magdeburger | 22.12.2016 17:20 | Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2016.12.22.08
rootkit: v2016.11.20.01
Windows 10 x64 NTFS
Internet Explorer 11.576.14393.0
db :: SONYDB [administrator]
22.12.2016 17:05:33
mbar-log-2016-12-22 (17-05-33).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 327519
Time elapsed: 7 minute(s), 5 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) Code:
17:15:06.0577 0x17f0 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
17:15:09.0042 0x17f0 ============================================================
17:15:09.0042 0x17f0 Current date / time: 2016/12/22 17:15:09.0042
17:15:09.0042 0x17f0 SystemInfo:
17:15:09.0043 0x17f0
17:15:09.0043 0x17f0 OS Version: 10.0.14393 ServicePack: 0.0
17:15:09.0043 0x17f0 Product type: Workstation
17:15:09.0043 0x17f0 ComputerName: SONYDB
17:15:09.0043 0x17f0 UserName: db
17:15:09.0043 0x17f0 Windows directory: C:\WINDOWS
17:15:09.0043 0x17f0 System windows directory: C:\WINDOWS
17:15:09.0043 0x17f0 Running under WOW64
17:15:09.0043 0x17f0 Processor architecture: Intel x64
17:15:09.0043 0x17f0 Number of processors: 4
17:15:09.0043 0x17f0 Page size: 0x1000
17:15:09.0043 0x17f0 Boot type: Normal boot
17:15:09.0043 0x17f0 CodeIntegrityOptions = 0x00000001
17:15:09.0043 0x17f0 ============================================================
17:15:09.0148 0x17f0 KLMD registered as C:\WINDOWS\system32\drivers\33984246.sys
17:15:09.0148 0x17f0 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.576, osProperties = 0x19
17:15:09.0206 0x17f0 System UUID: {89ED3A84-A01E-3FFA-4466-86F945B2E9B7}
17:15:09.0535 0x17f0 Drive \Device\Harddisk0\DR0 - Size: 0x1DCF856000 ( 119.24 Gb ), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:15:09.0593 0x17f0 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:15:09.0612 0x17f0 Drive \Device\Harddisk4\DR4 - Size: 0x773C00000 ( 29.81 Gb ), SectorSize: 0x200, Cylinders: 0xF33, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
17:15:09.0614 0x17f0 ============================================================
17:15:09.0615 0x17f0 \Device\Harddisk0\DR0:
17:15:09.0615 0x17f0 MBR partitions:
17:15:09.0615 0x17f0 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xED9A000
17:15:09.0615 0x17f0 \Device\Harddisk1\DR1:
17:15:09.0615 0x17f0 MBR partitions:
17:15:09.0625 0x17f0 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F00, BlocksNum 0x3A380D41
17:15:09.0625 0x17f0 \Device\Harddisk4\DR4:
17:15:09.0626 0x17f0 MBR partitions:
17:15:09.0626 0x17f0 \Device\Harddisk4\DR4\Partition1: MBR, Type 0xC, StartLBA 0x2000, BlocksNum 0x3B9E000
17:15:09.0626 0x17f0 ============================================================
17:15:09.0629 0x17f0 C: <-> \Device\Harddisk0\DR0\Partition1
17:15:09.0638 0x17f0 D: <-> \Device\Harddisk1\DR1\Partition1
17:15:09.0638 0x17f0 ============================================================
17:15:09.0638 0x17f0 Initialize success
17:15:09.0638 0x17f0 ============================================================
17:15:51.0103 0x144c ============================================================
17:15:51.0103 0x144c Scan started
17:15:51.0103 0x144c Mode: Manual; SigCheck; TDLFS;
17:15:51.0103 0x144c ============================================================
17:15:51.0103 0x144c KSN ping started
17:15:51.0194 0x144c KSN ping finished: true
17:15:53.0318 0x144c ================ Scan system memory ========================
17:15:53.0318 0x144c System memory - ok
17:15:53.0319 0x144c ================ Scan services =============================
17:15:53.0329 0x144c [ 970C70F6B2953ED43822D3797855D84C, CB22723678B514277BC6E6DDDD206F3B2377CD889C9D473A47A7056BE597BC6B ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
17:15:53.0455 0x144c !SASCORE - ok
17:15:53.0508 0x144c 1394ohci - ok
17:15:53.0513 0x144c 3ware - ok
17:15:53.0520 0x144c ACPI - ok
17:15:53.0526 0x144c AcpiDev - ok
17:15:53.0532 0x144c acpiex - ok
17:15:53.0540 0x144c acpipagr - ok
17:15:53.0546 0x144c AcpiPmi - ok
17:15:53.0552 0x144c acpitime - ok
17:15:53.0561 0x144c ADP80XX - ok
17:15:53.0570 0x144c AFD - ok
17:15:53.0580 0x144c ahcache - ok
17:15:53.0585 0x144c AJRouter - ok
17:15:53.0594 0x144c [ 808820DEF092FA0A6D93BAE3E5D069CD, D1F49B6D99E346242EF6A9C37D2EC9333411FBDB031BE87FE0F8CDFEC545DD89 ] AlcatelOTnet C:\WINDOWS\system32\DRIVERS\AlcatelOTUsbnet.sys
17:15:53.0636 0x144c AlcatelOTnet - ok
17:15:53.0642 0x144c ALG - ok
17:15:53.0654 0x144c [ D7A72B9BA6AB996DADB37BFCB0363D63, A223684978928B59D39DFB49F6658E0CF04ADD15AD8ACFCEC384DBD4D8C8CBCA ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
17:15:53.0702 0x144c AMD External Events Utility - ok
17:15:53.0708 0x144c AmdK8 - ok
17:15:53.0715 0x144c [ 83ADF64C5BEAC0A065D7D2811E9A79CA, C724DC6EC9CB0E93DC034054FFB79284E70502FA155EFF624E112243F6C8D8E8 ] amdkmafd C:\WINDOWS\system32\drivers\amdkmafd.sys
17:15:53.0732 0x144c amdkmafd - ok
17:15:53.0737 0x144c amdkmdag - ok
17:15:53.0758 0x144c [ C14D7E5F24381BC8F333C4EB77892400, 8B8EF49D2398AF39E36EFFE6D1E0489727D5612DEFA43C71E3C7E4C0650010A5 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
17:15:53.0810 0x144c amdkmdap - ok
17:15:53.0817 0x144c AmdPPM - ok
17:15:53.0823 0x144c amdsata - ok
17:15:53.0828 0x144c amdsbs - ok
17:15:53.0833 0x144c amdxata - ok
17:15:53.0842 0x144c AppID - ok
17:15:53.0848 0x144c AppIDSvc - ok
17:15:53.0854 0x144c Appinfo - ok
17:15:53.0860 0x144c applockerfltr - ok
17:15:53.0866 0x144c AppMgmt - ok
17:15:53.0873 0x144c AppReadiness - ok
17:15:53.0878 0x144c AppVClient - ok
17:15:53.0884 0x144c AppvStrm - ok
17:15:53.0891 0x144c AppvVemgr - ok
17:15:53.0897 0x144c AppvVfs - ok
17:15:53.0904 0x144c AppXSvc - ok
17:15:53.0910 0x144c arcsas - ok
17:15:53.0917 0x144c AsyncMac - ok
17:15:53.0924 0x144c atapi - ok
17:15:53.0931 0x144c athr - ok
17:15:53.0940 0x144c AudioEndpointBuilder - ok
17:15:53.0946 0x144c Audiosrv - ok
17:15:53.0963 0x144c [ 14FCA1D1720A68C2D586940ABBE2DB3C, 274DB01CFD3024357602748FE36882ACE6BB3764A9FB62B2B40F9232B84A9B3E ] Avira.ServiceHost C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
17:15:54.0000 0x144c Avira.ServiceHost - ok
17:15:54.0006 0x144c AxInstSV - ok
17:15:54.0013 0x144c b06bdrv - ok
17:15:54.0019 0x144c BasicDisplay - ok
17:15:54.0025 0x144c BasicRender - ok
17:15:54.0035 0x144c bcmfn - ok
17:15:54.0042 0x144c bcmfn2 - ok
17:15:54.0047 0x144c BDESVC - ok
17:15:54.0054 0x144c Beep - ok
17:15:54.0060 0x144c BFE - ok
17:15:54.0066 0x144c BITS - ok
17:15:54.0072 0x144c bowser - ok
17:15:54.0077 0x144c BrokerInfrastructure - ok
17:15:54.0083 0x144c Browser - ok
17:15:54.0089 0x144c BthAvrcpTg - ok
17:15:54.0095 0x144c BthHFEnum - ok
17:15:54.0101 0x144c bthhfhid - ok
17:15:54.0108 0x144c BthHFSrv - ok
17:15:54.0114 0x144c BTHMODEM - ok
17:15:54.0173 0x144c bthserv - ok
17:15:54.0180 0x144c buttonconverter - ok
17:15:54.0186 0x144c CapImg - ok
17:15:54.0193 0x144c cdfs - ok
17:15:54.0200 0x144c CDPSvc - ok
17:15:54.0205 0x144c CDPUserSvc - ok
17:15:54.0215 0x144c cdrom - ok
17:15:54.0220 0x144c CertPropSvc - ok
17:15:54.0227 0x144c cht4iscsi - ok
17:15:54.0232 0x144c cht4vbd - ok
17:15:54.0237 0x144c circlass - ok
17:15:54.0243 0x144c CLFS - ok
17:15:54.0248 0x144c ClipSVC - ok
17:15:54.0253 0x144c clreg - ok
17:15:54.0268 0x144c CmBatt - ok
17:15:54.0274 0x144c CNG - ok
