725D3C0329FD933 ] C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
16:54:36.0412 4268  C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll - ok
16:54:36.0412 4268  [ 72723D3E4781BADC62C3180C137E7B23 ] C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
16:54:36.0412 4268  C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll - ok
16:54:36.0412 4268  [ 884415BD4269C02EAF8E2613BF85500D ] C:\Windows\System32\msasn1.dll
16:54:36.0412 4268  C:\Windows\System32\msasn1.dll - ok
16:54:36.0428 4268  [ AA06902362B1422D7A7DA7061E07C624 ] C:\Windows\System32\wintrust.dll
16:54:36.0428 4268  C:\Windows\System32\wintrust.dll - ok
16:54:36.0428 4268  [ 287C6C9410B111B68B52CA298F7B8C24 ] C:\Windows\System32\drivers\usbhub.sys
16:54:36.0428 4268  C:\Windows\System32\drivers\usbhub.sys - ok
16:54:36.0428 4268  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] C:\Windows\System32\drivers\ndproxy.sys
16:54:36.0428 4268  C:\Windows\System32\drivers\ndproxy.sys - ok
16:54:36.0428 4268  [ 21D26064AEDB4988F785BB4A3A2C051E ] C:\Windows\System32\drivers\drmk.sys
16:54:36.0428 4268  C:\Windows\System32\drivers\drmk.sys - ok
16:54:36.0428 4268  [ 6869281E78CB31A43E969F06B57347C4 ] C:\Windows\System32\drivers\ksthunk.sys
16:54:36.0428 4268  C:\Windows\System32\drivers\ksthunk.sys - ok
16:54:36.0428 4268  [ 8D4AAC74B571FC356560E5B308955E93 ] C:\Windows\System32\drivers\nvhda64v.sys
16:54:36.0428 4268  C:\Windows\System32\drivers\nvhda64v.sys - ok
16:54:36.0443 4268  [ 32E11315B5126921FFD9074840EF13D3 ] C:\Windows\System32\drivers\portcls.sys
16:54:36.0443 4268  C:\Windows\System32\drivers\portcls.sys - ok
16:54:36.0443 4268  [ 975761C778E33CD22498059B91E7373A ] C:\Windows\System32\drivers\HdAudio.sys
16:54:36.0443 4268  C:\Windows\System32\drivers\HdAudio.sys - ok
16:54:36.0443 4268  [ 9C278785347BCC991F8EA2999D90F58D ] C:\Windows\SysWOW64\normaliz.dll
16:54:36.0443 4268  C:\Windows\SysWOW64\normaliz.dll - ok
16:54:36.0443 4268  [ BF24D6F2ED97FE830BFD52B246F98E67 ] C:\Windows\System32\drivers\dxapi.sys
16:54:36.0443 4268  C:\Windows\System32\drivers\dxapi.sys - ok
16:54:36.0443 4268  [ A11523523B31086DD760C0189C763359 ] C:\Windows\System32\win32k.sys
16:54:36.0443 4268  C:\Windows\System32\win32k.sys - ok
16:54:36.0443 4268  [ CEC1EDF4022DC4DCA40384DCEC672B0E ] C:\Windows\System32\csrsrv.dll
16:54:36.0443 4268  C:\Windows\System32\csrsrv.dll - ok
16:54:36.0459 4268  [ 60C2862B4BF0FD9F582EF344C2B1EC72 ] C:\Windows\System32\csrss.exe
16:54:36.0459 4268  C:\Windows\System32\csrss.exe - ok
16:54:36.0459 4268  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\System32\basesrv.dll
16:54:36.0459 4268  C:\Windows\System32\basesrv.dll - ok
16:54:36.0459 4268  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\System32\winsrv.dll
16:54:36.0459 4268  C:\Windows\System32\winsrv.dll - ok
16:54:36.0459 4268  [ B03D591DC7DA45ECE20B3B467E6AADAA ] C:\Windows\System32\drivers\monitor.sys
16:54:36.0459 4268  C:\Windows\System32\drivers\monitor.sys - ok
16:54:36.0459 4268  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\System32\sxssrv.dll
16:54:36.0459 4268  C:\Windows\System32\sxssrv.dll - ok
16:54:36.0459 4268  [ F29FE765E1448EF371CFE05BFAC74ADB ] C:\Windows\System32\tsddd.dll
16:54:36.0459 4268  C:\Windows\System32\tsddd.dll - ok
16:54:36.0475 4268  [ 94355C28C1970635A31B3FE52EB7CEBA ] C:\Windows\System32\wininit.exe
16:54:36.0475 4268  C:\Windows\System32\wininit.exe - ok
16:54:36.0475 4268  [ E38D1691B68FCB6224D69B4D4E25EBF3 ] C:\Windows\System32\KBDGR.DLL
16:54:36.0475 4268  C:\Windows\System32\KBDGR.DLL - ok
16:54:36.0475 4268  [ 2C942733A5983DD4502219FF37C7EBC7 ] C:\Windows\System32\profapi.dll
16:54:36.0475 4268  C:\Windows\System32\profapi.dll - ok
16:54:36.0475 4268  [ C2A8CB1275ECB85D246A9ECC02A728E3 ] C:\Windows\System32\RpcRtRemote.dll
16:54:36.0475 4268  C:\Windows\System32\RpcRtRemote.dll - ok
16:54:36.0475 4268  [ 943F527DF79E6B400104341AA7023C75 ] C:\Windows\System32\cdd.dll
16:54:36.0475 4268  C:\Windows\System32\cdd.dll - ok
16:54:36.0475 4268  [ 78523A26F5604C0568FE9D1CE86E36F4 ] C:\Windows\System32\KBDUS.DLL
16:54:36.0475 4268  C:\Windows\System32\KBDUS.DLL - ok
16:54:36.0475 4268  [ 9CEAD32E79A62150FE9F8557E58E008B ] C:\Windows\System32\sxs.dll
16:54:36.0475 4268  C:\Windows\System32\sxs.dll - ok
16:54:36.0490 4268  [ B26B1801356760841C3BC69F9F91537F ] C:\Windows\System32\WlS0WndH.dll
16:54:36.0490 4268  C:\Windows\System32\WlS0WndH.dll - ok
16:54:36.0490 4268  [ 784FA3DF338E2E8F5F0389D6FAC428AF ] C:\Windows\System32\cryptbase.dll
16:54:36.0490 4268  C:\Windows\System32\cryptbase.dll - ok
16:54:36.0490 4268  [ CCA2AB1752A61F29C3C941CD79D78CEA ] C:\Windows\System32\drivers\usbd.sys
16:54:36.0490 4268  C:\Windows\System32\drivers\usbd.sys - ok
16:54:36.0490 4268  [ 90499F3163A9F815CF196A205EA3CD5D ] C:\Windows\System32\apphelp.dll
16:54:36.0490 4268  C:\Windows\System32\apphelp.dll - ok
16:54:36.0490 4268  [ 6F1A3157A1C89435352CEB543CDB359C ] C:\Windows\System32\drivers\usbccgp.sys
16:54:36.0490 4268  C:\Windows\System32\drivers\usbccgp.sys - ok
16:54:36.0490 4268  [ 685527DA09EBFB681E98C515978BDEE2 ] C:\Windows\System32\lsasrv.dll
16:54:36.0490 4268  C:\Windows\System32\lsasrv.dll - ok
16:54:36.0506 4268  [ C118A82CD78818C29AB228366EBF81C3 ] C:\Windows\System32\lsass.exe
16:54:36.0506 4268  C:\Windows\System32\lsass.exe - ok
16:54:36.0506 4268  [ 9662EE182644511439F1C53745DC1C88 ] C:\Windows\System32\lsm.exe
16:54:36.0506 4268  C:\Windows\System32\lsm.exe - ok
16:54:36.0506 4268  [ BBCDF350817BA86416C0F06B6981BE8D ] C:\Windows\System32\scesrv.dll
16:54:36.0506 4268  C:\Windows\System32\scesrv.dll - ok
16:54:36.0506 4268  [ E914A50A151DFFE63D3935226DB5E2C1 ] C:\Windows\System32\scext.dll
16:54:36.0506 4268  C:\Windows\System32\scext.dll - ok
16:54:36.0506 4268  [ 0144D8D75A0B12938AEEE859E3310A46 ] C:\Windows\System32\secur32.dll
16:54:36.0506 4268  C:\Windows\System32\secur32.dll - ok
16:54:36.0506 4268  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\System32\services.exe
16:54:36.0506 4268  C:\Windows\System32\services.exe - ok
16:54:36.0506 4268  [ B66BC8B20B7F33975865B1DF99783FD8 ] C:\Windows\System32\sspicli.dll
16:54:36.0506 4268  C:\Windows\System32\sspicli.dll - ok
16:54:36.0521 4268  [ 3A0CE5FE781708CD6ABD55313607EC8B ] C:\Windows\System32\sspisrv.dll
16:54:36.0521 4268  C:\Windows\System32\sspisrv.dll - ok
16:54:36.0521 4268  [ 68083118797CAF30FB2EA3E71494D67E ] C:\Windows\System32\sysntfy.dll
16:54:36.0521 4268  C:\Windows\System32\sysntfy.dll - ok
16:54:36.0521 4268  [ DEE7267C5D232A3B816866872CE199E6 ] C:\Windows\System32\wmsgapi.dll
16:54:36.0521 4268  C:\Windows\System32\wmsgapi.dll - ok
16:54:36.0521 4268  [ A744BA6E04C8AA4592818178DBF89521 ] C:\Windows\System32\samsrv.dll
16:54:36.0521 4268  C:\Windows\System32\samsrv.dll - ok
16:54:36.0521 4268  [ 3A9C9BAF610B0DD4967086040B3B62A9 ] C:\Windows\System32\srvcli.dll
16:54:36.0521 4268  C:\Windows\System32\srvcli.dll - ok
16:54:36.0521 4268  [ 7FBEBD2229EA5FD48D41B199EC2D541C ] C:\Windows\System32\authz.dll
16:54:36.0521 4268  C:\Windows\System32\authz.dll - ok
16:54:36.0537 4268  [ 86FE1B1F8FD42CD0DB641AB1CDB13093 ] C:\Windows\System32\cngaudit.dll
16:54:36.0537 4268  C:\Windows\System32\cngaudit.dll - ok
16:54:36.0537 4268  [ 3A061472B38233BAFF9CFEFF2E49C46B ] C:\Windows\System32\cryptdll.dll
16:54:36.0537 4268  C:\Windows\System32\cryptdll.dll - ok
16:54:36.0537 4268  [ 3C073B0C596A0AF84933E7406766B040 ] C:\Windows\System32\wevtapi.dll
16:54:36.0537 4268  C:\Windows\System32\wevtapi.dll - ok
16:54:36.0537 4268  [ 5F3307352216618221A17CFEF273EEE2 ] C:\Windows\System32\ncrypt.dll
16:54:36.0537 4268  C:\Windows\System32\ncrypt.dll - ok
16:54:36.0537 4268  [ B9A95365E52F421A20E1501935FADDA5 ] C:\Windows\System32\bcrypt.dll
16:54:36.0537 4268  C:\Windows\System32\bcrypt.dll - ok
16:54:36.0537 4268  [ 02B64609F865A39365FF88580DF11738 ] C:\Windows\System32\msprivs.dll
16:54:36.0537 4268  C:\Windows\System32\msprivs.dll - ok
16:54:36.0537 4268  [ C6505DE3561537BA1004D638C2F93F2F ] C:\Windows\System32\netjoin.dll
16:54:36.0537 4268  C:\Windows\System32\netjoin.dll - ok
16:54:36.0553 4268  [ 1151B1BAA6F350B1DB6598E0FEA7C457 ] C:\Windows\System32\winlogon.exe
16:54:36.0553 4268  C:\Windows\System32\winlogon.exe - ok
16:54:36.0553 4268  [ 0D9764D58C5EFD672B7184854B152E5E ] C:\Windows\System32\winsta.dll
16:54:36.0553 4268  C:\Windows\System32\winsta.dll - ok
16:54:36.0553 4268  [ 44E1A196DFCB53B01FE4B855C3B56A15 ] C:\Windows\System32\kerberos.dll
16:54:36.0553 4268  C:\Windows\System32\kerberos.dll - ok
16:54:36.0553 4268  [ 50532FCD7ECF02DD169CE5C485F02534 ] C:\Windows\System32\negoexts.dll
16:54:36.0553 4268  C:\Windows\System32\negoexts.dll - ok
16:54:36.0553 4268  [ CB2ABB2DA1E9C977302A78D86D4AE3B0 ] C:\Windows\System32\atmfd.dll
16:54:36.0553 4268  C:\Windows\System32\atmfd.dll - ok
16:54:36.0553 4268  [ D0C2FBB6D97416B0166478FC7AE2B212 ] C:\Windows\System32\cryptsp.dll
16:54:36.0553 4268  C:\Windows\System32\cryptsp.dll - ok
16:54:36.0568 4268  [ 1D5185A4C7E6695431AE4B55C3D7D333 ] C:\Windows\System32\mswsock.dll
16:54:36.0568 4268  C:\Windows\System32\mswsock.dll - ok
16:54:36.0568 4268  [ 94E026870A55AAEAFF7853C1754091E9 ] C:\Windows\System32\version.dll
16:54:36.0568 4268  C:\Windows\System32\version.dll - ok
16:54:36.0568 4268  [ EF12B8385AA2849999008A977918F96B ] C:\Windows\System32\msv1_0.dll
16:54:36.0568 4268  C:\Windows\System32\msv1_0.dll - ok
16:54:36.0568 4268  [ EC7CBFF96B05ECF3D366355B3C64ADCF ] C:\Windows\System32\wship6.dll
16:54:36.0568 4268  C:\Windows\System32\wship6.dll - ok
16:54:36.0568 4268  [ AA339DD8BB128EF66660DFBBB59043D3 ] C:\Windows\System32\netlogon.dll
16:54:36.0568 4268  C:\Windows\System32\netlogon.dll - ok
16:54:36.0568 4268  [ 492D07D79E7024CA310867B526D9636D ] C:\Windows\System32\dnsapi.dll
16:54:36.0568 4268  C:\Windows\System32\dnsapi.dll - ok
16:54:36.0584 4268  [ FF3A488924B0032B1A9CA6948C1FA9E8 ] C:\Windows\System32\drivers\lvuvc64.sys
16:54:36.0584 4268  C:\Windows\System32\drivers\lvuvc64.sys - ok
16:54:36.0584 4268  [ 8FFE297B8449386E7B6851458B6E474E ] C:\Windows\System32\logoncli.dll
16:54:36.0584 4268  C:\Windows\System32\logoncli.dll - ok
16:54:36.0584 4268  [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] C:\Windows\System32\drivers\USBAUDIO.sys
16:54:36.0584 4268  C:\Windows\System32\drivers\USBAUDIO.sys - ok
16:54:36.0584 4268  [ B7D42CB36C08FA017E73FF2433CD7287 ] C:\Windows\System32\schannel.dll
16:54:36.0584 4268  C:\Windows\System32\schannel.dll - ok
16:54:36.0584 4268  [ 0C85B2B6FB74B36A251792D45E0EF860 ] C:\Windows\System32\drivers\lvrs64.sys
16:54:36.0584 4268  C:\Windows\System32\drivers\lvrs64.sys - ok
16:54:36.0584 4268  [ 95FB6CA4374E343DDD653FCC43F9D26B ] C:\Windows\System32\wdigest.dll
16:54:36.0584 4268  C:\Windows\System32\wdigest.dll - ok
16:54:36.0584 4268  [ E08088A97F95345E181C3DFCE2C615EF ] C:\Windows\System32\pku2u.dll
16:54:36.0584 4268  C:\Windows\System32\pku2u.dll - ok
16:54:36.0599 4268  [ 5D8874A8C11DDDDE29E12DE0E2013493 ] C:\Windows\System32\rsaenh.dll
16:54:36.0599 4268  C:\Windows\System32\rsaenh.dll - ok
16:54:36.0599 4268  [ 8A25506B6948EFBD5A7F37E53CCD36D9 ] C:\Windows\System32\TSpkg.dll
16:54:36.0599 4268  C:\Windows\System32\TSpkg.dll - ok
16:54:36.0599 4268  [ D6C7780A364C6BBACFA796BAB9F1B374 ] C:\Windows\System32\bcryptprimitives.dll
16:54:36.0599 4268  C:\Windows\System32\bcryptprimitives.dll - ok
16:54:36.0599 4268  [ 7DBA64AD70C2E2481C68D9E0F7CD7840 ] C:\Windows\System32\LIVESSP.DLL
16:54:36.0599 4268  C:\Windows\System32\LIVESSP.DLL - ok
16:54:36.0599 4268  [ 52D3D5E3586988D4D9E34ACAAC33105C ] C:\Windows\System32\credssp.dll
16:54:36.0599 4268  C:\Windows\System32\credssp.dll - ok
16:54:36.0599 4268  [ 90BDEFC5DF334E5100EAA781D798DE1A ] C:\Windows\System32\efslsaext.dll
16:54:36.0599 4268  C:\Windows\System32\efslsaext.dll - ok
16:54:36.0615 4268  [ ED78427259134C63ED69804D2132B86C ] C:\Windows\System32\scecli.dll
16:54:36.0615 4268  C:\Windows\System32\scecli.dll - ok
16:54:36.0615 4268  [ 7CC7DF5B654DA579613F811D8C637E29 ] C:\Windows\System32\ubpm.dll
16:54:36.0615 4268  C:\Windows\System32\ubpm.dll - ok
16:54:36.0615 4268  [ C78655BC80301D76ED4FEF1C1EA40A7D ] C:\Windows\System32\svchost.exe
16:54:36.0615 4268  C:\Windows\System32\svchost.exe - ok
16:54:36.0615 4268  [ 25FBDEF06C4D92815B353F6E792C8129 ] C:\Windows\System32\umpnpmgr.dll
16:54:36.0615 4268  C:\Windows\System32\umpnpmgr.dll - ok
16:54:36.0615 4268  [ CD1B5AD07E5F7FEF30E055DCC9E96180 ] C:\Windows\System32\devrtl.dll
16:54:36.0615 4268  C:\Windows\System32\devrtl.dll - ok
16:54:36.0615 4268  [ E6EB44ABAAF1F330119F854856C53EBE ] C:\Windows\System32\SPInf.dll
16:54:36.0615 4268  C:\Windows\System32\SPInf.dll - ok
16:54:36.0631 4268  [ 7A17485DC7D8A7AC81321A42CD034519 ] C:\Windows\System32\userenv.dll
16:54:36.0631 4268  C:\Windows\System32\userenv.dll - ok
16:54:36.0631 4268  [ 9C9307C95671AC962F3D6EB3A4A89BAE ] C:\Windows\System32\gpapi.dll
16:54:36.0631 4268  C:\Windows\System32\gpapi.dll - ok
16:54:36.0631 4268  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] C:\Windows\System32\umpo.dll
16:54:36.0631 4268  C:\Windows\System32\umpo.dll - ok
16:54:36.0631 4268  [ F6C011B46FAEEF33536B2E80F48B5CBE ] C:\Windows\System32\pcwum.dll
16:54:36.0631 4268  C:\Windows\System32\pcwum.dll - ok
16:54:36.0631 4268  [ 716175021BDA290504CE434273F666BC ] C:\Windows\System32\powrprof.dll
16:54:36.0631 4268  C:\Windows\System32\powrprof.dll - ok
16:54:36.0631 4268  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] C:\Windows\System32\drivers\luafv.sys
16:54:36.0631 4268  C:\Windows\System32\drivers\luafv.sys - ok
16:54:36.0631 4268  [ 09E6069EF94B345061B4BD3CEBD974C8 ] C:\Windows\System32\drivers\avgntflt.sys
16:54:36.0631 4268  C:\Windows\System32\drivers\avgntflt.sys - ok
16:54:36.0646 4268  [ 10C232F6CFFD51D2332898AE7AE0FF23 ] C:\Windows\System32\nvvsvc.exe
16:54:36.0646 4268  C:\Windows\System32\nvvsvc.exe - ok
16:54:36.0646 4268  [ BD3674BE7FC9D8D3732C83E8499576ED ] C:\Windows\System32\wtsapi32.dll
16:54:36.0646 4268  C:\Windows\System32\wtsapi32.dll - ok
16:54:36.0646 4268  [ 5A19667A580B1CE886EAF968B9743F45 ] C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
16:54:36.0646 4268  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe - ok
16:54:36.0646 4268  [ E73B0F1819602CB6EF176FB78D76A47B ] C:\Windows\SysWOW64\ntdll.dll
16:54:36.0646 4268  C:\Windows\SysWOW64\ntdll.dll - ok
16:54:36.0646 4268  [ 259EB5F7D95A29842B476C5B3EB6E186 ] C:\Windows\System32\wow64.dll
16:54:36.0646 4268  C:\Windows\System32\wow64.dll - ok
16:54:36.0646 4268  [ 3EE3AA76D8AB6D5644C4C8F34471CEB3 ] C:\Windows\System32\wow64cpu.dll
16:54:36.0646 4268  C:\Windows\System32\wow64cpu.dll - ok
16:54:36.0662 4268  [ 5674E21E82CFBEA36DDAD5DB285D6DBC ] C:\Windows\System32\wow64win.dll
16:54:36.0662 4268  C:\Windows\System32\wow64win.dll - ok
16:54:36.0662 4268  [ AC0B6F41882FC6ED186962D770EBF1D2 ] C:\Windows\SysWOW64\kernel32.dll
16:54:36.0662 4268  C:\Windows\SysWOW64\kernel32.dll - ok
16:54:36.0662 4268  [ E954A79D6A754A5475582CACED1565E6 ] C:\Windows\SysWOW64\KernelBase.dll
16:54:36.0662 4268  C:\Windows\SysWOW64\KernelBase.dll - ok
16:54:36.0662 4268  [ 9DC80A8AAAAAC397BDAB3C67165A824E ] C:\Windows\SysWOW64\msvcrt.dll
16:54:36.0662 4268  C:\Windows\SysWOW64\msvcrt.dll - ok
16:54:36.0662 4268  [ 702254574E7E52052DE39408457B7149 ] C:\Windows\SysWOW64\version.dll
16:54:36.0662 4268  C:\Windows\SysWOW64\version.dll - ok
16:54:36.0662 4268  [ 10FB16B50AFFDA6D44588F3C445DC273 ] C:\Windows\SysWOW64\setupapi.dll
16:54:36.0662 4268  C:\Windows\SysWOW64\setupapi.dll - ok
16:54:36.0677 4268  [ F436E847FA799ECD75AD8C313673F450 ] C:\Windows\SysWOW64\cfgmgr32.dll
16:54:36.0677 4268  C:\Windows\SysWOW64\cfgmgr32.dll - ok
16:54:36.0677 4268  [ C5AD8083CF94201F1F8084ECC696A8B7 ] C:\Windows\SysWOW64\rpcrt4.dll
16:54:36.0677 4268  C:\Windows\SysWOW64\rpcrt4.dll - ok
16:54:36.0677 4268  [ 95E2376B3323F062EB562B8586D0F14A ] C:\Windows\SysWOW64\advapi32.dll
16:54:36.0677 4268  C:\Windows\SysWOW64\advapi32.dll - ok
16:54:36.0677 4268  [ F08F6FCD09F9BE94C37ACC1B344685FF ] C:\Windows\SysWOW64\cryptbase.dll
16:54:36.0677 4268  C:\Windows\SysWOW64\cryptbase.dll - ok
16:54:36.0677 4268  [ CFC97F07904067A1E5FAE195D534DA3A ] C:\Windows\SysWOW64\sechost.dll
16:54:36.0677 4268  C:\Windows\SysWOW64\sechost.dll - ok
16:54:36.0677 4268  [ BFB26890612FB8AE8B0463EBEBE84B7E ] C:\Windows\SysWOW64\sspicli.dll
16:54:36.0677 4268  C:\Windows\SysWOW64\sspicli.dll - ok
16:54:36.0693 4268  [ D6D3AD7BF1D6F6CE9547613ED5E170A2 ] C:\Windows\SysWOW64\gdi32.dll
16:54:36.0693 4268  C:\Windows\SysWOW64\gdi32.dll - ok
16:54:36.0693 4268  [ 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 ] C:\Windows\SysWOW64\user32.dll
16:54:36.0693 4268  C:\Windows\SysWOW64\user32.dll - ok
16:54:36.0693 4268  [ 384721EF4024890092625E20CADFAF85 ] C:\Windows\SysWOW64\lpk.dll
16:54:36.0693 4268  C:\Windows\SysWOW64\lpk.dll - ok
16:54:36.0693 4268  [ 6C765E82B57F2E66CE9C54AC238471D9 ] C:\Windows\SysWOW64\oleaut32.dll
16:54:36.0693 4268  C:\Windows\SysWOW64\oleaut32.dll - ok
16:54:36.0693 4268  [ B7230010D97787AF3D25E4C82F2B06B9 ] C:\Windows\SysWOW64\usp10.dll
16:54:36.0693 4268  C:\Windows\SysWOW64\usp10.dll - ok
16:54:36.0693 4268  [ 928CF7268086631F54C3D8E17238C6DD ] C:\Windows\SysWOW64\ole32.dll
16:54:36.0693 4268  C:\Windows\SysWOW64\ole32.dll - ok
16:54:36.0693 4268  [ 2EEFF4502F5E13B1BED4A04CCAD64C08 ] C:\Windows\SysWOW64\devobj.dll
16:54:36.0693 4268  C:\Windows\SysWOW64\devobj.dll - ok
16:54:36.0709 4268  [ 9E4B0E7472B4CEBA9E17F440B8CB0AB8 ] C:\Windows\SysWOW64\winspool.drv
16:54:36.0709 4268  C:\Windows\SysWOW64\winspool.drv - ok
16:54:36.0709 4268  [ A6F09E5669D9A19035F6D942CAA15882 ] C:\Windows\SysWOW64\imm32.dll
16:54:36.0709 4268  C:\Windows\SysWOW64\imm32.dll - ok
16:54:36.0709 4268  [ C9618BC9B2B0FD7C1138D8774795A79B ] C:\Windows\SysWOW64\msctf.dll
16:54:36.0709 4268  C:\Windows\SysWOW64\msctf.dll - ok
16:54:36.0709 4268  [ 557C69A479F00DE9AB885A1A9C28889A ] C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstres.dll
16:54:36.0709 4268  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstres.dll - ok
16:54:36.0709 4268  [ BDA164FB03B649BBEE46F5CB5A6770B1 ] C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvwl.dll
16:54:36.0709 4268  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvwl.dll - ok
16:54:36.0709 4268  [ 5C627D1B1138676C0A7AB2C2C190D123 ] C:\Windows\System32\rpcss.dll
16:54:36.0709 4268  C:\Windows\System32\rpcss.dll - ok
16:54:36.0724 4268  [ 3FD15B4611D9BDA3F8013548C0ECAECA ] C:\Windows\SysWOW64\ntmarta.dll
16:54:36.0724 4268  C:\Windows\SysWOW64\ntmarta.dll - ok
16:54:36.0724 4268  [ A8BB45F9ECAD993461E0FEF8E2A99152 ] C:\Windows\SysWOW64\Wldap32.dll
16:54:36.0724 4268  C:\Windows\SysWOW64\Wldap32.dll - ok
16:54:36.0724 4268  [ 92245C959E5BC378809D2CC5E9F6E9C7 ] C:\Windows\SysWOW64\crypt32.dll
16:54:36.0724 4268  C:\Windows\SysWOW64\crypt32.dll - ok
16:54:36.0724 4268  [ 17448AF0BBA9E7AB5EC955AF93F271BD ] C:\Windows\SysWOW64\wintrust.dll
16:54:36.0724 4268  C:\Windows\SysWOW64\wintrust.dll - ok
16:54:36.0724 4268  [ 938F39B50BAFE13D6F58C7790682C010 ] C:\Windows\SysWOW64\msasn1.dll
16:54:36.0724 4268  C:\Windows\SysWOW64\msasn1.dll - ok
16:54:36.0724 4268  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] C:\Windows\System32\RpcEpMap.dll
16:54:36.0724 4268  C:\Windows\System32\RpcEpMap.dll - ok
16:54:36.0740 4268  [ AF5DEA3E6FAC465029C4690E75D2E52D ] C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll
16:54:36.0740 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll - ok
16:54:36.0740 4268  [ 2B81776DA02017A37FE26C662827470E ] C:\Windows\System32\IPHLPAPI.DLL
16:54:36.0740 4268  C:\Windows\System32\IPHLPAPI.DLL - ok
16:54:36.0740 4268  [ 4C9210E8F4E052F6A4EB87716DA0C24C ] C:\Windows\System32\winnsi.dll
16:54:36.0740 4268  C:\Windows\System32\winnsi.dll - ok
16:54:36.0740 4268  [ 31559F3244C6BC00A52030CAA83B6B91 ] C:\Windows\System32\WSHTCPIP.DLL
16:54:36.0740 4268  C:\Windows\System32\WSHTCPIP.DLL - ok
16:54:36.0740 4268  [ 483DF0B58CA532E5240E59DC41F30AA2 ] C:\Windows\System32\drivers\RtsUStor.sys
16:54:36.0740 4268  C:\Windows\System32\drivers\RtsUStor.sys - ok
16:54:36.0740 4268  [ 16E964ABF6D1E0F0CC7822FCA9BA754D ] C:\Windows\System32\wshqos.dll
16:54:36.0740 4268  C:\Windows\System32\wshqos.dll - ok
16:54:36.0740 4268  [ 3EF480BFED1B5947A32585E30A58D4ED ] C:\Windows\System32\authui.dll
16:54:36.0740 4268  C:\Windows\System32\authui.dll - ok
16:54:36.0755 4268  [ 9AD9E06F8656F296D91FAE8EE5B95A27 ] C:\Windows\System32\FirewallAPI.dll
16:54:36.0755 4268  C:\Windows\System32\FirewallAPI.dll - ok
16:54:36.0755 4268  [ 715F03B4C7223349768013EA95D9E5B7 ] C:\Windows\System32\LogonUI.exe
