mannyfred | 23.11.2016 22:09 | Guten Abend Sandra,
vielen Dank, das Du dir die Sache annimmst.
TDSSKILLER Code:
21:53:04.0031 0x13f8 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
21:53:04.0031 0x13f8 UEFI system
21:53:19.0865 0x13f8 ============================================================
21:53:19.0865 0x13f8 Current date / time: 2016/11/23 21:53:19.0865
21:53:19.0868 0x13f8 SystemInfo:
21:53:19.0868 0x13f8
21:53:19.0868 0x13f8 OS Version: 10.0.14393 ServicePack: 0.0
21:53:19.0868 0x13f8 Product type: Workstation
21:53:19.0868 0x13f8 ComputerName: WOLFGANGS-PC
21:53:19.0869 0x13f8 UserName: wolfg
21:53:19.0869 0x13f8 Windows directory: C:\WINDOWS
21:53:19.0869 0x13f8 System windows directory: C:\WINDOWS
21:53:19.0869 0x13f8 Running under WOW64
21:53:19.0869 0x13f8 Processor architecture: Intel x64
21:53:19.0869 0x13f8 Number of processors: 4
21:53:19.0869 0x13f8 Page size: 0x1000
21:53:19.0869 0x13f8 Boot type: Normal boot
21:53:19.0869 0x13f8 CodeIntegrityOptions = 0x00000001
21:53:19.0869 0x13f8 ============================================================
21:53:20.0115 0x13f8 KLMD registered as C:\WINDOWS\system32\drivers\30543711.sys
21:53:20.0115 0x13f8 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.447, osProperties = 0x19
21:53:20.0335 0x13f8 System UUID: {CCE03DEE-ECE8-1E7C-30B3-273FB5EE491E}
21:53:20.0728 0x13f8 Drive \Device\Harddisk0\DR0 - Size: 0x1DCF856000 ( 119.24 Gb ), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:53:20.0732 0x13f8 ============================================================
21:53:20.0732 0x13f8 \Device\Harddisk0\DR0:
21:53:20.0732 0x13f8 GPT partitions:
21:53:20.0733 0x13f8 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {DAE1CBE2-D6F8-471E-9E5B-10504F271619}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x82000
21:53:20.0733 0x13f8 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {653F084D-6213-4E6C-A0F4-84312B9DBB94}, Name: Microsoft reserved partition, StartLBA 0x82800, BlocksNum 0x8000
21:53:20.0733 0x13f8 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {0FB83E3F-1FBB-4B9F-9EC2-E76E56954657}, Name: Basic data partition, StartLBA 0x8A800, BlocksNum 0xC45D800
21:53:20.0733 0x13f8 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {C10C5FD3-BE24-46D1-83AB-B6512C026354}, Name: Basic data partition, StartLBA 0xC4E8000, BlocksNum 0x1F4000
21:53:20.0733 0x13f8 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {46F62646-500C-4509-8C7E-55D076E3FD05}, Name: Basic data partition, StartLBA 0xC6DC000, BlocksNum 0x25AC000
21:53:20.0733 0x13f8 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {0DF546DE-33A0-42FC-96FD-AE07658B136D}, Name: Basic data partition, StartLBA 0xEC88000, BlocksNum 0x1F4000
21:53:20.0733 0x13f8 MBR partitions:
21:53:20.0733 0x13f8 ============================================================
21:53:20.0735 0x13f8 C: <-> \Device\Harddisk0\DR0\Partition3
21:53:20.0735 0x13f8 ============================================================
21:53:20.0735 0x13f8 Initialize success
21:53:20.0735 0x13f8 ============================================================
21:53:44.0152 0x108c ============================================================
21:53:44.0152 0x108c Scan started
21:53:44.0152 0x108c Mode: Manual; SigCheck; TDLFS;
21:53:44.0152 0x108c ============================================================
21:53:44.0152 0x108c KSN ping started
21:53:44.0373 0x108c KSN ping finished: true
21:53:44.0890 0x108c ================ Scan system memory ========================
21:53:44.0890 0x108c System memory - ok
21:53:44.0891 0x108c ================ Scan services =============================
21:53:44.0958 0x108c 1394ohci - ok
21:53:44.0961 0x108c 3ware - ok
21:53:44.0965 0x108c ACPI - ok
21:53:44.0969 0x108c AcpiDev - ok
21:53:44.0973 0x108c acpiex - ok
21:53:44.0976 0x108c acpipagr - ok
21:53:44.0980 0x108c AcpiPmi - ok
21:53:44.0983 0x108c acpitime - ok
21:53:44.0987 0x108c [ E13DE7CD2B62254DD4FF658B7798A37D, 9FCCC90DEF6BE83F8C41D4552D235A7BB5534954D2E7CB7B1C336A31FCCAB3AD ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys
21:53:45.0031 0x108c ACPIVPC - ok
21:53:45.0043 0x108c [ C92B0A0957ACAD3CEEF502A2CA10ACB8, 78BF46318B69D9479ECDC83446DD8D454AA2A9A9D94B33C5FC68933DB18AFA3B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:53:45.0051 0x108c AdobeARMservice - ok
21:53:45.0090 0x108c [ 9BAF21BA600EC4E5FD9A66AD3E4FF5A6, 5E02E5E80557F6EC870EB7CC2DE95169D4225B87A2FE7E796736205F51C15816 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:53:45.0101 0x108c AdobeFlashPlayerUpdateSvc - ok
21:53:45.0110 0x108c ADP80XX - ok
21:53:45.0118 0x108c AFD - ok
21:53:45.0131 0x108c ahcache - ok