17:15:54.0279 0x144c cnghwassist - ok
17:15:54.0292 0x144c CompositeBus - ok
17:15:54.0298 0x144c COMSysApp - ok
17:15:54.0307 0x144c condrv - ok
17:15:54.0314 0x144c CoreMessagingRegistrar - ok
17:15:54.0326 0x144c CryptSvc - ok
17:15:54.0333 0x144c CSC - ok
17:15:54.0339 0x144c CscService - ok
17:15:54.0345 0x144c dam - ok
17:15:54.0354 0x144c DcomLaunch - ok
17:15:54.0360 0x144c DcpSvc - ok
17:15:54.0367 0x144c defragsvc - ok
17:15:54.0373 0x144c DeviceAssociationService - ok
17:15:54.0379 0x144c DeviceInstall - ok
17:15:54.0385 0x144c DevQueryBroker - ok
17:15:54.0391 0x144c Dfsc - ok
17:15:54.0401 0x144c [ 73BDD44A6088916964945886F9025409, 8E2ECC9AAEF3C6EBA2E61D25F657FDFCC72AB517CC4FD5FFF992E1F9EB942662 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
17:15:54.0426 0x144c dg_ssudbus - ok
17:15:54.0432 0x144c Dhcp - ok
17:15:54.0439 0x144c diagnosticshub.standardcollector.service - ok
17:15:54.0445 0x144c DiagTrack - ok
17:15:54.0451 0x144c disk - ok
17:15:54.0459 0x144c DmEnrollmentSvc - ok
17:15:54.0465 0x144c dmvsc - ok
17:15:54.0471 0x144c dmwappushservice - ok
17:15:54.0476 0x144c Dnscache - ok
17:15:54.0484 0x144c dot3svc - ok
17:15:54.0490 0x144c DPS - ok
17:15:54.0496 0x144c drmkaud - ok
17:15:54.0502 0x144c DsmSvc - ok
17:15:54.0508 0x144c DsSvc - ok
17:15:54.0521 0x144c [ 33F90B202E9DD9B7D489EB59310FDC34, 6ECF6669433E090E9CF6B1875AF18D2C06F8CDB3901D58BF89C3E2202574ABBD ] dtsoftbus01 C:\WINDOWS\System32\drivers\dtsoftbus01.sys
17:15:54.0546 0x144c dtsoftbus01 - ok
17:15:54.0552 0x144c DXGKrnl - ok
17:15:54.0557 0x144c EapHost - ok
17:15:54.0563 0x144c ebdrv - ok
17:15:54.0568 0x144c EFS - ok
17:15:54.0576 0x144c EhStorClass - ok
17:15:54.0584 0x144c EhStorTcgDrv - ok
17:15:54.0589 0x144c embeddedmode - ok
17:15:54.0594 0x144c EntAppSvc - ok
17:15:54.0601 0x144c [ 9EAFB3B3B60B8AD958985152A9309ACA, EC58F487D50A125DA3F747670282EA2104580CCAAF709EA494B61C7549576AE6 ] epmntdrv C:\Windows\system32\epmntdrv.sys
17:15:54.0620 0x144c epmntdrv - detected UnsignedFile.Multi.Generic ( 1 )
17:15:54.0718 0x144c Detect skipped due to KSN trusted
17:15:54.0718 0x144c epmntdrv - ok
17:15:54.0724 0x144c ErrDev - ok
17:15:54.0732 0x144c [ FB949ED2C93C878A189039F3D7730942, 857AFB9965F14C80C21948C05A44D37948BD206961101DFF087735D6A7CCAA8A ] EuGdiDrv C:\Windows\system32\EuGdiDrv.sys
17:15:54.0751 0x144c EuGdiDrv - detected UnsignedFile.Multi.Generic ( 1 )
17:15:54.0860 0x144c Detect skipped due to KSN trusted
17:15:54.0860 0x144c EuGdiDrv - ok
17:15:54.0868 0x144c EventSystem - ok
17:15:54.0886 0x144c [ CA2E486FE6212FFD5FD171AC1A0B17BE, 4534A8496C8044F4DF3573B4021391327BE3BED026BC5CD1A35A5708651A9E1D ] ewusbmbb C:\WINDOWS\system32\DRIVERS\ewusbwwan.sys
17:15:54.0934 0x144c ewusbmbb - ok
17:15:54.0943 0x144c [ 86F7951BBCEE4A86E79A97306BD14318, 84B52A0392DA53ED71A2C4D483DD93DDF552BF8AC764C7BD47BE0EB58C7C8219 ] ew_hwusbdev C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys
17:15:54.0980 0x144c ew_hwusbdev - ok
17:15:54.0986 0x144c exfat - ok
17:15:54.0992 0x144c fastfat - ok
17:15:54.0998 0x144c Fax - ok
17:15:55.0004 0x144c fdc - ok
17:15:55.0011 0x144c fdPHost - ok
17:15:55.0016 0x144c FDResPub - ok
17:15:55.0023 0x144c fhsvc - ok
17:15:55.0028 0x144c FileCrypt - ok
17:15:55.0034 0x144c FileInfo - ok
17:15:55.0040 0x144c Filetrace - ok
17:15:55.0047 0x144c flpydisk - ok
17:15:55.0052 0x144c FltMgr - ok
17:15:55.0059 0x144c FontCache - ok
17:15:55.0064 0x144c FontCache3.0.0.0 - ok
17:15:55.0113 0x144c [ B3A740CF5841D2087F2A8ACBAD9CA9AD, 587D966D8FF6A6704E8367B470B4F6CA5F6A29A25E960C718E9AB51899D53DD1 ] FoxitReaderService C:\Program Files (x86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe
17:15:55.0191 0x144c FoxitReaderService - ok
17:15:55.0200 0x144c FrameServer - ok
17:15:55.0206 0x144c FsDepends - ok
17:15:55.0212 0x144c Fs_Rec - ok
17:15:55.0219 0x144c fvevol - ok
17:15:55.0227 0x144c gencounter - ok
17:15:55.0233 0x144c genericusbfn - ok
17:15:55.0239 0x144c GPIOClx0101 - ok
17:15:55.0246 0x144c gpsvc - ok
17:15:55.0251 0x144c GpuEnergyDrv - ok
17:15:55.0262 0x144c [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:15:55.0284 0x144c gupdate - ok
17:15:55.0291 0x144c [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:15:55.0310 0x144c gupdatem - ok
17:15:55.0316 0x144c HdAudAddService - ok
17:15:55.0321 0x144c HDAudBus - ok
17:15:55.0329 0x144c [ B6AC71AAA2B10848F57FC49D55A651AF, 4FAD833654E86F9FAF972AC8AF87FD4A9A765B26B96F096BBD63506B5D521A91 ] HECIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
17:15:55.0348 0x144c HECIx64 - ok
17:15:55.0354 0x144c HidBatt - ok
17:15:55.0360 0x144c HidBth - ok
17:15:55.0366 0x144c hidi2c - ok
17:15:55.0375 0x144c hidinterrupt - ok
17:15:55.0382 0x144c HidIr - ok
17:15:55.0389 0x144c hidserv - ok
17:15:55.0395 0x144c HidUsb - ok
17:15:55.0401 0x144c HomeGroupListener - ok
17:15:55.0407 0x144c HomeGroupProvider - ok
17:15:55.0414 0x144c HpSAMD - ok
17:15:55.0420 0x144c HTTP - ok
17:15:55.0428 0x144c [ 1642C62F1FD5E1FF44608283994A7BB8, 4646AA0EF74A2AEE6C17D12206FCFE1E84D6FA712AD95A171F16D11BC9D3F11A ] huawei_enumerator C:\WINDOWS\System32\drivers\ew_jubusenum.sys
17:15:55.0458 0x144c huawei_enumerator - ok
17:15:55.0465 0x144c HvHost - ok
17:15:55.0470 0x144c hvservice - ok
17:15:55.0478 0x144c HWDeviceService64.exe - ok
17:15:55.0485 0x144c hwpolicy - ok
17:15:55.0494 0x144c hyperkbd - ok
17:15:55.0500 0x144c i8042prt - ok
17:15:55.0507 0x144c iagpio - ok
17:15:55.0513 0x144c iai2c - ok
17:15:55.0519 0x144c iaLPSS2i_GPIO2 - ok
17:15:55.0526 0x144c iaLPSS2i_I2C - ok
17:15:55.0532 0x144c iaLPSSi_GPIO - ok
17:15:55.0539 0x144c iaLPSSi_I2C - ok
17:15:55.0548 0x144c iaStorAV - ok
17:15:55.0554 0x144c iaStorV - ok
17:15:55.0561 0x144c ibbus - ok
17:15:55.0567 0x144c icssvc - ok
17:15:55.0573 0x144c IKEEXT - ok
17:15:55.0584 0x144c [ DD587A55390ED2295BCE6D36AD567DA9, AEB7DCB8EF89BEE8D9649A05FC482B1E4E3F44243D57A2577C862EB69166C48E ] Impcd C:\WINDOWS\System32\drivers\Impcd.sys
17:15:55.0620 0x144c Impcd - ok
17:15:55.0625 0x144c IndirectKmd - ok
17:15:55.0680 0x144c [ 1A6241B70453A6629A83DB942AA6B08C, EF93785E20E18BF36F667E35F89BBF2A17C86F57E2D17D077F5031CE70E9DC9D ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
17:15:55.0755 0x144c IntcAzAudAddService - ok
17:15:55.0764 0x144c intelide - ok
17:15:55.0770 0x144c intelpep - ok
17:15:55.0776 0x144c intelppm - ok
17:15:55.0782 0x144c iorate - ok
17:15:55.0787 0x144c IpFilterDriver - ok
17:15:55.0794 0x144c iphlpsvc - ok
17:15:55.0800 0x144c IPMIDRV - ok
17:15:55.0805 0x144c IPNAT - ok
17:15:55.0811 0x144c irda - ok
17:15:55.0818 0x144c IRENUM - ok
17:15:55.0824 0x144c irmon - ok
17:15:55.0830 0x144c isapnp - ok
17:15:55.0836 0x144c iScsiPrt - ok
17:15:55.0844 0x144c [ 5678EC677028221EC5C815BCD07AB697, 02FD1A0290A9A17823D24A0E55D4AB35C3F939C986AB8BB54C6248287466FE0D ] jrdusbser C:\WINDOWS\system32\DRIVERS\jrdusbser.sys
17:15:55.0878 0x144c jrdusbser - ok
17:15:55.0882 0x144c Juqokchukity - ok
17:15:55.0890 0x144c kbdclass - ok
17:15:55.0897 0x144c kbdhid - ok
17:15:55.0903 0x144c kdnic - ok
17:15:55.0910 0x144c KeyIso - ok
17:15:55.0917 0x144c KSecDD - ok
17:15:55.0924 0x144c KSecPkg - ok
17:15:55.0930 0x144c ksthunk - ok
17:15:55.0936 0x144c KtmRm - ok
17:15:55.0943 0x144c LanmanServer - ok
17:15:55.0949 0x144c LanmanWorkstation - ok