16:54:36.0755 4268  C:\Windows\System32\LogonUI.exe - ok
16:54:36.0755 4268  [ 6011714C8C5C55CBFFAD24D61E879FBD ] C:\Windows\System32\wevtsvc.dll
16:54:36.0755 4268  C:\Windows\System32\wevtsvc.dll - ok
16:54:36.0755 4268  [ F23FEF6D569FCE88671949894A8BECF1 ] C:\Windows\System32\audiosrv.dll
16:54:36.0755 4268  C:\Windows\System32\audiosrv.dll - ok
16:54:36.0755 4268  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] C:\Windows\System32\netprofm.dll
16:54:36.0755 4268  C:\Windows\System32\netprofm.dll - ok
16:54:36.0755 4268  [ 78A1E65207484B7F8D3217507745F47C ] C:\Windows\System32\avrt.dll
16:54:36.0755 4268  C:\Windows\System32\avrt.dll - ok
16:54:36.0771 4268  [ C4C183E6551084039EC862DA1C945E3D ] C:\Windows\System32\FntCache.dll
16:54:36.0771 4268  C:\Windows\System32\FntCache.dll - ok
16:54:36.0771 4268  [ E40E80D0304A73E8D269F7141D77250B ] C:\Windows\System32\mmcss.dll
16:54:36.0771 4268  C:\Windows\System32\mmcss.dll - ok
16:54:36.0771 4268  [ 227E2C382A1E02F8D4965E664D3BBE43 ] C:\Windows\System32\MMDevAPI.dll
16:54:36.0771 4268  C:\Windows\System32\MMDevAPI.dll - ok
16:54:36.0771 4268  [ F06BB4E336EA57511FDBAFAFCC47DE62 ] C:\Windows\System32\propsys.dll
16:54:36.0771 4268  C:\Windows\System32\propsys.dll - ok
16:54:36.0771 4268  [ 162D247E995EAEBF3EF4289069E1111C ] C:\Windows\SysWOW64\devrtl.dll
16:54:36.0771 4268  C:\Windows\SysWOW64\devrtl.dll - ok
16:54:36.0771 4268  [ 4BDBBE5E4208022DD794F7EEEB0F7366 ] C:\Windows\SysWOW64\SPInf.dll
16:54:36.0771 4268  C:\Windows\SysWOW64\SPInf.dll - ok
16:54:36.0787 4268  [ 49EE2E52E6CD03947DAD72F65367BE06 ] C:\Windows\System32\drivers\hidparse.sys
16:54:36.0787 4268  C:\Windows\System32\drivers\hidparse.sys - ok
16:54:36.0787 4268  [ 8B0E40E7E8BBF5ACF390465609D89FF1 ] C:\Windows\System32\drivers\hidclass.sys
16:54:36.0787 4268  C:\Windows\System32\drivers\hidclass.sys - ok
16:54:36.0787 4268  [ 9592090A7E2B61CD582B612B6DF70536 ] C:\Windows\System32\drivers\hidusb.sys
16:54:36.0787 4268  C:\Windows\System32\drivers\hidusb.sys - ok
16:54:36.0787 4268  [ 588CD0C78A7FAAE4186B5EEA0AF3ED67 ] C:\Windows\System32\adtschema.dll
16:54:36.0787 4268  C:\Windows\System32\adtschema.dll - ok
16:54:36.0787 4268  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] C:\Windows\System32\drivers\kbdhid.sys
16:54:36.0787 4268  C:\Windows\System32\drivers\kbdhid.sys - ok
16:54:36.0787 4268  [ 50544D04AD845C43130B70212EC05CCD ] C:\Windows\System32\microsoft-windows-kernel-power-events.dll
16:54:36.0787 4268  C:\Windows\System32\microsoft-windows-kernel-power-events.dll - ok
16:54:36.0787 4268  [ D5CCA1453B98A5801E6D5FF0FF89DC6C ] C:\Windows\System32\audiodg.exe
16:54:36.0787 4268  C:\Windows\System32\audiodg.exe - ok
16:54:36.0802 4268  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] C:\Windows\System32\drivers\mouhid.sys
16:54:36.0802 4268  C:\Windows\System32\drivers\mouhid.sys - ok
16:54:36.0802 4268  [ 1F4492FE41767CDB8B89D17655847CDD ] C:\Windows\System32\ntmarta.dll
16:54:36.0802 4268  C:\Windows\System32\ntmarta.dll - ok
16:54:36.0802 4268  [ 53E83F1F6CF9D62F32801CF66D8352A8 ] C:\Windows\System32\profsvc.dll
16:54:36.0802 4268  C:\Windows\System32\profsvc.dll - ok
16:54:36.0802 4268  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] C:\Windows\System32\gpsvc.dll
16:54:36.0802 4268  C:\Windows\System32\gpsvc.dll - ok
16:54:36.0802 4268  [ 58775492FFD419248B08325E583C527F ] C:\Windows\System32\atl.dll
16:54:36.0802 4268  C:\Windows\System32\atl.dll - ok
16:54:36.0802 4268  [ F0344071948D1A1FA732231785A0664C ] C:\Windows\System32\themeservice.dll
16:54:36.0802 4268  C:\Windows\System32\themeservice.dll - ok
16:54:36.0818 4268  [ 4166F82BE4D24938977DD1746BE9B8A0 ] C:\Windows\System32\es.dll
16:54:36.0818 4268  C:\Windows\System32\es.dll - ok
16:54:36.0818 4268  [ B3BFBD758506ECB50C5804AAA76318F9 ] C:\Windows\System32\cryptui.dll
16:54:36.0818 4268  C:\Windows\System32\cryptui.dll - ok
16:54:36.0818 4268  [ 7FA8FDC2C2A27817FD0F624E78D3B50C ] C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll
16:54:36.0818 4268  C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll - ok
16:54:36.0818 4268  [ 5B3EBFC3DA142324B388DDCC4465E1FF ] C:\Windows\System32\samlib.dll
16:54:36.0818 4268  C:\Windows\System32\samlib.dll - ok
16:54:36.0818 4268  [ 4E9C2DB10F7E6AE91BF761139D4B745B ] C:\Windows\System32\shacct.dll
16:54:36.0818 4268  C:\Windows\System32\shacct.dll - ok
16:54:36.0818 4268  [ D29E998E8277666982B4F0303BF4E7AF ] C:\Windows\System32\uxtheme.dll
16:54:36.0818 4268  C:\Windows\System32\uxtheme.dll - ok
16:54:36.0833 4268  [ 179E8401224D557ECFF3695F2016EA5B ] C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_2b253c8271ec7765\GdiPlus.dll
16:54:36.0833 4268  C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_2b253c8271ec7765\GdiPlus.dll - ok
16:54:36.0833 4268  [ 3CB6A7286422C72C34DAB54A5DFF1A34 ] C:\Windows\System32\dui70.dll
16:54:36.0833 4268  C:\Windows\System32\dui70.dll - ok
16:54:36.0833 4268  [ 8CCDE014A4CDF84564E03ACE064CA753 ] C:\Windows\System32\duser.dll
16:54:36.0833 4268  C:\Windows\System32\duser.dll - ok
16:54:36.0833 4268  [ D7F1EF374A90709B31591823B002F918 ] C:\Windows\System32\SndVolSSO.dll
16:54:36.0833 4268  C:\Windows\System32\SndVolSSO.dll - ok
16:54:36.0833 4268  [ DA1B7075260F3872585BFCDD668C648B ] C:\Windows\System32\dwmapi.dll
16:54:36.0833 4268  C:\Windows\System32\dwmapi.dll - ok
16:54:36.0833 4268  [ 896F15A6434D93EDB42519D5E18E6B50 ] C:\Windows\System32\hid.dll
16:54:36.0833 4268  C:\Windows\System32\hid.dll - ok
16:54:36.0849 4268  [ 6F8B48F3D343E4B186AB6A9E302B7E16 ] C:\Windows\System32\xmllite.dll
16:54:36.0849 4268  C:\Windows\System32\xmllite.dll - ok
16:54:36.0849 4268  [ C32AB8FA018EF34C0F113BD501436D21 ] C:\Windows\System32\Sens.dll
16:54:36.0849 4268  C:\Windows\System32\Sens.dll - ok
16:54:36.0849 4268  [ 1A47D52E303B7543E4E6026595B95422 ] C:\Windows\System32\comres.dll
16:54:36.0849 4268  C:\Windows\System32\comres.dll - ok
16:54:36.0849 4268  [ A77BE7CB3222B4FB0AC6C71D1C2698D4 ] C:\Windows\System32\dsrole.dll
16:54:36.0849 4268  C:\Windows\System32\dsrole.dll - ok
16:54:36.0849 4268  [ 46BB91A169B9B31FF44EB04C48EC1D41 ] C:\Windows\System32\nlaapi.dll
16:54:36.0849 4268  C:\Windows\System32\nlaapi.dll - ok
16:54:36.0849 4268  [ BE097F5BB10F9079FCEB2DC4E7E20F02 ] C:\Windows\System32\slc.dll
16:54:36.0849 4268  C:\Windows\System32\slc.dll - ok
16:54:36.0849 4268  [ EF2AE43BCD46ABB13FC3E5B2B1935C73 ] C:\Windows\System32\winmm.dll
16:54:36.0849 4268  C:\Windows\System32\winmm.dll - ok
16:54:36.0865 4268  [ 8560FFFC8EB3A806DCD4F82252CFC8C6 ] C:\Windows\System32\ksuser.dll
16:54:36.0865 4268  C:\Windows\System32\ksuser.dll - ok
16:54:36.0865 4268  [ 1473768973453DE50DC738C2955FC4DD ] C:\Windows\System32\wdmaud.drv
16:54:36.0865 4268  C:\Windows\System32\wdmaud.drv - ok
16:54:36.0865 4268  [ DA6B67270FD9DB3697B20FCE94950741 ] C:\Windows\System32\drivers\fltMgr.sys
16:54:36.0865 4268  C:\Windows\System32\drivers\fltMgr.sys - ok
16:54:36.0865 4268  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] C:\Windows\System32\MPSSVC.dll
16:54:36.0865 4268  C:\Windows\System32\MPSSVC.dll - ok
16:54:36.0865 4268  [ 908ACB1F594274965A53926B10C81E89 ] C:\Windows\System32\provsvc.dll
16:54:36.0865 4268  C:\Windows\System32\provsvc.dll - ok
16:54:36.0865 4268  [ 3D7BB6DD7A87B3E36E44CA94444247A8 ] C:\Windows\System32\WindowsCodecs.dll
16:54:36.0865 4268  C:\Windows\System32\WindowsCodecs.dll - ok
16:54:36.0880 4268  [ DC220AE6F64819099F7EBD6F137E32E7 ] C:\Windows\System32\AudioSes.dll
16:54:36.0880 4268  C:\Windows\System32\AudioSes.dll - ok
16:54:36.0880 4268  [ 10AC5CE9F78DC281A1BBD9B8CC587B8A ] C:\Windows\System32\msacm32.dll
16:54:36.0880 4268  C:\Windows\System32\msacm32.dll - ok
16:54:36.0880 4268  [ 1B7C3A37362C7B2890168C5FC61C8D9B ] C:\Windows\System32\msacm32.drv
16:54:36.0880 4268  C:\Windows\System32\msacm32.drv - ok
16:54:36.0880 4268  [ A3DB3C17EE6CAE65D53602B4E80BCCBC ] C:\Windows\System32\PSHED.DLL
16:54:36.0880 4268  C:\Windows\System32\PSHED.DLL - ok
16:54:36.0880 4268  [ CA2A0750ED830678997695FF61B04C30 ] C:\Windows\System32\midimap.dll
16:54:36.0880 4268  C:\Windows\System32\midimap.dll - ok
16:54:36.0880 4268  [ 5EDBB34736DD7AC1A73CF8792A835E10 ] C:\Windows\System32\AudioEng.dll
16:54:36.0880 4268  C:\Windows\System32\AudioEng.dll - ok
16:54:36.0896 4268  [ B0945E538CF906BBDDC5A11C8EE868CC ] C:\Windows\System32\microsoft-windows-kernel-processor-power-events.dll
16:54:36.0896 4268  C:\Windows\System32\microsoft-windows-kernel-processor-power-events.dll - ok
16:54:36.0896 4268  [ C1395286B822E306B4FE1568A8A77813 ] C:\Windows\System32\AUDIOKSE.dll
16:54:36.0896 4268  C:\Windows\System32\AUDIOKSE.dll - ok
16:54:36.0896 4268  [ 9F2BACD5E1776A4BB7CC0EC3C3A4F96D ] C:\Windows\System32\winbrand.dll
16:54:36.0896 4268  C:\Windows\System32\winbrand.dll - ok
16:54:36.0896 4268  [ C2762A57DF0EE85E63CE4893C5215313 ] C:\Windows\System32\VaultCredProvider.dll
16:54:36.0896 4268  C:\Windows\System32\VaultCredProvider.dll - ok
16:54:36.0896 4268  [ 6F3C559B82F2912354BE5B098744CC8C ] C:\Windows\System32\WMALFXGFXDSP.dll
16:54:36.0896 4268  C:\Windows\System32\WMALFXGFXDSP.dll - ok
16:54:36.0896 4268  [ CA2985996BB49924B677113DF95CFEA7 ] C:\Windows\System32\SmartcardCredentialProvider.dll
16:54:36.0896 4268  C:\Windows\System32\SmartcardCredentialProvider.dll - ok
16:54:36.0896 4268  [ BF352E73615F5461AA6884472435A544 ] C:\Windows\System32\BioCredProv.dll
16:54:36.0896 4268  C:\Windows\System32\BioCredProv.dll - ok
16:54:36.0911 4268  [ 796B8123A7859AFD3A4AE10514DBAEB5 ] C:\Windows\System32\winbio.dll
16:54:36.0911 4268  C:\Windows\System32\winbio.dll - ok
16:54:36.0911 4268  [ CC0AB40F02D2C2A12209715A3C1B07B8 ] C:\Windows\System32\credui.dll
16:54:36.0911 4268  C:\Windows\System32\credui.dll - ok
16:54:36.0911 4268  [ 54B5DCD55B223BC5DF50B82E1E9E86B1 ] C:\Windows\System32\mfplat.dll
16:54:36.0911 4268  C:\Windows\System32\mfplat.dll - ok
16:54:36.0911 4268  [ EEEA40F0EDB0A6E5359E539E15D0BC77 ] C:\Windows\System32\netapi32.dll
16:54:36.0911 4268  C:\Windows\System32\netapi32.dll - ok
16:54:36.0911 4268  [ 44B9C66177651F3F53C87B665D58D17A ] C:\Windows\System32\vaultcli.dll
16:54:36.0911 4268  C:\Windows\System32\vaultcli.dll - ok
16:54:36.0911 4268  [ 6CECA4C6A489C9B2E6073AFDAAE3F607 ] C:\Windows\System32\netutils.dll
16:54:36.0911 4268  C:\Windows\System32\netutils.dll - ok
16:54:36.0927 4268  [ 3C91392D448F6E5D525A85B7550D8BA9 ] C:\Windows\System32\wkscli.dll
16:54:36.0927 4268  C:\Windows\System32\wkscli.dll - ok
16:54:36.0927 4268  [ FC51229C7D4AFA0D6F186133728B95AB ] C:\Windows\System32\samcli.dll
16:54:36.0927 4268  C:\Windows\System32\samcli.dll - ok
16:54:36.0927 4268  [ 972C3301DB3DA91AE06A95F6B4160B1B ] C:\Windows\System32\certCredProvider.dll
16:54:36.0927 4268  C:\Windows\System32\certCredProvider.dll - ok
16:54:36.0927 4268  [ 654A24D71B9E6201A6A29602D3E23490 ] C:\Program Files\Sandboxie\SbieSvc.exe
16:54:36.0927 4268  C:\Program Files\Sandboxie\SbieSvc.exe - ok
16:54:36.0927 4268  [ C80755F3ACE49D82E7DC9CF863C030F0 ] C:\Program Files\Sandboxie\SbieDll.dll
16:54:36.0927 4268  C:\Program Files\Sandboxie\SbieDll.dll - ok
16:54:36.0927 4268  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] C:\Windows\System32\uxsms.dll
16:54:36.0927 4268  C:\Windows\System32\uxsms.dll - ok
16:54:36.0943 4268  [ 78AFA2B244DDF896BF1287B543842452 ] C:\Program Files\Sandboxie\SbieDrv.sys
16:54:36.0943 4268  C:\Program Files\Sandboxie\SbieDrv.sys - ok
16:54:36.0943 4268  [ 1538831CF8AD2979A04C423779465827 ] C:\Windows\System32\drivers\lltdio.sys
16:54:36.0943 4268  C:\Windows\System32\drivers\lltdio.sys - ok
16:54:36.0943 4268  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] C:\Windows\System32\drivers\nwifi.sys
16:54:36.0943 4268  C:\Windows\System32\drivers\nwifi.sys - ok
16:54:36.0943 4268  [ 136185F9FB2CC61E573E676AA5402356 ] C:\Windows\System32\drivers\ndisuio.sys
16:54:36.0943 4268  C:\Windows\System32\drivers\ndisuio.sys - ok
16:54:36.0943 4268  [ DDC86E4F8E7456261E637E3552E804FF ] C:\Windows\System32\drivers\rspndr.sys
16:54:36.0943 4268  C:\Windows\System32\drivers\rspndr.sys - ok
16:54:36.0943 4268  [ F993A32249B66C9D622EA5592A8B76B8 ] C:\Windows\System32\lmhsvc.dll
16:54:36.0943 4268  C:\Windows\System32\lmhsvc.dll - ok
16:54:36.0958 4268  [ B73A6E4B319AFFE64582AC5C1801BB3F ] C:\Windows\System32\nrpsrv.dll
16:54:36.0958 4268  C:\Windows\System32\nrpsrv.dll - ok
16:54:36.0958 4268  [ D54BFDF3E0C953F823B3D0BFE4732528 ] C:\Windows\System32\nsisvc.dll
16:54:36.0958 4268  C:\Windows\System32\nsisvc.dll - ok
16:54:36.0958 4268  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] C:\Windows\System32\dhcpcore.dll
16:54:36.0958 4268  C:\Windows\System32\dhcpcore.dll - ok
16:54:36.0958 4268  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] C:\Windows\System32\dnsrslvr.dll
16:54:36.0958 4268  C:\Windows\System32\dnsrslvr.dll - ok
16:54:36.0958 4268  [ F9EC845C5EECF20E9A67F9F805F2EF1F ] C:\Windows\System32\keyiso.dll
16:54:36.0958 4268  C:\Windows\System32\keyiso.dll - ok
16:54:36.0958 4268  [ 87356377F31DA5F20A833811CD59499C ] C:\Windows\System32\eapphost.dll
16:54:36.0958 4268  C:\Windows\System32\eapphost.dll - ok
16:54:36.0958 4268  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] C:\Windows\System32\eapsvc.dll
16:54:36.0958 4268  C:\Windows\System32\eapsvc.dll - ok
16:54:36.0974 4268  [ 3CC16A849E6092E43909F48EF0E60306 ] C:\Windows\System32\dhcpcore6.dll
16:54:36.0974 4268  C:\Windows\System32\dhcpcore6.dll - ok
16:54:36.0974 4268  [ 0040C486584A8E582C861CFB57AB5387 ] C:\Windows\System32\FWPUCLNT.DLL
16:54:36.0974 4268  C:\Windows\System32\FWPUCLNT.DLL - ok
16:54:36.0974 4268  [ 885D0942E0F28DB90919BE3129ECF279 ] C:\Windows\System32\dnsext.dll
16:54:36.0974 4268  C:\Windows\System32\dnsext.dll - ok
16:54:36.0974 4268  [ 9FCA3A84338ADEF2AFF67CDA46EF8539 ] C:\Windows\System32\umb.dll
16:54:36.0974 4268  C:\Windows\System32\umb.dll - ok
16:54:36.0974 4268  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] C:\Windows\System32\wlansvc.dll
16:54:36.0974 4268  C:\Windows\System32\wlansvc.dll - ok
16:54:36.0974 4268  [ F568F7C08458D69E4FCD8675BBB107E4 ] C:\Windows\System32\dhcpcsvc.dll
16:54:36.0974 4268  C:\Windows\System32\dhcpcsvc.dll - ok
16:54:36.0989 4268  [ 3C06D5A929B798D0B13F6481242A0FD2 ] C:\Windows\System32\dhcpcsvc6.dll
16:54:36.0989 4268  C:\Windows\System32\dhcpcsvc6.dll - ok
16:54:36.0989 4268  [ A648C4A06DE367065B24056D067B4460 ] C:\Windows\System32\wlanmsm.dll
16:54:36.0989 4268  C:\Windows\System32\wlanmsm.dll - ok
16:54:36.0989 4268  [ 06A1386B6E3A0CBC368665C1840906F4 ] C:\Windows\System32\wlansec.dll
16:54:36.0989 4268  C:\Windows\System32\wlansec.dll - ok
16:54:36.0989 4268  [ 73FCB7919DEE80EE556F2E498594EBAE ] C:\Windows\System32\onex.dll
16:54:36.0989 4268  C:\Windows\System32\onex.dll - ok
16:54:36.0989 4268  [ 0D753307D274F3688BD21C377B616700 ] C:\Windows\System32\eappcfg.dll
16:54:36.0989 4268  C:\Windows\System32\eappcfg.dll - ok
16:54:36.0989 4268  [ 65522E77A1360DBC8D199DA3BF5EFFE4 ] C:\Windows\System32\eappprxy.dll
16:54:36.0989 4268  C:\Windows\System32\eappprxy.dll - ok
16:54:36.0989 4268  [ 97E43F324BE1503CB2FFB058534688DA ] C:\Windows\System32\l2gpstore.dll
16:54:36.0989 4268  C:\Windows\System32\l2gpstore.dll - ok
16:54:37.0005 4268  [ 7D5645EE0EA77D539828433D9B95F5EB ] C:\Windows\System32\WinSCard.dll
16:54:37.0005 4268  C:\Windows\System32\WinSCard.dll - ok
16:54:37.0005 4268  [ 7F1B4C6FF3B85F9ADF74055187B8A22C ] C:\Windows\System32\wlanutil.dll
16:54:37.0005 4268  C:\Windows\System32\wlanutil.dll - ok
16:54:37.0005 4268  [ 730BF204A595D5B6D7DC57A247CC741C ] C:\Windows\System32\wlgpclnt.dll
16:54:37.0005 4268  C:\Windows\System32\wlgpclnt.dll - ok
16:54:37.0005 4268  [ 99B91C5D2FCEF218CAD3600ECB62A799 ] C:\Windows\System32\msxml6.dll
16:54:37.0005 4268  C:\Windows\System32\msxml6.dll - ok
16:54:37.0005 4268  [ 262F6592C3299C005FD6BEC90FC4463A ] C:\Windows\System32\schedsvc.dll
16:54:37.0005 4268  C:\Windows\System32\schedsvc.dll - ok
16:54:37.0005 4268  [ AAF932B4011D14052955D4B212A4DA8D ] C:\Windows\System32\shsvcs.dll
16:54:37.0005 4268  C:\Windows\System32\shsvcs.dll - ok
16:54:37.0021 4268  [ BC414631876B2F28B8DAB08E849C12C5 ] C:\Windows\System32\ktmw32.dll
16:54:37.0021 4268  C:\Windows\System32\ktmw32.dll - ok
16:54:37.0021 4268  [ 33FD2D719594DC9F49B80CE125D4B433 ] C:\Windows\System32\pstorec.dll
16:54:37.0021 4268  C:\Windows\System32\pstorec.dll - ok
16:54:37.0021 4268  [ 032229246107C5C7211E6D1498B52D3D ] C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL
16:54:37.0021 4268  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL - ok
16:54:37.0021 4268  [ 87FA0C48C3B2E9FEE518818FE26B15B5 ] C:\Windows\System32\rasplap.dll
16:54:37.0021 4268  C:\Windows\System32\rasplap.dll - ok
16:54:37.0021 4268  [ 019CD868461B646E09BDF04474C19341 ] C:\Windows\System32\rasapi32.dll
16:54:37.0021 4268  C:\Windows\System32\rasapi32.dll - ok
16:54:37.0021 4268  [ B28DEEC597C8DEB70C744C7CF9210E3E ] C:\Windows\System32\rasman.dll
16:54:37.0021 4268  C:\Windows\System32\rasman.dll - ok
16:54:37.0036 4268  [ B53C4B69B695EDA1B7E41D35CA4244E2 ] C:\Windows\System32\rtutils.dll
16:54:37.0036 4268  C:\Windows\System32\rtutils.dll - ok
16:54:37.0036 4268  [ 945E54F23C72D37B8CD1987AF0DB63BF ] C:\Windows\System32\fveapi.dll
16:54:37.0036 4268  C:\Windows\System32\fveapi.dll - ok
16:54:37.0036 4268  [ 9BC8610C32C96A2983A65DC21CAFA921 ] C:\Windows\System32\UXInit.dll
16:54:37.0036 4268  C:\Windows\System32\UXInit.dll - ok
16:54:37.0036 4268  [ CF636C92B762B26F0B39B38E92380A09 ] C:\Windows\System32\oleacc.dll
16:54:37.0036 4268  C:\Windows\System32\oleacc.dll - ok
16:54:37.0036 4268  [ 019BDD35DE269CB98B22DE8923C2AA3B ] C:\Windows\System32\UIAutomationCore.dll
16:54:37.0036 4268  C:\Windows\System32\UIAutomationCore.dll - ok
16:54:37.0036 4268  [ E424B3EF666B184CEE0B6871AAA8C9F6 ] C:\Windows\System32\msimg32.dll
16:54:37.0036 4268  C:\Windows\System32\msimg32.dll - ok
16:54:37.0052 4268  [ 891ECFD08E2C538B7948CBC45106D697 ] C:\Windows\System32\fvecerts.dll
16:54:37.0052 4268  C:\Windows\System32\fvecerts.dll - ok
16:54:37.0052 4268  [ 6DC4A7242F565C9E9C9CCC7BB0FA75C7 ] C:\Windows\System32\taskcomp.dll
16:54:37.0052 4268  C:\Windows\System32\taskcomp.dll - ok
16:54:37.0052 4268  [ 694865362F0965779F92BCFE97712323 ] C:\Windows\System32\tbs.dll
16:54:37.0052 4268  C:\Windows\System32\tbs.dll - ok
16:54:37.0052 4268  [ 8269210DAF3B12BC8300631B28A2A442 ] C:\Windows\System32\wiarpc.dll
16:54:37.0052 4268  C:\Windows\System32\wiarpc.dll - ok
16:54:37.0052 4268  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] C:\Windows\System32\drivers\http.sys
16:54:37.0052 4268  C:\Windows\System32\drivers\http.sys - ok
16:54:37.0052 4268  [ FEDB2BF1346168EBC6FE517386540182 ] C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll
16:54:37.0052 4268  C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll - ok
16:54:37.0052 4268  [ 39EF7D1A9A3954D66B907C5CB5E20E64 ] C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
16:54:37.0052 4268  C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe - ok
16:54:37.0067 4268  [ E9ADE601D6F90079E6D87EE0B88C890B ] C:\Windows\System32\nvsvc64.dll
16:54:37.0067 4268  C:\Windows\System32\nvsvc64.dll - ok
16:54:37.0067 4268  [ 5AA945234E9D4CCE4F715276B9AA712C ] C:\Windows\System32\imageres.dll
16:54:37.0067 4268  C:\Windows\System32\imageres.dll - ok
16:54:37.0067 4268  [ 3220C3D0A1BFE56B55ACE801B6CD2C17 ] C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
16:54:37.0067 4268  C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll - ok
16:54:37.0067 4268  [ 85DAA09A98C9286D4EA2BA8D0E644377 ] C:\Windows\System32\spoolsv.exe
16:54:37.0067 4268  C:\Windows\System32\spoolsv.exe - ok
16:54:37.0067 4268  [ BD33282EC067551060DC3A9628160E5B ] C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
16:54:37.0067 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe - ok
16:54:37.0067 4268  [ E3C817F7FE44CC870ECDBCBC3EA36132 ] C:\Windows\SysWOW64\msvcp100.dll
16:54:37.0067 4268  C:\Windows\SysWOW64\msvcp100.dll - ok
16:54:37.0083 4268  [ BF38660A9125935658CFA3E53FDC7D65 ] C:\Windows\SysWOW64\msvcr100.dll
16:54:37.0083 4268  C:\Windows\SysWOW64\msvcr100.dll - ok
16:54:37.0083 4268  [ D9D3549F1F6CD0AFBC2A01F607F92278 ] C:\Program Files (x86)\Avira\AntiVir Desktop\grdcore.dll
16:54:37.0083 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\grdcore.dll - ok
16:54:37.0083 4268  [ 565D78187494FB5F08B5A52DEB2AEA7A ] C:\Windows\SysWOW64\shell32.dll
16:54:37.0083 4268  C:\Windows\SysWOW64\shell32.dll - ok
16:54:37.0083 4268  [ 1834B31C749B86DAC233BBBA1C03BC48 ] C:\Windows\System32\mscms.dll
16:54:37.0083 4268  C:\Windows\System32\mscms.dll - ok
16:54:37.0083 4268  [ A4A923207A306DC77FA9155BF59DE849 ] C:\Windows\System32\nvapi64.dll