21:53:45.0135 0x108c AJRouter - ok
21:53:45.0138 0x108c ALG - ok
21:53:45.0145 0x108c AmdK8 - ok
21:53:45.0149 0x108c AmdPPM - ok
21:53:45.0152 0x108c amdsata - ok
21:53:45.0156 0x108c amdsbs - ok
21:53:45.0163 0x108c amdxata - ok
21:53:45.0185 0x108c [ A1454210C3B0B8A326F63097300E1593, C295CADCA6F4FA6C447B4B4AD050E606017023CF378ED16A64F6D2E0878B662C ] ApfiltrService C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
21:53:45.0209 0x108c ApfiltrService - ok
21:53:45.0219 0x108c [ 35F56C4ED521AD0D4DD62A87E73FFA5D, DB1C73299B6F21000F41C3C3942899EB110FCB92774690F4372369CF97D7BF4B ] ApHidMonitorService C:\Program Files\Apoint2K\HidMonitorSvc.exe
21:53:45.0227 0x108c ApHidMonitorService - ok
21:53:45.0232 0x108c AppID - ok
21:53:45.0239 0x108c AppIDSvc - ok
21:53:45.0242 0x108c Appinfo - ok
21:53:45.0245 0x108c applockerfltr - ok
21:53:45.0249 0x108c AppReadiness - ok
21:53:45.0260 0x108c AppXSvc - ok
21:53:45.0266 0x108c arcsas - ok
21:53:45.0274 0x108c AsyncMac - ok
21:53:45.0278 0x108c atapi - ok
21:53:45.0292 0x108c [ C345E697B68BE9A45BB6CBD03F1E66F2, F50E0CC874A67A9EED3C792599ADA92C888348E7256663F7C784FBBF51D19EAC ] AtherosSvc C:\WINDOWS\system32\AdminService.exe
21:53:45.0314 0x108c AtherosSvc - ok
21:53:45.0318 0x108c AudioEndpointBuilder - ok
21:53:45.0328 0x108c Audiosrv - ok
21:53:45.0334 0x108c AxInstSV - ok
21:53:45.0340 0x108c b06bdrv - ok
21:53:45.0349 0x108c BasicDisplay - ok
21:53:45.0352 0x108c BasicRender - ok
21:53:45.0357 0x108c bcmfn - ok
21:53:45.0365 0x108c bcmfn2 - ok
21:53:45.0368 0x108c BDESVC - ok
21:53:45.0371 0x108c Beep - ok
21:53:45.0374 0x108c BFE - ok
21:53:45.0384 0x108c BITS - ok
21:53:45.0390 0x108c bowser - ok
21:53:45.0398 0x108c BrokerInfrastructure - ok
21:53:45.0402 0x108c Browser - ok
21:53:45.0421 0x108c [ 7170961E98A4F47175972D7F096AA7C5, 8D060277A7C1371DBA1CAFBFB23632664FFFFD3FA2B512F811A25C1871E5CE7D ] BtFilter C:\WINDOWS\system32\DRIVERS\btfilter.sys
21:53:45.0444 0x108c BtFilter - ok
21:53:45.0452 0x108c BthAvrcpTg - ok
21:53:45.0462 0x108c BthHFEnum - ok
21:53:45.0471 0x108c bthhfhid - ok
21:53:45.0475 0x108c BthHFSrv - ok
21:53:45.0479 0x108c BTHMODEM - ok
21:53:45.0482 0x108c BTHPORT - ok
21:53:45.0491 0x108c bthserv - ok
21:53:45.0498 0x108c BTHUSB - ok
21:53:45.0508 0x108c buttonconverter - ok
21:53:45.0511 0x108c CapImg - ok
21:53:45.0527 0x108c [ 8189001F994864B4C4CAE344494749E3, 19CF815639588CAA5A85FCE76E3780A004350654B7917E9F0DB7B5245E4CF9B7 ] CCSDK C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
21:53:45.0553 0x108c CCSDK - ok
21:53:45.0557 0x108c cdfs - ok
21:53:45.0560 0x108c CDPSvc - ok
21:53:45.0564 0x108c CDPUserSvc - ok
21:53:45.0575 0x108c cdrom - ok
21:53:45.0581 0x108c CertPropSvc - ok
21:53:45.0587 0x108c cht4iscsi - ok
21:53:45.0597 0x108c cht4vbd - ok
21:53:45.0601 0x108c circlass - ok
21:53:45.0605 0x108c CLFS - ok
21:53:45.0685 0x108c [ BDED70145D7F931CAD02BD531BEB38B7, 6B6355482F7FD44ECD958BBFDC9795C8F79A60EB5294349DCB0DBBECE607A5B6 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
21:53:45.0758 0x108c ClickToRunSvc - ok
21:53:45.0773 0x108c ClipSVC - ok
21:53:45.0779 0x108c clreg - ok
21:53:45.0798 0x108c [ 3E76A1547F2448BCEE3D2F4AE3931AB5, 31B41723FAA4210A86B1AE02D6C052BD8B738C4B89FB0177C1AE997D24BA5B8C ] CLVirtualDrive C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys
21:53:45.0806 0x108c CLVirtualDrive - ok
21:53:45.0816 0x108c CmBatt - ok
21:53:45.0822 0x108c CNG - ok
21:53:45.0831 0x108c cnghwassist - ok
21:53:45.0855 0x108c CompositeBus - ok
21:53:45.0862 0x108c COMSysApp - ok
21:53:45.0868 0x108c condrv - ok
21:53:45.0873 0x108c CoreMessagingRegistrar - ok
21:53:45.0917 0x108c [ C6A2B8A2FBEBF4127A8791EEEBDEF034, 105463D877E46E9D077EA0B46A1568CCC93FA210C267C62F3321B8DD09EBC2EE ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
21:53:45.0939 0x108c cphs - ok
21:53:45.0957 0x108c [ 48F40B30772B503CEC6C09F974E18F92, BBB5D752025819B77BB26C305D2C38897C97A6D709AF53A570ACE1C7E47F97DD ] cplspcon C:\WINDOWS\system32\IntelCpHDCPSvc.exe
21:53:45.0980 0x108c cplspcon - ok
21:53:45.0986 0x108c CryptSvc - ok
21:53:45.0989 0x108c dam - ok
21:53:45.0996 0x108c [ 7D59855C30C01839CC6F8C28313B8E28, 9E37AF9CB6DF4A0A785519FA09BD6396C9D8A737A5B8D19E69F65175376D4170 ] DAX2API C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
21:53:46.0013 0x108c DAX2API - detected UnsignedFile.Multi.Generic ( 1 )
21:53:46.0167 0x108c Detect skipped due to KSN trusted
21:53:46.0168 0x108c DAX2API - ok
21:53:46.0176 0x108c DcomLaunch - ok
21:53:46.0181 0x108c DcpSvc - ok
21:53:46.0188 0x108c defragsvc - ok
21:53:46.0195 0x108c DeviceAssociationService - ok
21:53:46.0201 0x108c DeviceInstall - ok