17:15:55.0957 0x144c lfsvc - ok
17:15:55.0963 0x144c LicenseManager - ok
17:15:55.0969 0x144c lltdio - ok
17:15:55.0976 0x144c lltdsvc - ok
17:15:55.0982 0x144c lmhosts - ok
17:15:55.0991 0x144c LSI_SAS - ok
17:15:55.0997 0x144c LSI_SAS2i - ok
17:15:56.0003 0x144c LSI_SAS3i - ok
17:15:56.0010 0x144c LSI_SSS - ok
17:15:56.0018 0x144c LSM - ok
17:15:56.0024 0x144c luafv - ok
17:15:56.0041 0x144c [ A0A527569856B9814E8920F52EBB67F5, 4347277C84B47E4CC048850BDEFB258CFB3B476AA99FD503FD71FBB70FFF5ACF ] LVRS64 C:\WINDOWS\system32\DRIVERS\lvrs64.sys
17:15:56.0075 0x144c LVRS64 - ok
17:15:56.0202 0x144c [ 415E344294D1C0D04627B29146F68481, B4A1A05BDF07E8F226A98E51F62BE18BE2C046A084C495BD8A95CABC79FD0614 ] LVUVC64 C:\WINDOWS\system32\DRIVERS\lvuvc64.sys
17:15:56.0351 0x144c LVUVC64 - ok
17:15:56.0366 0x144c MapsBroker - ok
17:15:56.0378 0x144c [ 3BEC6134F1E45AEF5E971F69F0D38510, 245D7CEEB6561166EE0472551D39A9D3CFDDA52A6BF2E924AB243CCA7FBC9009 ] MBAMChameleon C:\WINDOWS\system32\drivers\MBAMChameleon.sys
17:15:56.0406 0x144c MBAMChameleon - ok
17:15:56.0414 0x144c [ 88BD122C3A35DE63D75D382DF75554CE, ABDF59543CAD186A6ED4E66257205D9CF5047732A5DA74A96A28B468B41BC396 ] MBAMProtection C:\WINDOWS\system32\drivers\mbam.sys
17:15:56.0436 0x144c MBAMProtection - ok
17:15:56.0557 0x144c [ 28E521A6ABA9DE062A3719452816F495, B312A37DA052229DFB19353170CD5828582F8AC6426E857CA7C8ACA0DD91C160 ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
17:15:56.0711 0x144c MBAMService - ok
17:15:56.0724 0x144c megasas - ok
17:15:56.0730 0x144c megasas2i - ok
17:15:56.0736 0x144c megasr - ok
17:15:56.0742 0x144c MessagingService - ok
17:15:56.0752 0x144c mlx4_bus - ok
17:15:56.0758 0x144c MMCSS - ok
17:15:56.0770 0x144c [ 1CE0621B591913C12BECAA5B50E88BB2, 115068C57570140C9389BD923A4E68236ACEBB4F733DA09D05AEEDAD7317AB46 ] Mobile Partner. RunOuc C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe
17:15:56.0791 0x144c Mobile Partner. RunOuc - ok
17:15:56.0797 0x144c Modem - ok
17:15:56.0803 0x144c monitor - ok
17:15:56.0810 0x144c mouclass - ok
17:15:56.0816 0x144c mouhid - ok
17:15:56.0821 0x144c mountmgr - ok
17:15:56.0828 0x144c mpsdrv - ok
17:15:56.0835 0x144c MpsSvc - ok
17:15:56.0841 0x144c MRxDAV - ok
17:15:56.0847 0x144c mrxsmb - ok
17:15:56.0853 0x144c mrxsmb10 - ok
17:15:56.0860 0x144c mrxsmb20 - ok
17:15:56.0867 0x144c MsBridge - ok
17:15:56.0874 0x144c MSDTC - ok
17:15:56.0886 0x144c Msfs - ok
17:15:56.0893 0x144c msgpiowin32 - ok
17:15:56.0899 0x144c mshidkmdf - ok
17:15:56.0906 0x144c mshidumdf - ok
17:15:56.0912 0x144c msisadrv - ok
17:15:56.0919 0x144c MSiSCSI - ok
17:15:56.0925 0x144c msiserver - ok
17:15:56.0931 0x144c MSKSSRV - ok
17:15:56.0939 0x144c MsLldp - ok
17:15:56.0945 0x144c MSPCLOCK - ok
17:15:56.0952 0x144c MSPQM - ok
17:15:56.0958 0x144c MsRPC - ok
17:15:56.0967 0x144c MsSecFlt - ok
17:15:56.0974 0x144c mssmbios - ok
17:15:56.0980 0x144c MSTEE - ok
17:15:56.0987 0x144c MTConfig - ok
17:15:56.0993 0x144c Mup - ok
17:15:56.0999 0x144c mvumis - ok
17:15:57.0009 0x144c NativeWifiP - ok
17:15:57.0035 0x144c [ E0E4A1F81A7D69C595A8A9DDAD084C19, 8F55F3637AE8BFFB0ACE37AFC5122026525137E0B2923899B779C1BD08DF0E22 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
17:15:57.0075 0x144c NAUpdate - ok
17:15:57.0083 0x144c NcaSvc - ok
17:15:57.0089 0x144c NcbService - ok
17:15:57.0102 0x144c NcdAutoSetup - ok
17:15:57.0108 0x144c ndfltr - ok
17:15:57.0114 0x144c NDIS - ok
17:15:57.0121 0x144c NdisCap - ok
17:15:57.0127 0x144c NdisImPlatform - ok
17:15:57.0134 0x144c NdisTapi - ok
17:15:57.0140 0x144c Ndisuio - ok
17:15:57.0146 0x144c NdisVirtualBus - ok
17:15:57.0153 0x144c NdisWan - ok
17:15:57.0159 0x144c ndiswanlegacy - ok
17:15:57.0165 0x144c ndproxy - ok
17:15:57.0172 0x144c Ndu - ok
17:15:57.0178 0x144c NetAdapterCx - ok
17:15:57.0184 0x144c NetBIOS - ok
17:15:57.0194 0x144c NetBT - ok
17:15:57.0202 0x144c Netlogon - ok
17:15:57.0209 0x144c Netman - ok
17:15:57.0215 0x144c netprofm - ok
17:15:57.0222 0x144c NetSetupSvc - ok
17:15:57.0229 0x144c NetTcpPortSharing - ok
17:15:57.0238 0x144c NgcCtnrSvc - ok
17:15:57.0244 0x144c NgcSvc - ok
17:15:57.0251 0x144c NlaSvc - ok
17:15:57.0258 0x144c [ DE7FCC77F4A503AF4CA6A47D49B3713D, 4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6 ] npf C:\WINDOWS\system32\drivers\npf.sys
17:15:57.0279 0x144c npf - ok
17:15:57.0285 0x144c Npfs - ok
17:15:57.0291 0x144c npsvctrig - ok
17:15:57.0303 0x144c nsi - ok
17:15:57.0317 0x144c nsiproxy - ok
17:15:57.0334 0x144c NTFS - ok
17:15:57.0341 0x144c Null - ok
17:15:57.0351 0x144c [ B01C1E6D7477961D6D1CBDCD44AF3E67, 407BD335FE7C87DFBD9EDE49BDD828263D8C8D25C8216FF04AC70320E74AE8B6 ] nusb3hub C:\WINDOWS\System32\drivers\nusb3hub.sys
17:15:57.0374 0x144c nusb3hub - ok
17:15:57.0383 0x144c nvraid - ok
17:15:57.0389 0x144c nvstor - ok
17:15:57.0397 0x144c OneSyncSvc - ok
17:15:57.0410 0x144c [ 11E0B35479C895888BA3D7F619DCFFF3, 6ED82C19898101EC00BD64A9F90595C3D20AD2D2902AA8765B740FB3B9312DDF ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:15:57.0441 0x144c ose64 - ok
17:15:57.0450 0x144c p2pimsvc - ok
17:15:57.0457 0x144c p2psvc - ok
17:15:57.0465 0x144c Parport - ok
17:15:57.0473 0x144c partmgr - ok
17:15:57.0480 0x144c PcaSvc - ok
17:15:57.0487 0x144c pci - ok
17:15:57.0493 0x144c pciide - ok
17:15:57.0499 0x144c pcmcia - ok
17:15:57.0505 0x144c pcw - ok
17:15:57.0511 0x144c pdc - ok
17:15:57.0517 0x144c PEAUTH - ok
17:15:57.0523 0x144c PeerDistSvc - ok
17:15:57.0529 0x144c percsas2i - ok
17:15:57.0535 0x144c percsas3i - ok
17:15:57.0555 0x144c PerfHost - ok
17:15:57.0568 0x144c PhoneSvc - ok
17:15:57.0577 0x144c PimIndexMaintenanceSvc - ok
17:15:57.0587 0x144c pla - ok
17:15:57.0594 0x144c PlugPlay - ok
17:15:57.0601 0x144c PnkBstrA - ok
17:15:57.0606 0x144c PnkBstrB - ok
17:15:57.0613 0x144c PNRPAutoReg - ok
17:15:57.0619 0x144c PNRPsvc - ok
17:15:57.0625 0x144c PolicyAgent - ok
17:15:57.0634 0x144c Power - ok
17:15:57.0640 0x144c PptpMiniport - ok
17:15:57.0742 0x144c [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
17:15:57.0939 0x144c PrintNotify - ok
17:15:57.0952 0x144c Processor - ok
17:15:57.0965 0x144c ProfSvc - ok
17:15:57.0972 0x144c Psched - ok
17:15:57.0978 0x144c [ C32ECB99AD25E9A04F01C8665DF29EF8, 0489B3DEC6A33E50D8A48A8DAD3F5B923A81F7300E4A71358D90D2879BAC9AA2 ] pwdrvio C:\Windows\system32\pwdrvio.sys
17:15:58.0012 0x144c pwdrvio - ok
17:15:58.0018 0x144c [ D619356B955EEFA642F5FF72755E8B3C, 1FD54978A77ACD6FBF1236E177ED074894743A9141E4169FE9AFE28680FC93C5 ] pwdspio C:\Windows\system32\pwdspio.sys
17:15:58.0047 0x144c pwdspio - ok
17:15:58.0053 0x144c QWAVE - ok
17:15:58.0059 0x144c QWAVEdrv - ok
17:15:58.0065 0x144c RasAcd - ok
17:15:58.0072 0x144c RasAgileVpn - ok
17:15:58.0079 0x144c RasAuto - ok
17:15:58.0085 0x144c Rasl2tp - ok
17:15:58.0092 0x144c RasMan - ok
17:15:58.0098 0x144c RasPppoe - ok
17:15:58.0104 0x144c RasSstp - ok
17:15:58.0111 0x144c rdbss - ok
17:15:58.0121 0x144c rdpbus - ok
17:15:58.0127 0x144c RDPDR - ok
17:15:58.0140 0x144c RdpVideoMiniport - ok
17:15:58.0146 0x144c rdyboost - ok
17:15:58.0152 0x144c ReFSv1 - ok
17:15:58.0162 0x144c RemoteAccess - ok
17:15:58.0169 0x144c RemoteRegistry - ok
17:15:58.0175 0x144c RetailDemo - ok