16:54:37.0083 4268  C:\Windows\System32\nvapi64.dll - ok
16:54:37.0083 4268  [ 77CE18C15582C129CF5594E2CD8A3DAC ] C:\Windows\System32\nvsvcr.dll
16:54:37.0083 4268  C:\Windows\System32\nvsvcr.dll - ok
16:54:37.0099 4268  [ 0B4BFE53C6CE1DC7D83DD92BC2F7C080 ] C:\Program Files\NVIDIA Corporation\Display\nvui.dll
16:54:37.0099 4268  C:\Program Files\NVIDIA Corporation\Display\nvui.dll - ok
16:54:37.0099 4268  [ 14DFDEAF4E589ED3F1FF187A86B9408C ] C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll
16:54:37.0099 4268  C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll - ok
16:54:37.0099 4268  [ 0015ACFBBDD164A8A730009908868CA7 ] C:\Windows\System32\winspool.drv
16:54:37.0099 4268  C:\Windows\System32\winspool.drv - ok
16:54:37.0099 4268  [ 3571AE135A605787EA4B63DDB96E9359 ] C:\Program Files\NVIDIA Corporation\Display\nvuir.dll
16:54:37.0099 4268  C:\Program Files\NVIDIA Corporation\Display\nvuir.dll - ok
16:54:37.0099 4268  [ 401B576AD78849284CE918CA79DC3AF7 ] C:\Program Files\NVIDIA Corporation\Display\nvxdplcy.dll
16:54:37.0099 4268  C:\Program Files\NVIDIA Corporation\Display\nvxdplcy.dll - ok
16:54:37.0099 4268  [ 56C729C0B6E9C1B73176E057E12CD720 ] C:\Windows\System32\nvcpl.dll
16:54:37.0099 4268  C:\Windows\System32\nvcpl.dll - ok
16:54:37.0114 4268  [ 8CC3C111D653E96F3EA1590891491D71 ] C:\Windows\SysWOW64\shlwapi.dll
16:54:37.0114 4268  C:\Windows\SysWOW64\shlwapi.dll - ok
16:54:37.0114 4268  [ 665A83FA9E6F545EBCEE41FFEB453FF8 ] C:\Program Files (x86)\Avira\AntiVir Desktop\cfglib.dll
16:54:37.0114 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\cfglib.dll - ok
16:54:37.0114 4268  [ D571899CA27B9710052CDE9BC8180209 ] C:\Program Files (x86)\Avira\AntiVir Desktop\scewxmlw.dll
16:54:37.0114 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\scewxmlw.dll - ok
16:54:37.0114 4268  [ 82974D6A2FD19445CC5171FC378668A4 ] C:\Windows\System32\BFE.DLL
16:54:37.0114 4268  C:\Windows\System32\BFE.DLL - ok
16:54:37.0114 4268  [ 6FA73FF1E5A365E6FBC78177079AEDA7 ] C:\Program Files (x86)\Avira\AntiVir Desktop\gpipc.dll
16:54:37.0114 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gpipc.dll - ok
16:54:37.0114 4268  [ B9A8CBCFCD3EC9D2EA4740AF347BF108 ] C:\Windows\SysWOW64\mpr.dll
16:54:37.0114 4268  C:\Windows\SysWOW64\mpr.dll - ok
16:54:37.0130 4268  [ 9EF0B17580DFB0EB4234C2BF5B40FD15 ] C:\Program Files (x86)\Avira\AntiVir Desktop\gpgen.dll
16:54:37.0130 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gpgen.dll - ok
16:54:37.0130 4268  [ 4DDB3A92E833EAD0002BEBDF9ABBDA97 ] C:\Program Files (x86)\Avira\AntiVir Desktop\gpschd.dll
16:54:37.0130 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gpschd.dll - ok
16:54:37.0130 4268  [ 6C02A83164F5CC0A262F4199F0871CF5 ] C:\Windows\System32\drivers\bowser.sys
16:54:37.0130 4268  C:\Windows\System32\drivers\bowser.sys - ok
16:54:37.0130 4268  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] C:\Windows\System32\drivers\mpsdrv.sys
16:54:37.0130 4268  C:\Windows\System32\drivers\mpsdrv.sys - ok
16:54:37.0130 4268  [ A90DC9ABD65DB1A8902F361103029952 ] C:\Windows\SysWOW64\IPHLPAPI.DLL
16:54:37.0130 4268  C:\Windows\SysWOW64\IPHLPAPI.DLL - ok
16:54:37.0130 4268  [ 6377051C63D5552A311935C67E9FDFDC ] C:\Windows\SysWOW64\nsi.dll
16:54:37.0130 4268  C:\Windows\SysWOW64\nsi.dll - ok
16:54:37.0145 4268  [ CFF35B879D1618D42C86644C717BA947 ] C:\Windows\SysWOW64\winnsi.dll
16:54:37.0145 4268  C:\Windows\SysWOW64\winnsi.dll - ok
16:54:37.0145 4268  [ 6A6B2EE4565A178035BE2A4FF6F2C968 ] C:\Windows\SysWOW64\wtsapi32.dll
16:54:37.0145 4268  C:\Windows\SysWOW64\wtsapi32.dll - ok
16:54:37.0145 4268  [ C67F8A962B2534224D5908D16D2AD3CE ] C:\Windows\System32\wfapigp.dll
16:54:37.0145 4268  C:\Windows\System32\wfapigp.dll - ok
16:54:37.0145 4268  [ 839F96DBAAFD3353E0B248A5E0BD2A51 ] C:\Windows\SysWOW64\rasapi32.dll
16:54:37.0145 4268  C:\Windows\SysWOW64\rasapi32.dll - ok
16:54:37.0145 4268  [ A5D9106A73DC88564C825D317CAC68AC ] C:\Windows\System32\drivers\mrxsmb.sys
16:54:37.0145 4268  C:\Windows\System32\drivers\mrxsmb.sys - ok
16:54:37.0145 4268  [ FFA7172354B9256DBB2CDD75F16F33FE ] C:\Windows\SysWOW64\rasman.dll
16:54:37.0145 4268  C:\Windows\SysWOW64\rasman.dll - ok
16:54:37.0145 4268  [ 7FF15A4F092CD4A96055BA69F903E3E9 ] C:\Windows\SysWOW64\ws2_32.dll
16:54:37.0145 4268  C:\Windows\SysWOW64\ws2_32.dll - ok
16:54:37.0161 4268  [ 3AEAA8B561E63452C655DC0584922257 ] C:\Windows\System32\pcasvc.dll
16:54:37.0161 4268  C:\Windows\System32\pcasvc.dll - ok
16:54:37.0161 4268  [ A061A458C7A640C0E2CDE32111006A76 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avevtlog.dll
16:54:37.0161 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avevtlog.dll - ok
16:54:37.0161 4268  [ C66DFA6B9829DF83E9C206F004705393 ] C:\Program Files (x86)\Avira\AntiVir Desktop\schedr.dll
16:54:37.0161 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\schedr.dll - ok
16:54:37.0161 4268  [ D711B3C1D5F42C0C2415687BE09FC163 ] C:\Windows\System32\drivers\mrxsmb10.sys
16:54:37.0161 4268  C:\Windows\System32\drivers\mrxsmb10.sys - ok
16:54:37.0161 4268  [ 7DC69D2B0A77BB365AE934AE2E06AB41 ] C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
16:54:37.0161 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll - ok
16:54:37.0161 4268  [ 6313F223E817CC09AA41811DAA7F541D ] C:\Windows\System32\snmptrap.exe
16:54:37.0161 4268  C:\Windows\System32\snmptrap.exe - ok
16:54:37.0177 4268  [ 10EAB90C1AE8271B5FE5A8930987EE5C ] C:\Program Files\Windows Live\Mesh\WLRemoteServiceResource.dll
16:54:37.0177 4268  C:\Program Files\Windows Live\Mesh\WLRemoteServiceResource.dll - ok
16:54:37.0177 4268  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] C:\Windows\System32\drivers\mrxsmb20.sys
16:54:37.0177 4268  C:\Windows\System32\drivers\mrxsmb20.sys - ok
16:54:37.0177 4268  [ 851A1382EED3E3A7476DB004F4EE3E1A ] C:\Windows\System32\wkssvc.dll
16:54:37.0177 4268  C:\Windows\System32\wkssvc.dll - ok
16:54:37.0177 4268  [ 82F8049992C25D77F65903983878FE31 ] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
16:54:37.0177 4268  C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe - ok
16:54:37.0177 4268  [ E9A0777DCA9148157E0EF9B71D7DE353 ] C:\Windows\System32\RdpGroupPolicyExtension.dll
16:54:37.0177 4268  C:\Windows\System32\RdpGroupPolicyExtension.dll - ok
16:54:37.0177 4268  [ 6CEF7856A3EFAC59470F6208F0F585CE ] C:\Windows\System32\mpr.dll
16:54:37.0177 4268  C:\Windows\System32\mpr.dll - ok
16:54:37.0192 4268  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] C:\Windows\System32\sstpsvc.dll
16:54:37.0192 4268  C:\Windows\System32\sstpsvc.dll - ok
16:54:37.0192 4268  [ ADDA5E1951B90D3D23C56D3CF0622ADC ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
16:54:37.0192 4268  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe - ok
16:54:37.0192 4268  [ CDBE9690CF2B8409FACAD94FAC9479C9 ] C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
16:54:37.0192 4268  C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll - ok
16:54:37.0192 4268  [ B6FC28E1B17B4FB6F3CFFA0AE8CEE250 ] C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
16:54:37.0192 4268  C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe - ok
16:54:37.0192 4268  [ D1DE1EAFDE97BE41CF6585027FF3E732 ] C:\Windows\SysWOW64\comdlg32.dll
16:54:37.0192 4268  C:\Windows\SysWOW64\comdlg32.dll - ok
16:54:37.0192 4268  [ BDAC1AA64495D0F7E1FF810EBBF1F018 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
16:54:37.0192 4268  C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll - ok
16:54:37.0208 4268  [ 1EBE9524683C7C4EED8B8BC93FB6FBCC ] C:\Windows\SysWOW64\fltLib.dll
16:54:37.0208 4268  C:\Windows\SysWOW64\fltLib.dll - ok
16:54:37.0208 4268  [ 0B3595A4FF0B36D68E5FC67FD7D70FDC ] C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll
16:54:37.0208 4268  C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll - ok
16:54:37.0208 4268  [ C9564CF4976E7E96B4052737AA2492B4 ] C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll
16:54:37.0208 4268  C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll - ok
16:54:37.0208 4268  [ C733D233B623B7FFCE5031E4B756EE26 ] C:\Windows\SysWOW64\profapi.dll
16:54:37.0208 4268  C:\Windows\SysWOW64\profapi.dll - ok
16:54:37.0208 4268  [ D15618A0FF8DBC2C5BF3726BACC75A0B ] C:\Windows\SysWOW64\userenv.dll
16:54:37.0208 4268  C:\Windows\SysWOW64\userenv.dll - ok
16:54:37.0208 4268  [ 07B0B7175C61F65483D60577AC864B41 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
16:54:37.0208 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe - ok
16:54:37.0223 4268  [ A200E1BAE91B2CD9CC6D0769080A4C74 ] C:\Program Files (x86)\Common Files\Acronis\SnapAPI\snapapi.dll
16:54:37.0223 4268  C:\Program Files (x86)\Common Files\Acronis\SnapAPI\snapapi.dll - ok
16:54:37.0223 4268  [ A543AC1F7138376D778D630A35FCBC4C ] C:\Windows\SysWOW64\psapi.dll
16:54:37.0223 4268  C:\Windows\SysWOW64\psapi.dll - ok
16:54:37.0223 4268  [ 2FCA0D2C59A855C54BAFA22AA329DF0F ] C:\Windows\SysWOW64\netapi32.dll
16:54:37.0223 4268  C:\Windows\SysWOW64\netapi32.dll - ok
16:54:37.0223 4268  [ 7321F18D1F820612ED0E9F2D4B578A7E ] C:\Windows\SysWOW64\cryptsp.dll
16:54:37.0223 4268  C:\Windows\SysWOW64\cryptsp.dll - ok
16:54:37.0223 4268  [ 20B3934DB73EABA2B49B7177873CB81F ] C:\Windows\SysWOW64\netutils.dll
16:54:37.0223 4268  C:\Windows\SysWOW64\netutils.dll - ok
16:54:37.0223 4268  [ 5CCDCD40E732D54E0F7451AC66AC1C87 ] C:\Windows\SysWOW64\srvcli.dll
16:54:37.0223 4268  C:\Windows\SysWOW64\srvcli.dll - ok
16:54:37.0239 4268  [ E5A4A1326A02F8E7B59E6C3270CE7202 ] C:\Windows\SysWOW64\wkscli.dll
16:54:37.0239 4268  C:\Windows\SysWOW64\wkscli.dll - ok
16:54:37.0239 4268  [ 68ECCA523ED760AAFC03C5D587569859 ] C:\Windows\SysWOW64\samcli.dll
16:54:37.0239 4268  C:\Windows\SysWOW64\samcli.dll - ok
16:54:37.0239 4268  [ ED8EC63F7522DF4852147C84EC62C36A ] C:\Windows\SysWOW64\rsaenh.dll
16:54:37.0239 4268  C:\Windows\SysWOW64\rsaenh.dll - ok
16:54:37.0239 4268  [ 26156239B34093F2BF63367CA7EDF5EA ] C:\Program Files (x86)\Avira\AntiVir Desktop\fwstr.dll
16:54:37.0239 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\fwstr.dll - ok
16:54:37.0239 4268  [ 2B73EF0F975642509AB66827C4E9D6C8 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
16:54:37.0239 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe - ok
16:54:37.0239 4268  [ 76F6EA750C7DFC2C184895A5EB8FE336 ] C:\Program Files (x86)\Avira\AntiVir Desktop\fwrc.dll
16:54:37.0239 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\fwrc.dll - ok
16:54:37.0255 4268  [ E53C6A78C00D69EA5FF2A64A25F4A965 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avwinll.dll
16:54:37.0255 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avwinll.dll - ok
16:54:37.0255 4268  [ 12206CF57A965BB32F6EEB1841D4180D ] C:\Program Files (x86)\Avira\AntiVir Desktop\aecore.dll
16:54:37.0255 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aecore.dll - ok
16:54:37.0255 4268  [ 4FE5C6D40664AE07BE5105874357D2ED ] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:54:37.0255 4268  C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - ok
16:54:37.0255 4268  [ 4ED033308D9F248FF02F3AF2B11D72D4 ] C:\Program Files (x86)\Avira\AntiVir Desktop\gpgrd.dll
16:54:37.0255 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gpgrd.dll - ok
16:54:37.0255 4268  [ 60C079CB2150760263D1FE5FF6218961 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\AppleVersions.dll
16:54:37.0255 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\AppleVersions.dll - ok
16:54:37.0255 4268  [ 6D41F6AA35220E7A54543075B27E8F83 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\YSCrashDump.dll
16:54:37.0255 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\YSCrashDump.dll - ok
16:54:37.0270 4268  [ 0FC15C1C52A384025C28DB3FEF9E7A91 ] C:\Program Files (x86)\Avira\AntiVir Desktop\gpavgio.dll
16:54:37.0270 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gpavgio.dll - ok
16:54:37.0270 4268  [ B30F23026AA2F12A690153FFB6983993 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aevdf.dll
16:54:37.0270 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aevdf.dll - ok
16:54:37.0270 4268  [ 8EA53101FF2B15BDFF934B62A8FB326D ] C:\Windows\SysWOW64\logoncli.dll
16:54:37.0270 4268  C:\Windows\SysWOW64\logoncli.dll - ok
16:54:37.0270 4268  [ EF8CD3C64EE9C08980D6D06CCCE46C68 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreFoundation.dll
16:54:37.0270 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreFoundation.dll - ok
16:54:37.0270 4268  [ B4C5EB5327B91C726C373151AD772144 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aescript.dll
16:54:37.0270 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aescript.dll - ok
16:54:37.0270 4268  [ DF1C1CD0C7EE95CC00D71E9E415E7BCD ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\pthreadVC2.dll
16:54:37.0270 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\pthreadVC2.dll - ok
16:54:37.0286 4268  [ 72910F1DEB838E6E08A9017BFB7D4F0B ] C:\Windows\SysWOW64\browcli.dll
16:54:37.0286 4268  C:\Windows\SysWOW64\browcli.dll - ok
16:54:37.0286 4268  [ 521B748A7F9923302CA18B7E6AA2EEAE ] C:\Windows\SysWOW64\activeds.dll
16:54:37.0286 4268  C:\Windows\SysWOW64\activeds.dll - ok
16:54:37.0286 4268  [ DF13A51A5C591887D2EC6AE64CEED0FA ] C:\Windows\SysWOW64\wsock32.dll
16:54:37.0286 4268  C:\Windows\SysWOW64\wsock32.dll - ok
16:54:37.0286 4268  [ 25419E7D1DED175B21113D819B3970DC ] C:\Program Files (x86)\Avira\AntiVir Desktop\aescn.dll
16:54:37.0286 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aescn.dll - ok
16:54:37.0286 4268  [ 418E881201583A3039D81F43E39E6C78 ] C:\Windows\SysWOW64\winsta.dll
16:54:37.0286 4268  C:\Windows\SysWOW64\winsta.dll - ok
16:54:37.0286 4268  [ 8E79090CB0987CA102E845341E052537 ] C:\Windows\SysWOW64\vdmdbg.dll
16:54:37.0286 4268  C:\Windows\SysWOW64\vdmdbg.dll - ok
16:54:37.0301 4268  [ 0915C4DB6DBC3BB9E11B7ECBBE4B7159 ] C:\Windows\SysWOW64\rtutils.dll
16:54:37.0301 4268  C:\Windows\SysWOW64\rtutils.dll - ok
16:54:37.0301 4268  [ 64605B72B605DEDE66D38E3D7094E73B ] C:\Program Files (x86)\Avira\AntiVir Desktop\aesbx.dll
16:54:37.0301 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aesbx.dll - ok
16:54:37.0301 4268  [ 51F5CC1E7DA3D9C664C2D0D61F315E06 ] C:\Windows\SysWOW64\adsldpc.dll
16:54:37.0301 4268  C:\Windows\SysWOW64\adsldpc.dll - ok
16:54:37.0301 4268  [ FF9831030678C7B6D70BAC00F68F8976 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libdispatch.dll
16:54:37.0301 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libdispatch.dll - ok
16:54:37.0301 4268  [ 78865ABC5F5D13190F8B35BD9044714A ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\objc.dll
16:54:37.0301 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\objc.dll - ok
16:54:37.0301 4268  [ F10E5311E5093FA3C00FF88C54C32FCA ] C:\Windows\SysWOW64\atl.dll
16:54:37.0301 4268  C:\Windows\SysWOW64\atl.dll - ok
16:54:37.0317 4268  [ 9D4DB1309BB1D86FDC7CFAFB315E3E5A ] C:\Program Files (x86)\Avira\AntiVir Desktop\aerdl.dll
16:54:37.0317 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aerdl.dll - ok
16:54:37.0317 4268  [ 2900795D34342A6BC02B209A9AB5CE9F ] C:\Program Files (x86)\Avira\AntiVir Desktop\gpgui.dll
16:54:37.0317 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gpgui.dll - ok
16:54:37.0317 4268  [ B03EF49D903EADF267B8F092095D1517 ] C:\Program Files (x86)\Avira\AntiVir Desktop\gplegacy.dll
16:54:37.0317 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gplegacy.dll - ok
16:54:37.0317 4268  [ EFD867317DA6C2F0DFA653AF92B47DA2 ] C:\Program Files (x86)\Avira\AntiVir Desktop\gpgavid.dll
16:54:37.0317 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gpgavid.dll - ok
16:54:37.0317 4268  [ D5AEFAD57C08349A4393D987DF7C715D ] C:\Windows\SysWOW64\winmm.dll
16:54:37.0317 4268  C:\Windows\SysWOW64\winmm.dll - ok
16:54:37.0317 4268  [ 0C3BF6691668478FF6B7E6D40FD04335 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aepack.dll
16:54:37.0317 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aepack.dll - ok
16:54:37.0333 4268  [ 8F9F50F3810672AC36503B72A0B1808A ] C:\Program Files (x86)\Avira\AntiVir Desktop\libdb44.dll
16:54:37.0333 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\libdb44.dll - ok
16:54:37.0333 4268  [ 35970C00018BF0755A53EF929C426F2E ] C:\Program Files (x86)\Avira\AntiVir Desktop\aeoffice.dll
16:54:37.0333 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aeoffice.dll - ok
16:54:37.0333 4268  [ FD86C605FD7AD4A41C01EC7A4A1E1C5D ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libicuin.dll
16:54:37.0333 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libicuin.dll - ok
16:54:37.0333 4268  [ 952F9418E081B7A9663C8AD780F37465 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aeheur.dll
16:54:37.0333 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aeheur.dll - ok
16:54:37.0333 4268  [ 20FF9C1AC224A84F3833E6D7B1ADED05 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aehelp.dll
16:54:37.0333 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aehelp.dll - ok
16:54:37.0333 4268  [ 10D5EB6682A01D82062C7094187F814B ] C:\Program Files (x86)\Avira\AntiVir Desktop\gpgenrep.dll
16:54:37.0333 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\gpgenrep.dll - ok
16:54:37.0348 4268  [ 1153A5CA7E9ECE8825BEA9ED02D526D9 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aegen.dll
16:54:37.0348 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aegen.dll - ok
16:54:37.0348 4268  [ FDAE72CBAF49E4694A3BDEFD5B59B4AC ] C:\Program Files (x86)\Avira\AntiVir Desktop\onlcfg.dll
16:54:37.0348 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\onlcfg.dll - ok
16:54:37.0348 4268  [ 59CDF1B8C9277DACC842118062E93134 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aeexp.dll
16:54:37.0348 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aeexp.dll - ok
16:54:37.0348 4268  [ 2B459F2972E8167335CA89E8B6FFA3F0 ] C:\Program Files (x86)\Avira\AntiVir Desktop\guardmsg.dll
16:54:37.0348 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\guardmsg.dll - ok
16:54:37.0348 4268  [ CD7B65E600B8EBC91B292C1AC9EC1215 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aeemu.dll
16:54:37.0348 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aeemu.dll - ok
16:54:37.0348 4268  [ 434049E557861645FA160F3035025F51 ] C:\Program Files (x86)\Avira\AntiVir Desktop\aebb.dll
16:54:37.0348 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\aebb.dll - ok
16:54:37.0364 4268  [ A3609397EF273B03295DBB10274BE12C ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libicuuc.dll
16:54:37.0364 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libicuuc.dll - ok
16:54:37.0364 4268  [ A63827E03E7A6683E51E15EDE1DA6DDC ] C:\Program Files (x86)\Avira\AntiVir Desktop\avgio.dll
16:54:37.0364 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avgio.dll - ok
16:54:37.0364 4268  [ 5E51DF536BE00DF1AA5E6A7F0F4E9EFF ] C:\Program Files (x86)\Avira\AntiVir Desktop\avipc.dll
16:54:37.0364 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avipc.dll - ok
16:54:37.0364 4268  [ C27651AE31386A88BF3F893B04A5D0BD ] C:\Program Files (x86)\Avira\AntiVir Desktop\avpref.dll
16:54:37.0364 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avpref.dll - ok
16:54:37.0364 4268  [ 149D74E1128A86DC9CFB2851FBEA11EB ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\icudt46.dll
16:54:37.0364 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\icudt46.dll - ok
16:54:37.0364 4268  [ F6FD367C9EAAEDF90CD7A7952AE0B336 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\ASL.dll
16:54:37.0364 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\ASL.dll - ok
16:54:37.0379 4268  [ 4327CF9A9D0864CA0FFC97FCDA97315A ] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll
16:54:37.0379 4268  C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll - ok
16:54:37.0379 4268  [ 062373995EAE5F0EAC9EAA9192136BFB ] C:\Windows\SysWOW64\dnssd.dll
16:54:37.0379 4268  C:\Windows\SysWOW64\dnssd.dll - ok
16:54:37.0379 4268  [ A0CFF6001114943967EC5CE39A0D66E5 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll
16:54:37.0379 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll - ok
16:54:37.0379 4268  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] C:\Program Files\Bonjour\mDNSResponder.exe
16:54:37.0379 4268  C:\Program Files\Bonjour\mDNSResponder.exe - ok
16:54:37.0379 4268  [ 8999B8631C7FD9F7F9EC3CAFD953BA24 ] C:\Windows\SysWOW64\mswsock.dll
16:54:37.0379 4268  C:\Windows\SysWOW64\mswsock.dll - ok
16:54:37.0379 4268  [ 73E8667A19FEEDD856DF2695E9E511D4 ] C:\Windows\SysWOW64\wship6.dll
16:54:37.0379 4268  C:\Windows\SysWOW64\wship6.dll - ok
16:54:37.0395 4268  [ 81F08948A0F1475894C99D4D19A158A8 ] C:\Windows\SysWOW64\wshqos.dll
16:54:37.0395 4268  C:\Windows\SysWOW64\wshqos.dll - ok