21:53:46.0210 0x108c DevQueryBroker - ok
21:53:46.0213 0x108c Dfsc - ok
21:53:46.0217 0x108c Dhcp - ok
21:53:46.0221 0x108c diagnosticshub.standardcollector.service - ok
21:53:46.0230 0x108c DiagTrack - ok
21:53:46.0234 0x108c disk - ok
21:53:46.0237 0x108c DmEnrollmentSvc - ok
21:53:46.0246 0x108c dmvsc - ok
21:53:46.0253 0x108c dmwappushservice - ok
21:53:46.0262 0x108c Dnscache - ok
21:53:46.0269 0x108c dot3svc - ok
21:53:46.0272 0x108c DPS - ok
21:53:46.0276 0x108c drmkaud - ok
21:53:46.0287 0x108c DsmSvc - ok
21:53:46.0294 0x108c DsSvc - ok
21:53:46.0303 0x108c DXGKrnl - ok
21:53:46.0312 0x108c [ 107F101A02BB0FBA1140E406895FF570, 7B22AB5D3380F6AADB6F94CAAF2DC737C96FC6F38E62C7D53F9C863451E52F1D ] eamonm C:\WINDOWS\system32\DRIVERS\eamonm.sys
21:53:46.0330 0x108c eamonm - ok
21:53:46.0334 0x108c EapHost - ok
21:53:46.0337 0x108c ebdrv - ok
21:53:46.0345 0x108c [ 4AF1BB78DF0325BA59963FB8FC7A8C73, 20D2FA7A1BFC30329745106AF2E9456C52D2F18CFFE1AD44B75B912F1E3E2DA1 ] edevmon C:\WINDOWS\system32\DRIVERS\edevmon.sys
21:53:46.0358 0x108c edevmon - ok
21:53:46.0362 0x108c [ A6E666A2C13782E7D012202351DE0FFB, 1FC886F68681FC34738A562C2AD0B294DC614AEE5467ECC8AEADA8AE698B1450 ] eelam C:\WINDOWS\system32\DRIVERS\eelam.sys
21:53:46.0379 0x108c eelam - ok
21:53:46.0384 0x108c EFS - ok
21:53:46.0395 0x108c [ 3944E86529A072405EADA8A8D9B27CE8, 7274675754470F922791651665E7C0F3F840CE03B3889002D91C0F5936978594 ] ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys
21:53:46.0410 0x108c ehdrv - ok
21:53:46.0416 0x108c EhStorClass - ok
21:53:46.0426 0x108c EhStorTcgDrv - ok
21:53:46.0482 0x108c [ 3C52420285C0E12061EE1FF76930E3A6, 12C8F7EC91D23A589A3AB1C1F7F7F4E8B6754B392E92D645632DEBB6F881EF5A ] ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
21:53:46.0543 0x108c ekrn - ok
21:53:46.0554 0x108c embeddedmode - ok
21:53:46.0557 0x108c EntAppSvc - ok
21:53:46.0564 0x108c [ 9C5A9121C4381755E9924889B1B819E5, 167400770981825BF5C35EB1DF24F14DF3178A04F7EE817353584622D75621E5 ] epfwwfpr C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys
21:53:46.0581 0x108c epfwwfpr - ok
21:53:46.0585 0x108c ErrDev - ok
21:53:46.0592 0x108c EventSystem - ok
21:53:46.0595 0x108c exfat - ok
21:53:46.0599 0x108c fastfat - ok
21:53:46.0606 0x108c Fax - ok
21:53:46.0613 0x108c fdc - ok
21:53:46.0618 0x108c fdPHost - ok
21:53:46.0627 0x108c FDResPub - ok
21:53:46.0630 0x108c fhsvc - ok
21:53:46.0634 0x108c FileCrypt - ok
21:53:46.0637 0x108c FileInfo - ok
21:53:46.0646 0x108c Filetrace - ok
21:53:46.0653 0x108c flpydisk - ok
21:53:46.0661 0x108c FltMgr - ok
21:53:46.0665 0x108c FontCache - ok
21:53:46.0669 0x108c FontCache3.0.0.0 - ok
21:53:46.0672 0x108c FrameServer - ok
21:53:46.0679 0x108c FsDepends - ok
21:53:46.0683 0x108c Fs_Rec - ok
21:53:46.0686 0x108c fvevol - ok
21:53:46.0723 0x108c [ D56EE61F9B62AD677395BF003A49B4A7, A4B657AF38253F4BAE2A8BE7E9453E662BC378773A93631C0445C96267296B53 ] GDCAgent C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe
21:53:46.0752 0x108c GDCAgent - ok
21:53:46.0757 0x108c gencounter - ok
21:53:46.0761 0x108c genericusbfn - ok
21:53:46.0795 0x108c [ F78BC07DCED5EDDD6D477E923620F8EA, ABE28155100A38A5E1B58FFC8099EF416145278B440A67B8DAFD7715FE412624 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
21:53:46.0827 0x108c GfExperienceService - ok
21:53:46.0832 0x108c GPIOClx0101 - ok
21:53:46.0835 0x108c gpsvc - ok
21:53:46.0843 0x108c GpuEnergyDrv - ok
21:53:46.0849 0x108c [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:53:46.0862 0x108c gupdate - ok
21:53:46.0870 0x108c [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:53:46.0883 0x108c gupdatem - ok
21:53:46.0887 0x108c HDAudBus - ok
21:53:46.0890 0x108c HidBatt - ok
21:53:46.0900 0x108c HidBth - ok
21:53:46.0906 0x108c hidi2c - ok
21:53:46.0915 0x108c hidinterrupt - ok
21:53:46.0918 0x108c HidIr - ok
21:53:46.0922 0x108c hidserv - ok
21:53:46.0926 0x108c HidUsb - ok
21:53:46.0935 0x108c HomeGroupListener - ok
21:53:46.0942 0x108c HomeGroupProvider - ok
21:53:46.0951 0x108c HpSAMD - ok
21:53:46.0954 0x108c HTTP - ok
21:53:46.0958 0x108c HvHost - ok
21:53:46.0963 0x108c hvservice - ok
21:53:46.0973 0x108c hwpolicy - ok
21:53:46.0979 0x108c hyperkbd - ok
21:53:46.0988 0x108c i8042prt - ok
21:53:46.0992 0x108c iagpio - ok
21:53:46.0995 0x108c iai2c - ok
21:53:46.0999 0x108c iaLPSS2i_GPIO2 - ok
21:53:47.0009 0x108c iaLPSS2i_I2C - ok
21:53:47.0015 0x108c iaLPSSi_GPIO - ok
21:53:47.0024 0x108c iaLPSSi_I2C - ok
21:53:47.0061 0x108c [ 827933B762F90EB4E7690D4484190D77, 7400FA7CB1FDCC3142D9F56156C41427FB394CA32BC8887D17B1FB2DFC962C34 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
21:53:47.0099 0x108c iaStorA - ok