17:15:58.0184 0x144c [ 5CA4ABD888B602551B59BAA26941C167, F6FC0F828153E07EAFFAB6E11556DA23A5F6D9FC063E36947B1AC73E7E7E705E ] rimspci C:\WINDOWS\System32\drivers\rimssne64.sys
17:15:58.0218 0x144c rimspci - ok
17:15:58.0227 0x144c [ BB6E138AEB351728959DA5E2731D8140, E6656869A03380EB96A31E4E5FF4D565916EB0A7ED334330D2DD039390441D15 ] risdsnpe C:\WINDOWS\System32\drivers\risdsne64.sys
17:15:58.0257 0x144c risdsnpe - ok
17:15:58.0263 0x144c RmSvc - ok
17:15:58.0269 0x144c RpcEptMapper - ok
17:15:58.0276 0x144c RpcLocator - ok
17:15:58.0283 0x144c RpcSs - ok
17:15:58.0290 0x144c rspndr - ok
17:15:58.0302 0x144c [ 7421A35C45484B95E83B5E9E107CEFC2, 128BB6A7552B9D57284056FB8946A6FE3C620F7B706F709F896828304A6FCD77 ] RTHDMIAzAudService C:\WINDOWS\system32\drivers\RtHDMIVX.sys
17:15:58.0326 0x144c RTHDMIAzAudService - ok
17:15:58.0332 0x144c s3cap - ok
17:15:58.0351 0x144c SamSs - ok
17:15:58.0357 0x144c [ 3289766038DB2CB14D07DC84392138D5, A7790B787690CC1A8B97E4532090C5295350A836A9474DEA74CEB3E81CF26124 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
17:15:58.0374 0x144c SASDIFSV - ok
17:15:58.0378 0x144c [ 58A38E75F3316A83C23DF6173D41F2B5, B0A8CDA1D164B7534FB41AB80792861384709BF0F914F44553275CF20194F1A1 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
17:15:58.0395 0x144c SASKUTIL - ok
17:15:58.0401 0x144c sbp2port - ok
17:15:58.0408 0x144c SCardSvr - ok
17:15:58.0414 0x144c ScDeviceEnum - ok
17:15:58.0420 0x144c scfilter - ok
17:15:58.0438 0x144c Schedule - ok
17:15:58.0451 0x144c scmbus - ok
17:15:58.0458 0x144c scmdisk0101 - ok
17:15:58.0464 0x144c SCPolicySvc - ok
17:15:58.0472 0x144c sdbus - ok
17:15:58.0479 0x144c SDRSVC - ok
17:15:58.0486 0x144c sdstor - ok
17:15:58.0492 0x144c seclogon - ok
17:15:58.0498 0x144c SENS - ok
17:15:58.0504 0x144c Sense - ok
17:15:58.0512 0x144c SensorDataService - ok
17:15:58.0519 0x144c SensorService - ok
17:15:58.0526 0x144c SensrSvc - ok
17:15:58.0532 0x144c SerCx - ok
17:15:58.0540 0x144c SerCx2 - ok
17:15:58.0553 0x144c Serenum - ok
17:15:58.0565 0x144c Serial - ok
17:15:58.0578 0x144c sermouse - ok
17:15:58.0602 0x144c SessionEnv - ok
17:15:58.0608 0x144c [ 70F9C476B62DE4F2823E918A6C181ADE, E1A641418A6CB4FA38BB29B86934838B28D8909B8066E5089D85BF72FD61F4C4 ] SFEP C:\WINDOWS\System32\drivers\SFEP.sys
17:15:58.0634 0x144c SFEP - ok
17:15:58.0639 0x144c sfloppy - ok
17:15:58.0647 0x144c SharedAccess - ok
17:15:58.0653 0x144c ShellHWDetection - ok
17:15:58.0660 0x144c shpamsvc - ok
17:15:58.0667 0x144c SiSRaid2 - ok
17:15:58.0673 0x144c SiSRaid4 - ok
17:15:58.0687 0x144c [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
17:15:58.0722 0x144c SkypeUpdate - ok
17:15:58.0728 0x144c smphost - ok
17:15:58.0736 0x144c SmsRouter - ok
17:15:58.0749 0x144c SNMPTRAP - ok
17:15:58.0755 0x144c spaceport - ok
17:15:58.0761 0x144c Sparhandy_Germany Silverstone Modem Device Helper - ok
17:15:58.0768 0x144c SpbCx - ok
17:15:58.0786 0x144c [ 0FFE35F0B0CD5A324BBE22F02569AE3B, F4EE803EEFDB4EAEEDB3024C3516F1F9A202C77F4870D6B74356BBDE32B3B560 ] speedfan C:\Windows\SysWOW64\speedfan.sys
17:15:58.0821 0x144c speedfan - ok
17:15:58.0827 0x144c Spooler - ok
17:15:58.0834 0x144c sppsvc - ok
17:15:58.0840 0x144c srv - ok
17:15:58.0847 0x144c srv2 - ok
17:15:58.0854 0x144c srvnet - ok
17:15:58.0861 0x144c SSDPSRV - ok
17:15:58.0868 0x144c SstpSvc - ok
17:15:58.0881 0x144c [ 5252D7BC56E5E0ED715AEA8FE173A455, 1408B3E98B35A449434718777EE70595F0D306197A428279C6281D2F1953F259 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
17:15:58.0904 0x144c ssudmdm - ok
17:15:58.0911 0x144c StateRepository - ok
17:15:58.0918 0x144c stexstor - ok
17:15:58.0924 0x144c stisvc - ok
17:15:58.0931 0x144c storahci - ok
17:15:58.0938 0x144c storflt - ok
17:15:58.0944 0x144c stornvme - ok
17:15:58.0951 0x144c storqosflt - ok
17:15:58.0958 0x144c StorSvc - ok
17:15:58.0964 0x144c storufs - ok
17:15:58.0971 0x144c storvsc - ok
17:15:58.0977 0x144c svsvc - ok
17:15:58.0984 0x144c swenum - ok
17:15:58.0991 0x144c swprv - ok
17:15:58.0997 0x144c Synth3dVsc - ok
17:15:59.0004 0x144c SysMain - ok
17:15:59.0011 0x144c SystemEventsBroker - ok
17:15:59.0018 0x144c TabletInputService - ok
17:15:59.0026 0x144c [ 3C32FF010F869BC184DF71290477384E, 55CFCEC7F026C6E2E96A2FBE846AB513BB12BB0348735274FE1B71AF019C837B ] tap0901 C:\WINDOWS\System32\drivers\tap0901.sys
17:15:59.0050 0x144c tap0901 - ok
17:15:59.0056 0x144c TapiSrv - ok
17:15:59.0063 0x144c Tcpip - ok
17:15:59.0069 0x144c Tcpip6 - ok
17:15:59.0078 0x144c tcpipreg - ok
17:15:59.0088 0x144c tdx - ok
17:15:59.0094 0x144c terminpt - ok
17:15:59.0101 0x144c TermService - ok
17:15:59.0107 0x144c Themes - ok
17:15:59.0113 0x144c TieringEngineService - ok
17:15:59.0120 0x144c tiledatamodelsvc - ok
17:15:59.0126 0x144c TimeBrokerSvc - ok
17:15:59.0133 0x144c TPM - ok
17:15:59.0140 0x144c TrkWks - ok
17:15:59.0146 0x144c TrustedInstaller - ok
17:15:59.0155 0x144c tsusbflt - ok
17:15:59.0162 0x144c TsUsbGD - ok
17:15:59.0169 0x144c tsusbhub - ok
17:15:59.0175 0x144c tunnel - ok
17:15:59.0181 0x144c tzautoupdate - ok
17:15:59.0188 0x144c UASPStor - ok
17:15:59.0196 0x144c [ 209F5CEAAAFE601851E7B40902FC230D, B7BFD753DF9EA1AD6D6BD8FB47F24E79FA84208E7A66C88B934C3A13B087901D ] ucdrv C:\WINDOWS\System32\drivers:ucdrv-x64.sys
17:15:59.0217 0x144c Suspicious file ( Hidden ): C:\WINDOWS\System32\drivers:ucdrv-x64.sys. md5: 209F5CEAAAFE601851E7B40902FC230D, sha256: B7BFD753DF9EA1AD6D6BD8FB47F24E79FA84208E7A66C88B934C3A13B087901D
17:15:59.0217 0x144c ucdrv - detected HiddenFile.Multi.Generic ( 1 )
17:15:59.0333 0x144c Detect skipped due to KSN trusted
17:15:59.0333 0x144c ucdrv - ok
17:15:59.0338 0x144c UcmCx0101 - ok
17:15:59.0346 0x144c UcmTcpciCx0101 - ok
17:15:59.0352 0x144c UcmUcsi - ok
17:15:59.0358 0x144c Ucx01000 - ok
17:15:59.0365 0x144c UdeCx - ok
17:15:59.0371 0x144c udfs - ok
17:15:59.0378 0x144c UEFI - ok
17:15:59.0385 0x144c UevAgentDriver - ok
17:15:59.0392 0x144c UevAgentService - ok
17:15:59.0398 0x144c Ufx01000 - ok
17:15:59.0404 0x144c UfxChipidea - ok
17:15:59.0411 0x144c ufxsynopsys - ok
17:15:59.0424 0x144c UI0Detect - ok
17:15:59.0430 0x144c umbus - ok
17:15:59.0436 0x144c UmPass - ok
17:15:59.0443 0x144c UmRdpService - ok
17:15:59.0450 0x144c UnistoreSvc - ok
17:15:59.0460 0x144c [ 9DC07E73A4ABB9ACF692113B36A5009F, CA7176FC219515D58DCFA66EC61880ECE5617275C9B83701BB74D8B60E733D34 ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys
17:15:59.0478 0x144c UnlockerDriver5 - ok
17:15:59.0485 0x144c upnphost - ok
17:15:59.0491 0x144c UrsChipidea - ok
17:15:59.0498 0x144c UrsCx01000 - ok
17:15:59.0505 0x144c UrsSynopsys - ok
17:15:59.0529 0x144c [ 55020D37C29F05D583A76F20127B4FD7, 9BFB5F16D5C15ADF3ECB8769B66F443250497F6A2F58FA74954EC64EF2F6C33E ] USB28xxBGA C:\WINDOWS\system32\DRIVERS\emBDA64.sys
17:15:59.0596 0x144c USB28xxBGA - ok
17:15:59.0606 0x144c [ D7940283C43E440FCF83AB55B85689C9, C41DD0E5CE66328694047FF468BBBB3D35FBB9CB41A249202A05DB411EFEEFB1 ] USB28xxOEM C:\WINDOWS\system32\DRIVERS\emOEM64.sys
17:15:59.0636 0x144c USB28xxOEM - ok
17:15:59.0643 0x144c usbaudio - ok
17:15:59.0650 0x144c usbccgp - ok
17:15:59.0656 0x144c usbcir - ok
17:15:59.0663 0x144c usbehci - ok
17:15:59.0670 0x144c usbhub - ok
17:15:59.0677 0x144c USBHUB3 - ok
17:15:59.0685 0x144c usbohci - ok
17:15:59.0692 0x144c usbprint - ok
17:15:59.0698 0x144c usbscan - ok
17:15:59.0705 0x144c usbser - ok