16:54:37.0395 4268  [ EE5C8E27C37B79CB54A2FCEEED2DC262 ] C:\Windows\SysWOW64\WSHTCPIP.DLL
16:54:37.0395 4268  C:\Windows\SysWOW64\WSHTCPIP.DLL - ok
16:54:37.0395 4268  [ D8129C49798CBBFB2E4351D4B7B8EF9C ] C:\Windows\System32\cryptsvc.dll
16:54:37.0395 4268  C:\Windows\System32\cryptsvc.dll - ok
16:54:37.0395 4268  [ 2C4C22EA1735F21F355EB1A39832F7DF ] C:\Windows\System32\cryptnet.dll
16:54:37.0395 4268  C:\Windows\System32\cryptnet.dll - ok
16:54:37.0395 4268  [ C4002B6B41975F057D98C439030CEA07 ] C:\Windows\ehome\ehrecvr.exe
16:54:37.0395 4268  C:\Windows\ehome\ehrecvr.exe - ok
16:54:37.0395 4268  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] C:\Windows\System32\dps.dll
16:54:37.0395 4268  C:\Windows\System32\dps.dll - ok
16:54:37.0411 4268  [ 0E2F58F6E698EDCB9E58FAD0CBCD0567 ] C:\Windows\System32\vssapi.dll
16:54:37.0411 4268  C:\Windows\System32\vssapi.dll - ok
16:54:37.0411 4268  [ 24665B221424FFD7B71F0D2C398F2F4F ] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\MobileDevice.dll
16:54:37.0411 4268  C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\MobileDevice.dll - ok
16:54:37.0411 4268  [ 4D842C5081F06E61BFF461CF87D13525 ] C:\Windows\ehome\ehtrace.dll
16:54:37.0411 4268  C:\Windows\ehome\ehtrace.dll - ok
16:54:37.0411 4268  [ BAAFAF9CEAEC0B73C2A3550A01F6CECB ] C:\Windows\System32\taskschd.dll
16:54:37.0411 4268  C:\Windows\System32\taskschd.dll - ok
16:54:37.0411 4268  [ 4705E8EF9934482C5BB488CE28AFC681 ] C:\Windows\ehome\ehsched.exe
16:54:37.0411 4268  C:\Windows\ehome\ehsched.exe - ok
16:54:37.0411 4268  [ 2473CA6595A2659D7039A4A89FECA269 ] C:\Windows\SysWOW64\wininet.dll
16:54:37.0411 4268  C:\Windows\SysWOW64\wininet.dll - ok
16:54:37.0426 4268  [ FCD84C381E0140AF901E58D48882D26B ] C:\Windows\System32\IKEEXT.DLL
16:54:37.0426 4268  C:\Windows\System32\IKEEXT.DLL - ok
16:54:37.0426 4268  [ 0F5FAAC852DB4C340B7A2F187E3358B8 ] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
16:54:37.0426 4268  C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe - ok
16:54:37.0426 4268  [ BF1FC3F79B863C914687A737C2F3D681 ] C:\Windows\System32\wdi.dll
16:54:37.0426 4268  C:\Windows\System32\wdi.dll - ok
16:54:37.0426 4268  [ C07D5582F2107ACAB4564E1DAE977C64 ] C:\Windows\ehome\ehprivjob.exe
16:54:37.0426 4268  C:\Windows\ehome\ehprivjob.exe - ok
16:54:37.0426 4268  [ F22495B45864F8AABB63105E76A075F9 ] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\sysenv.dll
16:54:37.0426 4268  C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\sysenv.dll - ok
16:54:37.0426 4268  [ 287923557447D7E4BDD7E65B1F0F5428 ] C:\Windows\System32\vsstrace.dll
16:54:37.0426 4268  C:\Windows\System32\vsstrace.dll - ok
16:54:37.0426 4268  [ 77B5035BC6EDF4D1B6265391AECEE4C0 ] C:\Windows\System32\vpnikeapi.dll
16:54:37.0426 4268  C:\Windows\System32\vpnikeapi.dll - ok
16:54:37.0442 4268  [ 1BCDB508143B517F21BBDAC10F5777BF ] C:\Windows\System32\conhost.exe
16:54:37.0442 4268  C:\Windows\System32\conhost.exe - ok
16:54:37.0442 4268  [ A5AE40808B72A25379A5499AD9977743 ] C:\Windows\System32\sbe.dll
16:54:37.0442 4268  C:\Windows\System32\sbe.dll - ok
16:54:37.0442 4268  [ 2F22E4F40CBEBB980F923D64A78FEA2B ] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\xmllite.dll
16:54:37.0442 4268  C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\xmllite.dll - ok
16:54:37.0442 4268  [ 6A13B4F3B3F575F1E24B877B9359AABA ] C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
16:54:37.0442 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll - ok
16:54:37.0442 4268  [ 2E33DFD10F28F86C3FC40EE123CC3904 ] C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
16:54:37.0442 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll - ok
16:54:37.0442 4268  [ 6951562DC4625EEFC6EACD52AD165866 ] C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
16:54:37.0442 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll - ok
16:54:37.0457 4268  [ 589CBC4989F750E1DA35625AB481CF43 ] C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
16:54:37.0457 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll - ok
16:54:37.0457 4268  [ 3BE0D923AA45A4DBE091C2D84F0B4FE7 ] C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
16:54:37.0457 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll - ok
16:54:37.0457 4268  [ F383B1AD5D7FDC1ACB0D900B50572F8D ] C:\Windows\SysWOW64\iertutil.dll
16:54:37.0457 4268  C:\Windows\SysWOW64\iertutil.dll - ok


robili 30.06.2013 16:30

Code:

16:54:37.0457 4268  [ F383B1AD5D7FDC1ACB0D900B50572F8D ] C:\Windows\SysWOW64\iertutil.dll
16:54:37.0457 4268  C:\Windows\SysWOW64\iertutil.dll - ok
16:54:37.0457 4268  [ E49DF2DD8763AD6C53B5E5BD1736115E ] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlOP.dll
16:54:37.0457 4268  C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlOP.dll - ok
16:54:37.0457 4268  [ 955CCE0330AB406DE9B8999C35975187 ] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\CryptoAPI.dll
16:54:37.0457 4268  C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\CryptoAPI.dll - ok
16:54:37.0457 4268  [ 0191E738BF521FE6EC567148E73C086B ] C:\Windows\System32\MSVidCtl.dll
16:54:37.0457 4268  C:\Windows\System32\MSVidCtl.dll - ok
16:54:37.0473 4268  [ DB76DB15EFC6E4D1153A6C5BC895948D ] C:\Windows\System32\sppc.dll
16:54:37.0473 4268  C:\Windows\System32\sppc.dll - ok
16:54:37.0473 4268  [ 9E0FF5DDD8B908DA5611445C35D6CD24 ] C:\Windows\System32\slcext.dll
16:54:37.0473 4268  C:\Windows\System32\slcext.dll - ok
16:54:37.0473 4268  [ 6F5BE3F67D7F66FFA861ABBFC6A8C973 ] C:\Windows\System32\sppcext.dll
16:54:37.0473 4268  C:\Windows\System32\sppcext.dll - ok
16:54:37.0473 4268  [ 847D3AE376C0817161A14A82C8922A9E ] C:\Windows\System32\netman.dll
16:54:37.0473 4268  C:\Windows\System32\netman.dll - ok
16:54:37.0473 4268  [ A56CCBBFCCEDCE2FD9C69FED24E035E3 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
16:54:37.0473 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll - ok
16:54:37.0473 4268  [ 8AD77806D336673F270DB31645267293 ] C:\Windows\System32\nlasvc.dll
16:54:37.0473 4268  C:\Windows\System32\nlasvc.dll - ok
16:54:37.0489 4268  [ 1727B2A2F379A32B864C096FA794AADC ] C:\Windows\System32\aepic.dll
16:54:37.0489 4268  C:\Windows\System32\aepic.dll - ok
16:54:37.0489 4268  [ A7DDDDE163F16AB49DF3DE9EEC715495 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CFNetwork.dll
16:54:37.0489 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CFNetwork.dll - ok
16:54:37.0489 4268  [ D4FAC263861BAE06971C7F7D0A8EBF15 ] C:\Windows\System32\ncsi.dll
16:54:37.0489 4268  C:\Windows\System32\ncsi.dll - ok
16:54:37.0489 4268  [ C6DCD1D11ED6827F05C00773C3E7053C ] C:\Windows\System32\sfc.dll
16:54:37.0489 4268  C:\Windows\System32\sfc.dll - ok
16:54:37.0489 4268  [ 68769C3356B3BE5D1C732C97B9A80D6E ] C:\Windows\System32\drivers\PEAuth.sys
16:54:37.0489 4268  C:\Windows\System32\drivers\PEAuth.sys - ok
16:54:37.0489 4268  [ 895C9AB0A855547445C4181195230757 ] C:\Windows\System32\sfc_os.dll
16:54:37.0489 4268  C:\Windows\System32\sfc_os.dll - ok
16:54:37.0504 4268  [ 58F4493BF748A3A89689997B7BD00E95 ] C:\Windows\System32\winhttp.dll
16:54:37.0504 4268  C:\Windows\System32\winhttp.dll - ok
16:54:37.0504 4268  [ 603EBD34E216C5654A2D774EAC98D278 ] C:\Windows\System32\webio.dll
16:54:37.0504 4268  C:\Windows\System32\webio.dll - ok
16:54:37.0504 4268  [ FF0DB4D9A08864A5C7B67477CD8E3B2A ] C:\Program Files (x86)\Skype\Updater\Updater.exe
16:54:37.0504 4268  C:\Program Files (x86)\Skype\Updater\Updater.exe - ok
16:54:37.0504 4268  [ 3EA8A16169C26AFBEB544E0E48421186 ] C:\Windows\System32\drivers\secdrv.sys
16:54:37.0504 4268  C:\Windows\System32\drivers\secdrv.sys - ok
16:54:37.0504 4268  [ 2BBF3FDB70B8965DFA0258CBAB41ECCE ] C:\Windows\System32\ssdpapi.dll
16:54:37.0504 4268  C:\Windows\System32\ssdpapi.dll - ok
16:54:37.0504 4268  [ 3BDCBB29D727C49DC3E3256253467281 ] C:\Windows\System32\wmdrmsdk.dll
16:54:37.0504 4268  C:\Windows\System32\wmdrmsdk.dll - ok
16:54:37.0520 4268  [ FF5688D309347F2720911D8796912834 ] C:\Windows\SysWOW64\clbcatq.dll
16:54:37.0520 4268  C:\Windows\SysWOW64\clbcatq.dll - ok
16:54:37.0520 4268  [ BC617A4E1B4FA8DF523A061739A0BD87 ] C:\Windows\System32\seclogon.dll
16:54:37.0520 4268  C:\Windows\System32\seclogon.dll - ok
16:54:37.0520 4268  [ E17E0188BB90FAE42D83E98707EFA59C ] C:\Windows\System32\sppsvc.exe
16:54:37.0520 4268  C:\Windows\System32\sppsvc.exe - ok
16:54:37.0520 4268  [ 5997D769CDB108390DCFAEBF442BF816 ] C:\Windows\SysWOW64\RpcRtRemote.dll
16:54:37.0520 4268  C:\Windows\SysWOW64\RpcRtRemote.dll - ok
16:54:37.0520 4268  [ C28FD3B37B6F18751C99E6022A2A9782 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\SQLite3.dll
16:54:37.0520 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\SQLite3.dll - ok
16:54:37.0520 4268  [ 44A8B9185030EA57F7999383643ADFFB ] C:\Windows\System32\quartz.dll
16:54:37.0520 4268  C:\Windows\System32\quartz.dll - ok
16:54:37.0520 4268  [ 18301B40411B2108076AB685B4E4B6DC ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
16:54:37.0520 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll - ok
16:54:37.0535 4268  [ 46767946E7B559D981C1DC04EC0AB36F ] C:\Windows\System32\devenum.dll
16:54:37.0535 4268  C:\Windows\System32\devenum.dll - ok
16:54:37.0535 4268  [ 558C42D165DB5799B4072DC0A9C27C0B ] C:\Windows\System32\msdmo.dll
16:54:37.0535 4268  C:\Windows\System32\msdmo.dll - ok
16:54:37.0535 4268  [ D38535978F93F9FC9F28BE6093A87DBE ] C:\Windows\System32\msdri.dll
16:54:37.0535 4268  C:\Windows\System32\msdri.dll - ok
16:54:37.0535 4268  [ 27E461F0BE5BFF5FC737328F749538C3 ] C:\Windows\System32\drivers\srvnet.sys
16:54:37.0535 4268  C:\Windows\System32\drivers\srvnet.sys - ok
16:54:37.0535 4268  [ BCEA9AB347E53BC03B2E36BE0B8BA0EF ] C:\Windows\System32\httpapi.dll
16:54:37.0535 4268  C:\Windows\System32\httpapi.dll - ok
16:54:37.0535 4268  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] C:\Windows\System32\wiaservc.dll
16:54:37.0535 4268  C:\Windows\System32\wiaservc.dll - ok
16:54:37.0551 4268  [ DEE1262C3BF7784CAEDE42D0AD0262EC ] C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
16:54:37.0551 4268  C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe - ok
16:54:37.0551 4268  [ FFF95479C7AB1550F0750A5D01744211 ] C:\Windows\System32\drivers\spsys.sys
16:54:37.0551 4268  C:\Windows\System32\drivers\spsys.sys - ok
16:54:37.0551 4268  [ 0364256B4A2A93A8C8CDA6B3B5A0EFF5 ] C:\Windows\System32\wiatrace.dll
16:54:37.0551 4268  C:\Windows\System32\wiatrace.dll - ok
16:54:37.0551 4268  [ 96DB78C9C50CEED9DA5050EFFEE272A2 ] C:\Windows\System32\upnp.dll
16:54:37.0551 4268  C:\Windows\System32\upnp.dll - ok
16:54:37.0551 4268  [ FF35A9108D3D2F6DB6A48054A9055896 ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\resource.dll
16:54:37.0551 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\resource.dll - ok
16:54:37.0551 4268  [ 62A0BFDFC3877CC8CF555259411D3AEE ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\libssl10.dll
16:54:37.0551 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\libssl10.dll - ok
16:54:37.0567 4268  [ 2432C789B5995022D0D20CFE3FD179D4 ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\libcrypto10.dll
16:54:37.0567 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\libcrypto10.dll - ok
16:54:37.0567 4268  [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] C:\Windows\System32\sysmain.dll
16:54:37.0567 4268  C:\Windows\System32\sysmain.dll - ok
16:54:37.0567 4268  [ A8EDB86FC2A4D6D1285E4C70384AC35A ] C:\Windows\System32\dllhost.exe
16:54:37.0567 4268  C:\Windows\System32\dllhost.exe - ok
16:54:37.0567 4268  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] C:\Windows\System32\tapisrv.dll
16:54:37.0567 4268  C:\Windows\System32\tapisrv.dll - ok
16:54:37.0567 4268  [ 539C49CEBB3C50957AC8A09D95ECD880 ] C:\Windows\SysWOW64\shfolder.dll
16:54:37.0567 4268  C:\Windows\SysWOW64\shfolder.dll - ok
16:54:37.0567 4268  [ A0A2C1D812C231C9BFE119FDC68E341B ] C:\Windows\System32\IDStore.dll
16:54:37.0567 4268  C:\Windows\System32\IDStore.dll - ok
16:54:37.0582 4268  [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] C:\Windows\System32\drivers\tcpipreg.sys
16:54:37.0582 4268  C:\Windows\System32\drivers\tcpipreg.sys - ok
16:54:37.0582 4268  [ 352B3DC62A0D259A82A052238425C872 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
16:54:37.0582 4268  C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - ok
16:54:37.0582 4268  [ 23566F9723771108D2E6CD768AC27407 ] C:\Windows\System32\AtBroker.exe
16:54:37.0582 4268  C:\Windows\System32\AtBroker.exe - ok
16:54:37.0582 4268  [ BAFE84E637BF7388C96EF48D4D3FDD53 ] C:\Windows\System32\userinit.exe
16:54:37.0582 4268  C:\Windows\System32\userinit.exe - ok
16:54:37.0582 4268  [ 210FCACAF902B2CD47CF9FD17D846146 ] C:\Windows\System32\aeevts.dll
16:54:37.0582 4268  C:\Windows\System32\aeevts.dll - ok
16:54:37.0582 4268  [ 639774C9ACD063F028F6084ABF5593AD ] C:\Windows\System32\taskhost.exe
16:54:37.0582 4268  C:\Windows\System32\taskhost.exe - ok
16:54:37.0598 4268  [ 9BB99503D6A4DD62569EDE9E5E2672A5 ] C:\Windows\System32\HotStartUserAgent.dll
16:54:37.0598 4268  C:\Windows\System32\HotStartUserAgent.dll - ok
16:54:37.0598 4268  [ 7E7AFD841694F6AC397E99D75CEAD49D ] C:\Windows\System32\trkwks.dll
16:54:37.0598 4268  C:\Windows\System32\trkwks.dll - ok
16:54:37.0598 4268  [ C79D8D326264269D3F6DBA5746679810 ] C:\Program Files (x86)\TwonkyMedia\twonkymediaserverwatchdog.exe
16:54:37.0598 4268  C:\Program Files (x86)\TwonkyMedia\twonkymediaserverwatchdog.exe - ok
16:54:37.0598 4268  [ AFB5B500AD69E24ED1BC15D1161641EF ] C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
16:54:37.0598 4268  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL - ok
16:54:37.0598 4268  [ F162D5F5E845B9DC352DD1BAD8CEF1BC ] C:\Windows\System32\dwm.exe
16:54:37.0598 4268  C:\Windows\System32\dwm.exe - ok
16:54:37.0598 4268  [ FCFCD1101C5DA23B4B95F93D02B2C169 ] C:\Windows\System32\dwmredir.dll
16:54:37.0598 4268  C:\Windows\System32\dwmredir.dll - ok
16:54:37.0598 4268  [ 65EA57712340C09B1B0C427B4848AE05 ] C:\Windows\System32\taskeng.exe
16:54:37.0598 4268  C:\Windows\System32\taskeng.exe - ok
16:54:37.0613 4268  [ 1F1CA9E99DD5BF918BE0BF30B5A42FDA ] C:\Windows\System32\MsCtfMonitor.dll
16:54:37.0613 4268  C:\Windows\System32\MsCtfMonitor.dll - ok
16:54:37.0613 4268  [ A9F3BFC9345F49614D5859EC95B9E994 ] C:\Program Files\Windows Media Player\wmpnetwk.exe
16:54:37.0613 4268  C:\Program Files\Windows Media Player\wmpnetwk.exe - ok
16:54:37.0613 4268  [ 4BA77A5EF71C14C764B0ED4701683E3E ] C:\Windows\System32\dwmcore.dll
16:54:37.0613 4268  C:\Windows\System32\dwmcore.dll - ok
16:54:37.0613 4268  [ 19B07E7E8915D701225DA41CB3877306 ] C:\Windows\System32\wbem\WMIsvc.dll
16:54:37.0613 4268  C:\Windows\System32\wbem\WMIsvc.dll - ok
16:54:37.0613 4268  [ F09A9A1AD21FE618C4C8B0A0D830C886 ] C:\Windows\System32\msutb.dll
16:54:37.0613 4268  C:\Windows\System32\msutb.dll - ok
16:54:37.0613 4268  [ F9D908DE6B166DAC9B89BF62FA291CE8 ] C:\Program Files\Bonjour\mdnsNSP.dll
16:54:37.0613 4268  C:\Program Files\Bonjour\mdnsNSP.dll - ok
16:54:37.0629 4268  [ F5CEF064C7E6D95DA86B9D064A56A969 ] C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
16:54:37.0629 4268  C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll - ok
16:54:37.0629 4268  [ 94EEAC26F57811BD1AEFC164412F7FCE ] C:\Windows\System32\PlaySndSrv.dll
16:54:37.0629 4268  C:\Windows\System32\PlaySndSrv.dll - ok
16:54:37.0629 4268  [ 7DB5AA22A8A8E5C2D335F44853C1F6DE ] C:\Windows\System32\wbemcomn.dll
16:54:37.0629 4268  C:\Windows\System32\wbemcomn.dll - ok
16:54:37.0629 4268  [ 522B0466ED967A0762E9AF5B37D8F40A ] C:\Windows\System32\esent.dll
16:54:37.0629 4268  C:\Windows\System32\esent.dll - ok
16:54:37.0629 4268  [ 45CFBFA8EDC3DF4E2B7FB0D0260FE051 ] C:\Windows\System32\localspl.dll
16:54:37.0629 4268  C:\Windows\System32\localspl.dll - ok
16:54:37.0629 4268  [ 88351B29B622B30962D2FEB6CA8D860B ] C:\Windows\System32\rasadhlp.dll
16:54:37.0629 4268  C:\Windows\System32\rasadhlp.dll - ok
16:54:37.0645 4268  [ 0255C22D99602534F15CBB8D9B6F152F ] C:\Windows\System32\wbem\WinMgmtR.dll
16:54:37.0645 4268  C:\Windows\System32\wbem\WinMgmtR.dll - ok
16:54:37.0645 4268  [ 805A52C5AE26C28E88FDD9BCCFE6F312 ] C:\Windows\System32\TSChannel.dll
16:54:37.0645 4268  C:\Windows\System32\TSChannel.dll - ok
16:54:37.0645 4268  [ 0C52762C606BCF6A377D5E4688191A6B ] C:\Windows\System32\wbem\WmiDcPrv.dll
16:54:37.0645 4268  C:\Windows\System32\wbem\WmiDcPrv.dll - ok
16:54:37.0645 4268  [ A3F5E8EC1316C3E2562B82694A251C9E ] C:\Windows\System32\wbem\fastprox.dll
16:54:37.0645 4268  C:\Windows\System32\wbem\fastprox.dll - ok
16:54:37.0645 4268  [ 332FEAB1435662FC6C672E25BEB37BE3 ] C:\Windows\explorer.exe
16:54:37.0645 4268  C:\Windows\explorer.exe - ok
16:54:37.0645 4268  [ E36112A8A6C7F840169A7E92C12F4203 ] C:\Windows\System32\wsock32.dll
16:54:37.0645 4268  C:\Windows\System32\wsock32.dll - ok
16:54:37.0660 4268  [ F6F22291024906E43D135A4B1705FEAC ] C:\Windows\System32\sppwinob.dll
16:54:37.0660 4268  C:\Windows\System32\sppwinob.dll - ok
16:54:37.0660 4268  [ E0B340996A41C9A75DFA3B99BBA9C500 ] C:\Windows\System32\SearchIndexer.exe
16:54:37.0660 4268  C:\Windows\System32\SearchIndexer.exe - ok
16:54:37.0660 4268  [ EE26D130808D16C0E417BBBED0451B34 ] C:\Windows\System32\ntdsapi.dll
16:54:37.0660 4268  C:\Windows\System32\ntdsapi.dll - ok
16:54:37.0660 4268  [ C5AC93CF3BA30D367FB49148A2B673B9 ] C:\Windows\System32\PrintIsolationProxy.dll
16:54:37.0660 4268  C:\Windows\System32\PrintIsolationProxy.dll - ok
16:54:37.0660 4268  [ 3285481F5C12305CA104A6C493CA5A0B ] C:\Windows\System32\spoolss.dll
16:54:37.0660 4268  C:\Windows\System32\spoolss.dll - ok
16:54:37.0660 4268  [ 666A60F6F5E719856FF6254E0966EFF7 ] C:\Windows\System32\wbem\wbemprox.dll
16:54:37.0660 4268  C:\Windows\System32\wbem\wbemprox.dll - ok
16:54:37.0676 4268  [ 423982DD851406A52B6399DDB196C606 ] C:\Windows\System32\wmdrmdev.dll
16:54:37.0676 4268  C:\Windows\System32\wmdrmdev.dll - ok
16:54:37.0676 4268  [ 589DF683A6C81424A6CECE52ABF98A50 ] C:\Windows\System32\tquery.dll
16:54:37.0676 4268  C:\Windows\System32\tquery.dll - ok
16:54:37.0676 4268  [ 5EB55F661DEBF156E126160BCD4D89F8 ] C:\Windows\System32\wbem\wbemcore.dll
16:54:37.0676 4268  C:\Windows\System32\wbem\wbemcore.dll - ok
16:54:37.0676 4268  [ 9AE80F6A66B30E3ED8CDF858CF28B11B ] C:\Windows\System32\d3d10_1.dll
16:54:37.0676 4268  C:\Windows\System32\d3d10_1.dll - ok
16:54:37.0676 4268  [ A45DF599526357A2D4E418FCB2ACFB3D ] C:\Windows\System32\CNBLM3_3.DLL
16:54:37.0676 4268  C:\Windows\System32\CNBLM3_3.DLL - ok
16:54:37.0676 4268  [ 63F72417CA38D8FC8F53709649B589E3 ] C:\Windows\System32\d3d10_1core.dll
16:54:37.0676 4268  C:\Windows\System32\d3d10_1core.dll - ok
16:54:37.0676 4268  [ 3353B667E1EF7898B1B936EE631D9FE0 ] C:\Windows\System32\CNMLMA2.DLL
16:54:37.0676 4268  C:\Windows\System32\CNMLMA2.DLL - ok
16:54:37.0691 4268  [ 6F79F69BD894EADC42D62365EEC823D2 ] C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
16:54:37.0691 4268  C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe - ok
16:54:37.0691 4268  [ 4DB7376155E964D49AE8296FA36F2290 ] C:\Windows\System32\CNMN6PPM.DLL
16:54:37.0691 4268  C:\Windows\System32\CNMN6PPM.DLL - ok
16:54:37.0691 4268  [ 8DFB5752FCE145A6B295093C0A8BE131 ] C:\Windows\System32\dxgi.dll
16:54:37.0691 4268  C:\Windows\System32\dxgi.dll - ok
16:54:37.0691 4268  [ 2C1055E2C6D42753241FB2A129136994 ] C:\Windows\System32\drmv2clt.dll
16:54:37.0691 4268  C:\Windows\System32\drmv2clt.dll - ok
16:54:37.0691 4268  [ 087D8668C71634A3A3761135ABF16EEE ] C:\Windows\System32\wbem\esscli.dll
16:54:37.0691 4268  C:\Windows\System32\wbem\esscli.dll - ok
16:54:37.0691 4268  [ EED05D42D91835064703E2318552ED25 ] C:\Windows\System32\ExplorerFrame.dll
16:54:37.0691 4268  C:\Windows\System32\ExplorerFrame.dll - ok
16:54:37.0707 4268  [ 46B8E04B3C35CB93F89EF27746D7A908 ] C:\Windows\System32\EP0SLM01.DLL
16:54:37.0707 4268  C:\Windows\System32\EP0SLM01.DLL - ok
16:54:37.0707 4268  [ 19E41CCCEE697CC9465396B370929792 ] C:\Windows\System32\FXSMON.dll
16:54:37.0707 4268  C:\Windows\System32\FXSMON.dll - ok
16:54:37.0707 4268  [ 4C92EB7535CAA1681A77D928FBF9771F ] C:\Windows\System32\d3d11.dll
16:54:37.0707 4268  C:\Windows\System32\d3d11.dll - ok
16:54:37.0707 4268  [ 32A3C8600AF124CBAAD845F13CFAE3CB ] C:\Windows\System32\tcpmon.dll
16:54:37.0707 4268  C:\Windows\System32\tcpmon.dll - ok
16:54:37.0707 4268  [ 462DDD0E424B8B6EE7271C245539FFFE ] C:\Program Files (x86)\TwonkyMedia\twonkymediaserver.exe
16:54:37.0707 4268  C:\Program Files (x86)\TwonkyMedia\twonkymediaserver.exe - ok
16:54:37.0707 4268  [ 718B6F51AB7F6FE2988A36868F9AD3AB ] C:\Windows\System32\wbem\wbemsvc.dll
16:54:37.0707 4268  C:\Windows\System32\wbem\wbemsvc.dll - ok