21:53:47.0107 0x108c iaStorAV - ok
21:53:47.0113 0x108c [ F28CAA094A64E02E8EA9F42C81D4482E, B5908752FFEB9509C52436B520C2D56CDB4E180D84462ECD7FEA9F074D780093 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
21:53:47.0121 0x108c IAStorDataMgrSvc - ok
21:53:47.0124 0x108c iaStorV - ok
21:53:47.0134 0x108c ibbus - ok
21:53:47.0141 0x108c icssvc - ok
21:53:47.0263 0x108c [ AEFF8BE94EBA58138962BE3F448F55D4, F7E431A780555A547989A62D3088DB71633EE92C5BF3767588EE6E2DB285254A ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
21:53:47.0394 0x108c igfx - ok
21:53:47.0421 0x108c [ ED2CD8EF96422754E89A6C52F6AB8570, 86AA260FF1D5A8C9BEF3A9EFD450FDE56F3BD3A900808E19790D01C3186B3099 ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
21:53:47.0438 0x108c igfxCUIService2.0.0.0 - ok
21:53:47.0442 0x108c IKEEXT - ok
21:53:47.0451 0x108c [ D10CAFE291F7440D29A6F25343F8B5F3, ECEA095FE6A28BE1198AA258CB22CFBFC40FB5B053D76CDF130717249B12608B ] ImControllerService C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
21:53:47.0458 0x108c ImControllerService - ok
21:53:47.0462 0x108c IndirectKmd - ok
21:53:47.0554 0x108c [ 353F1955822732E5D2C4613AEA1D528D, D1A33ED9D0D829317E51D8135BF48F66B7D7E1752D225D10A4EFC2366AE3A416 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
21:53:47.0654 0x108c IntcAzAudAddService - ok
21:53:47.0689 0x108c [ 00FD074D6CE5DBAAD76D7D7C7F99A99B, 0B9DD56D94D1B53F998BBDAC95011BFC23C7AB53988239782F12C41307CFA7DD ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
21:53:47.0722 0x108c IntcDAud - ok
21:53:47.0728 0x108c intelide - ok
21:53:47.0732 0x108c intelpep - ok
21:53:47.0736 0x108c intelppm - ok
21:53:47.0741 0x108c iorate - ok
21:53:47.0745 0x108c IpFilterDriver - ok
21:53:47.0754 0x108c iphlpsvc - ok
21:53:47.0760 0x108c IPMIDRV - ok
21:53:47.0769 0x108c IPNAT - ok
21:53:47.0773 0x108c irda - ok
21:53:47.0777 0x108c IRENUM - ok
21:53:47.0787 0x108c irmon - ok
21:53:47.0792 0x108c isapnp - ok
21:53:47.0802 0x108c iScsiPrt - ok
21:53:47.0806 0x108c kbdclass - ok
21:53:47.0809 0x108c kbdhid - ok
21:53:47.0813 0x108c kdnic - ok
21:53:47.0820 0x108c KeyIso - ok
21:53:47.0823 0x108c KSecDD - ok
21:53:47.0826 0x108c KSecPkg - ok
21:53:47.0835 0x108c ksthunk - ok
21:53:47.0841 0x108c KtmRm - ok
21:53:47.0847 0x108c LanmanServer - ok
21:53:47.0856 0x108c LanmanWorkstation - ok
21:53:47.0860 0x108c lfsvc - ok
21:53:47.0863 0x108c LicenseManager - ok
21:53:47.0871 0x108c lltdio - ok
21:53:47.0877 0x108c lltdsvc - ok
21:53:47.0883 0x108c lmhosts - ok
21:53:47.0894 0x108c LSI_SAS - ok
21:53:47.0897 0x108c LSI_SAS2i - ok
21:53:47.0901 0x108c LSI_SAS3i - ok
21:53:47.0911 0x108c LSI_SSS - ok
21:53:47.0917 0x108c LSM - ok
21:53:47.0925 0x108c luafv - ok
21:53:47.0929 0x108c MapsBroker - ok
21:53:47.0933 0x108c megasas - ok
21:53:47.0936 0x108c megasas2i - ok
21:53:47.0943 0x108c megasr - ok
21:53:47.0951 0x108c [ 48F64A35BA9F2E4AC0587DDA555FF951, 77FE2BE86ADCE103F4220A641139C42B1407CF8EFFEB66F841ABF9CFC3621558 ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
21:53:47.0968 0x108c MEIx64 - ok
21:53:47.0974 0x108c MessagingService - ok
21:53:47.0984 0x108c mlx4_bus - ok
21:53:47.0987 0x108c MMCSS - ok
21:53:47.0991 0x108c Modem - ok
21:53:47.0999 0x108c monitor - ok
21:53:48.0005 0x108c mouclass - ok
21:53:48.0011 0x108c mouhid - ok
21:53:48.0019 0x108c mountmgr - ok
21:53:48.0025 0x108c [ 86320BA9D6A972C79D467931518B165A, 4D7ABD7E5637B9AF98D7F3D4C4DAE595C27C8FEEBAAFF9E6443271C41598FCE1 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:53:48.0041 0x108c MozillaMaintenance - ok
21:53:48.0046 0x108c mpsdrv - ok
21:53:48.0050 0x108c MpsSvc - ok
21:53:48.0054 0x108c MRxDAV - ok
21:53:48.0057 0x108c mrxsmb - ok
21:53:48.0060 0x108c mrxsmb10 - ok
21:53:48.0063 0x108c mrxsmb20 - ok
21:53:48.0072 0x108c MsBridge - ok
21:53:48.0079 0x108c MSDTC - ok
21:53:48.0091 0x108c Msfs - ok
21:53:48.0095 0x108c msgpiowin32 - ok
21:53:48.0098 0x108c mshidkmdf - ok
21:53:48.0106 0x108c mshidumdf - ok
21:53:48.0113 0x108c msisadrv - ok
21:53:48.0119 0x108c MSiSCSI - ok
21:53:48.0127 0x108c msiserver - ok
21:53:48.0131 0x108c MSKSSRV - ok
21:53:48.0134 0x108c MsLldp - ok
21:53:48.0137 0x108c MSPCLOCK - ok
21:53:48.0145 0x108c MSPQM - ok
21:53:48.0148 0x108c MsRPC - ok
21:53:48.0152 0x108c mssmbios - ok
21:53:48.0156 0x108c MSTEE - ok
21:53:48.0166 0x108c MTConfig - ok
21:53:48.0171 0x108c Mup - ok
21:53:48.0181 0x108c mvumis - ok
21:53:48.0186 0x108c NativeWifiP - ok
21:53:48.0189 0x108c NcaSvc - ok
21:53:48.0197 0x108c NcbService - ok
21:53:48.0204 0x108c NcdAutoSetup - ok
21:53:48.0215 0x108c ndfltr - ok
21:53:48.0219 0x108c NDIS - ok
21:53:48.0222 0x108c NdisCap - ok
21:53:48.0226 0x108c NdisImPlatform - ok