17:15:59.0712 0x144c USBSTOR - ok
17:15:59.0719 0x144c usbuhci - ok
17:15:59.0726 0x144c usbvideo - ok
17:15:59.0733 0x144c USBXHCI - ok
17:15:59.0741 0x144c UserDataSvc - ok
17:15:59.0752 0x144c UserManager - ok
17:15:59.0759 0x144c UsoSvc - ok
17:15:59.0766 0x144c VaultSvc - ok
17:15:59.0773 0x144c vdrvroot - ok
17:15:59.0780 0x144c vds - ok
17:15:59.0787 0x144c VerifierExt - ok
17:15:59.0794 0x144c vhdmp - ok
17:15:59.0802 0x144c vhf - ok
17:15:59.0809 0x144c vmbus - ok
17:15:59.0816 0x144c VMBusHID - ok
17:15:59.0824 0x144c vmgid - ok
17:15:59.0831 0x144c vmicguestinterface - ok
17:15:59.0838 0x144c vmicheartbeat - ok
17:15:59.0844 0x144c vmickvpexchange - ok
17:15:59.0852 0x144c vmicrdv - ok
17:15:59.0858 0x144c vmicshutdown - ok
17:15:59.0865 0x144c vmictimesync - ok
17:15:59.0872 0x144c vmicvmsession - ok
17:15:59.0879 0x144c vmicvss - ok
17:15:59.0886 0x144c volmgr - ok
17:15:59.0893 0x144c volmgrx - ok
17:15:59.0901 0x144c volsnap - ok
17:15:59.0908 0x144c volume - ok
17:15:59.0915 0x144c vpci - ok
17:15:59.0922 0x144c vsmraid - ok
17:15:59.0929 0x144c VSS - ok
17:15:59.0936 0x144c VSTXRAID - ok
17:15:59.0943 0x144c vwifibus - ok
17:15:59.0950 0x144c vwififlt - ok
17:15:59.0957 0x144c vwifimp - ok
17:15:59.0965 0x144c W32Time - ok
17:15:59.0971 0x144c WacomPen - ok
17:15:59.0979 0x144c WalletService - ok
17:15:59.0986 0x144c wanarp - ok
17:15:59.0993 0x144c wanarpv6 - ok
17:16:00.0000 0x144c wbengine - ok
17:16:00.0008 0x144c WbioSrvc - ok
17:16:00.0015 0x144c wcifs - ok
17:16:00.0022 0x144c Wcmsvc - ok
17:16:00.0029 0x144c wcncsvc - ok
17:16:00.0036 0x144c wcnfs - ok
17:16:00.0044 0x144c WdBoot - ok
17:16:00.0052 0x144c Wdf01000 - ok
17:16:00.0059 0x144c WdFilter - ok
17:16:00.0066 0x144c WdiServiceHost - ok
17:16:00.0072 0x144c WdiSystemHost - ok
17:16:00.0079 0x144c wdiwifi - ok
17:16:00.0086 0x144c WdNisDrv - ok
17:16:00.0092 0x144c WdNisSvc - ok
17:16:00.0099 0x144c WebClient - ok
17:16:00.0106 0x144c Wecsvc - ok
17:16:00.0112 0x144c WEPHOSTSVC - ok
17:16:00.0120 0x144c wercplsupport - ok
17:16:00.0129 0x144c WerSvc - ok
17:16:00.0135 0x144c WFPLWFS - ok
17:16:00.0142 0x144c WiaRpc - ok
17:16:00.0149 0x144c WIMMount - ok
17:16:00.0154 0x144c WinDefend - ok
17:16:00.0169 0x144c WindowsTrustedRT - ok
17:16:00.0176 0x144c WindowsTrustedRTProxy - ok
17:16:00.0183 0x144c WinHttpAutoProxySvc - ok
17:16:00.0191 0x144c WinMad - ok
17:16:00.0199 0x144c Winmgmt - ok
17:16:00.0206 0x144c WinRM - ok
17:16:00.0219 0x144c WINUSB - ok
17:16:00.0225 0x144c WinVerbs - ok
17:16:00.0232 0x144c wisvc - ok
17:16:00.0239 0x144c WlanSvc - ok
17:16:00.0247 0x144c wlidsvc - ok
17:16:00.0253 0x144c WmiAcpi - ok
17:16:00.0263 0x144c wmiApSrv - ok
17:16:00.0269 0x144c WMPNetworkSvc - ok
17:16:00.0277 0x144c Wof - ok
17:16:00.0287 0x144c workfolderssvc - ok
17:16:00.0294 0x144c WPDBusEnum - ok
17:16:00.0301 0x144c WpdUpFltr - ok
17:16:00.0308 0x144c WpnService - ok
17:16:00.0315 0x144c WpnUserService - ok
17:16:00.0326 0x144c ws2ifsl - ok
17:16:00.0333 0x144c wscsvc - ok
17:16:00.0339 0x144c WSearch - ok
17:16:00.0350 0x144c wuauserv - ok
17:16:00.0357 0x144c WudfPf - ok
17:16:00.0364 0x144c WUDFRd - ok
17:16:00.0371 0x144c wudfsvc - ok
17:16:00.0380 0x144c WUDFWpdFs - ok
17:16:00.0387 0x144c WUDFWpdMtp - ok
17:16:00.0394 0x144c WwanSvc - ok
17:16:00.0401 0x144c XblAuthManager - ok
17:16:00.0408 0x144c XblGameSave - ok
17:16:00.0415 0x144c xboxgip - ok
17:16:00.0422 0x144c XboxNetApiSvc - ok
17:16:00.0429 0x144c xinputhid - ok
17:16:00.0440 0x144c ykinw8 - ok
17:16:00.0441 0x144c ================ Scan global ===============================
17:16:00.0462 0x144c [ Global ] - ok
17:16:00.0463 0x144c ================ Scan MBR ==================================
17:16:00.0466 0x144c [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:16:00.0568 0x144c \Device\Harddisk0\DR0 - ok
17:16:00.0631 0x144c [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
17:16:00.0768 0x144c \Device\Harddisk1\DR1 - ok
17:16:00.0773 0x144c [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk4\DR4
17:16:00.0850 0x144c \Device\Harddisk4\DR4 - ok
17:16:00.0851 0x144c ================ Scan VBR ==================================
17:16:00.0854 0x144c [ B75D89CA6D84C3CB1A6CA73A56716F49 ] \Device\Harddisk0\DR0\Partition1
17:16:00.0856 0x144c \Device\Harddisk0\DR0\Partition1 - ok
17:16:00.0859 0x144c [ BF802D8035F06A0BA68F026159CA8763 ] \Device\Harddisk1\DR1\Partition1
17:16:00.0862 0x144c \Device\Harddisk1\DR1\Partition1 - ok
17:16:00.0865 0x144c [ 55D863E4CA2B9A5E1BB7A9B572FDDD70 ] \Device\Harddisk4\DR4\Partition1
17:16:00.0867 0x144c \Device\Harddisk4\DR4\Partition1 - ok
17:16:00.0868 0x144c ================ Scan generic autorun ======================
17:16:01.0085 0x144c [ 5229C2546E151D368A1CE0E451351231, 2E421986933D70789665195A92D2A9022500E9382B2881881B741F0023D6422E ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
17:16:01.0333 0x144c RtHDVCpl - ok
17:16:01.0353 0x144c [ 5677C8C60F4659E8626AC9036EEF38DF, 1C7D3EC3BCB3E34900DD9556A3EBAF449C68585DC8E07682E680790497105B8B ] C:\Program Files\Classic Shell\ClassicStartMenu.exe
17:16:01.0377 0x144c Classic Start Menu - ok
17:16:01.0385 0x144c [ 8943465BEFA91044227D42E84ECB8280, 76D19CE3EB7E6C6573F250543CDC10B3601604535BFB756805AE246FA55AC265 ] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
17:16:01.0404 0x144c NUSB3MON - ok
17:16:01.0414 0x144c [ CD0362AEE36CFE1EF5DF973230742E67, 9F1D8AD4E09D16C39CD6A35CB298456468C1808226FFA8AD65BF9562A6ECC07D ] C:\Program Files (x86)\PDF24\pdf24.exe
17:16:01.0441 0x144c PDFPrint - ok
17:16:01.0447 0x144c [ B69B3F28C5DB496202C88F5A181640AC, 6ECD6DCFE27A043457BA910289849534ED9D173856DAF694687366E1A2C7A135 ] C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
17:16:01.0465 0x144c Avira SystrayStartTrigger - ok
17:16:01.0479 0x144c OneDriveSetup - ok
17:16:01.0482 0x144c OneDriveSetup - ok
17:16:01.0502 0x144c [ 7D0F245088942BCB888A0AC149A6F378, 20B8145FC6988DB195E7E153FB8CA20DDE39CFC540AC5DC9BC1E91497E3ACC92 ] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEJE.EXE
17:16:01.0540 0x144c EPSON Stylus Office BX300F - ok
17:16:01.0672 0x144c [ F73154E180105822A5F9B755BA933737, 1CD775B6CE3736A70EC5FC7A6B77A2FEDA70D59B49A66046CC20B341005501D9 ] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
17:16:01.0827 0x144c DAEMON Tools Lite - ok
17:16:01.0833 0x144c Waiting for KSN requests completion. In queue: 51
17:16:02.0866 0x144c AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
17:16:02.0870 0x144c AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.134 ), 0x60000 ( disabled : updated )
17:16:02.0880 0x144c Win FW state via NFP2: enabled ( trusted )
17:16:02.0982 0x144c ============================================================
17:16:02.0982 0x144c Scan finished
17:16:02.0982 0x144c ============================================================
17:16:02.0993 0x1754 Detected object count: 0
17:16:02.0993 0x1754 Actual detected object count: 0
17:16:35.0469 0x0fd4 ============================================================
17:16:35.0469 0x0fd4 Scan started
17:16:35.0469 0x0fd4 Mode: Manual; SigCheck; TDLFS;
17:16:35.0469 0x0fd4 ============================================================
17:16:35.0469 0x0fd4 KSN ping started
17:16:35.0548 0x0fd4 KSN ping finished: true