16:54:37.0723 4268  [ 7568CC720ACE4D03B84AF97817E745EF ] C:\Windows\System32\mssrch.dll
16:54:37.0723 4268  C:\Windows\System32\mssrch.dll - ok
16:54:37.0723 4268  [ 93518C6EDE0B61BCBD02BDB02BD05FEE ] C:\Windows\System32\snmpapi.dll
16:54:37.0723 4268  C:\Windows\System32\snmpapi.dll - ok
16:54:37.0723 4268  [ DF72A9936D0C3F517083119648814B09 ] C:\Windows\System32\usbmon.dll
16:54:37.0723 4268  C:\Windows\System32\usbmon.dll - ok
16:54:37.0723 4268  [ FFF9D00CF16397C64317F213484F94BD ] C:\Windows\System32\wsnmp32.dll
16:54:37.0723 4268  C:\Windows\System32\wsnmp32.dll - ok
16:54:37.0723 4268  [ A1D7E3ADCDB07DDB6F423862DCB1A52B ] C:\Windows\System32\WSDMon.dll
16:54:37.0723 4268  C:\Windows\System32\WSDMon.dll - ok
16:54:37.0723 4268  [ 0143DB80DACFB7C2B5B7009ED9063353 ] C:\Windows\System32\wbem\wmiutils.dll
16:54:37.0723 4268  C:\Windows\System32\wbem\wmiutils.dll - ok
16:54:37.0738 4268  [ F1B205F932F62F94506A5F332C895DAF ] C:\Windows\System32\WSDApi.dll
16:54:37.0738 4268  C:\Windows\System32\WSDApi.dll - ok
16:54:37.0738 4268  [ 0AB34456654C283DAA13B8D2BA21439B ] C:\Windows\System32\wbem\repdrvfs.dll
16:54:37.0738 4268  C:\Windows\System32\wbem\repdrvfs.dll - ok
16:54:37.0738 4268  [ 4E35D4D943D6D00668BE4B0C344F3BC9 ] C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
16:54:37.0738 4268  C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe - ok
16:54:37.0738 4268  [ C55516D98DD5D8F0153C2A9B4227DA86 ] C:\Windows\System32\webservices.dll
16:54:37.0738 4268  C:\Windows\System32\webservices.dll - ok
16:54:37.0738 4268  [ 3121A79D13A61562BE9CC902CD46B542 ] C:\Windows\System32\msidle.dll
16:54:37.0738 4268  C:\Windows\System32\msidle.dll - ok
16:54:37.0738 4268  [ 7548066DF68A8A1A56B043359F915F37 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
16:54:37.0738 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe - ok
16:54:37.0754 4268  [ 984BDAC9F4FC9993CE8D3A7D7DA3E9A5 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ISDI.dll
16:54:37.0754 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ISDI.dll - ok
16:54:37.0754 4268  [ 863F793D15B4026B1A5FDECA873D4D84 ] C:\Windows\SysWOW64\apphelp.dll
16:54:37.0754 4268  C:\Windows\SysWOW64\apphelp.dll - ok
16:54:37.0754 4268  [ 3960CEB4A6B13784252D827ECF65CED3 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ARA\Shell_ARA.dll
16:54:37.0754 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ARA\Shell_ARA.dll - ok
16:54:37.0754 4268  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] C:\Windows\System32\drivers\srv2.sys
16:54:37.0754 4268  C:\Windows\System32\drivers\srv2.sys - ok
16:54:37.0754 4268  [ 1530DFBDFD68AAD1FD5FDA52EA44925E ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\CHS\Shell_CHS.dll
16:54:37.0754 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\CHS\Shell_CHS.dll - ok
16:54:37.0754 4268  [ B5055B51BAA0FD0A736A88653DA3C1C0 ] C:\Windows\System32\fundisc.dll
16:54:37.0754 4268  C:\Windows\System32\fundisc.dll - ok
16:54:37.0769 4268  [ 58F0F6D94BF8DB65F6D76CCCB14F272A ] C:\Windows\System32\nvwgf2umx.dll
16:54:37.0769 4268  C:\Windows\System32\nvwgf2umx.dll - ok
16:54:37.0769 4268  [ 7FC0F6C8A0CEFBE4E60D8577C6FF8584 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\CHT\Shell_CHT.dll
16:54:37.0769 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\CHT\Shell_CHT.dll - ok
16:54:37.0769 4268  [ 4581716B4BF76ACFD8E167EB0B26D82A ] C:\Windows\System32\fdPnp.dll
16:54:37.0769 4268  C:\Windows\System32\fdPnp.dll - ok
16:54:37.0769 4268  [ 1D626FE2E13C1CE49CA0136CFF214E93 ] C:\Windows\System32\spool\prtprocs\x64\winprint.dll
16:54:37.0769 4268  C:\Windows\System32\spool\prtprocs\x64\winprint.dll - ok
16:54:37.0769 4268  [ 08C2957BB30058E663720C5606885653 ] C:\Windows\System32\iphlpsvc.dll
16:54:37.0769 4268  C:\Windows\System32\iphlpsvc.dll - ok
16:54:37.0769 4268  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] C:\Windows\System32\drivers\srv.sys
16:54:37.0769 4268  C:\Windows\System32\drivers\srv.sys - ok
16:54:37.0785 4268  [ 371D003DE5D81C7465A0E8CD911D2E9C ] C:\Windows\System32\spool\prtprocs\x64\CNBPP3.DLL
16:54:37.0785 4268  C:\Windows\System32\spool\prtprocs\x64\CNBPP3.DLL - ok
16:54:37.0785 4268  [ EEA7E552C2C992CFD4B50857010F39EA ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\CSY\Shell_CSY.dll
16:54:37.0785 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\CSY\Shell_CSY.dll - ok
16:54:37.0785 4268  [ 345709E87E47A9F028E8973AEC9D3BC2 ] C:\Windows\System32\spool\prtprocs\x64\CNMPDA2.DLL
16:54:37.0785 4268  C:\Windows\System32\spool\prtprocs\x64\CNMPDA2.DLL - ok
16:54:37.0785 4268  [ DAEEAD506E5B84E177D88C4D7B739401 ] C:\Windows\System32\spool\prtprocs\x64\EP0NPP01.DLL
16:54:37.0785 4268  C:\Windows\System32\spool\prtprocs\x64\EP0NPP01.DLL - ok
16:54:37.0785 4268  [ 67CF11E00D026A5C0C88EA5F84D501E5 ] C:\Windows\System32\win32spl.dll
16:54:37.0785 4268  C:\Windows\System32\win32spl.dll - ok
16:54:37.0785 4268  [ 24AAD92FD83120C3288E0FA04CB05D13 ] C:\Program Files (x86)\TwonkyMedia\wmdrmdll.dll
16:54:37.0785 4268  C:\Program Files (x86)\TwonkyMedia\wmdrmdll.dll - ok
16:54:37.0785 4268  [ 27B9E163740A226B65E4B9E186117911 ] C:\Windows\System32\sqmapi.dll
16:54:37.0785 4268  C:\Windows\System32\sqmapi.dll - ok
16:54:37.0801 4268  [ 5E2623439A9936D320FE8DC1AB84526A ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\DAN\Shell_DAN.dll
16:54:37.0801 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\DAN\Shell_DAN.dll - ok
16:54:37.0801 4268  [ 7B38D7916A7CD058C16A0A6CA5077901 ] C:\Windows\System32\wdscore.dll
16:54:37.0801 4268  C:\Windows\System32\wdscore.dll - ok
16:54:37.0801 4268  [ EE867A0870FC9E4972BA9EAAD35651E2 ] C:\Windows\System32\rasmans.dll
16:54:37.0801 4268  C:\Windows\System32\rasmans.dll - ok
16:54:37.0801 4268  [ 507D5567A0A4EE86C4B0CE2CE1777025 ] C:\Windows\System32\inetpp.dll
16:54:37.0801 4268  C:\Windows\System32\inetpp.dll - ok
16:54:37.0801 4268  [ 8F1656DEB2E861D608909792F5A68C3B ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\DEU\Shell_DEU.dll
16:54:37.0801 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\DEU\Shell_DEU.dll - ok
16:54:37.0801 4268  [ D9F42719019740BAA6D1C6D536CBDAA6 ] C:\Windows\System32\srvsvc.dll
16:54:37.0801 4268  C:\Windows\System32\srvsvc.dll - ok
16:54:37.0816 4268  [ 1BF0CB861A48FEB1638228760750F3CB ] C:\Windows\System32\cscapi.dll
16:54:37.0816 4268  C:\Windows\System32\cscapi.dll - ok
16:54:37.0816 4268  [ 58A0CDABEA255616827B1C22C9994466 ] C:\Windows\System32\NapiNSP.dll
16:54:37.0816 4268  C:\Windows\System32\NapiNSP.dll - ok
16:54:37.0816 4268  [ 613C8CE10A5FDE582BA5FA64C4D56AAA ] C:\Windows\System32\pnrpnsp.dll
16:54:37.0816 4268  C:\Windows\System32\pnrpnsp.dll - ok
16:54:37.0816 4268  [ 349B1D5D8D1B5A7B10BCD01470BD5F64 ] C:\Windows\System32\msvcp110.dll
16:54:37.0816 4268  C:\Windows\System32\msvcp110.dll - ok
16:54:37.0816 4268  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] C:\Windows\System32\browser.dll
16:54:37.0816 4268  C:\Windows\System32\browser.dll - ok
16:54:37.0816 4268  [ 78193AA97D679531522C3E2FA4A5EDFE ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ELL\Shell_ELL.dll
16:54:37.0816 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ELL\Shell_ELL.dll - ok
16:54:37.0832 4268  [ DDD0357A92FA843EFF8915ED17253D6C ] C:\Windows\System32\wbem\WmiPrvSD.dll
16:54:37.0832 4268  C:\Windows\System32\wbem\WmiPrvSD.dll - ok
16:54:37.0832 4268  [ 793A19EAB66BB232F019DFF9D1977A41 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ENU\Shell_ENU.dll
16:54:37.0832 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ENU\Shell_ENU.dll - ok
16:54:37.0832 4268  [ C72ABC6B7B90A61364B6DD889B5435F3 ] C:\Windows\System32\msvcr110.dll
16:54:37.0832 4268  C:\Windows\System32\msvcr110.dll - ok
16:54:37.0832 4268  [ D41FEBD098234F02485A4EA98D4730A4 ] C:\Windows\System32\ncobjapi.dll
16:54:37.0832 4268  C:\Windows\System32\ncobjapi.dll - ok
16:54:37.0832 4268  [ 2B373B5F7E36B5ED5DA176D4400EF091 ] C:\Windows\System32\sppobjs.dll
16:54:37.0832 4268  C:\Windows\System32\sppobjs.dll - ok
16:54:37.0832 4268  [ 44C96B48112EB24AE7764EBF1C527000 ] C:\Windows\System32\rastapi.dll
16:54:37.0832 4268  C:\Windows\System32\rastapi.dll - ok
16:54:37.0847 4268  [ FAFAE01E889DC9C05A6CA2138CFC220B ] C:\Windows\System32\tapi32.dll
16:54:37.0847 4268  C:\Windows\System32\tapi32.dll - ok
16:54:37.0847 4268  [ BA726152513EC650EED219B7995DE852 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ESP\Shell_ESP.dll
16:54:37.0847 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ESP\Shell_ESP.dll - ok
16:54:37.0847 4268  [ 2E2072EB48238FCA8FBB7A9F5FABAC45 ] C:\Windows\System32\winrnr.dll
16:54:37.0847 4268  C:\Windows\System32\winrnr.dll - ok
16:54:37.0847 4268  [ CFEFA40DDE34659BE5211966EAD86437 ] C:\Windows\System32\netmsg.dll
16:54:37.0847 4268  C:\Windows\System32\netmsg.dll - ok
16:54:37.0847 4268  [ 03706015DB44368375AEBE6339490E66 ] C:\Windows\System32\netcfgx.dll
16:54:37.0847 4268  C:\Windows\System32\netcfgx.dll - ok
16:54:37.0847 4268  [ 77C8E1779E784189EA29D9A5ECCDD9E9 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\FIN\Shell_FIN.dll
16:54:37.0847 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\FIN\Shell_FIN.dll - ok
16:54:37.0863 4268  [ 93812FDC01AA864195816CD814445F95 ] C:\Program Files\Microsoft Mouse and Keyboard Center\SQMAPI.dll
16:54:37.0863 4268  C:\Program Files\Microsoft Mouse and Keyboard Center\SQMAPI.dll - ok
16:54:37.0863 4268  [ 3B367397320C26DBA890B260F80D1B1B ] C:\Windows\System32\hnetcfg.dll
16:54:37.0863 4268  C:\Windows\System32\hnetcfg.dll - ok
16:54:37.0863 4268  [ A7A8CA53D9C9FD90C07AB0EB38E5316B ] C:\Windows\System32\dbghelp.dll
16:54:37.0863 4268  C:\Windows\System32\dbghelp.dll - ok
16:54:37.0863 4268  [ 9689A9C7F7C2A1A423CDA2C3B43FFF65 ] C:\Windows\System32\wer.dll
16:54:37.0863 4268  C:\Windows\System32\wer.dll - ok
16:54:37.0863 4268  [ FF80CAD87555E8E4D2CFD7B9058343F8 ] C:\Windows\System32\sscore.dll
16:54:37.0863 4268  C:\Windows\System32\sscore.dll - ok
16:54:37.0863 4268  [ AFD87B70E2C48EC080CA28ADCC3175B5 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\FRA\Shell_FRA.dll
16:54:37.0863 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\FRA\Shell_FRA.dll - ok
16:54:37.0879 4268  [ 81749E073AC5857B044A686B406E5244 ] C:\Windows\System32\clusapi.dll
16:54:37.0879 4268  C:\Windows\System32\clusapi.dll - ok
16:54:37.0879 4268  [ 344FCC9850C3A8A3B4D3C65151AF8E4C ] C:\Windows\System32\resutils.dll
16:54:37.0879 4268  C:\Windows\System32\resutils.dll - ok
16:54:37.0879 4268  [ FDC385A0F7D7DD880C4622D1DF08ABE9 ] C:\Windows\System32\ntprint.dll
16:54:37.0879 4268  C:\Windows\System32\ntprint.dll - ok
16:54:37.0879 4268  [ 5ECEA5F29DCEE8D320454C86A1CB3366 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\HEB\Shell_HEB.dll
16:54:37.0879 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\HEB\Shell_HEB.dll - ok
16:54:37.0879 4268  [ D2A0FFA75AB181B19B5EB93BB29C7686 ] C:\Windows\System32\unimdm.tsp
16:54:37.0879 4268  C:\Windows\System32\unimdm.tsp - ok
16:54:37.0879 4268  [ 94B7DF336815B47236724019FAB24B7C ] C:\Windows\System32\uniplat.dll
16:54:37.0879 4268  C:\Windows\System32\uniplat.dll - ok
16:54:37.0879 4268  [ 41326DD08ACC0CDC5F8177AF96C066E8 ] C:\Windows\System32\kmddsp.tsp
16:54:37.0879 4268  C:\Windows\System32\kmddsp.tsp - ok
16:54:37.0894 4268  [ 7C1BAE7D23D4874FEE256A2B9C00E019 ] C:\Windows\System32\hidphone.tsp
16:54:37.0894 4268  C:\Windows\System32\hidphone.tsp - ok
16:54:37.0894 4268  [ 1D6BC2769DA66C1145F4DA5A65F52E61 ] C:\Windows\System32\ndptsp.tsp
16:54:37.0894 4268  C:\Windows\System32\ndptsp.tsp - ok
16:54:37.0894 4268  [ 6F40D6FB05E0C1E5402812B426971AF0 ] C:\Windows\System32\wbem\wbemess.dll
16:54:37.0894 4268  C:\Windows\System32\wbem\wbemess.dll - ok
16:54:37.0894 4268  [ 34E306CDA632F09793A851C86026B0DC ] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll
16:54:37.0894 4268  C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll - ok
16:54:37.0894 4268  [ FEB91B4DA0D540865260A33838654FA3 ] C:\Windows\System32\nci.dll
16:54:37.0894 4268  C:\Windows\System32\nci.dll - ok
16:54:37.0894 4268  [ 3B9F6EDE1288FD756237203460F57FF8 ] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\sysenv.dll
16:54:37.0894 4268  C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\sysenv.dll - ok
16:54:37.0910 4268  [ 18873D2B1ABBB8826ED18F840CB8E0D3 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\HUN\Shell_HUN.dll
16:54:37.0910 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\HUN\Shell_HUN.dll - ok
16:54:37.0910 4268  [ 024352FEEC9042260BB4CFB4D79A206B ] C:\Windows\System32\EhStorShell.dll
16:54:37.0910 4268  C:\Windows\System32\EhStorShell.dll - ok
16:54:37.0910 4268  [ 037A719DAD50603202C978CD802623E4 ] C:\Windows\System32\ntshrui.dll
16:54:37.0910 4268  C:\Windows\System32\ntshrui.dll - ok
16:54:37.0910 4268  [ 79ECBC83B844F7A474C66BE77AAF7180 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ITA\Shell_ITA.dll
16:54:37.0910 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ITA\Shell_ITA.dll - ok
16:54:37.0910 4268  [ A717A35120DBAB5AB707AB40662AF9DD ] C:\Windows\System32\rasppp.dll
16:54:37.0910 4268  C:\Windows\System32\rasppp.dll - ok
16:54:37.0910 4268  [ 0FE5CD5F9C9248F42D1EF56E495B182E ] C:\Windows\System32\vpnike.dll
16:54:37.0910 4268  C:\Windows\System32\vpnike.dll - ok
16:54:37.0925 4268  [ 6A84E68B538B8B04608BF2F0D426CE6F ] C:\Windows\System32\raschap.dll
16:54:37.0925 4268  C:\Windows\System32\raschap.dll - ok
16:54:37.0925 4268  [ B794DD8ACC5CC76177156463DAB4BEBB ] C:\Windows\System32\drivers\afcdp.sys
16:54:37.0925 4268  C:\Windows\System32\drivers\afcdp.sys - ok
16:54:37.0925 4268  [ D73FF818BDA7A73846A6DFF6E24E47F4 ] C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll
16:54:37.0925 4268  C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll - ok
16:54:37.0925 4268  [ B95F6501A2F8B2E78C697FEC401970CE ] C:\Windows\System32\ipnathlp.dll
16:54:37.0925 4268  C:\Windows\System32\ipnathlp.dll - ok
16:54:37.0925 4268  [ 2DF29664ED261F0FC448E58F338F0671 ] C:\Windows\System32\mprapi.dll
16:54:37.0925 4268  C:\Windows\System32\mprapi.dll - ok
16:54:37.0925 4268  [ A42F2C1EB3B66C54FB3C7B79D30C1A6D ] C:\Windows\System32\netshell.dll
16:54:37.0925 4268  C:\Windows\System32\netshell.dll - ok
16:54:37.0941 4268  [ 069006BF253F32CD980E67E8671DFE3C ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\JPN\Shell_JPN.dll
16:54:37.0941 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\JPN\Shell_JPN.dll - ok
16:54:37.0941 4268  [ 5925F32114BF5ACF50C66500433B35CC ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\KOR\Shell_KOR.dll
16:54:37.0941 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\KOR\Shell_KOR.dll - ok
16:54:37.0941 4268  [ 03C7D7A1553E3009CEBE3013A578B0ED ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\NLD\Shell_NLD.dll
16:54:37.0941 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\NLD\Shell_NLD.dll - ok
16:54:37.0941 4268  [ 4FFD3E3363EBAC7FC8BBA58EAD594AFF ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\NOR\Shell_NOR.dll
16:54:37.0941 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\NOR\Shell_NOR.dll - ok
16:54:37.0941 4268  [ 2499E32320905E68F9710527593A0EDB ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\PLK\Shell_PLK.dll
16:54:37.0941 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\PLK\Shell_PLK.dll - ok
16:54:37.0941 4268  [ FF2F985A1CE7922E1D7ADAA914B9332F ] C:\Program Files (x86)\Acronis\TrueImageHome\timounter64.dll
16:54:37.0941 4268  C:\Program Files (x86)\Acronis\TrueImageHome\timounter64.dll - ok
16:54:37.0957 4268  [ 591EA8B6991D99720B36EBC1CC16CEA8 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\PTB\Shell_PTB.dll
16:54:37.0957 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\PTB\Shell_PTB.dll - ok
16:54:37.0957 4268  [ A8704A10FFDE468F4AB18EBF82A9A86F ] C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_88e41e092fab0294\msvcp80.dll
16:54:37.0957 4268  C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_88e41e092fab0294\msvcp80.dll - ok
16:54:37.0957 4268  [ A4487F6CEFED12F2C1257F6DBCDAEB1E ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\PTG\Shell_PTG.dll
16:54:37.0957 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\PTG\Shell_PTG.dll - ok
16:54:37.0957 4268  [ EC6BA7C92FA5B2AA4AFDF4DF22AEDAB7 ] C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_88e41e092fab0294\msvcr80.dll
16:54:37.0957 4268  C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_88e41e092fab0294\msvcr80.dll - ok
16:54:37.0957 4268  [ 35989A505DEEC24DEF8D327D22FF14D4 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RUS\Shell_RUS.dll
16:54:37.0957 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RUS\Shell_RUS.dll - ok
16:54:37.0972 4268  [ 1D63F4366288B8A7595397E27010FD44 ] C:\Windows\System32\IconCodecService.dll
16:54:37.0972 4268  C:\Windows\System32\IconCodecService.dll - ok
16:54:37.0972 4268  [ 9D825B4E6B28F93F326538515EFC880B ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\SVE\Shell_SVE.dll
16:54:37.0972 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\SVE\Shell_SVE.dll - ok
16:54:37.0972 4268  [ D9BFF3E59CBE32FE72D6D68F6AF348BD ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\THA\Shell_THA.dll
16:54:37.0972 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\THA\Shell_THA.dll - ok
16:54:37.0972 4268  [ E84CB5D899098DDEA6D013057C9E4B5F ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\TRK\Shell_TRK.dll
16:54:37.0972 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\TRK\Shell_TRK.dll - ok
16:54:37.0972 4268  [ FCE23E27F62989AD0BB88E256E847A41 ] C:\Windows\System32\CertPolEng.dll
16:54:37.0972 4268  C:\Windows\System32\CertPolEng.dll - ok
16:54:37.0972 4268  [ 371948BC5911ABA06168FAC91ED25F06 ] C:\Windows\System32\msxml3.dll
16:54:37.0972 4268  C:\Windows\System32\msxml3.dll - ok
16:54:37.0988 4268  [ CDFB177247FD4F7A5EFBF2C504473D39 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\DEU\PlugInRAID_DEU.dll
16:54:37.0988 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\DEU\PlugInRAID_DEU.dll - ok
16:54:37.0988 4268  [ C5B0324DB461559ADD070E632A6919FA ] C:\Windows\SysWOW64\wbem\wbemprox.dll
16:54:37.0988 4268  C:\Windows\SysWOW64\wbem\wbemprox.dll - ok
16:54:37.0988 4268  [ 49E5753D923F1AC63B22D3DCB0B47E00 ] C:\Windows\System32\uDWM.dll
16:54:37.0988 4268  C:\Windows\System32\uDWM.dll - ok
16:54:37.0988 4268  [ 704314FD398C81D5F342CAA5DF7B7F21 ] C:\Windows\SysWOW64\wbemcomn.dll
16:54:37.0988 4268  C:\Windows\SysWOW64\wbemcomn.dll - ok
16:54:37.0988 4268  [ 776AE0564F8B1C282E331FD95A1BDC5F ] C:\Windows\SysWOW64\wbem\wbemsvc.dll
16:54:37.0988 4268  C:\Windows\SysWOW64\wbem\wbemsvc.dll - ok
16:54:37.0988 4268  [ CFC7D8289D2B5F3CF8D16E2DB7F93D4A ] C:\Windows\SysWOW64\wbem\fastprox.dll
16:54:37.0988 4268  C:\Windows\SysWOW64\wbem\fastprox.dll - ok
16:54:38.0003 4268  [ E3E811471DE781900FF21C1FD84E941E ] C:\Windows\SysWOW64\ntdsapi.dll
16:54:38.0003 4268  C:\Windows\SysWOW64\ntdsapi.dll - ok
16:54:38.0003 4268  [ F11A57E91FDAECFB41A5CB21EB1EBC8E ] C:\Windows\System32\dssenh.dll
16:54:38.0003 4268  C:\Windows\System32\dssenh.dll - ok
16:54:38.0003 4268  [ A5DBC74C5B91CF6E43B73D62936F8186 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\PlugInRAID.pin
16:54:38.0003 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\PlugInRAID.pin - ok
16:54:38.0003 4268  [ 9288710312B116586E7480FD606DEDE0 ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\thread_pool.dll
16:54:38.0003 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\thread_pool.dll - ok
16:54:38.0003 4268  [ 3CEF96890064B3CDB190963157F24BAC ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizM.dll
16:54:38.0003 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizM.dll - ok
16:54:38.0003 4268  [ 22F020C76E339EB2B2187BA73A7E4173 ] C:\Windows\System32\PrintIsolationHost.exe
16:54:38.0003 4268  C:\Windows\System32\PrintIsolationHost.exe - ok
16:54:38.0019 4268  [ 8E01332CC4B68BC6B5B7EFFE374442AA ] C:\Windows\SysWOW64\oleacc.dll
16:54:38.0019 4268  C:\Windows\SysWOW64\oleacc.dll - ok
16:54:38.0019 4268  [ B40420876B9288E0A1C8CCA8A84E5DC9 ] C:\Windows\SysWOW64\dnsapi.dll
16:54:38.0019 4268  C:\Windows\SysWOW64\dnsapi.dll - ok
16:54:38.0019 4268  [ 12B79422A23814429CDA9E734C58F78F ] C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL
16:54:38.0019 4268  C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL - ok
16:54:38.0019 4268  [ 5BFB02BDA2700D078400E149BC4CF87A ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizD.dll
16:54:38.0019 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizD.dll - ok
16:54:38.0019 4268  [ 99A29CEB52D6A61AF3A32EC1409DFD77 ] C:\Windows\System32\spool\drivers\x64\3\CNMDRA2.DLL
16:54:38.0019 4268  C:\Windows\System32\spool\drivers\x64\3\CNMDRA2.DLL - ok