21:53:48.0235 0x108c NdisTapi - ok
21:53:48.0243 0x108c Ndisuio - ok
21:53:48.0251 0x108c NdisVirtualBus - ok
21:53:48.0256 0x108c NdisWan - ok
21:53:48.0259 0x108c ndiswanlegacy - ok
21:53:48.0262 0x108c ndproxy - ok
21:53:48.0269 0x108c Ndu - ok
21:53:48.0273 0x108c NetAdapterCx - ok
21:53:48.0276 0x108c NetBIOS - ok
21:53:48.0280 0x108c NetBT - ok
21:53:48.0289 0x108c Netlogon - ok
21:53:48.0296 0x108c Netman - ok
21:53:48.0305 0x108c netprofm - ok
21:53:48.0310 0x108c NetSetupSvc - ok
21:53:48.0317 0x108c NetTcpPortSharing - ok
21:53:48.0390 0x108c [ 0F76FA3A3F8D169B1CA6F54DC7561CD5, F6C49E5D4F627FD539670DFCBC20C69F627A90CBA473873640D4DD378EE34ED5 ] NETwNe64 C:\WINDOWS\System32\drivers\NETwew01.sys
21:53:48.0461 0x108c NETwNe64 - ok
21:53:48.0480 0x108c NgcCtnrSvc - ok
21:53:48.0489 0x108c NgcSvc - ok
21:53:48.0493 0x108c NlaSvc - ok
21:53:48.0496 0x108c Npfs - ok
21:53:48.0503 0x108c npsvctrig - ok
21:53:48.0507 0x108c nsi - ok
21:53:48.0510 0x108c nsiproxy - ok
21:53:48.0515 0x108c NTFS - ok
21:53:48.0523 0x108c Null - ok
21:53:48.0785 0x108c [ A51617881CEF500F8139494CBFBD543E, 2B5912D7D0490CC654DE0B8745D6F1574389E929C71DB0F5B8F504BAC691E790 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_561c3173c020f30d\nvlddmkm.sys
21:53:49.0084 0x108c nvlddmkm - ok
21:53:49.0143 0x108c [ 020F45E362D3B57CCC5735582BB1A6EC, E2D953CEF208528382153D06FED8394BEB52657C547E4D2D2954E537C9A382DC ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
21:53:49.0186 0x108c NvNetworkService - ok
21:53:49.0195 0x108c nvraid - ok
21:53:49.0198 0x108c nvstor - ok
21:53:49.0236 0x108c [ 1D97F4D3B6D1F64E6419317EF0DA5768, B06D07D5757BF0760EAC2F2DF6FA3E841FF20C25E21D28E76DFB16187A385A46 ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
21:53:49.0278 0x108c nvsvc - ok
21:53:49.0284 0x108c OneSyncSvc - ok
21:53:49.0295 0x108c [ D1AF4C86F851F9A345A400FD3B9D673A, BCC7B3AF92A2AB09CC52FB10107E209C02AC078E5F0197AEC40D7AE56F3A7CA0 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:53:49.0311 0x108c ose64 - ok
21:53:49.0314 0x108c p2pimsvc - ok
21:53:49.0317 0x108c p2psvc - ok
21:53:49.0325 0x108c Parport - ok
21:53:49.0332 0x108c partmgr - ok
21:53:49.0338 0x108c PcaSvc - ok
21:53:49.0347 0x108c pci - ok
21:53:49.0351 0x108c pciide - ok
21:53:49.0355 0x108c pcmcia - ok
21:53:49.0358 0x108c pcw - ok
21:53:49.0368 0x108c pdc - ok
21:53:49.0376 0x108c PEAUTH - ok
21:53:49.0384 0x108c percsas2i - ok
21:53:49.0388 0x108c percsas3i - ok
21:53:49.0425 0x108c PerfHost - ok
21:53:49.0437 0x108c PhoneSvc - ok
21:53:49.0444 0x108c PimIndexMaintenanceSvc - ok
21:53:49.0455 0x108c pla - ok
21:53:49.0458 0x108c PlugPlay - ok
21:53:49.0462 0x108c PNRPAutoReg - ok
21:53:49.0465 0x108c PNRPsvc - ok
21:53:49.0472 0x108c PolicyAgent - ok
21:53:49.0476 0x108c Power - ok
21:53:49.0480 0x108c PptpMiniport - ok
21:53:49.0560 0x108c [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
21:53:49.0671 0x108c PrintNotify - ok
21:53:49.0681 0x108c Processor - ok
21:53:49.0690 0x108c ProfSvc - ok
21:53:49.0697 0x108c Psched - ok
21:53:49.0755 0x108c [ D76F885983B04E8BE2D1BDEF118A097E, 34D293F7E9D2E4BF43B2BB575D77E6A8D45D54C22F8F0214EA26712BE6CE9A49 ] Qcamain C:\WINDOWS\System32\drivers\Qcamainx64.sys
21:53:49.0831 0x108c Qcamain - detected UnsignedFile.Multi.Generic ( 1 )
21:53:49.0995 0x108c Detect skipped due to KSN trusted
21:53:49.0996 0x108c Qcamain - ok
21:53:50.0005 0x108c Qcamain10x64 - ok
21:53:50.0010 0x108c QWAVE - ok
21:53:50.0021 0x108c QWAVEdrv - ok
21:53:50.0027 0x108c RasAcd - ok
21:53:50.0036 0x108c RasAgileVpn - ok
21:53:50.0039 0x108c RasAuto - ok
21:53:50.0042 0x108c Rasl2tp - ok
21:53:50.0046 0x108c RasMan - ok
21:53:50.0053 0x108c RasPppoe - ok
21:53:50.0056 0x108c RasSstp - ok
21:53:50.0060 0x108c rdbss - ok
21:53:50.0068 0x108c rdpbus - ok
21:53:50.0074 0x108c RDPDR - ok
21:53:50.0091 0x108c RdpVideoMiniport - ok
21:53:50.0094 0x108c rdyboost - ok
21:53:50.0098 0x108c ReFSv1 - ok
21:53:50.0105 0x108c RemoteAccess - ok
21:53:50.0112 0x108c RemoteRegistry - ok
21:53:50.0118 0x108c RetailDemo - ok
21:53:50.0128 0x108c RmSvc - ok
21:53:50.0132 0x108c RpcEptMapper - ok
21:53:50.0136 0x108c RpcLocator - ok
21:53:50.0145 0x108c RpcSs - ok
21:53:50.0153 0x108c rspndr - ok
21:53:50.0181 0x108c [ 3D54ACD83F774C73D213A976A3F53C1A, D819CA427795CE11601DCCDD7DF33A6EB2C59E6E697AB6E7919D9A75490FA8A1 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
21:53:50.0207 0x108c rt640x64 - ok
21:53:50.0219 0x108c [ 229B924BFA63BC39CC3D9A72B6465562, F4A980DDF79A4B4DCF1BA0A40C2C9145862AC24AD1F5C40805019940231A2ADF ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys
21:53:50.0241 0x108c RTSUER - ok