17:16:36.0438 0x0fd4 ================ Scan system memory ========================
17:16:36.0438 0x0fd4 System memory - ok
17:16:36.0438 0x0fd4 ================ Scan services =============================
17:16:36.0454 0x0fd4 [ 970C70F6B2953ED43822D3797855D84C, CB22723678B514277BC6E6DDDD206F3B2377CD889C9D473A47A7056BE597BC6B ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
17:16:36.0470 0x0fd4 !SASCORE - ok
17:16:36.0516 0x0fd4 1394ohci - ok
17:16:36.0516 0x0fd4 3ware - ok
17:16:36.0532 0x0fd4 ACPI - ok
17:16:36.0532 0x0fd4 AcpiDev - ok
17:16:36.0548 0x0fd4 acpiex - ok
17:16:36.0548 0x0fd4 acpipagr - ok
17:16:36.0548 0x0fd4 AcpiPmi - ok
17:16:36.0563 0x0fd4 acpitime - ok
17:16:36.0563 0x0fd4 ADP80XX - ok
17:16:36.0579 0x0fd4 AFD - ok
17:16:36.0579 0x0fd4 ahcache - ok
17:16:36.0579 0x0fd4 AJRouter - ok
17:16:36.0595 0x0fd4 [ 808820DEF092FA0A6D93BAE3E5D069CD, D1F49B6D99E346242EF6A9C37D2EC9333411FBDB031BE87FE0F8CDFEC545DD89 ] AlcatelOTnet C:\WINDOWS\system32\DRIVERS\AlcatelOTUsbnet.sys
17:16:36.0626 0x0fd4 AlcatelOTnet - ok
17:16:36.0626 0x0fd4 ALG - ok
17:16:36.0641 0x0fd4 [ D7A72B9BA6AB996DADB37BFCB0363D63, A223684978928B59D39DFB49F6658E0CF04ADD15AD8ACFCEC384DBD4D8C8CBCA ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
17:16:36.0673 0x0fd4 AMD External Events Utility - ok
17:16:36.0673 0x0fd4 AmdK8 - ok
17:16:36.0688 0x0fd4 [ 83ADF64C5BEAC0A065D7D2811E9A79CA, C724DC6EC9CB0E93DC034054FFB79284E70502FA155EFF624E112243F6C8D8E8 ] amdkmafd C:\WINDOWS\system32\drivers\amdkmafd.sys
17:16:36.0688 0x0fd4 amdkmafd - ok
17:16:36.0704 0x0fd4 amdkmdag - ok
17:16:36.0720 0x0fd4 [ C14D7E5F24381BC8F333C4EB77892400, 8B8EF49D2398AF39E36EFFE6D1E0489727D5612DEFA43C71E3C7E4C0650010A5 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
17:16:36.0766 0x0fd4 amdkmdap - ok
17:16:36.0766 0x0fd4 AmdPPM - ok
17:16:36.0782 0x0fd4 amdsata - ok
17:16:36.0782 0x0fd4 amdsbs - ok
17:16:36.0782 0x0fd4 amdxata - ok
17:16:36.0798 0x0fd4 AppID - ok
17:16:36.0798 0x0fd4 AppIDSvc - ok
17:16:36.0813 0x0fd4 Appinfo - ok
17:16:36.0813 0x0fd4 applockerfltr - ok
17:16:36.0813 0x0fd4 AppMgmt - ok
17:16:36.0829 0x0fd4 AppReadiness - ok
17:16:36.0829 0x0fd4 AppVClient - ok
17:16:36.0829 0x0fd4 AppvStrm - ok
17:16:36.0845 0x0fd4 AppvVemgr - ok
17:16:36.0845 0x0fd4 AppvVfs - ok
17:16:36.0845 0x0fd4 AppXSvc - ok
17:16:36.0860 0x0fd4 arcsas - ok
17:16:36.0860 0x0fd4 AsyncMac - ok
17:16:36.0860 0x0fd4 atapi - ok
17:16:36.0876 0x0fd4 athr - ok
17:16:36.0876 0x0fd4 AudioEndpointBuilder - ok
17:16:36.0891 0x0fd4 Audiosrv - ok
17:16:36.0907 0x0fd4 [ 14FCA1D1720A68C2D586940ABBE2DB3C, 274DB01CFD3024357602748FE36882ACE6BB3764A9FB62B2B40F9232B84A9B3E ] Avira.ServiceHost C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
17:16:36.0923 0x0fd4 Avira.ServiceHost - ok
17:16:36.0938 0x0fd4 AxInstSV - ok
17:16:36.0938 0x0fd4 b06bdrv - ok
17:16:36.0938 0x0fd4 BasicDisplay - ok
17:16:36.0954 0x0fd4 BasicRender - ok
17:16:36.0954 0x0fd4 bcmfn - ok
17:16:36.0970 0x0fd4 bcmfn2 - ok
17:16:36.0970 0x0fd4 BDESVC - ok
17:16:36.0970 0x0fd4 Beep - ok
17:16:36.0985 0x0fd4 BFE - ok
17:16:36.0985 0x0fd4 BITS - ok
17:16:36.0985 0x0fd4 bowser - ok
17:16:37.0001 0x0fd4 BrokerInfrastructure - ok
17:16:37.0001 0x0fd4 Browser - ok
17:16:37.0001 0x0fd4 BthAvrcpTg - ok
17:16:37.0016 0x0fd4 BthHFEnum - ok
17:16:37.0016 0x0fd4 bthhfhid - ok
17:16:37.0016 0x0fd4 BthHFSrv - ok
17:16:37.0032 0x0fd4 BTHMODEM - ok
17:16:37.0032 0x0fd4 bthserv - ok
17:16:37.0048 0x0fd4 buttonconverter - ok
17:16:37.0048 0x0fd4 CapImg - ok
17:16:37.0048 0x0fd4 cdfs - ok
17:16:37.0063 0x0fd4 CDPSvc - ok
17:16:37.0063 0x0fd4 CDPUserSvc - ok
17:16:37.0063 0x0fd4 cdrom - ok
17:16:37.0079 0x0fd4 CertPropSvc - ok
17:16:37.0079 0x0fd4 cht4iscsi - ok
17:16:37.0095 0x0fd4 cht4vbd - ok
17:16:37.0095 0x0fd4 circlass - ok
17:16:37.0095 0x0fd4 CLFS - ok
17:16:37.0110 0x0fd4 ClipSVC - ok
17:16:37.0110 0x0fd4 clreg - ok
17:16:37.0126 0x0fd4 CmBatt - ok
17:16:37.0126 0x0fd4 CNG - ok
17:16:37.0141 0x0fd4 cnghwassist - ok
17:16:37.0157 0x0fd4 CompositeBus - ok
17:16:37.0157 0x0fd4 COMSysApp - ok
17:16:37.0157 0x0fd4 condrv - ok
17:16:37.0173 0x0fd4 CoreMessagingRegistrar - ok
17:16:37.0173 0x0fd4 CryptSvc - ok
17:16:37.0188 0x0fd4 CSC - ok
17:16:37.0188 0x0fd4 CscService - ok
17:16:37.0188 0x0fd4 dam - ok
17:16:37.0204 0x0fd4 DcomLaunch - ok
17:16:37.0204 0x0fd4 DcpSvc - ok
17:16:37.0220 0x0fd4 defragsvc - ok
17:16:37.0220 0x0fd4 DeviceAssociationService - ok
17:16:37.0220 0x0fd4 DeviceInstall - ok
17:16:37.0235 0x0fd4 DevQueryBroker - ok
17:16:37.0235 0x0fd4 Dfsc - ok
17:16:37.0251 0x0fd4 [ 73BDD44A6088916964945886F9025409, 8E2ECC9AAEF3C6EBA2E61D25F657FDFCC72AB517CC4FD5FFF992E1F9EB942662 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
17:16:37.0266 0x0fd4 dg_ssudbus - ok
17:16:37.0266 0x0fd4 Dhcp - ok
17:16:37.0282 0x0fd4 diagnosticshub.standardcollector.service - ok
17:16:37.0282 0x0fd4 DiagTrack - ok
17:16:37.0282 0x0fd4 disk - ok
17:16:37.0298 0x0fd4 DmEnrollmentSvc - ok
17:16:37.0298 0x0fd4 dmvsc - ok
17:16:37.0313 0x0fd4 dmwappushservice - ok
17:16:37.0313 0x0fd4 Dnscache - ok
17:16:37.0313 0x0fd4 dot3svc - ok
17:16:37.0329 0x0fd4 DPS - ok
17:16:37.0329 0x0fd4 drmkaud - ok
17:16:37.0329 0x0fd4 DsmSvc - ok
17:16:37.0345 0x0fd4 DsSvc - ok
17:16:37.0360 0x0fd4 [ 33F90B202E9DD9B7D489EB59310FDC34, 6ECF6669433E090E9CF6B1875AF18D2C06F8CDB3901D58BF89C3E2202574ABBD ] dtsoftbus01 C:\WINDOWS\System32\drivers\dtsoftbus01.sys
17:16:37.0376 0x0fd4 dtsoftbus01 - ok
17:16:37.0376 0x0fd4 DXGKrnl - ok
17:16:37.0391 0x0fd4 EapHost - ok
17:16:37.0391 0x0fd4 ebdrv - ok
17:16:37.0391 0x0fd4 EFS - ok
17:16:37.0407 0x0fd4 EhStorClass - ok
17:16:37.0407 0x0fd4 EhStorTcgDrv - ok
17:16:37.0423 0x0fd4 embeddedmode - ok
17:16:37.0423 0x0fd4 EntAppSvc - ok
17:16:37.0423 0x0fd4 [ 9EAFB3B3B60B8AD958985152A9309ACA, EC58F487D50A125DA3F747670282EA2104580CCAAF709EA494B61C7549576AE6 ] epmntdrv C:\Windows\system32\epmntdrv.sys
17:16:37.0438 0x0fd4 epmntdrv - detected UnsignedFile.Multi.Generic ( 1 )
17:16:37.0438 0x0fd4 Detect skipped due to KSN trusted
17:16:37.0438 0x0fd4 epmntdrv - ok
17:16:37.0454 0x0fd4 ErrDev - ok
17:16:37.0454 0x0fd4 [ FB949ED2C93C878A189039F3D7730942, 857AFB9965F14C80C21948C05A44D37948BD206961101DFF087735D6A7CCAA8A ] EuGdiDrv C:\Windows\system32\EuGdiDrv.sys
17:16:37.0470 0x0fd4 EuGdiDrv - detected UnsignedFile.Multi.Generic ( 1 )
17:16:37.0470 0x0fd4 Detect skipped due to KSN trusted
17:16:37.0470 0x0fd4 EuGdiDrv - ok
17:16:37.0485 0x0fd4 EventSystem - ok
17:16:37.0501 0x0fd4 [ CA2E486FE6212FFD5FD171AC1A0B17BE, 4534A8496C8044F4DF3573B4021391327BE3BED026BC5CD1A35A5708651A9E1D ] ewusbmbb C:\WINDOWS\system32\DRIVERS\ewusbwwan.sys
17:16:37.0532 0x0fd4 ewusbmbb - ok
17:16:37.0532 0x0fd4 [ 86F7951BBCEE4A86E79A97306BD14318, 84B52A0392DA53ED71A2C4D483DD93DDF552BF8AC764C7BD47BE0EB58C7C8219 ] ew_hwusbdev C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys
17:16:37.0563 0x0fd4 ew_hwusbdev - ok
17:16:37.0563 0x0fd4 exfat - ok
17:16:37.0563 0x0fd4 fastfat - ok
17:16:37.0579 0x0fd4 Fax - ok
17:16:37.0579 0x0fd4 fdc - ok
17:16:37.0595 0x0fd4 fdPHost - ok
17:16:37.0595 0x0fd4 FDResPub - ok
17:16:37.0595 0x0fd4 fhsvc - ok
17:16:37.0610 0x0fd4 FileCrypt - ok
17:16:37.0610 0x0fd4 FileInfo - ok
17:16:37.0610 0x0fd4 Filetrace - ok
17:16:37.0626 0x0fd4 flpydisk - ok