16:54:38.0019 4268  [ 40947436A70E0034E41123DF5A0A7702 ] C:\Program Files (x86)\Bonjour\mdnsNSP.dll
16:54:38.0019 4268  C:\Program Files (x86)\Bonjour\mdnsNSP.dll - ok
16:54:38.0035 4268  [ 3C29B98149A28FEDA42796D3EA904F62 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizR.dll
16:54:38.0035 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizR.dll - ok
16:54:38.0035 4268  [ ED6EE83D61EBC683C2CD8E899EA6FEBE ] C:\Windows\SysWOW64\rasadhlp.dll
16:54:38.0035 4268  C:\Windows\SysWOW64\rasadhlp.dll - ok
16:54:38.0035 4268  [ 7AD2F5A872000540431EAC575B2AC36C ] C:\Windows\System32\spool\drivers\x64\3\CNMUIA2.DLL
16:54:38.0035 4268  C:\Windows\System32\spool\drivers\x64\3\CNMUIA2.DLL - ok
16:54:38.0035 4268  [ 38ADD53ECFC5F040EF1C647ECD22A2A4 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RaidWizCnG.dll
16:54:38.0035 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RaidWizCnG.dll - ok
16:54:38.0035 4268  [ 03A03A453F1AAAE0C73AAAF895321C7A ] C:\Windows\SysWOW64\FWPUCLNT.DLL
16:54:38.0035 4268  C:\Windows\SysWOW64\FWPUCLNT.DLL - ok
16:54:38.0035 4268  [ F0BFA0FE6317B40CD4A3FE5EB6F8C55F ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizC.dll
16:54:38.0035 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizC.dll - ok
16:54:38.0050 4268  [ 43B02D7C43B77775F1DA63B1D1014F38 ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizCFE.dll
16:54:38.0050 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\RAIDWizCFE.dll - ok
16:54:38.0050 4268  [ 5AF1E9600E3FF841E522703A4993ED0C ] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
16:54:38.0050 4268  C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe - ok
16:54:38.0050 4268  [ AC595AD075660B6FBE285C4FE58E06F8 ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\ulxmlrpcpp.dll
16:54:38.0050 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\ulxmlrpcpp.dll - ok
16:54:38.0050 4268  [ 3507D1EAA107A78F9EF9F76C760FDF3A ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\expat.dll
16:54:38.0050 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\expat.dll - ok
16:54:38.0050 4268  [ 0BA65122FFA7E37564EE86422DBF7AE8 ] C:\Windows\SysWOW64\nlaapi.dll
16:54:38.0050 4268  C:\Windows\SysWOW64\nlaapi.dll - ok
16:54:38.0050 4268  [ 0B7E85364CB878E2AD531DB7B601A9E5 ] C:\Windows\SysWOW64\NapiNSP.dll
16:54:38.0050 4268  C:\Windows\SysWOW64\NapiNSP.dll - ok
16:54:38.0066 4268  [ 5CF640EDDB1E40A5AB1BB743BCDEC610 ] C:\Windows\SysWOW64\pnrpnsp.dll
16:54:38.0066 4268  C:\Windows\SysWOW64\pnrpnsp.dll - ok
16:54:38.0066 4268  [ 5DF5D8CFD9B9573FA3B2C89D9061A240 ] C:\Windows\SysWOW64\winrnr.dll
16:54:38.0066 4268  C:\Windows\SysWOW64\winrnr.dll - ok
16:54:38.0066 4268  [ 9A85ABCE0FDD1AF8E79E731EB0B679F3 ] C:\Windows\SysWOW64\dhcpcsvc.dll
16:54:38.0066 4268  C:\Windows\SysWOW64\dhcpcsvc.dll - ok
16:54:38.0066 4268  [ FB4045578F5180BDB1963AB352B78548 ] C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
16:54:38.0066 4268  C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll - ok
16:54:38.0066 4268  [ 66C87DB880052104808507D6FA84D68E ] C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
16:54:38.0066 4268  C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL - ok
16:54:38.0066 4268  [ D233C7FEAE3FAA25F93A9E6B46815ADC ] C:\Windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_08e61857a83bc251\msvcr90.dll
16:54:38.0066 4268  C:\Windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_08e61857a83bc251\msvcr90.dll - ok
16:54:38.0081 4268  [ D9E21CBF9E6A87847AFFD39EA3FA28EE ] C:\Windows\System32\SearchProtocolHost.exe
16:54:38.0081 4268  C:\Windows\System32\SearchProtocolHost.exe - ok
16:54:38.0081 4268  [ D2A5B2B09F2AF5ED13BF494508B09788 ] C:\Windows\System32\msshooks.dll
16:54:38.0081 4268  C:\Windows\System32\msshooks.dll - ok
16:54:38.0081 4268  [ 49A3AD5CE578CD77F445F3D244AEAB2D ] C:\Windows\System32\SearchFilterHost.exe
16:54:38.0081 4268  C:\Windows\System32\SearchFilterHost.exe - ok
16:54:38.0081 4268  [ A08C010D859F8EB42BDD7E1D55B8CA27 ] C:\Windows\System32\mscoree.dll
16:54:38.0081 4268  C:\Windows\System32\mscoree.dll - ok
16:54:38.0081 4268  [ AA794B099F776B37ACCDEAD00E0FBFC9 ] C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
16:54:38.0081 4268  C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll - ok
16:54:38.0081 4268  [ ACE1BB07E0377E37A2C514CD2EC119B1 ] C:\Windows\System32\mssprxy.dll
16:54:38.0081 4268  C:\Windows\System32\mssprxy.dll - ok
16:54:38.0097 4268  [ 48041BAEB60CE5F34F13CC2A1361E49C ] C:\Windows\System32\mssph.dll
16:54:38.0097 4268  C:\Windows\System32\mssph.dll - ok
16:54:38.0097 4268  [ 8F4BB0CFECED925D440ABC2481278360 ] C:\Windows\System32\mapi32.dll
16:54:38.0097 4268  C:\Windows\System32\mapi32.dll - ok
16:54:38.0097 4268  [ 1685B21A19632B44894D94476C0AAA88 ] C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-20\Indiv01_64.key
16:54:38.0097 4268  C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-20\Indiv01_64.key - ok
16:54:38.0097 4268  [ A1FA08852EDF01BB92D4BD87E8F75685 ] C:\Program Files\NVIDIA Corporation\Display\nvsmartmax64.dll
16:54:38.0097 4268  C:\Program Files\NVIDIA Corporation\Display\nvsmartmax64.dll - ok
16:54:38.0097 4268  [ 59893040D368399B8420D7089A560642 ] C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
16:54:38.0097 4268  C:\Program Files\NVIDIA Corporation\Display\nvtray.exe - ok
16:54:38.0097 4268  [ 7F4E9F6A38F43B66CF6F1C663E293E74 ] C:\Program Files\NVIDIA Corporation\Update Common\NvUpdt.dll
16:54:38.0097 4268  C:\Program Files\NVIDIA Corporation\Update Common\NvUpdt.dll - ok
16:54:38.0113 4268  [ 3F0AA87E945516B370A76FF398716DBF ] C:\Program Files\NVIDIA Corporation\Update Common\EasyDaemonAPIU64.dll
16:54:38.0113 4268  C:\Program Files\NVIDIA Corporation\Update Common\EasyDaemonAPIU64.dll - ok
16:54:38.0113 4268  [ 255EAB0CFA32DE75E1622C2F6D4D1FFE ] C:\Program Files\NVIDIA Corporation\Update Common\NvUpdtr.dll
16:54:38.0113 4268  C:\Program Files\NVIDIA Corporation\Update Common\NvUpdtr.dll - ok
16:54:38.0113 4268  [ 1C10E59024357AA7CAB8B836B767FB5B ] C:\Program Files\Microsoft Mouse and Keyboard Center\dpgcmd.dll
16:54:38.0113 4268  C:\Program Files\Microsoft Mouse and Keyboard Center\dpgcmd.dll - ok
16:54:38.0113 4268  [ 5EB6E9C8BE1ACC5830780E0F9A846255 ] C:\Windows\System32\msi.dll
16:54:38.0113 4268  C:\Windows\System32\msi.dll - ok
16:54:38.0113 4268  [ 9776DC73C92C0919B29BB6AEF5A20FDF ] C:\Program Files\Microsoft Mouse and Keyboard Center\Components\Commands\DPGHnt\DPGHnt.dll
16:54:38.0113 4268  C:\Program Files\Microsoft Mouse and Keyboard Center\Components\Commands\DPGHnt\DPGHnt.dll - ok
16:54:38.0113 4268  [ 1C6F2BF5E6CD537CD5C25A30D6C49AC1 ] C:\Program Files\7-Zip\7zFM.exe
16:54:38.0113 4268  C:\Program Files\7-Zip\7zFM.exe - ok
16:54:38.0128 4268  [ 7F3717F4DDA68FFF5F8AB2CBEB3EB751 ] C:\Program Files\Microsoft Office\Office14\CLVIEW.EXE
16:54:38.0128 4268  C:\Program Files\Microsoft Office\Office14\CLVIEW.EXE - ok
16:54:38.0128 4268  [ 3F50200237961034FACE602373838980 ] C:\Windows\SysWOW64\FirewallAPI.dll
16:54:38.0128 4268  C:\Windows\SysWOW64\FirewallAPI.dll - ok
16:54:38.0128 4268  [ 2427ABF5319463B9B7DF062C79967E9E ] C:\Program Files (x86)\Avira\AntiVir Desktop\avfwot.sys
16:54:38.0128 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avfwot.sys - ok
16:54:38.0128 4268  [ 1FF7E4F548C7C372C804938F0D5B36AE ] C:\Windows\SysWOW64\netcfgx.dll
16:54:38.0128 4268  C:\Windows\SysWOW64\netcfgx.dll - ok
16:54:38.0128 4268  [ 8B74CEC6980D4816B0037AE9A27E538F ] C:\Windows\SysWOW64\slc.dll
16:54:38.0128 4268  C:\Windows\SysWOW64\slc.dll - ok
16:54:38.0128 4268  [ AA63DDD55F620BF96F1114F3BE3691C0 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avfwim.sys
16:54:38.0128 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avfwim.sys - ok
16:54:38.0144 4268  [ 649C331E521056253365FE337E283931 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avesvc.dll
16:54:38.0144 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avesvc.dll - ok
16:54:38.0144 4268  [ CE665151AF23BA722045933532CE54CD ] C:\Program Files (x86)\Avira\AntiVir Desktop\avesvcr.dll
16:54:38.0144 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avesvcr.dll - ok
16:54:38.0144 4268  [ 8A599BAE9BAA19D98F216029800F2101 ] C:\Program Files (x86)\Avira\AntiVir Desktop\webcat.dll
16:54:38.0144 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\webcat.dll - ok
16:54:38.0144 4268  [ FC801AC984D2DAAEFEDEB427FAC88AC3 ] C:\Program Files (x86)\Avira\AntiVir Desktop\webcatrc.dll
16:54:38.0144 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\webcatrc.dll - ok
16:54:38.0144 4268  [ B7FDBE2CFEFBA99718D6EC49D3E4AC3C ] C:\Program Files (x86)\Avira\AntiVir Desktop\webprot.dll
16:54:38.0144 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\webprot.dll - ok
16:54:38.0144 4268  [ CA9F7888B524D8100B977C81F44C3234 ] C:\Windows\SysWOW64\winhttp.dll
16:54:38.0144 4268  C:\Windows\SysWOW64\winhttp.dll - ok
16:54:38.0159 4268  [ FB19FC5951A88F3C523E35C2C98D23C0 ] C:\Windows\SysWOW64\webio.dll
16:54:38.0159 4268  C:\Windows\SysWOW64\webio.dll - ok
16:54:38.0159 4268  [ 4E5FE39C1076D115EC8BFCFE14D75B80 ] C:\Windows\SysWOW64\credssp.dll
16:54:38.0159 4268  C:\Windows\SysWOW64\credssp.dll - ok
16:54:38.0159 4268  [ 0D036F9230D0F8C2F571D3CD5A69EFE3 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
16:54:38.0159 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe - ok
16:54:38.0159 4268  [ B201DC42A8C1275CBFFBA762A941D4E5 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avipc64.dll
16:54:38.0159 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avipc64.dll - ok
16:54:38.0159 4268  [ F97D4477F7352DC49BB95EA9DF9E4654 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avreg.dll
16:54:38.0159 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avreg.dll - ok
16:54:38.0159 4268  [ 50DDEB8CA3620655B9FF68FFFC41248E ] C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
16:54:38.0159 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe - ok
16:54:38.0175 4268  [ F46BD152C8A9C4EBAE2EC51B063DE0ED ] C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
16:54:38.0175 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe - ok
16:54:38.0175 4268  [ EA00081A598B366441E7F07426C69B33 ] C:\Program Files (x86)\Avira\AntiVir Desktop\antispam.dll
16:54:38.0175 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\antispam.dll - ok
16:54:38.0175 4268  [ B3DC4D1658093C1E486CA9F22180BECF ] C:\Windows\SysWOW64\urlmon.dll
16:54:38.0175 4268  C:\Windows\SysWOW64\urlmon.dll - ok
16:54:38.0175 4268  [ 8B42EB6D3F205100D5122BB9C6D95566 ] C:\Program Files (x86)\Avira\AntiVir Desktop\pcre.dll
16:54:38.0175 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\pcre.dll - ok
16:54:38.0175 4268  [ 1C60E09CA1C3A045BC4D367F67C915B7 ] C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
16:54:38.0175 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll - ok
16:54:38.0175 4268  [ 5DE0B954B2A36B37BB4E5FE9180B77A2 ] C:\Program Files (x86)\Avira\AntiVir Desktop\libxml2.dll
16:54:38.0175 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\libxml2.dll - ok
16:54:38.0191 4268  [ B731D7AB373C5DB1E2909A9ECACC3F1C ] C:\Program Files (x86)\Avira\AntiVir Desktop\libiconv2.dll
16:54:38.0191 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\libiconv2.dll - ok
16:54:38.0191 4268  [ 32912204CE7D97BFE4332486B6A3E886 ] C:\Program Files (x86)\Avira\AntiVir Desktop\msgclient.dll
16:54:38.0191 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\msgclient.dll - ok
16:54:38.0191 4268  [ F3DE10AABD5C7A1A186C9966F037D0C0 ] C:\Windows\SysWOW64\mfc100u.dll
16:54:38.0191 4268  C:\Windows\SysWOW64\mfc100u.dll - ok
16:54:38.0191 4268  [ 5F2575CF10DC25B30AEC0A0171022B6F ] C:\Program Files (x86)\Avira\AntiVir Desktop\cares.dll
16:54:38.0191 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\cares.dll - ok
16:54:38.0191 4268  [ D05AE156A837520D1B8F6B51D0FBF7A6 ] C:\Program Files (x86)\Avira\AntiVir Desktop\asata.dll
16:54:38.0191 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\asata.dll - ok
16:54:38.0191 4268  [ 18AB2E5A40064ED5F7791AC5946A90F3 ] C:\Windows\SysWOW64\msimg32.dll
16:54:38.0191 4268  C:\Windows\SysWOW64\msimg32.dll - ok
16:54:38.0206 4268  [ 3EBAB84D6F46EC9C8BF3AB079F859532 ] C:\Program Files (x86)\Avira\AntiVir Desktop\mgrs.dll
16:54:38.0206 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\mgrs.dll - ok
16:54:38.0206 4268  [ 43964FA89CCF97BA6BE34D69455AC65F ] C:\Windows\SysWOW64\uxtheme.dll
16:54:38.0206 4268  C:\Windows\SysWOW64\uxtheme.dll - ok
16:54:38.0206 4268  [ C3EEFEE20FE458379BD61C4630B9B6EA ] C:\Program Files (x86)\Avira\AntiVir Desktop\avmailcr.dll
16:54:38.0206 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avmailcr.dll - ok
16:54:38.0206 4268  [ 39C5F32747B3414D1BB216FDB1DEFC58 ] C:\Windows\SysWOW64\dwmapi.dll
16:54:38.0206 4268  C:\Windows\SysWOW64\dwmapi.dll - ok
16:54:38.0206 4268  [ ECA6624EFEBBE2C0C320AC942620C404 ] C:\Windows\SysWOW64\mfc100deu.dll
16:54:38.0206 4268  C:\Windows\SysWOW64\mfc100deu.dll - ok
16:54:38.0206 4268  [ CC13DA82CC24F7DCCCC8731101FA9380 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrc.dll
16:54:38.0206 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrc.dll - ok
16:54:38.0206 4268  [ 7E5BA9484CFC39767A951881364705F6 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccupdw.dll
16:54:38.0206 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccupdw.dll - ok
16:54:38.0222 4268  [ CDFB296916BA7314C91FE847974B13CA ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccwkrlib.dll
16:54:38.0222 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccwkrlib.dll - ok
16:54:38.0222 4268  [ 9D2A2369AB4B08A4905FE72DB104498F ] C:\Windows\System32\appinfo.dll
16:54:38.0222 4268  C:\Windows\System32\appinfo.dll - ok
16:54:38.0222 4268  [ F7073C962C4FB7C415565DDE109DE49F ] C:\Windows\System32\npmproxy.dll
16:54:38.0222 4268  C:\Windows\System32\npmproxy.dll - ok
16:54:38.0222 4268  [ 4449D23E8F197862F1B16F1E6C89C36C ] C:\Windows\System32\diagperf.dll
16:54:38.0222 4268  C:\Windows\System32\diagperf.dll - ok
16:54:38.0222 4268  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] C:\Windows\System32\IPSECSVC.DLL
16:54:38.0222 4268  C:\Windows\System32\IPSECSVC.DLL - ok
16:54:38.0222 4268  [ 35BA5AA671887FE8A62B88A9A6229FD5 ] C:\Windows\System32\pstorsvc.dll
16:54:38.0222 4268  C:\Windows\System32\pstorsvc.dll - ok
16:54:38.0237 4268  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] C:\Windows\System32\ssdpsrv.dll
16:54:38.0237 4268  C:\Windows\System32\ssdpsrv.dll - ok
16:54:38.0237 4268  [ 93221146D4EBBF314C29B23CD6CC391D ] C:\Windows\System32\wpdbusenum.dll
16:54:38.0237 4268  C:\Windows\System32\wpdbusenum.dll - ok
16:54:38.0237 4268  [ BD9EB3958F213F96B97B1D897DEE006D ] C:\Windows\System32\hidserv.dll
16:54:38.0237 4268  C:\Windows\System32\hidserv.dll - ok
16:54:38.0237 4268  [ AB95FBAE4F9A5A56B177CEC427B2B35E ] C:\Windows\System32\psbase.dll
16:54:38.0237 4268  C:\Windows\System32\psbase.dll - ok
16:54:38.0237 4268  [ 9BC93C9ACFA34DB5A41B89357B31E4ED ] C:\Windows\System32\FwRemoteSvr.dll
16:54:38.0237 4268  C:\Windows\System32\FwRemoteSvr.dll - ok
16:54:38.0237 4268  [ E64D9EC8018C55873B40FDEE9DBEF5B3 ] C:\Windows\System32\PortableDeviceApi.dll
16:54:38.0237 4268  C:\Windows\System32\PortableDeviceApi.dll - ok
16:54:38.0253 4268  [ BF4AC709BE5BF64F331F5D67773A0C82 ] C:\Windows\System32\perftrack.dll
16:54:38.0253 4268  C:\Windows\System32\perftrack.dll - ok
16:54:38.0253 4268  [ 9719E3D834F5C8C43F56A93DFA497023 ] C:\Windows\System32\pnpts.dll
16:54:38.0253 4268  C:\Windows\System32\pnpts.dll - ok
16:54:38.0253 4268  [ E1B22739C933BE33F53DB58C5393ADD3 ] C:\Windows\System32\Apphlpdm.dll
16:54:38.0253 4268  C:\Windows\System32\Apphlpdm.dll - ok
16:54:38.0253 4268  [ E811F8510B133E70CF6E509FB809824F ] C:\Windows\System32\wdiasqmmodule.dll
16:54:38.0253 4268  C:\Windows\System32\wdiasqmmodule.dll - ok
16:54:38.0253 4268  [ AFA79C343F9D1555F7E5D5FA70BB2A14 ] C:\Windows\System32\PortableDeviceConnectApi.dll
16:54:38.0253 4268  C:\Windows\System32\PortableDeviceConnectApi.dll - ok
16:54:38.0253 4268  [ 92E0508D924512F63FFEEFE498CBD11F ] C:\Windows\System32\p2pcollab.dll
16:54:38.0253 4268  C:\Windows\System32\p2pcollab.dll - ok
16:54:38.0269 4268  [ D47EC6A8E81633DD18D2436B19BAF6DE ] C:\Windows\System32\upnphost.dll
16:54:38.0269 4268  C:\Windows\System32\upnphost.dll - ok
16:54:38.0269 4268  [ 582AC6D9873E31DFA28A4547270862DD ] C:\Windows\System32\QAGENTRT.DLL
16:54:38.0269 4268  C:\Windows\System32\QAGENTRT.DLL - ok
16:54:38.0269 4268  [ 506A83A3BEEE9FCA09F0170DE9FC7D1B ] C:\Windows\System32\fveui.dll
16:54:38.0269 4268  C:\Windows\System32\fveui.dll - ok
16:54:38.0269 4268  [ 025E7DBDB98866ED3CB2D4DDA70B364D ] C:\Windows\System32\runonce.exe
16:54:38.0269 4268  C:\Windows\System32\runonce.exe - ok
16:54:38.0269 4268  [ B837D1528CE2E3CB79F09496BC08DDC6 ] C:\Windows\System32\SensApi.dll
16:54:38.0269 4268  C:\Windows\System32\SensApi.dll - ok
16:54:38.0269 4268  [ D44741F65A1D71F65814A12CF6E2400A ] C:\Windows\SysWOW64\runonce.exe
16:54:38.0269 4268  C:\Windows\SysWOW64\runonce.exe - ok
16:54:38.0284 4268  [ 12C45E3CB6D65F73209549E2D02ECA7A ] C:\Windows\SysWOW64\propsys.dll
16:54:38.0284 4268  C:\Windows\SysWOW64\propsys.dll - ok
16:54:38.0284 4268  [ E629F1A051C82795DDFFD3E8D4855811 ] C:\Windows\System32\dimsjob.dll
16:54:38.0284 4268  C:\Windows\System32\dimsjob.dll - ok
16:54:38.0284 4268  [ 35CB97CBC3EDC463418ED4997AAB29B6 ] C:\Windows\System32\pautoenr.dll
16:54:38.0284 4268  C:\Windows\System32\pautoenr.dll - ok
16:54:38.0284 4268  [ 94DFBB481BF51158B216E23C5C1C9D6E ] C:\Windows\System32\certcli.dll
16:54:38.0284 4268  C:\Windows\System32\certcli.dll - ok
16:54:38.0284 4268  [ 263B26106606A010CF877472B535E4BB ] C:\Windows\System32\CertEnroll.dll
16:54:38.0284 4268  C:\Windows\System32\CertEnroll.dll - ok
16:54:38.0284 4268  [ A113AFEED3159A1ED52D78CB0226006D ] C:\Windows\SysWOW64\secur32.dll
16:54:38.0284 4268  C:\Windows\SysWOW64\secur32.dll - ok
16:54:38.0284 4268  [ AD7B9C14083B52BC532FBA5948342B98 ] C:\Windows\SysWOW64\cmd.exe
16:54:38.0284 4268  C:\Windows\SysWOW64\cmd.exe - ok
16:54:38.0300 4268  [ 326C7F76A29897A892AA7726E91C1C67 ] C:\Windows\SysWOW64\winbrand.dll
16:54:38.0300 4268  C:\Windows\SysWOW64\winbrand.dll - ok
16:54:38.0300 4268  [ FCA0837B2739C044EEC00AF0DDD73FFC ] C:\Windows\SysWOW64\ieframe.dll
16:54:38.0300 4268  C:\Windows\SysWOW64\ieframe.dll - ok
16:54:38.0300 4268  [ 4B78B431F225FD8624C5655CB1DE7B61 ] C:\Windows\System32\aelupsvc.dll
16:54:38.0300 4268  C:\Windows\System32\aelupsvc.dll - ok
16:54:38.0300 4268  [ 007863E45F25AA47A4C30D0930BBFD85 ] C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
16:54:38.0300 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll - ok
16:54:38.0300 4268  [ 49ACA548B2423F1C67898E6AC719A9A6 ] C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
16:54:38.0300 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll - ok
16:54:38.0300 4268  [ 60F4AEFA103D421EA4A40E31409B4756 ] C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
16:54:38.0300 4268  C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll - ok
16:54:38.0315 4268  [ 1F05F5A16881CD928C82D53CEFCF4477 ] C:\Windows\SysWOW64\shdocvw.dll
16:54:38.0315 4268  C:\Windows\SysWOW64\shdocvw.dll - ok
16:54:38.0315 4268  [ 178A34E5554DCE485E1262DDF027960C ] C:\Users\Dieter\AppData\Local\Temp\83C3200F-4C63-4AAE-BCA3-16FB1D3E1E51.exe
16:54:38.0315 4268  C:\Users\Dieter\AppData\Local\Temp\83C3200F-4C63-4AAE-BCA3-16FB1D3E1E51.exe - ok
16:54:38.0315 4268  [ 46863C4CC5B68EB09EA2D5EEF0F1193A ] C:\Windows\System32\radardt.dll
16:54:38.0315 4268  C:\Windows\System32\radardt.dll - ok
16:54:38.0315 4268  [ FBD879D17B26D49DD7A48FF58062FAE6 ] C:\Windows\System32\tdh.dll
16:54:38.0315 4268  C:\Windows\System32\tdh.dll - ok
16:54:38.0315 4268  [ B2DB6ABA2E292235749B80A9C3DFA867 ] C:\Windows\SysWOW64\imagehlp.dll
16:54:38.0315 4268  C:\Windows\SysWOW64\imagehlp.dll - ok
16:54:38.0315 4268  [ BF6D6ED5FADCEEE885BD0144ECF1BA27 ] C:\Windows\SysWOW64\ncrypt.dll
16:54:38.0315 4268  C:\Windows\SysWOW64\ncrypt.dll - ok
16:54:38.0331 4268  [ CE71B9119A258EDD0A05B37D7B0F92E3 ] C:\Windows\SysWOW64\bcrypt.dll
16:54:38.0331 4268  C:\Windows\SysWOW64\bcrypt.dll - ok
16:54:38.0331 4268  [ 10F815BE90A66AAFC6C713D1BD626064 ] C:\Windows\System32\pnidui.dll
16:54:38.0331 4268  C:\Windows\System32\pnidui.dll - ok
16:54:38.0331 4268  [ E8449FE262D7406BCB2AC2A45C53EC5F ] C:\Windows\SysWOW64\bcryptprimitives.dll
16:54:38.0331 4268  C:\Windows\SysWOW64\bcryptprimitives.dll - ok
16:54:38.0331 4268  [ 1097F3035BAF46CED8B332B3564C5108 ] C:\Windows\SysWOW64\gpapi.dll
16:54:38.0331 4268  C:\Windows\SysWOW64\gpapi.dll - ok
16:54:38.0331 4268  [ 8A8B277067C22F4BF6AA9A31692FC4D3 ] C:\Windows\SysWOW64\cryptnet.dll