21:53:50.0306 0x108c [ 3AE5B0877348E9399C7C2B1B1CFA6167, 3B19BDE0E2322537DC47F7E698F8081BF1B9E52617DF85C4078DCD3B9D34A826 ] rtsuvc C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
21:53:50.0373 0x108c rtsuvc - ok
21:53:50.0382 0x108c s3cap - ok
21:53:50.0386 0x108c SamSs - ok
21:53:50.0397 0x108c sbp2port - ok
21:53:50.0403 0x108c SCardSvr - ok
21:53:50.0411 0x108c ScDeviceEnum - ok
21:53:50.0415 0x108c scfilter - ok
21:53:50.0419 0x108c Schedule - ok
21:53:50.0422 0x108c scmbus - ok
21:53:50.0432 0x108c scmdisk0101 - ok
21:53:50.0438 0x108c SCPolicySvc - ok
21:53:50.0447 0x108c sdbus - ok
21:53:50.0451 0x108c SDRSVC - ok
21:53:50.0455 0x108c sdstor - ok
21:53:50.0458 0x108c seclogon - ok
21:53:50.0467 0x108c SENS - ok
21:53:50.0473 0x108c SensorDataService - ok
21:53:50.0483 0x108c SensorService - ok
21:53:50.0487 0x108c SensrSvc - ok
21:53:50.0490 0x108c SerCx - ok
21:53:50.0493 0x108c SerCx2 - ok
21:53:50.0501 0x108c Serenum - ok
21:53:50.0504 0x108c Serial - ok
21:53:50.0507 0x108c sermouse - ok
21:53:50.0521 0x108c SessionEnv - ok
21:53:50.0528 0x108c sfloppy - ok
21:53:50.0538 0x108c SharedAccess - ok
21:53:50.0542 0x108c ShellHWDetection - ok
21:53:50.0546 0x108c shpamsvc - ok
21:53:50.0549 0x108c SiSRaid2 - ok
21:53:50.0559 0x108c SiSRaid4 - ok
21:53:50.0566 0x108c smphost - ok
21:53:50.0575 0x108c SmsRouter - ok
21:53:50.0581 0x108c SNMPTRAP - ok
21:53:50.0585 0x108c spaceport - ok
21:53:50.0595 0x108c SpbCx - ok
21:53:50.0601 0x108c Spooler - ok
21:53:50.0610 0x108c sppsvc - ok
21:53:50.0614 0x108c srv - ok
21:53:50.0617 0x108c srv2 - ok
21:53:50.0620 0x108c srvnet - ok
21:53:50.0629 0x108c SSDPSRV - ok
21:53:50.0635 0x108c SstpSvc - ok
21:53:50.0641 0x108c StateRepository - ok
21:53:50.0657 0x108c [ 86E93885D05EF3DE8561D4A4A7E3B1E4, 0B7A0459853588C23E2ADFCBF34F5F16FBB856563418D622C828BAA718BF15B8 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
21:53:50.0674 0x108c Stereo Service - ok
21:53:50.0684 0x108c stexstor - ok
21:53:50.0692 0x108c stisvc - ok
21:53:50.0697 0x108c storahci - ok
21:53:50.0702 0x108c storflt - ok
21:53:50.0705 0x108c stornvme - ok
21:53:50.0709 0x108c storqosflt - ok
21:53:50.0717 0x108c StorSvc - ok
21:53:50.0723 0x108c storufs - ok
21:53:50.0729 0x108c storvsc - ok
21:53:50.0738 0x108c svsvc - ok
21:53:50.0741 0x108c swenum - ok
21:53:50.0745 0x108c swprv - ok
21:53:50.0752 0x108c Synth3dVsc - ok
21:53:50.0759 0x108c SysMain - ok
21:53:50.0767 0x108c SystemEventsBroker - ok
21:53:50.0775 0x108c TabletInputService - ok
21:53:50.0779 0x108c TapiSrv - ok
21:53:50.0784 0x108c Tcpip - ok
21:53:50.0793 0x108c Tcpip6 - ok
21:53:50.0800 0x108c tcpipreg - ok
21:53:50.0814 0x108c tdx - ok
21:53:50.0960 0x108c [ F2F02E436BA56A96A06E4427C5787B6E, 1562FF264011A15AC69808CB74F387917C4E8ED3B91546B12933BE10B6E20B3A ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
21:53:51.0120 0x108c TeamViewer - ok
21:53:51.0136 0x108c terminpt - ok
21:53:51.0145 0x108c TermService - ok
21:53:51.0149 0x108c Themes - ok
21:53:51.0157 0x108c TieringEngineService - ok
21:53:51.0160 0x108c tiledatamodelsvc - ok
21:53:51.0164 0x108c TimeBrokerSvc - ok
21:53:51.0167 0x108c TPM - ok
21:53:51.0177 0x108c TrkWks - ok
21:53:51.0182 0x108c TrustedInstaller - ok
21:53:51.0193 0x108c tsusbflt - ok
21:53:51.0198 0x108c TsUsbGD - ok
21:53:51.0201 0x108c tunnel - ok
21:53:51.0205 0x108c tzautoupdate - ok
21:53:51.0215 0x108c UASPStor - ok
21:53:51.0220 0x108c UcmCx0101 - ok
21:53:51.0229 0x108c UcmTcpciCx0101 - ok
21:53:51.0233 0x108c UcmUcsi - ok
21:53:51.0236 0x108c Ucx01000 - ok
21:53:51.0239 0x108c UdeCx - ok
21:53:51.0248 0x108c udfs - ok
21:53:51.0255 0x108c UEFI - ok
21:53:51.0260 0x108c Ufx01000 - ok
21:53:51.0267 0x108c UfxChipidea - ok
21:53:51.0271 0x108c ufxsynopsys - ok
21:53:51.0277 0x108c UI0Detect - ok
21:53:51.0287 0x108c umbus - ok
21:53:51.0293 0x108c UmPass - ok
21:53:51.0302 0x108c UmRdpService - ok
21:53:51.0306 0x108c UnistoreSvc - ok
21:53:51.0311 0x108c upnphost - ok
21:53:51.0318 0x108c UrsChipidea - ok
21:53:51.0322 0x108c UrsCx01000 - ok
21:53:51.0325 0x108c UrsSynopsys - ok
21:53:51.0328 0x108c usbccgp - ok
21:53:51.0336 0x108c usbcir - ok
21:53:51.0343 0x108c usbehci - ok
21:53:51.0348 0x108c usbhub - ok
21:53:51.0357 0x108c USBHUB3 - ok
21:53:51.0361 0x108c usbohci - ok
21:53:51.0364 0x108c usbprint - ok
21:53:51.0373 0x108c [ 2EC7B2C8123236B1233A77281D378DF7, D97DB59C9CAE2B8B33C707E8CEA7A65BF88712842CC715D270F7432A99D21BB6 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:53:51.0393 0x108c usbscan - ok
21:53:51.0397 0x108c usbser - ok
21:53:51.0400 0x108c USBSTOR - ok
21:53:51.0407 0x108c usbuhci - ok
21:53:51.0414 0x108c USBXHCI - ok