17:16:37.0626 0x0fd4 FltMgr - ok
17:16:37.0626 0x0fd4 FontCache - ok
17:16:37.0641 0x0fd4 FontCache3.0.0.0 - ok
17:16:37.0673 0x0fd4 [ B3A740CF5841D2087F2A8ACBAD9CA9AD, 587D966D8FF6A6704E8367B470B4F6CA5F6A29A25E960C718E9AB51899D53DD1 ] FoxitReaderService C:\Program Files (x86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe
17:16:37.0735 0x0fd4 FoxitReaderService - ok
17:16:37.0735 0x0fd4 FrameServer - ok
17:16:37.0735 0x0fd4 FsDepends - ok
17:16:37.0751 0x0fd4 Fs_Rec - ok
17:16:37.0751 0x0fd4 fvevol - ok
17:16:37.0766 0x0fd4 gencounter - ok
17:16:37.0766 0x0fd4 genericusbfn - ok
17:16:37.0766 0x0fd4 GPIOClx0101 - ok
17:16:37.0782 0x0fd4 gpsvc - ok
17:16:37.0782 0x0fd4 GpuEnergyDrv - ok
17:16:37.0782 0x0fd4 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:16:37.0813 0x0fd4 gupdate - ok
17:16:37.0813 0x0fd4 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:16:37.0829 0x0fd4 gupdatem - ok
17:16:37.0829 0x0fd4 HdAudAddService - ok
17:16:37.0845 0x0fd4 HDAudBus - ok
17:16:37.0845 0x0fd4 [ B6AC71AAA2B10848F57FC49D55A651AF, 4FAD833654E86F9FAF972AC8AF87FD4A9A765B26B96F096BBD63506B5D521A91 ] HECIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
17:16:37.0860 0x0fd4 HECIx64 - ok
17:16:37.0860 0x0fd4 HidBatt - ok
17:16:37.0876 0x0fd4 HidBth - ok
17:16:37.0876 0x0fd4 hidi2c - ok
17:16:37.0891 0x0fd4 hidinterrupt - ok
17:16:37.0891 0x0fd4 HidIr - ok
17:16:37.0891 0x0fd4 hidserv - ok
17:16:37.0907 0x0fd4 HidUsb - ok
17:16:37.0907 0x0fd4 HomeGroupListener - ok
17:16:37.0907 0x0fd4 HomeGroupProvider - ok
17:16:37.0923 0x0fd4 HpSAMD - ok
17:16:37.0923 0x0fd4 HTTP - ok
17:16:37.0938 0x0fd4 [ 1642C62F1FD5E1FF44608283994A7BB8, 4646AA0EF74A2AEE6C17D12206FCFE1E84D6FA712AD95A171F16D11BC9D3F11A ] huawei_enumerator C:\WINDOWS\System32\drivers\ew_jubusenum.sys
17:16:37.0954 0x0fd4 huawei_enumerator - ok
17:16:37.0954 0x0fd4 HvHost - ok
17:16:37.0970 0x0fd4 hvservice - ok
17:16:37.0970 0x0fd4 HWDeviceService64.exe - ok
17:16:37.0985 0x0fd4 hwpolicy - ok
17:16:37.0985 0x0fd4 hyperkbd - ok
17:16:38.0001 0x0fd4 i8042prt - ok
17:16:38.0001 0x0fd4 iagpio - ok
17:16:38.0001 0x0fd4 iai2c - ok
17:16:38.0016 0x0fd4 iaLPSS2i_GPIO2 - ok
17:16:38.0016 0x0fd4 iaLPSS2i_I2C - ok
17:16:38.0016 0x0fd4 iaLPSSi_GPIO - ok
17:16:38.0016 0x0fd4 iaLPSSi_I2C - ok
17:16:38.0032 0x0fd4 iaStorAV - ok
17:16:38.0032 0x0fd4 iaStorV - ok
17:16:38.0048 0x0fd4 ibbus - ok
17:16:38.0048 0x0fd4 icssvc - ok
17:16:38.0048 0x0fd4 IKEEXT - ok
17:16:38.0063 0x0fd4 [ DD587A55390ED2295BCE6D36AD567DA9, AEB7DCB8EF89BEE8D9649A05FC482B1E4E3F44243D57A2577C862EB69166C48E ] Impcd C:\WINDOWS\System32\drivers\Impcd.sys
17:16:38.0095 0x0fd4 Impcd - ok
17:16:38.0095 0x0fd4 IndirectKmd - ok
17:16:38.0157 0x0fd4 [ 1A6241B70453A6629A83DB942AA6B08C, EF93785E20E18BF36F667E35F89BBF2A17C86F57E2D17D077F5031CE70E9DC9D ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
17:16:38.0220 0x0fd4 IntcAzAudAddService - ok
17:16:38.0235 0x0fd4 intelide - ok
17:16:38.0235 0x0fd4 intelpep - ok
17:16:38.0251 0x0fd4 intelppm - ok
17:16:38.0251 0x0fd4 iorate - ok
17:16:38.0266 0x0fd4 IpFilterDriver - ok
17:16:38.0266 0x0fd4 iphlpsvc - ok
17:16:38.0266 0x0fd4 IPMIDRV - ok
17:16:38.0282 0x0fd4 IPNAT - ok
17:16:38.0282 0x0fd4 irda - ok
17:16:38.0282 0x0fd4 IRENUM - ok
17:16:38.0298 0x0fd4 irmon - ok
17:16:38.0298 0x0fd4 isapnp - ok
17:16:38.0298 0x0fd4 iScsiPrt - ok
17:16:38.0313 0x0fd4 [ 5678EC677028221EC5C815BCD07AB697, 02FD1A0290A9A17823D24A0E55D4AB35C3F939C986AB8BB54C6248287466FE0D ] jrdusbser C:\WINDOWS\system32\DRIVERS\jrdusbser.sys
17:16:38.0345 0x0fd4 jrdusbser - ok
17:16:38.0345 0x0fd4 Juqokchukity - ok
17:16:38.0345 0x0fd4 kbdclass - ok
17:16:38.0360 0x0fd4 kbdhid - ok
17:16:38.0360 0x0fd4 kdnic - ok
17:16:38.0360 0x0fd4 KeyIso - ok
17:16:38.0376 0x0fd4 KSecDD - ok
17:16:38.0376 0x0fd4 KSecPkg - ok
17:16:38.0376 0x0fd4 ksthunk - ok
17:16:38.0391 0x0fd4 KtmRm - ok
17:16:38.0391 0x0fd4 LanmanServer - ok
17:16:38.0407 0x0fd4 LanmanWorkstation - ok
17:16:38.0407 0x0fd4 lfsvc - ok
17:16:38.0407 0x0fd4 LicenseManager - ok
17:16:38.0423 0x0fd4 lltdio - ok
17:16:38.0423 0x0fd4 lltdsvc - ok
17:16:38.0423 0x0fd4 lmhosts - ok
17:16:38.0438 0x0fd4 LSI_SAS - ok
17:16:38.0438 0x0fd4 LSI_SAS2i - ok
17:16:38.0454 0x0fd4 LSI_SAS3i - ok
17:16:38.0454 0x0fd4 LSI_SSS - ok
17:16:38.0454 0x0fd4 LSM - ok
17:16:38.0470 0x0fd4 luafv - ok
17:16:38.0485 0x0fd4 [ A0A527569856B9814E8920F52EBB67F5, 4347277C84B47E4CC048850BDEFB258CFB3B476AA99FD503FD71FBB70FFF5ACF ] LVRS64 C:\WINDOWS\system32\DRIVERS\lvrs64.sys
17:16:38.0501 0x0fd4 LVRS64 - ok
17:16:38.0626 0x0fd4 [ 415E344294D1C0D04627B29146F68481, B4A1A05BDF07E8F226A98E51F62BE18BE2C046A084C495BD8A95CABC79FD0614 ] LVUVC64 C:\WINDOWS\system32\DRIVERS\lvuvc64.sys
17:16:38.0767 0x0fd4 LVUVC64 - ok
17:16:38.0782 0x0fd4 MapsBroker - ok
17:16:38.0782 0x0fd4 [ 3BEC6134F1E45AEF5E971F69F0D38510, 245D7CEEB6561166EE0472551D39A9D3CFDDA52A6BF2E924AB243CCA7FBC9009 ] MBAMChameleon C:\WINDOWS\system32\drivers\MBAMChameleon.sys
17:16:38.0798 0x0fd4 MBAMChameleon - ok
17:16:38.0813 0x0fd4 [ 88BD122C3A35DE63D75D382DF75554CE, ABDF59543CAD186A6ED4E66257205D9CF5047732A5DA74A96A28B468B41BC396 ] MBAMProtection C:\WINDOWS\system32\drivers\mbam.sys
17:16:38.0829 0x0fd4 MBAMProtection - ok
17:16:38.0938 0x0fd4 [ 28E521A6ABA9DE062A3719452816F495, B312A37DA052229DFB19353170CD5828582F8AC6426E857CA7C8ACA0DD91C160 ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
17:16:39.0063 0x0fd4 MBAMService - ok
17:16:39.0079 0x0fd4 megasas - ok
17:16:39.0079 0x0fd4 megasas2i - ok
17:16:39.0095 0x0fd4 megasr - ok
17:16:39.0095 0x0fd4 MessagingService - ok
17:16:39.0110 0x0fd4 mlx4_bus - ok
17:16:39.0110 0x0fd4 MMCSS - ok
17:16:39.0126 0x0fd4 [ 1CE0621B591913C12BECAA5B50E88BB2, 115068C57570140C9389BD923A4E68236ACEBB4F733DA09D05AEEDAD7317AB46 ] Mobile Partner. RunOuc C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe
17:16:39.0142 0x0fd4 Mobile Partner. RunOuc - ok
17:16:39.0157 0x0fd4 Modem - ok
17:16:39.0157 0x0fd4 monitor - ok
17:16:39.0157 0x0fd4 mouclass - ok
17:16:39.0173 0x0fd4 mouhid - ok
17:16:39.0173 0x0fd4 mountmgr - ok
17:16:39.0173 0x0fd4 mpsdrv - ok
17:16:39.0188 0x0fd4 MpsSvc - ok
17:16:39.0188 0x0fd4 MRxDAV - ok
17:16:39.0204 0x0fd4 mrxsmb - ok
17:16:39.0204 0x0fd4 mrxsmb10 - ok
17:16:39.0204 0x0fd4 mrxsmb20 - ok
17:16:39.0220 0x0fd4 MsBridge - ok
17:16:39.0220 0x0fd4 MSDTC - ok
17:16:39.0235 0x0fd4 Msfs - ok
17:16:39.0235 0x0fd4 msgpiowin32 - ok
17:16:39.0251 0x0fd4 mshidkmdf - ok
17:16:39.0251 0x0fd4 mshidumdf - ok
17:16:39.0251 0x0fd4 msisadrv - ok
17:16:39.0267 0x0fd4 MSiSCSI - ok
17:16:39.0267 0x0fd4 msiserver - ok
17:16:39.0267 0x0fd4 MSKSSRV - ok
17:16:39.0282 0x0fd4 MsLldp - ok
17:16:39.0282 0x0fd4 MSPCLOCK - ok
17:16:39.0298 0x0fd4 MSPQM - ok
17:16:39.0298 0x0fd4 MsRPC - ok
17:16:39.0298 0x0fd4 MsSecFlt - ok
17:16:39.0313 0x0fd4 mssmbios - ok
17:16:39.0313 0x0fd4 MSTEE - ok
17:16:39.0329 0x0fd4 MTConfig - ok
17:16:39.0329 0x0fd4 Mup - ok
17:16:39.0329 0x0fd4 mvumis - ok
17:16:39.0345 0x0fd4 NativeWifiP - ok
17:16:39.0376 0x0fd4 [ E0E4A1F81A7D69C595A8A9DDAD084C19, 8F55F3637AE8BFFB0ACE37AFC5122026525137E0B2923899B779C1BD08DF0E22 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
17:16:39.0407 0x0fd4 NAUpdate - ok
17:16:39.0407 0x0fd4 NcaSvc - ok
17:16:39.0423 0x0fd4 NcbService - ok
17:16:39.0423 0x0fd4 NcdAutoSetup - ok