16:54:38.0331 4268  C:\Windows\SysWOW64\cryptnet.dll - ok
16:54:38.0331 4268  [ 6F8E3B7B70E1BBA871212940C1FBDF60 ] C:\Windows\SysWOW64\SensApi.dll
16:54:38.0331 4268  C:\Windows\SysWOW64\SensApi.dll - ok
16:54:38.0347 4268  [ 1EB82516F21F27EED1833B4F9FD9614E ] C:\Windows\System32\wmp.dll
16:54:38.0347 4268  C:\Windows\System32\wmp.dll - ok
16:54:38.0347 4268  [ 81F6C1AE23B1C493D9E996C3103915D7 ] C:\Windows\SysWOW64\dhcpcsvc6.dll
16:54:38.0347 4268  C:\Windows\SysWOW64\dhcpcsvc6.dll - ok
16:54:38.0347 4268  [ 71AC6DC6BDDA70F1960CA322AC577986 ] C:\Program Files (x86)\Avira\AntiVir Desktop\checkt.exe
16:54:38.0347 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\checkt.exe - ok
16:54:38.0347 4268  [ 5B2E4E90C04FB9AE9F2C5E99FF59B283 ] C:\Windows\SysWOW64\WindowsCodecs.dll
16:54:38.0347 4268  C:\Windows\SysWOW64\WindowsCodecs.dll - ok
16:54:38.0347 4268  [ D872846AC2DE73FAF747315B416F80EA ] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
16:54:38.0347 4268  C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll - ok
16:54:38.0347 4268  [ 53223B673A3FA2F9A4D1C31C8D3F6CD8 ] C:\Windows\SysWOW64\dbghelp.dll
16:54:38.0347 4268  C:\Windows\SysWOW64\dbghelp.dll - ok
16:54:38.0362 4268  [ 846D0E4DB261CFAF363902E41498E961 ] C:\Windows\SysWOW64\EhStorShell.dll
16:54:38.0362 4268  C:\Windows\SysWOW64\EhStorShell.dll - ok
16:54:38.0362 4268  [ 03F3B770DFBED6131653CEDA8CA780F0 ] C:\Windows\SysWOW64\ntshrui.dll
16:54:38.0362 4268  C:\Windows\SysWOW64\ntshrui.dll - ok
16:54:38.0362 4268  [ 465BEA35F7ED4A4A57686DEA7EA10F47 ] C:\Windows\SysWOW64\cscapi.dll
16:54:38.0362 4268  C:\Windows\SysWOW64\cscapi.dll - ok
16:54:38.0362 4268  [ 827CB0D6C3F8057EA037FF271F8E9795 ] C:\Windows\SysWOW64\imageres.dll
16:54:38.0362 4268  C:\Windows\SysWOW64\imageres.dll - ok
16:54:38.0362 4268  [ E83D2495D5867E224FBF42EF40D8856C ] C:\Program Files\DVD Maker\DVDMaker.exe
16:54:38.0362 4268  C:\Program Files\DVD Maker\DVDMaker.exe - ok
16:54:38.0362 4268  [ DF98006F86D2B5A2E81DA778EEEE8223 ] C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
16:54:38.0362 4268  C:\Program Files\Microsoft Office\Office14\EXCEL.EXE - ok
16:54:38.0362 4268  [ 220159496484D34009DE71CA1A68E0D4 ] C:\Windows\System32\wbem\NCProv.dll
16:54:38.0362 4268  C:\Windows\System32\wbem\NCProv.dll - ok
16:54:38.0378 4268  [ 40CAEEE0EAF1B8569F7C8DF6420F2CB9 ] C:\Windows\SysWOW64\sfc.dll
16:54:38.0378 4268  C:\Windows\SysWOW64\sfc.dll - ok
16:54:38.0378 4268  [ 84799328D87B3091A3BDD251E1AD31F9 ] C:\Windows\SysWOW64\sfc_os.dll
16:54:38.0378 4268  C:\Windows\SysWOW64\sfc_os.dll - ok
16:54:38.0378 4268  [ 2C647ABE9A424E55B5F3DAE4629B4277 ] C:\Windows\System32\themeui.dll
16:54:38.0378 4268  C:\Windows\System32\themeui.dll - ok
16:54:38.0378 4268  [ FB10715E4099AF9FA389C71873245226 ] C:\Windows\System32\timedate.cpl
16:54:38.0378 4268  C:\Windows\System32\timedate.cpl - ok
16:54:38.0378 4268  [ E6F0F82788E8BD0F7A616350EFA0761C ] C:\Windows\System32\actxprxy.dll
16:54:38.0378 4268  C:\Windows\System32\actxprxy.dll - ok
16:54:38.0378 4268  [ 22A0AE97360C1B146FDD9AA55AC0E989 ] C:\Windows\System32\shdocvw.dll
16:54:38.0378 4268  C:\Windows\System32\shdocvw.dll - ok
16:54:38.0393 4268  [ A0A65D306A5490D2EB8E7DE66898ECFD ] C:\Windows\System32\linkinfo.dll
16:54:38.0393 4268  C:\Windows\System32\linkinfo.dll - ok
16:54:38.0393 4268  [ 69754747274B76E7FAF287239333D7E6 ] C:\Windows\System32\msiltcfg.dll
16:54:38.0393 4268  C:\Windows\System32\msiltcfg.dll - ok
16:54:38.0393 4268  [ 402065EF5AC87892014682AC7B3E700A ] C:\Program Files (x86)\Avira\AntiVir Desktop\usrreq.exe
16:54:38.0393 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\usrreq.exe - ok
16:54:38.0393 4268  [ 750F9F3C612E07DF26E953096BE7C431 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwitf.dll
16:54:38.0393 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwitf.dll - ok
16:54:38.0393 4268  [ F1AF5DEC108235979561A7AD5B30EF67 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwrc.dll
16:54:38.0393 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwrc.dll - ok
16:54:38.0393 4268  [ B99B707D716DCEF3E91735658D46E239 ] C:\Program Files (x86)\Avira\AntiVir Desktop\rcimage.dll
16:54:38.0393 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\rcimage.dll - ok
16:54:38.0409 4268  [ 1EAC1A8CA6874BF5B15E2EFB9A9A7B86 ] C:\Windows\System32\msftedit.dll
16:54:38.0409 4268  C:\Windows\System32\msftedit.dll - ok
16:54:38.0409 4268  [ 2BCBA6052374959A30BD7948444DBB79 ] C:\Windows\System32\gameux.dll
16:54:38.0409 4268  C:\Windows\System32\gameux.dll - ok
16:54:38.0409 4268  [ 112183DF91C9BAECB498E4A86ECDE598 ] C:\Windows\System32\msls31.dll
16:54:38.0409 4268  C:\Windows\System32\msls31.dll - ok
16:54:38.0409 4268  [ 7DBA84667DC18877AEF693E3543DFAD7 ] C:\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll
16:54:38.0409 4268  C:\Program Files\Common Files\Microsoft Shared\ink\tiptsf.dll - ok
16:54:38.0409 4268  [ 4C2C4640BF23AAFCF90519E0F34436CE ] C:\Windows\System32\DeviceCenter.dll
16:54:38.0409 4268  C:\Windows\System32\DeviceCenter.dll - ok
16:54:38.0409 4268  [ E3BF29CED96790CDAAFA981FFDDF53A3 ] C:\Program Files\Windows Sidebar\sidebar.exe
16:54:38.0409 4268  C:\Program Files\Windows Sidebar\sidebar.exe - ok
16:54:38.0409 4268  [ 405F4D32D2185F1F1BD753D8EEAFFB3A ] C:\Windows\System32\networkexplorer.dll
16:54:38.0409 4268  C:\Windows\System32\networkexplorer.dll - ok
16:54:38.0425 4268  [ B0F69B9DE0AEBFD7E4CEADE6758DF627 ] C:\Windows\System32\SearchFolder.dll
16:54:38.0425 4268  C:\Windows\System32\SearchFolder.dll - ok
16:54:38.0425 4268  [ E835CEDEF0C69A2013E6A210F3DD7879 ] C:\Program Files\Sandboxie\SbieCtrl.exe
16:54:38.0425 4268  C:\Program Files\Sandboxie\SbieCtrl.exe - ok
16:54:38.0425 4268  [ 5F639198C4137075DA50E61C23963C11 ] C:\Windows\System32\drprov.dll
16:54:38.0425 4268  C:\Windows\System32\drprov.dll - ok
16:54:38.0425 4268  [ BC566D17914B07ABAAB3A5A385CC3300 ] C:\Windows\System32\ntlanman.dll
16:54:38.0425 4268  C:\Windows\System32\ntlanman.dll - ok
16:54:38.0425 4268  [ 19F9B524A525D202194247E96656CB88 ] C:\Windows\System32\mfc42u.dll
16:54:38.0425 4268  C:\Windows\System32\mfc42u.dll - ok
16:54:38.0425 4268  [ B3A33600DCDFB84D7FBE09ADEB1C9B8A ] C:\Windows\System32\davclnt.dll
16:54:38.0425 4268  C:\Windows\System32\davclnt.dll - ok
16:54:38.0440 4268  [ 45B24A357C801CE62052FE0CDC8BD4D2 ] C:\Windows\System32\davhlpr.dll
16:54:38.0440 4268  C:\Windows\System32\davhlpr.dll - ok
16:54:38.0440 4268  [ 7FF8E121AFA05BDAB23B9FEDCDAB7A33 ] C:\Windows\System32\odbc32.dll
16:54:38.0440 4268  C:\Windows\System32\odbc32.dll - ok
16:54:38.0440 4268  [ 4E81439902079C348B61D7FF027FE147 ] C:\Windows\System32\StructuredQuery.dll
16:54:38.0440 4268  C:\Windows\System32\StructuredQuery.dll - ok
16:54:38.0440 4268  [ 5C41AF3F4B83340D2783CE8FDE30566A ] C:\Windows\System32\mshtml.dll
16:54:38.0440 4268  C:\Windows\System32\mshtml.dll - ok
16:54:38.0440 4268  [ A2418D3C557C0A0C634DA713A8AC3789 ] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
16:54:38.0440 4268  C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe - ok
16:54:38.0440 4268  [ 3E466073C3B1033FF92ADE9031E3D4A2 ] C:\Windows\System32\odbcint.dll
16:54:38.0440 4268  C:\Windows\System32\odbcint.dll - ok
16:54:38.0456 4268  [ 24081AE1E47A890025A91A25D79EC9B0 ] C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll
16:54:38.0456 4268  C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll - ok
16:54:38.0456 4268  [ 0DBD0CEFC13DBA6394D1A77E4F83F7A2 ] C:\Program Files (x86)\TeamDrive 3\TeamDrive3.exe
16:54:38.0456 4268  C:\Program Files (x86)\TeamDrive 3\TeamDrive3.exe - ok
16:54:38.0456 4268  [ 48BE298F7FD1BEF4D8FBACB04D8D95C4 ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
16:54:38.0456 4268  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe - ok
16:54:38.0456 4268  [ 9ACCBC5891BA51B5B29C1A88F80D4CE3 ] C:\Program Files (x86)\QuickTime\QTTask.exe
16:54:38.0456 4268  C:\Program Files (x86)\QuickTime\QTTask.exe - ok
16:54:38.0456 4268  [ 61E4289E91E88C90478D7F4BEB10DCF7 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
16:54:38.0456 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe - ok
16:54:38.0456 4268  [ A6C29DB53ECA94FA8591C5388D604B82 ] C:\Windows\SysWOW64\msi.dll
16:54:38.0456 4268  C:\Windows\SysWOW64\msi.dll - ok
16:54:38.0471 4268  [ 4C39358EBDD2FFCD9132A30E1EC31E16 ] C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
16:54:38.0471 4268  C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll - ok
16:54:38.0471 4268  [ 9BE95786D648A9D0D31CAF5D98DBE3A2 ] C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll
16:54:38.0471 4268  C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll - ok
16:54:38.0471 4268  [ A9F9D081518AC03A51C1195986076F42 ] C:\Program Files (x86)\iTunes\iTunesHelper.exe
16:54:38.0471 4268  C:\Program Files (x86)\iTunes\iTunesHelper.exe - ok
16:54:38.0471 4268  [ 0B62EEFF9499190E27AE2FD33CBFA25E ] C:\Program Files (x86)\TeamDrive 3\libeay32.dll
16:54:38.0471 4268  C:\Program Files (x86)\TeamDrive 3\libeay32.dll - ok
16:54:38.0471 4268  [ C3761661C17C2248A9379A8FB89E3DE1 ] C:\Windows\System32\stobject.dll
16:54:38.0471 4268  C:\Windows\System32\stobject.dll - ok
16:54:38.0471 4268  [ 8B7CAF43358224AFA75D4C718AC37738 ] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
16:54:38.0471 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe - ok
16:54:38.0487 4268  [ C653D7F4BDC08A06A187BF48050FE23C ] C:\Program Files (x86)\iTunes\iTunesHelper.dll
16:54:38.0487 4268  C:\Program Files (x86)\iTunes\iTunesHelper.dll - ok
16:54:38.0487 4268  [ F832EEEA97CDDA1AF577E721F652A0D1 ] C:\Windows\System32\batmeter.dll
16:54:38.0487 4268  C:\Windows\System32\batmeter.dll - ok
16:54:38.0487 4268  [ AAFD4396ADB37503032E4B2FC8B2F59C ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccguard.dll
16:54:38.0487 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccguard.dll - ok
16:54:38.0487 4268  [ 7717F84F483002815490033BF069DABD ] C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\GdiPlus.dll
16:54:38.0487 4268  C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\GdiPlus.dll - ok
16:54:38.0487 4268  [ E7FC2CFE8953E69D665A4A798F4D69D4 ] C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll
16:54:38.0487 4268  C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll - ok
16:54:38.0487 4268  [ B3CE0951E3C1EA3C733573C472EE85F9 ] C:\Windows\System32\msimtf.dll
16:54:38.0487 4268  C:\Windows\System32\msimtf.dll - ok
16:54:38.0503 4268  [ DC5ECEA062C0633346B6D199FA2B578D ] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
16:54:38.0503 4268  C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe - ok
16:54:38.0503 4268  [ 5CF4033C1967A6C290CF310A2A8539D6 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccgrdrc.dll
16:54:38.0503 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccgrdrc.dll - ok
16:54:38.0503 4268  [ FE4783DA9C7106F903FE3EC5EEE456FD ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccgrdw.dll
16:54:38.0503 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccgrdw.dll - ok
16:54:38.0503 4268  [ F6BE37CCBDAE0D7F3A1F45DE2CD4C792 ] C:\Program Files (x86)\TeamDrive 3\QtWebKit4.dll
16:54:38.0503 4268  C:\Program Files (x86)\TeamDrive 3\QtWebKit4.dll - ok
16:54:38.0503 4268  [ 8A79704F44B43A3A88424325D167D2D6 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccmguard.dll
16:54:38.0503 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccmguard.dll - ok
16:54:38.0503 4268  [ 520320540DD8DF8E8451706D740DB876 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccmgrdrc.dll
16:54:38.0503 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccmgrdrc.dll - ok
16:54:38.0518 4268  [ 6D137963730144698CBD10F202E9F251 ] C:\Windows\System32\wersvc.dll
16:54:38.0518 4268  C:\Windows\System32\wersvc.dll - ok
16:54:38.0518 4268  [ 396D851E3B6ECB9990718C25567ABBB9 ] C:\Windows\System32\jscript9.dll
16:54:38.0518 4268  C:\Windows\System32\jscript9.dll - ok
16:54:38.0518 4268  [ D20694A22D5A570C31D050EDCF0678B1 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccwgrd.dll
16:54:38.0518 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccwgrd.dll - ok
16:54:38.0518 4268  [ 18C73C745E93E0991F5FAF804B6D2C32 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccwgrdrc.dll
16:54:38.0518 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccwgrdrc.dll - ok
16:54:38.0518 4268  [ D5FF44124F7D08A6B1C7B6A751AF4606 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccwgrdw.dll
16:54:38.0518 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccwgrdw.dll - ok
16:54:38.0518 4268  [ 2D2A6EC8EAD30EC3ACE2FD6FB1B3E122 ] C:\Windows\System32\prnfldr.dll
16:54:38.0518 4268  C:\Windows\System32\prnfldr.dll - ok
16:54:38.0534 4268  [ DD81D91FF3B0763C392422865C9AC12E ] C:\Windows\System32\rundll32.exe
16:54:38.0534 4268  C:\Windows\System32\rundll32.exe - ok
16:54:38.0534 4268  [ 5E0B7296A2A274282F827CB48FF112D7 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwmgt.dll
16:54:38.0534 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwmgt.dll - ok
16:54:38.0534 4268  [ B7E2DE7B0D1203DC90686391CF317D2B ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwmgtrc.dll
16:54:38.0534 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwmgtrc.dll - ok
16:54:38.0534 4268  [ 2A436796758BF2555A26C770FE8A6FEE ] C:\Windows\System32\fdProxy.dll
16:54:38.0534 4268  C:\Windows\System32\fdProxy.dll - ok
16:54:38.0534 4268  [ 4BC63466E104393AE3A4729B8122D299 ] C:\Program Files (x86)\Common Files\LogiShrd\LWSPlugins\LWS\Applets\HelpMain\Main_help.dll
16:54:38.0534 4268  C:\Program Files (x86)\Common Files\LogiShrd\LWSPlugins\LWS\Applets\HelpMain\Main_help.dll - ok
16:54:38.0534 4268  [ BB9E0701C9D36A61B9DEA240A90C8C51 ] C:\Program Files (x86)\Avira\AntiVir Desktop\firewall.dll
16:54:38.0534 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\firewall.dll - ok
16:54:38.0549 4268  [ 58D7E236009D65D16DD716F00840B48C ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwgnt.dll
16:54:38.0549 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccfwgnt.dll - ok
16:54:38.0549 4268  [ CE835F65E2BCA03CE380575DEB04805A ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccgen.dll
16:54:38.0549 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccgen.dll - ok
16:54:38.0549 4268  [ A7F558D0CFEA4A2FA81311D3575EB486 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccgenrc.dll
16:54:38.0549 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccgenrc.dll - ok
16:54:38.0549 4268  [ 5E7C782015199702590C432557571ADD ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccupdate.dll
16:54:38.0549 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccupdate.dll - ok
16:54:38.0549 4268  [ F090D5FEB7D6E196EC30EEC641C3A44A ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccupdrc.dll
16:54:38.0549 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccupdrc.dll - ok
16:54:38.0549 4268  [ 2BFC8C6268A3A0EC1E6822A393486285 ] C:\Program Files (x86)\Avira\AntiVir Desktop\cclic.dll
16:54:38.0549 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\cclic.dll - ok
16:54:38.0565 4268  [ C83470111578D3039DB619529AF40720 ] C:\Program Files (x86)\iTunes\iTunesHelper.Resources\iTunesHelper.dll
16:54:38.0565 4268  C:\Program Files (x86)\iTunes\iTunesHelper.Resources\iTunesHelper.dll - ok
16:54:38.0565 4268  [ 8FAD04A00BFE6977AA4743C067364B5F ] C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
16:54:38.0565 4268  C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll - ok
16:54:38.0565 4268  [ CD6C3415F23554D77AB0980DA16E9FF0 ] C:\Program Files (x86)\Avira\AntiVir Desktop\cclicrc.dll
16:54:38.0565 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\cclicrc.dll - ok
16:54:38.0565 4268  [ 13820B972D74B3DE4F6552A57AC799A7 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon_main.dll
16:54:38.0565 4268  C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon_main.dll - ok
16:54:38.0565 4268  [ 42A9CB6906D9A8BEDC83B57163E62924 ] C:\Windows\System32\DXP.dll
16:54:38.0565 4268  C:\Windows\System32\DXP.dll - ok
16:54:38.0581 4268  [ C68804336475DB18DD636970866E8B8F ] C:\Program Files (x86)\iTunes\iTunesHelper.Resources\de.lproj\iTunesHelperLocalized.dll
16:54:38.0581 4268  C:\Program Files (x86)\iTunes\iTunesHelper.Resources\de.lproj\iTunesHelperLocalized.dll - ok
16:54:38.0581 4268  [ 5C938FD3DD5FC24BD16DF15336E80370 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccmsg.dll
16:54:38.0581 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccmsg.dll - ok
16:54:38.0581 4268  [ F9ABABFE24F243A6BB8D785F2ECB97A9 ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccmsgrc.dll
16:54:38.0581 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccmsgrc.dll - ok
16:54:38.0581 4268  [ 58B8702C20DE211D1FCB248D2FDD71D1 ] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\reader_sl.exe
16:54:38.0581 4268  C:\Program Files (x86)\Adobe\Reader 11.0\Reader\reader_sl.exe - ok
16:54:38.0581 4268  [ CEF58ABD7D7CC34431C9AD79D123F37D ] C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
16:54:38.0581 4268  C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll - ok
16:54:38.0581 4268  [ 24F4B480F335A6C724AF352253C5D98B ] C:\Windows\System32\thumbcache.dll
16:54:38.0581 4268  C:\Windows\System32\thumbcache.dll - ok
16:54:38.0596 4268  [ AB2F2F56064E8AA8634C790956860A3D ] C:\Windows\System32\ieframe.dll
16:54:38.0596 4268  C:\Windows\System32\ieframe.dll - ok
16:54:38.0596 4268  [ 2BC7C9FD0A9F2C9AFC373F3AD1EE3891 ] C:\Windows\System32\Syncreg.dll
16:54:38.0596 4268  C:\Windows\System32\Syncreg.dll - ok
16:54:38.0596 4268  [ 2E13FFCDF44F4713084898781DE3A34C ] C:\Program Files (x86)\Avira\AntiVir Desktop\ccmainrc.dll
16:54:38.0596 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\ccmainrc.dll - ok
16:54:38.0596 4268  [ C836175870E00ACC546066632E15BD10 ] C:\Windows\ehome\ehSSO.dll
16:54:38.0596 4268  C:\Windows\ehome\ehSSO.dll - ok
16:54:38.0596 4268  [ 92DBF0A4C9239169010FC6E07859C82E ] C:\Windows\System32\ActionCenter.dll
16:54:38.0596 4268  C:\Windows\System32\ActionCenter.dll - ok
16:54:38.0596 4268  [ C8FDF0FA9E97E2FAAF3F814716AAA881 ] C:\Windows\System32\WPDShServiceObj.dll
16:54:38.0596 4268  C:\Windows\System32\WPDShServiceObj.dll - ok
16:54:38.0596 4268  [ 4F3CD1C59EA71401E155C432BCECE180 ] C:\Windows\System32\PortableDeviceTypes.dll
16:54:38.0596 4268  C:\Windows\System32\PortableDeviceTypes.dll - ok
16:54:38.0612 4268  [ 9108540E866F75C7AF2B91DD921A8091 ] C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
16:54:38.0612 4268  C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll - ok
16:54:38.0612 4268  [ 8569E35D00F45972E506502EEE622BA4 ] C:\Windows\System32\srchadmin.dll
16:54:38.0612 4268  C:\Windows\System32\srchadmin.dll - ok
16:54:38.0612 4268  [ AD594EEC1DA1EC54E90E21D174C12F9A ] C:\Program Files (x86)\TeamDrive 3\QtGui4.dll
16:54:38.0612 4268  C:\Program Files (x86)\TeamDrive 3\QtGui4.dll - ok
16:54:38.0612 4268  [ E7368F0A8D19445EAF5C5D0DBB8B8DAB ] C:\Windows\System32\AltTab.dll
16:54:38.0612 4268  C:\Windows\System32\AltTab.dll - ok
16:54:38.0612 4268  [ B9F0A4020AA98B7A20287BF7FE99A1FD ] C:\Windows\System32\QUTIL.DLL
16:54:38.0612 4268  C:\Windows\System32\QUTIL.DLL - ok
16:54:38.0612 4268  [ F7A256EC899C72B4ECDD2C02CB592EFD ] C:\Windows\System32\bthprops.cpl
16:54:38.0612 4268  C:\Windows\System32\bthprops.cpl - ok
16:54:38.0627 4268  [ 7E8A672B7B06A6EB11960C22E0360C59 ] C:\Windows\System32\d2d1.dll
16:54:38.0627 4268  C:\Windows\System32\d2d1.dll - ok
16:54:38.0627 4268  [ A63DC5C2EA944E6657203E0C8EDEAF61 ] C:\Windows\SysWOW64\dllhost.exe
16:54:38.0627 4268  C:\Windows\SysWOW64\dllhost.exe - ok
16:54:38.0627 4268  [ BC0D4AFBE94D8E1F81C8926D805C3366 ] C:\Windows\System32\webcheck.dll
16:54:38.0627 4268  C:\Windows\System32\webcheck.dll - ok
16:54:38.0627 4268  [ 8494E126F0B10180F3293AF861CE1F7A ] C:\Windows\System32\mlang.dll
16:54:38.0627 4268  C:\Windows\System32\mlang.dll - ok
16:54:38.0627 4268  [ 63BB89DED1E9104E68D33E54DE4D340D ] C:\Windows\System32\DWrite.dll
16:54:38.0627 4268  C:\Windows\System32\DWrite.dll - ok
16:54:38.0627 4268  [ CD667576186A124E4753DDF46C97F6AA ] C:\Program Files (x86)\TeamDrive 3\QtCore4.dll
16:54:38.0627 4268  C:\Program Files (x86)\TeamDrive 3\QtCore4.dll - ok
16:54:38.0643 4268  [ 37CF3324F46CEB3A4F2686C617CBB35C ] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll
16:54:38.0643 4268  C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll - ok
16:54:38.0643 4268  [ 101797BA603D227946B4B5109867EB19 ] C:\Windows\System32\SyncCenter.dll
16:54:38.0643 4268  C:\Windows\System32\SyncCenter.dll - ok
16:54:38.0643 4268  [ 50F9394F53CF8015C703EBD2EF3BABC6 ] C:\Windows\System32\LocationApi.dll
16:54:38.0643 4268  C:\Windows\System32\LocationApi.dll - ok