21:53:51.0420 0x108c UserDataSvc - ok
21:53:51.0431 0x108c UserManager - ok
21:53:51.0434 0x108c UsoSvc - ok
21:53:51.0437 0x108c VaultSvc - ok
21:53:51.0443 0x108c vdrvroot - ok
21:53:51.0449 0x108c vds - ok
21:53:51.0452 0x108c VerifierExt - ok
21:53:51.0455 0x108c vhdmp - ok
21:53:51.0463 0x108c vhf - ok
21:53:51.0470 0x108c vmbus - ok
21:53:51.0476 0x108c VMBusHID - ok
21:53:51.0484 0x108c vmgid - ok
21:53:51.0488 0x108c vmicguestinterface - ok
21:53:51.0491 0x108c vmicheartbeat - ok
21:53:51.0499 0x108c vmickvpexchange - ok
21:53:51.0506 0x108c vmicrdv - ok
21:53:51.0511 0x108c vmicshutdown - ok
21:53:51.0519 0x108c vmictimesync - ok
21:53:51.0522 0x108c vmicvmsession - ok
21:53:51.0525 0x108c vmicvss - ok
21:53:51.0529 0x108c volmgr - ok
21:53:51.0539 0x108c volmgrx - ok
21:53:51.0546 0x108c volsnap - ok
21:53:51.0555 0x108c volume - ok
21:53:51.0558 0x108c vpci - ok
21:53:51.0562 0x108c vsmraid - ok
21:53:51.0566 0x108c VSS - ok
21:53:51.0576 0x108c VSTXRAID - ok
21:53:51.0582 0x108c vwifibus - ok
21:53:51.0590 0x108c vwififlt - ok
21:53:51.0594 0x108c vwifimp - ok
21:53:51.0597 0x108c W32Time - ok
21:53:51.0601 0x108c WacomPen - ok
21:53:51.0612 0x108c WalletService - ok
21:53:51.0618 0x108c wanarp - ok
21:53:51.0627 0x108c wanarpv6 - ok
21:53:51.0630 0x108c wbengine - ok
21:53:51.0634 0x108c WbioSrvc - ok
21:53:51.0637 0x108c wcifs - ok
21:53:51.0645 0x108c Wcmsvc - ok
21:53:51.0648 0x108c wcncsvc - ok
21:53:51.0652 0x108c wcnfs - ok
21:53:51.0656 0x108c WdBoot - ok
21:53:51.0665 0x108c Wdf01000 - ok
21:53:51.0671 0x108c WdFilter - ok
21:53:51.0680 0x108c WdiServiceHost - ok
21:53:51.0685 0x108c WdiSystemHost - ok
21:53:51.0688 0x108c wdiwifi - ok
21:53:51.0692 0x108c WdNisDrv - ok
21:53:51.0699 0x108c WdNisSvc - ok
21:53:51.0707 0x108c WebClient - ok
21:53:51.0716 0x108c Wecsvc - ok
21:53:51.0720 0x108c WEPHOSTSVC - ok
21:53:51.0724 0x108c wercplsupport - ok
21:53:51.0727 0x108c WerSvc - ok
21:53:51.0737 0x108c WFPLWFS - ok
21:53:51.0743 0x108c WiaRpc - ok
21:53:51.0752 0x108c WIMMount - ok
21:53:51.0754 0x108c WinDefend - ok
21:53:51.0761 0x108c WindowsTrustedRT - ok
21:53:51.0765 0x108c WindowsTrustedRTProxy - ok
21:53:51.0775 0x108c WinHttpAutoProxySvc - ok
21:53:51.0783 0x108c WinMad - ok
21:53:51.0796 0x108c Winmgmt - ok
21:53:51.0799 0x108c WinRM - ok
21:53:51.0810 0x108c WINUSB - ok
21:53:51.0814 0x108c WinVerbs - ok
21:53:51.0818 0x108c wisvc - ok
21:53:51.0826 0x108c WlanSvc - ok
21:53:51.0833 0x108c wlidsvc - ok
21:53:51.0842 0x108c WmiAcpi - ok
21:53:51.0849 0x108c wmiApSrv - ok
21:53:51.0852 0x108c WMPNetworkSvc - ok
21:53:51.0860 0x108c Wof - ok
21:53:51.0870 0x108c workfolderssvc - ok
21:53:51.0878 0x108c WPDBusEnum - ok
21:53:51.0883 0x108c WpdUpFltr - ok
21:53:51.0887 0x108c WpnService - ok
21:53:51.0890 0x108c WpnUserService - ok
21:53:51.0904 0x108c ws2ifsl - ok
21:53:51.0913 0x108c wscsvc - ok
21:53:51.0918 0x108c WSDPrintDevice - ok
21:53:51.0922 0x108c WSDScan - ok
21:53:51.0925 0x108c WSearch - ok
21:53:51.0936 0x108c [ 72B4E9DF6456C43C42A1419B09486045, 536BA7377B5BEA7EA46864453933111DB88DB8FB689C68915ACD7261A996E61D ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
21:53:51.0949 0x108c wsvd - ok
21:53:51.0955 0x108c wuauserv - ok
21:53:51.0961 0x108c WudfPf - ok
21:53:51.0970 0x108c WUDFRd - ok
21:53:51.0975 0x108c wudfsvc - ok
21:53:51.0978 0x108c WUDFWpdFs - ok
21:53:51.0982 0x108c WUDFWpdMtp - ok
21:53:51.0993 0x108c WwanSvc - ok
21:53:51.0998 0x108c XblAuthManager - ok
21:53:52.0008 0x108c XblGameSave - ok
21:53:52.0012 0x108c xboxgip - ok
21:53:52.0016 0x108c XboxNetApiSvc - ok
21:53:52.0024 0x108c xinputhid - ok
21:53:52.0028 0x108c ================ Scan global ===============================
21:53:52.0048 0x108c [ Global ] - ok
21:53:52.0049 0x108c ================ Scan MBR ==================================
21:53:52.0051 0x108c [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
21:53:52.0090 0x108c \Device\Harddisk0\DR0 - ok
21:53:52.0090 0x108c ================ Scan VBR ==================================
21:53:52.0092 0x108c [ FC983D66B62CDD8DFD04169DEB58F679 ] \Device\Harddisk0\DR0\Partition1
21:53:52.0093 0x108c \Device\Harddisk0\DR0\Partition1 - ok
21:53:52.0095 0x108c [ EAA9ACF1B7B38FEE49CB7EE48A5CA163 ] \Device\Harddisk0\DR0\Partition2
21:53:52.0095 0x108c \Device\Harddisk0\DR0\Partition2 - ok
21:53:52.0098 0x108c [ F6B8394D9ED1E336B4ACAE4B1E0B7313 ] \Device\Harddisk0\DR0\Partition3
21:53:52.0099 0x108c \Device\Harddisk0\DR0\Partition3 - ok
21:53:52.0101 0x108c [ 71E5790B244955F37AE1931FDB511226 ] \Device\Harddisk0\DR0\Partition4
21:53:52.0102 0x108c \Device\Harddisk0\DR0\Partition4 - ok