16:54:38.0643 4268  [ 9111354A308612483F8DA995A1DD1835 ] C:\Windows\System32\SensorsApi.dll
16:54:38.0643 4268  C:\Windows\System32\SensorsApi.dll - ok
16:54:38.0643 4268  [ 10035E4C014522FE740172FF0B4FF43E ] C:\Windows\ehome\ehtray.exe
16:54:38.0643 4268  C:\Windows\ehome\ehtray.exe - ok
16:54:38.0643 4268  [ 8130391F82D52D36C0441F714136957F ] C:\Windows\System32\imapi2.dll
16:54:38.0643 4268  C:\Windows\System32\imapi2.dll - ok
16:54:38.0643 4268  [ 2CA0FD413772FBA00BF10B5FD889459A ] C:\Program Files (x86)\TeamDrive 3\QtNetwork4.dll
16:54:38.0643 4268  C:\Program Files (x86)\TeamDrive 3\QtNetwork4.dll - ok
16:54:38.0659 4268  [ D2155709E336C3BC15729EB87FEC6064 ] C:\Windows\System32\rasdlg.dll
16:54:38.0659 4268  C:\Windows\System32\rasdlg.dll - ok
16:54:38.0659 4268  [ 6A5C1A8AC0B572679361026D0E900420 ] C:\Windows\System32\hgcpl.dll
16:54:38.0659 4268  C:\Windows\System32\hgcpl.dll - ok
16:54:38.0659 4268  [ 39146BAB94F7B0E840F82CE2CEC74334 ] C:\Program Files (x86)\TeamDrive 3\QtScript4.dll
16:54:38.0659 4268  C:\Program Files (x86)\TeamDrive 3\QtScript4.dll - ok
16:54:38.0659 4268  [ 4F4C283C375CF2CF263390C50BD675AF ] C:\Program Files (x86)\TeamDrive 3\QtSql4.dll
16:54:38.0659 4268  C:\Program Files (x86)\TeamDrive 3\QtSql4.dll - ok
16:54:38.0659 4268  [ C498EF41B93986BCBD483597573EB96D ] C:\Windows\System32\d3d10warp.dll
16:54:38.0659 4268  C:\Windows\System32\d3d10warp.dll - ok
16:54:38.0659 4268  [ C746F3BF98E92FB137B5BD2B8B5925BD ] C:\Windows\System32\FXSST.dll
16:54:38.0659 4268  C:\Windows\System32\FXSST.dll - ok
16:54:38.0674 4268  [ 0FF335D687C85097725A53458160E81E ] C:\Program Files\iPod\bin\iPodService.exe
16:54:38.0674 4268  C:\Program Files\iPod\bin\iPodService.exe - ok
16:54:38.0674 4268  [ 9CD3D8DEA7AC093B53CE2B556A387319 ] C:\Program Files (x86)\TeamDrive 3\QtXmlPatterns4.dll
16:54:38.0674 4268  C:\Program Files (x86)\TeamDrive 3\QtXmlPatterns4.dll - ok
16:54:38.0674 4268  [ 75EAA6150FD1D7B0C042A1A48AEF1752 ] C:\Program Files\iPod\bin\iPodService.Resources\iPodService.dll
16:54:38.0674 4268  C:\Program Files\iPod\bin\iPodService.Resources\iPodService.dll - ok
16:54:38.0674 4268  [ 650CAEA856943E29F25A25D31E004B18 ] C:\Windows\System32\FXSAPI.dll
16:54:38.0674 4268  C:\Windows\System32\FXSAPI.dll - ok
16:54:38.0674 4268  [ 13CC69C104811026DCEA334911BEC835 ] C:\Program Files\iPod\bin\iPodService.Resources\de.lproj\iPodServiceLocalized.dll
16:54:38.0674 4268  C:\Program Files\iPod\bin\iPodService.Resources\de.lproj\iPodServiceLocalized.dll - ok
16:54:38.0674 4268  [ F9AFD12BB4B1CFA5FCC0A5B37C604FD2 ] C:\Windows\System32\dot3api.dll
16:54:38.0674 4268  C:\Windows\System32\dot3api.dll - ok
16:54:38.0690 4268  [ E4FCA0F99A41E460C84016DEFD31E6EF ] C:\Windows\System32\wlanhlp.dll
16:54:38.0690 4268  C:\Windows\System32\wlanhlp.dll - ok
16:54:38.0690 4268  [ B7D3A1185C23A129072AC3D93C1052FB ] C:\Program Files (x86)\TeamDrive 3\QtXml4.dll
16:54:38.0690 4268  C:\Program Files (x86)\TeamDrive 3\QtXml4.dll - ok
16:54:38.0690 4268  [ C8E8B8239FCF17BEA10E751BE5854631 ] C:\Windows\System32\FXSRESM.dll
16:54:38.0690 4268  C:\Windows\System32\FXSRESM.dll - ok
16:54:38.0690 4268  [ 4CFBEC37E4FAD530E623E1541E1EA958 ] C:\Windows\System32\vbscript.dll
16:54:38.0690 4268  C:\Windows\System32\vbscript.dll - ok
16:54:38.0690 4268  [ 357BE883C5236BFC7341CB9E82308908 ] C:\Windows\System32\wlanapi.dll
16:54:38.0690 4268  C:\Windows\System32\wlanapi.dll - ok
16:54:38.0690 4268  [ 919001D2BB17DF06CA3F8AC16AD039F6 ] C:\Windows\SysWOW64\sxs.dll
16:54:38.0690 4268  C:\Windows\SysWOW64\sxs.dll - ok
16:54:38.0705 4268  [ 0438CAB2E03F4FB61455A7956026FE86 ] C:\Windows\System32\fdPHost.dll
16:54:38.0705 4268  C:\Windows\System32\fdPHost.dll - ok
16:54:38.0705 4268  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] C:\Windows\System32\FXSSVC.exe
16:54:38.0705 4268  C:\Windows\System32\FXSSVC.exe - ok
16:54:38.0705 4268  [ F492180314252BBB9687510490EC7921 ] C:\Program Files (x86)\TeamDrive 3\ssleay32.dll
16:54:38.0705 4268  C:\Program Files (x86)\TeamDrive 3\ssleay32.dll - ok
16:54:38.0705 4268  [ 802496CB59A30349F9A6DD22D6947644 ] C:\Windows\System32\FDResPub.dll
16:54:38.0705 4268  C:\Windows\System32\FDResPub.dll - ok
16:54:38.0705 4268  [ 171D7DB433314A868507C4326E8209DC ] C:\Windows\System32\fdWSD.dll
16:54:38.0705 4268  C:\Windows\System32\fdWSD.dll - ok
16:54:38.0705 4268  [ 3D2D108E14AD21889A2621B94C80A3DD ] C:\Windows\System32\tzres.dll
16:54:38.0705 4268  C:\Windows\System32\tzres.dll - ok
16:54:38.0721 4268  [ 3E130FA0D5289C8812021FF57F3851F5 ] C:\Program Files\Internet Explorer\sqmapi.dll
16:54:38.0721 4268  C:\Program Files\Internet Explorer\sqmapi.dll - ok
16:54:38.0721 4268  [ A2E5B2D20954210DCE1A75A1FC8CC36D ] C:\Windows\System32\fdSSDP.dll
16:54:38.0721 4268  C:\Windows\System32\fdSSDP.dll - ok
16:54:38.0721 4268  [ A6C09924C6730DE8DEED9890A12AA691 ] C:\Windows\System32\ddraw.dll
16:54:38.0721 4268  C:\Windows\System32\ddraw.dll - ok
16:54:38.0721 4268  [ 29C22748937F45C26590909E9F8E7137 ] C:\Windows\System32\dciman32.dll
16:54:38.0721 4268  C:\Windows\System32\dciman32.dll - ok
16:54:38.0721 4268  [ 8DA3E4ABA5A229C7F3DFD01576287FD8 ] C:\Program Files (x86)\Avira\AntiVir Desktop\cclicw.dll
16:54:38.0721 4268  C:\Program Files (x86)\Avira\AntiVir Desktop\cclicw.dll - ok
16:54:38.0721 4268  [ 26A46AED813A3BC39FC61AF68EBFA8F9 ] C:\Program Files (x86)\TeamDrive 3\plugins\bearer\qgenericbearer4.dll
16:54:38.0721 4268  C:\Program Files (x86)\TeamDrive 3\plugins\bearer\qgenericbearer4.dll - ok
16:54:38.0721 4268  [ 8A9B76907E3AA0C5A764C15C9EB5E647 ] C:\Windows\System32\nvd3dumx.dll
16:54:38.0721 4268  C:\Windows\System32\nvd3dumx.dll - ok
16:54:38.0737 4268  [ 51222CBDEF9834A12AC765A8BAA8EE3A ] C:\Program Files (x86)\TeamDrive 3\plugins\bearer\qnativewifibearer4.dll
16:54:38.0737 4268  C:\Program Files (x86)\TeamDrive 3\plugins\bearer\qnativewifibearer4.dll - ok
16:54:38.0737 4268  [ 6699A112A3BDC9B52338512894EBA9D6 ] C:\Program Files\Windows Media Player\wmpnscfg.exe
16:54:38.0737 4268  C:\Program Files\Windows Media Player\wmpnscfg.exe - ok
16:54:38.0737 4268  [ B010CF886420EE29C2C276646721D255 ] C:\Windows\SysWOW64\wlanapi.dll
16:54:38.0737 4268  C:\Windows\SysWOW64\wlanapi.dll - ok
16:54:38.0737 4268  [ 5DA219F57A9076FB6FBD3C9C3713A672 ] C:\Windows\System32\WWanAPI.dll
16:54:38.0737 4268  C:\Windows\System32\WWanAPI.dll - ok
16:54:38.0737 4268  [ 62C7AACC746C9723468A8F2169ED3E85 ] C:\Windows\System32\wwapi.dll
16:54:38.0737 4268  C:\Windows\System32\wwapi.dll - ok
16:54:38.0737 4268  [ 1D6A771D1D702AE07919DB52C889A249 ] C:\Windows\SysWOW64\wlanutil.dll
16:54:38.0737 4268  C:\Windows\SysWOW64\wlanutil.dll - ok
16:54:38.0752 4268  [ 6B851E682A36453E1B1EE297FFB6E2AB ] C:\Windows\System32\QAGENT.DLL
16:54:38.0752 4268  C:\Windows\System32\QAGENT.DLL - ok
16:54:38.0752 4268  [ 20DB4C9D3DF83DD5F302FBEF5D3DA6B7 ] C:\Program Files (x86)\TeamDrive 3\plugins\sqldrivers\qsqlite4.dll
16:54:38.0752 4268  C:\Program Files (x86)\TeamDrive 3\plugins\sqldrivers\qsqlite4.dll - ok
16:54:38.0752 4268  [ B6411CED931AFD059E48C52DBFBA95B4 ] C:\Windows\System32\P2P.dll
16:54:38.0752 4268  C:\Windows\System32\P2P.dll - ok
16:54:38.0752 4268  [ EFDFB3DD38A4376F93E7985173813ABD ] C:\Windows\System32\ListSvc.dll
16:54:38.0752 4268  C:\Windows\System32\ListSvc.dll - ok
16:54:38.0752 4268  [ 0EFFB318E02F3DFC5260AE0E8F64DC59 ] C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy.dll
16:54:38.0752 4268  C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy.dll - ok
16:54:38.0752 4268  [ 4A82EA2807B16FF577AEAF8ADB8779FF ] C:\Windows\System32\IdListen.dll
16:54:38.0752 4268  C:\Windows\System32\IdListen.dll - ok
16:54:38.0768 4268  [ FAD7BE100E4A865B0C94641E11E4C64D ] C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qgif4.dll
16:54:38.0768 4268  C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qgif4.dll - ok
16:54:38.0768 4268  [ 2E76FF14C5987BE45AB65A91332E3C58 ] C:\Program Files\Windows Sidebar\wlsrvc.dll
16:54:38.0768 4268  C:\Program Files\Windows Sidebar\wlsrvc.dll - ok
16:54:38.0768 4268  [ 527FE7AE5234D40C128276153401E773 ] C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qico4.dll
16:54:38.0768 4268  C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qico4.dll - ok
16:54:38.0768 4268  [ 552752470023E7E83EF602C289CE1215 ] C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qjpeg4.dll
16:54:38.0768 4268  C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qjpeg4.dll - ok
16:54:38.0768 4268  [ AC107B82D8900B7387DC77A0906A40E5 ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\ti_managers.dll
16:54:38.0768 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\ti_managers.dll - ok
16:54:38.0768 4268  [ F146E2BA475893DD77B2370DC1211FC6 ] C:\Windows\System32\drivers\21935323.sys
16:54:38.0768 4268  C:\Windows\System32\drivers\21935323.sys - ok
16:54:38.0783 4268  [ 96464A0E431FE9BC189B22D90E3192C9 ] C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qmng4.dll
16:54:38.0783 4268  C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qmng4.dll - ok
16:54:38.0783 4268  [ 3EAC4455472CC2C97107B5291E0DCAFE ] C:\Windows\System32\pnrpsvc.dll
16:54:38.0783 4268  C:\Windows\System32\pnrpsvc.dll - ok
16:54:38.0783 4268  [ A0524499F4C63CADA7E1529FC77F5DC1 ] C:\Windows\System32\hgprint.dll
16:54:38.0783 4268  C:\Windows\System32\hgprint.dll - ok
16:54:38.0783 4268  [ 55CF79F0D3E64EED4E5600B95C3DC293 ] C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qsvg4.dll
16:54:38.0783 4268  C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qsvg4.dll - ok
16:54:38.0783 4268  [ B68866D271BD782243725A34E2ABB670 ] C:\Program Files (x86)\TeamDrive 3\QtSvg4.dll
16:54:38.0783 4268  C:\Program Files (x86)\TeamDrive 3\QtSvg4.dll - ok
16:54:38.0799 4268  [ A5BE518E515EF80EFD10B6727F31E366 ] C:\Program Files\Internet Explorer\ieproxy.dll
16:54:38.0799 4268  C:\Program Files\Internet Explorer\ieproxy.dll - ok
16:54:38.0799 4268  [ F91A1FB57B5829F8C2F6412C78C68150 ] C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qtiff4.dll
16:54:38.0799 4268  C:\Program Files (x86)\TeamDrive 3\plugins\imageformats\qtiff4.dll - ok
16:54:38.0799 4268  [ 5987EA8A82C53359BCD2C29D6588583E ] C:\Windows\SysWOW64\linkinfo.dll
16:54:38.0799 4268  C:\Windows\SysWOW64\linkinfo.dll - ok
16:54:38.0799 4268  [ 85EB058B89AF29B8363FB6C87B46C91C ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\icu38.dll
16:54:38.0799 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\icu38.dll - ok
16:54:38.0799 4268  [ 82D4F801AB1C3D652C5F69A5E13033B7 ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\icudt38.dll
16:54:38.0799 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\icudt38.dll - ok
16:54:38.0799 4268  [ 102CF6879887BBE846A00C459E6D4ABC ] C:\Windows\SysWOW64\riched20.dll
16:54:38.0799 4268  C:\Windows\SysWOW64\riched20.dll - ok
16:54:38.0815 4268  [ E2A17BCC08D92F42E08AF6BA2F93ABA7 ] C:\Windows\SysWOW64\ExplorerFrame.dll
16:54:38.0815 4268  C:\Windows\SysWOW64\ExplorerFrame.dll - ok
16:54:38.0815 4268  [ 58A0183E67E1F90D46826B2E9E136E01 ] C:\Program Files (x86)\Acronis\TrueImageHome\Common\sync_agent_api.dll
16:54:38.0815 4268  C:\Program Files (x86)\Acronis\TrueImageHome\Common\sync_agent_api.dll - ok
16:54:38.0815 4268  [ BDB6AF90FDA3FFFF75A0E27A8A61D892 ] C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy_stub.dll
16:54:38.0815 4268  C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy_stub.dll - ok
16:54:38.0815 4268  [ 6E1F8165C365D35C8E3C045AF0CDD481 ] C:\Windows\SysWOW64\duser.dll
16:54:38.0815 4268  C:\Windows\SysWOW64\duser.dll - ok
16:54:38.0815 4268  [ EE06B85BC69F18826302348A2AD089E0 ] C:\Windows\SysWOW64\dui70.dll
16:54:38.0815 4268  C:\Windows\SysWOW64\dui70.dll - ok
16:54:38.0815 4268  [ 04CB7C8FDC6D9640DD82A527208F72C4 ] C:\Windows\System32\UIAnimation.dll
16:54:38.0815 4268  C:\Windows\System32\UIAnimation.dll - ok
16:54:38.0815 4268  [ C7494C67A6BF6FE914808E42F8265FEF ] C:\Program Files\Windows Media Player\wmpnssci.dll
16:54:38.0815 4268  C:\Program Files\Windows Media Player\wmpnssci.dll - ok
16:54:38.0815 4268  [ 5CC7AF82752165A2A966BF557E2C7EB5 ] C:\Windows\ehome\ehProxy.dll
16:54:38.0815 4268  C:\Windows\ehome\ehProxy.dll - ok
16:54:38.0830 4268  [ 368A9F6BB589BAD67A55AD4C6A1C9BA8 ] C:\Program Files (x86)\TwonkyMedia\plugins\auto-update-plugin.exe
16:54:38.0830 4268  C:\Program Files (x86)\TwonkyMedia\plugins\auto-update-plugin.exe - ok
16:54:38.0830 4268  [ DFFAE10E3A1B0C664B9383B7C1809B0A ] C:\Windows\ehome\ehrec.exe
16:54:38.0830 4268  C:\Windows\ehome\ehrec.exe - ok
16:54:38.0830 4268  [ 02CD5B2C3B017122CAC00BDB520CD7AC ] C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
16:54:38.0830 4268  C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll - ok
16:54:38.0830 4268  [ 24767A050E072FEF97F4EA1D9B237C44 ] C:\Program Files (x86)\TwonkyMedia\plugins\iTunes-import.exe
16:54:38.0830 4268  C:\Program Files (x86)\TwonkyMedia\plugins\iTunes-import.exe - ok
16:54:38.0830 4268  [ DD502A2E7B85EA7A3814C1034E6C23D3 ] C:\Windows\AppPatch\AcGenral.dll
16:54:38.0830 4268  C:\Windows\AppPatch\AcGenral.dll - ok
16:54:38.0830 4268  [ 85683DF1F917E4D7F6BE1A04986BF1C8 ] C:\Windows\SysWOW64\msacm32.dll
16:54:38.0830 4268  C:\Windows\SysWOW64\msacm32.dll - ok
16:54:38.0846 4268  [ 271B0A9B81B186BA1DDA2E19DDF20C90 ] C:\Program Files (x86)\TwonkyMedia\plugins\mediafusion-integration-plugin.exe
16:54:38.0846 4268  C:\Program Files (x86)\TwonkyMedia\plugins\mediafusion-integration-plugin.exe - ok
16:54:38.0846 4268  [ E19AD0D49BFF5938B3E374873AC174DE ] C:\Windows\System32\wmploc.DLL
16:54:38.0846 4268  C:\Windows\System32\wmploc.DLL - ok
16:54:38.0846 4268  [ 355A138ABDFD43FBABCAE3A1B06AB93D ] C:\Windows\System32\wmpps.dll
16:54:38.0846 4268  C:\Windows\System32\wmpps.dll - ok
16:54:38.0846 4268  [ F149E8CAE538DBF7059B00326673F602 ] C:\Windows\System32\wmpmde.dll
16:54:38.0846 4268  C:\Windows\System32\wmpmde.dll - ok
16:54:38.0846 4268  [ 2C1BB3AD51826AA96C9802CBC123814F ] C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\51a23687fdafc32b697f5a719e364651\mscorlib.ni.dll
16:54:38.0846 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\51a23687fdafc32b697f5a719e364651\mscorlib.ni.dll - ok
16:54:38.0846 4268  [ 021287C2050FD5DB4A8B084E2C38139C ] C:\Windows\System32\WinSATAPI.dll
16:54:38.0846 4268  C:\Windows\System32\WinSATAPI.dll - ok
16:54:38.0861 4268  [ 28A7D7C7E2FDD1D55F12F750CD6331EC ] C:\Windows\System32\MSMPEG2ENC.DLL
16:54:38.0861 4268  C:\Windows\System32\MSMPEG2ENC.DLL - ok
16:54:38.0861 4268  [ 3AD59C6B34AEF8E93633167A1D4A5173 ] C:\Windows\assembly\NativeImages_v2.0.50727_64\ehCIR\5d2b1c09deb32f6b0bca3adb1d1acd6d\ehCIR.ni.dll
16:54:38.0861 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\ehCIR\5d2b1c09deb32f6b0bca3adb1d1acd6d\ehCIR.ni.dll - ok
16:54:38.0861 4268  [ F5C8C77C482EC73BBBD298170424BDCE ] C:\Windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\48351cf5a8a89aed48e08ae15c4fc8b0\ehRecObj.ni.dll
16:54:38.0861 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\ehRecObj\48351cf5a8a89aed48e08ae15c4fc8b0\ehRecObj.ni.dll - ok
16:54:38.0861 4268  [ 619A67C9F617B7E69315BB28ECD5E1DF ] C:\Windows\System32\wbem\WmiPrvSE.exe
16:54:38.0861 4268  C:\Windows\System32\wbem\WmiPrvSE.exe - ok
16:54:38.0861 4268  [ BF3BA1CFBB4629B9024EC904522B403A ] C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\d2ebd0d61ee21c0efb51dc960547e649\ehiProxy.ni.dll
16:54:38.0861 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\ehiProxy\d2ebd0d61ee21c0efb51dc960547e649\ehiProxy.ni.dll - ok
16:54:38.0861 4268  [ 02B2888170A5D6057D504DE15EF829FE ] C:\Windows\assembly\NativeImages_v2.0.50727_64\mcepg\e6390cafa2bfca3745a3410d0e988482\mcepg.ni.dll
16:54:38.0861 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\mcepg\e6390cafa2bfca3745a3410d0e988482\mcepg.ni.dll - ok
16:54:38.0877 4268  [ 07AD88DF9EF73215458867EFC1BFFE9E ] C:\Windows\System32\wbem\wmiprov.dll
16:54:38.0877 4268  C:\Windows\System32\wbem\wmiprov.dll - ok
16:54:38.0877 4268  [ 9682D5B9D9309377C1A7E08C3E6B7B3D ] C:\Windows\assembly\NativeImages_v2.0.50727_64\System\6be6efa1e2ffc9d46e99839edac5c5a8\System.ni.dll
16:54:38.0877 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\System\6be6efa1e2ffc9d46e99839edac5c5a8\System.ni.dll - ok
16:54:38.0877 4268  [ 67E233068D4C4873AC225A0B8A8F2141 ] C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstore\27eb6ffce4ae8cfbc12e1e0503e3c0a2\mcstore.ni.dll
16:54:38.0877 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstore\27eb6ffce4ae8cfbc12e1e0503e3c0a2\mcstore.ni.dll - ok
16:54:38.0877 4268  [ CCFB9AD8CE9FAB08ACB99DB92B1DCE9D ] C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\723ae04dd9a625af72e04d978e5422db\Microsoft.MediaCenter.UI.ni.dll
16:54:38.0877 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.MediaCent#\723ae04dd9a625af72e04d978e5422db\Microsoft.MediaCenter.UI.ni.dll - ok
16:54:38.0877 4268  [ 0428E8993F397320F31EB1282059828D ] C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\1b316687fc4b2ebbdce0c36b3799ddf4\mcstoredb.ni.dll
16:54:38.0877 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\mcstoredb\1b316687fc4b2ebbdce0c36b3799ddf4\mcstoredb.ni.dll - ok
16:54:38.0893 4268  [ D32088C67317F5B64C13352E6EB5FFB1 ] C:\Windows\assembly\GAC_64\mcstoredb\6.1.0.0__31bf3856ad364e35\mcstoredb.dll
16:54:38.0893 4268  C:\Windows\assembly\GAC_64\mcstoredb\6.1.0.0__31bf3856ad364e35\mcstoredb.dll - ok
16:54:38.0893 4268  [ CDAD3376DFF3D9AC7FDCBE2B94B0D3C8 ] C:\Windows\System32\shfolder.dll
16:54:38.0893 4268  C:\Windows\System32\shfolder.dll - ok
16:54:38.0893 4268  [ 1B1431D9520C7578AD5633ED2A70625F ] C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
16:54:38.0893 4268  C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll - ok
16:54:38.0893 4268  [ 71E68F2443A80BD4DA89181889C457EA ] C:\Windows\System32\udhisapi.dll
16:54:38.0893 4268  C:\Windows\System32\udhisapi.dll - ok
16:54:38.0893 4268  [ AA61A7047E854A9E914FDD17C2F35675 ] C:\Windows\System32\sqlceoledb30.dll
16:54:38.0893 4268  C:\Windows\System32\sqlceoledb30.dll - ok
16:54:38.0893 4268  [ 9C75CB8B98610F0CD85D99BB5876308B ] C:\Windows\System32\sqlcese30.dll
16:54:38.0893 4268  C:\Windows\System32\sqlcese30.dll - ok
16:54:38.0893 4268  [ E5744D18C88737C6356D0A8D6D49D512 ] C:\Windows\System32\sqlceqp30.dll
16:54:38.0893 4268  C:\Windows\System32\sqlceqp30.dll - ok
16:54:38.0908 4268  [ DC3E0DFB43ED05FF8290B38E3F94C0DE ] C:\Windows\ehome\ehepgres.dll
16:54:38.0908 4268  C:\Windows\ehome\ehepgres.dll - ok
16:54:38.0908 4268  [ 536DC83D6A53C0AFA9C62B92624414AC ] C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\30429364cdd65e4d7dfdcf10319eef6a\System.Xml.ni.dll
16:54:38.0908 4268  C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\30429364cdd65e4d7dfdcf10319eef6a\System.Xml.ni.dll - ok
16:54:38.0908 4268  [ 7B7E8D545A6DCB8CE67B5AD5AC26A565 ] C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe
16:54:38.0908 4268  C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe - ok
16:54:38.0908 4268  [ 8BD764766AF457C10E62837F5F324734 ] C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE
16:54:38.0908 4268  C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE - ok
16:54:38.0908 4268  [ D8B26652359A23C4D57EA546B164A77C ] C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
16:54:38.0908 4268  C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE - ok
16:54:38.0908 4268  [ 8C562D23A6B8626E1D555B981530B849 ] C:\Program Files\Sandboxie\Start.exe
16:54:38.0908 4268  C:\Program Files\Sandboxie\Start.exe - ok
16:54:38.0924 4268  [ B540D64EFE0E63286A4C0BBA9A4C7A21 ] C:\Program Files\Windows Media Player\wmprph.exe
16:54:38.0924 4268  C:\Program Files\Windows Media Player\wmprph.exe - ok
16:54:38.0924 4268  ============================================================
16:54:38.0924 4268  Scan finished
16:54:38.0924 4268  ============================================================
16:54:38.0924 6140  Detected object count: 0
16:54:38.0924 6140  Actual detected object count: 0

gruß
robili
[/CODE]

schrauber 30.06.2013 19:45

Immer noch alles sauber :)

robili 30.06.2013 20:53

hallo schrauber,
du kannst mir glauben, niemand ist über diese Nachrich mehr erfreut als ich,
aber da ist immer noch meine Sorge, wo kommen diese Meldungen her ??
gruß
robili

schrauber 01.07.2013 08:04

kommen die immer noch?

robili 01.07.2013 08:56

hallo,
in der Ereigniskontrolle kommt diese Meldung aktuell nicht mehr, dort war die Meldung zum letzten Mal am 30.05.13, allerdings meldet der Avira seinen Fund immer noch, aber da werde ich ja versuchen einen anderen Virenscanner zu installieren.
gruß
robili

schrauber 01.07.2013 11:16

Mach das mal und melde dich wieder :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:10 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131