21:53:52.0104 0x108c [ 871946DA8EB38C0710D19ED6BF29E54D ] \Device\Harddisk0\DR0\Partition5
21:53:52.0106 0x108c \Device\Harddisk0\DR0\Partition5 - ok
21:53:52.0111 0x108c [ 1ECC2FCF8438A8A438D3E45812AA6C6E ] \Device\Harddisk0\DR0\Partition6
21:53:52.0112 0x108c \Device\Harddisk0\DR0\Partition6 - ok
21:53:52.0114 0x108c ================ Scan generic autorun ======================
21:53:52.0134 0x108c [ 85AC79F070737D721056881F898A1C37, 4AD8B1A016BB9C66ED76827480EA12EB5853C8536B60B4F79BBA19993DBD1912 ] C:\Program Files\Apoint2K\Apoint.exe
21:53:52.0164 0x108c Apoint - ok
21:53:52.0437 0x108c [ B34F985FBD8FF7C6D99581145EA794A2, 52B4D0E79CEC07FB73584FD952329CDA4AA525D2DE92DFCE123131EDA1699CB6 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
21:53:52.0794 0x108c RTHDVCPL - ok
21:53:52.0842 0x108c [ 5E2875923B7D0BE1CF35D456A708EBE1, 1769B9FD25C53406EF5A8152A89723F4BD8235052E626850A2D90CA0FDD33C03 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
21:53:52.0878 0x108c RtHDVBg_Dolby - ok
21:53:52.0910 0x108c [ 5E2875923B7D0BE1CF35D456A708EBE1, 1769B9FD25C53406EF5A8152A89723F4BD8235052E626850A2D90CA0FDD33C03 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
21:53:52.0941 0x108c RtHDVBg_LENOVO_DOLBYDRAGON - ok
21:53:52.0974 0x108c [ 5E2875923B7D0BE1CF35D456A708EBE1, 1769B9FD25C53406EF5A8152A89723F4BD8235052E626850A2D90CA0FDD33C03 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
21:53:53.0007 0x108c RtHDVBg_LENOVO_MICPKEY - ok
21:53:53.0011 0x108c Logitech Download Assistant - ok
21:53:53.0031 0x108c [ 773864F1C5C2F7D9711EDD842B555CAD, 593ABC4042B78BAD835E503557FDA853431CD3173DD786E9271E4E1B2603E19D ] C:\Program Files\Lenovo\LenovoUtility\utility.exe
21:53:53.0061 0x108c LenovoUtility - ok
21:53:53.0066 0x108c [ CAFF91D18E85FEDB51F5EFBB73335227, 20939026D4AD9CB3E8284DB353102273A49B10A53A794566AE9B8B28110D3736 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
21:53:53.0072 0x108c IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
21:53:53.0229 0x108c Detect skipped due to KSN trusted
21:53:53.0229 0x108c IAStorIcon - ok
21:53:53.0251 0x108c [ 5DB2D863BEECABABE5AFBD36AD055919, EDA57E210834275DD78650C55267F1EB55BB03964D0BCB8C87CCB5CCE290AE51 ] C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe
21:53:53.0281 0x108c DAX2_APP - detected UnsignedFile.Multi.Generic ( 1 )
21:53:53.0424 0x108c Detect skipped due to KSN trusted
21:53:53.0424 0x108c DAX2_APP - ok
21:53:53.0482 0x108c [ 94A8196066774252DF015EEDF02CCA44, AD2DFDA427E3CCB5C8404F0AFAFE71C64B862D2E26A67E1BFC2B40738FD0B873 ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
21:53:53.0546 0x108c NvBackend - ok
21:53:53.0563 0x108c [ 4E9AF25BA5E8219310E384AEA5B0EED8, 743062F755E7A88BA394E96CA26A988CCFDF73B441B779B3149D54A769CBC411 ] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
21:53:53.0571 0x108c CLMLServer_For_P2G8 - ok
21:53:53.0586 0x108c [ 87DFBEA4D27170B0A54378DFBF0BE8E4, CA98EA1CADAF6712F1E828386902EF590253286AC860D077FD5C5971022C2146 ] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe
21:53:53.0610 0x108c CLVirtualDrive - ok
21:53:53.0650 0x108c OneDriveSetup - ok
21:53:53.0654 0x108c OneDriveSetup - ok
21:53:53.0673 0x108c [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\wolfg\AppData\Local\Microsoft\OneDrive\OneDrive.exe
21:53:53.0698 0x108c OneDrive - ok
21:53:53.0743 0x108c [ CAC8165B201CD4A30B3944BA3FCDD9C0, DA6289D950C641FD78AB57EC0A391BFBC0577DD87E48F707EAE4C50AB3DF3311 ] C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe
21:53:53.0794 0x108c Power2GoExpress8 - ok
21:53:53.0797 0x108c Waiting for KSN requests completion. In queue: 55
21:53:54.0820 0x108c AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
21:53:54.0820 0x108c AV detected via SS2: ESET NOD32 Antivirus 9.0.402.1, C:\Program Files\ESET\ESET NOD32 Antivirus\ecmd.exe ( 9.0.395.0 ), 0x41000 ( enabled : updated )
21:53:54.0834 0x108c Win FW state via NFP2: enabled ( trusted )
21:53:54.0995 0x108c ============================================================
21:53:54.0995 0x108c Scan finished
21:53:54.0995 0x108c ============================================================
21:53:55.0006 0x08a4 Detected object count: 0
21:53:55.0006 0x08a4 Actual detected object count: 0 MBAR: Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2016.11.23.15
rootkit: v2016.11.20.01
Windows 10 x64 NTFS
Internet Explorer 11.447.14393.0
wolfg :: WOLFGANGS-PC [administrator]
23.11.2016 21:57:38
mbar-log-2016-11-23 (21-57-38).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 316716
Time elapsed: 9 minute(s), 57 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) So, ich hoffe das hilft. Werde jetzt erstmal schlafen gehen. Gute nacht & bis Morgen.:abklatsch:
VG
Fabi |