17:16:39.0423 0x0fd4 ndfltr - ok
17:16:39.0438 0x0fd4 NDIS - ok
17:16:39.0438 0x0fd4 NdisCap - ok
17:16:39.0438 0x0fd4 NdisImPlatform - ok
17:16:39.0454 0x0fd4 NdisTapi - ok
17:16:39.0454 0x0fd4 Ndisuio - ok
17:16:39.0470 0x0fd4 NdisVirtualBus - ok
17:16:39.0470 0x0fd4 NdisWan - ok
17:16:39.0470 0x0fd4 ndiswanlegacy - ok
17:16:39.0485 0x0fd4 ndproxy - ok
17:16:39.0485 0x0fd4 Ndu - ok
17:16:39.0485 0x0fd4 NetAdapterCx - ok
17:16:39.0501 0x0fd4 NetBIOS - ok
17:16:39.0501 0x0fd4 NetBT - ok
17:16:39.0501 0x0fd4 Netlogon - ok
17:16:39.0517 0x0fd4 Netman - ok
17:16:39.0517 0x0fd4 netprofm - ok
17:16:39.0532 0x0fd4 NetSetupSvc - ok
17:16:39.0532 0x0fd4 NetTcpPortSharing - ok
17:16:39.0548 0x0fd4 NgcCtnrSvc - ok
17:16:39.0548 0x0fd4 NgcSvc - ok
17:16:39.0548 0x0fd4 NlaSvc - ok
17:16:39.0563 0x0fd4 [ DE7FCC77F4A503AF4CA6A47D49B3713D, 4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6 ] npf C:\WINDOWS\system32\drivers\npf.sys
17:16:39.0579 0x0fd4 npf - ok
17:16:39.0579 0x0fd4 Npfs - ok
17:16:39.0579 0x0fd4 npsvctrig - ok
17:16:39.0595 0x0fd4 nsi - ok
17:16:39.0595 0x0fd4 nsiproxy - ok
17:16:39.0610 0x0fd4 NTFS - ok
17:16:39.0610 0x0fd4 Null - ok
17:16:39.0610 0x0fd4 [ B01C1E6D7477961D6D1CBDCD44AF3E67, 407BD335FE7C87DFBD9EDE49BDD828263D8C8D25C8216FF04AC70320E74AE8B6 ] nusb3hub C:\WINDOWS\System32\drivers\nusb3hub.sys
17:16:39.0626 0x0fd4 nusb3hub - ok
17:16:39.0642 0x0fd4 nvraid - ok
17:16:39.0642 0x0fd4 nvstor - ok
17:16:39.0657 0x0fd4 OneSyncSvc - ok
17:16:39.0673 0x0fd4 [ 11E0B35479C895888BA3D7F619DCFFF3, 6ED82C19898101EC00BD64A9F90595C3D20AD2D2902AA8765B740FB3B9312DDF ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:16:39.0688 0x0fd4 ose64 - ok
17:16:39.0704 0x0fd4 p2pimsvc - ok
17:16:39.0704 0x0fd4 p2psvc - ok
17:16:39.0720 0x0fd4 Parport - ok
17:16:39.0720 0x0fd4 partmgr - ok
17:16:39.0735 0x0fd4 PcaSvc - ok
17:16:39.0735 0x0fd4 pci - ok
17:16:39.0735 0x0fd4 pciide - ok
17:16:39.0751 0x0fd4 pcmcia - ok
17:16:39.0751 0x0fd4 pcw - ok
17:16:39.0751 0x0fd4 pdc - ok
17:16:39.0767 0x0fd4 PEAUTH - ok
17:16:39.0767 0x0fd4 PeerDistSvc - ok
17:16:39.0782 0x0fd4 percsas2i - ok
17:16:39.0782 0x0fd4 percsas3i - ok
17:16:39.0798 0x0fd4 PerfHost - ok
17:16:39.0813 0x0fd4 PhoneSvc - ok
17:16:39.0813 0x0fd4 PimIndexMaintenanceSvc - ok
17:16:39.0829 0x0fd4 pla - ok
17:16:39.0829 0x0fd4 PlugPlay - ok
17:16:39.0845 0x0fd4 PnkBstrA - ok
17:16:39.0845 0x0fd4 PnkBstrB - ok
17:16:39.0845 0x0fd4 PNRPAutoReg - ok
17:16:39.0860 0x0fd4 PNRPsvc - ok
17:16:39.0860 0x0fd4 PolicyAgent - ok
17:16:39.0860 0x0fd4 Power - ok
17:16:39.0876 0x0fd4 PptpMiniport - ok
17:16:39.0954 0x0fd4 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
17:16:40.0095 0x0fd4 PrintNotify - ok
17:16:40.0110 0x0fd4 Processor - ok
17:16:40.0110 0x0fd4 ProfSvc - ok
17:16:40.0110 0x0fd4 Psched - ok
17:16:40.0126 0x0fd4 [ C32ECB99AD25E9A04F01C8665DF29EF8, 0489B3DEC6A33E50D8A48A8DAD3F5B923A81F7300E4A71358D90D2879BAC9AA2 ] pwdrvio C:\Windows\system32\pwdrvio.sys
17:16:40.0142 0x0fd4 pwdrvio - ok
17:16:40.0157 0x0fd4 [ D619356B955EEFA642F5FF72755E8B3C, 1FD54978A77ACD6FBF1236E177ED074894743A9141E4169FE9AFE28680FC93C5 ] pwdspio C:\Windows\system32\pwdspio.sys
17:16:40.0173 0x0fd4 pwdspio - ok
17:16:40.0188 0x0fd4 QWAVE - ok
17:16:40.0188 0x0fd4 QWAVEdrv - ok
17:16:40.0188 0x0fd4 RasAcd - ok
17:16:40.0204 0x0fd4 RasAgileVpn - ok
17:16:40.0204 0x0fd4 RasAuto - ok
17:16:40.0204 0x0fd4 Rasl2tp - ok
17:16:40.0220 0x0fd4 RasMan - ok
17:16:40.0220 0x0fd4 RasPppoe - ok
17:16:40.0235 0x0fd4 RasSstp - ok
17:16:40.0235 0x0fd4 rdbss - ok
17:16:40.0235 0x0fd4 rdpbus - ok
17:16:40.0251 0x0fd4 RDPDR - ok
17:16:40.0251 0x0fd4 RdpVideoMiniport - ok
17:16:40.0267 0x0fd4 rdyboost - ok
17:16:40.0267 0x0fd4 ReFSv1 - ok
17:16:40.0282 0x0fd4 RemoteAccess - ok
17:16:40.0282 0x0fd4 RemoteRegistry - ok
17:16:40.0298 0x0fd4 RetailDemo - ok
17:16:40.0298 0x0fd4 [ 5CA4ABD888B602551B59BAA26941C167, F6FC0F828153E07EAFFAB6E11556DA23A5F6D9FC063E36947B1AC73E7E7E705E ] rimspci C:\WINDOWS\System32\drivers\rimssne64.sys
17:16:40.0329 0x0fd4 rimspci - ok
17:16:40.0329 0x0fd4 [ BB6E138AEB351728959DA5E2731D8140, E6656869A03380EB96A31E4E5FF4D565916EB0A7ED334330D2DD039390441D15 ] risdsnpe C:\WINDOWS\System32\drivers\risdsne64.sys
17:16:40.0360 0x0fd4 risdsnpe - ok
17:16:40.0360 0x0fd4 RmSvc - ok
17:16:40.0360 0x0fd4 RpcEptMapper - ok
17:16:40.0376 0x0fd4 RpcLocator - ok
17:16:40.0376 0x0fd4 RpcSs - ok
17:16:40.0392 0x0fd4 rspndr - ok
17:16:40.0392 0x0fd4 [ 7421A35C45484B95E83B5E9E107CEFC2, 128BB6A7552B9D57284056FB8946A6FE3C620F7B706F709F896828304A6FCD77 ] RTHDMIAzAudService C:\WINDOWS\system32\drivers\RtHDMIVX.sys
17:16:40.0407 0x0fd4 RTHDMIAzAudService - ok
17:16:40.0423 0x0fd4 s3cap - ok
17:16:40.0423 0x0fd4 SamSs - ok
17:16:40.0423 0x0fd4 [ 3289766038DB2CB14D07DC84392138D5, A7790B787690CC1A8B97E4532090C5295350A836A9474DEA74CEB3E81CF26124 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
17:16:40.0438 0x0fd4 SASDIFSV - ok
17:16:40.0454 0x0fd4 [ 58A38E75F3316A83C23DF6173D41F2B5, B0A8CDA1D164B7534FB41AB80792861384709BF0F914F44553275CF20194F1A1 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
17:16:40.0454 0x0fd4 SASKUTIL - ok
17:16:40.0470 0x0fd4 sbp2port - ok
17:16:40.0470 0x0fd4 SCardSvr - ok
17:16:40.0485 0x0fd4 ScDeviceEnum - ok
17:16:40.0485 0x0fd4 scfilter - ok
17:16:40.0501 0x0fd4 Schedule - ok
17:16:40.0501 0x0fd4 scmbus - ok
17:16:40.0501 0x0fd4 scmdisk0101 - ok
17:16:40.0517 0x0fd4 SCPolicySvc - ok
17:16:40.0517 0x0fd4 sdbus - ok
17:16:40.0532 0x0fd4 SDRSVC - ok
17:16:40.0532 0x0fd4 sdstor - ok
17:16:40.0532 0x0fd4 seclogon - ok
17:16:40.0548 0x0fd4 SENS - ok
17:16:40.0548 0x0fd4 Sense - ok
17:16:40.0563 0x0fd4 SensorDataService - ok
17:16:40.0563 0x0fd4 SensorService - ok
17:16:40.0563 0x0fd4 SensrSvc - ok
17:16:40.0579 0x0fd4 SerCx - ok
17:16:40.0579 0x0fd4 SerCx2 - ok
17:16:40.0595 0x0fd4 Serenum - ok
17:16:40.0595 0x0fd4 Serial - ok
17:16:40.0595 0x0fd4 sermouse - ok
17:16:40.0610 0x0fd4 SessionEnv - ok
17:16:40.0626 0x0fd4 [ 70F9C476B62DE4F2823E918A6C181ADE, E1A641418A6CB4FA38BB29B86934838B28D8909B8066E5089D85BF72FD61F4C4 ] SFEP C:\WINDOWS\System32\drivers\SFEP.sys
17:16:40.0642 0x0fd4 SFEP - ok
17:16:40.0642 0x0fd4 sfloppy - ok
17:16:40.0657 0x0fd4 SharedAccess - ok
17:16:40.0657 0x0fd4 ShellHWDetection - ok
17:16:40.0657 0x0fd4 shpamsvc - ok
17:16:40.0673 0x0fd4 SiSRaid2 - ok
17:16:40.0673 0x0fd4 SiSRaid4 - ok
17:16:40.0688 0x0fd4 [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
17:16:40.0720 0x0fd4 SkypeUpdate - ok
17:16:40.0720 0x0fd4 smphost - ok
17:16:40.0735 0x0fd4 SmsRouter - ok
17:16:40.0751 0x0fd4 SNMPTRAP - ok
17:16:40.0751 0x0fd4 spaceport - ok
17:16:40.0751 0x0fd4 Sparhandy_Germany Silverstone Modem Device Helper - ok
17:16:40.0767 0x0fd4 SpbCx - ok
17:16:40.0782 0x0fd4 [ 0FFE35F0B0CD5A324BBE22F02569AE3B, F4EE803EEFDB4EAEEDB3024C3516F1F9A202C77F4870D6B74356BBDE32B3B560 ] speedfan C:\Windows\SysWOW64\speedfan.sys
17:16:40.0798 0x0fd4 speedfan - ok
17:16:40.0813 0x0fd4 Spooler - ok
17:16:40.0813 0x0fd4 sppsvc - ok
17:16:40.0813 0x0fd4 srv - ok
17:16:40.0829 0x0fd4 srv2 - ok
17:16:40.0829 0x0fd4 srvnet - ok
17:16:40.0845 0x0fd4 SSDPSRV - ok
17:16:40.0845 0x0fd4 SstpSvc - ok
17:16:40.0860 0x0fd4 [ 5252D7BC56E5E0ED715AEA8FE173A455, 1408B3E98B35A449434718777EE70595F0D306197A428279C6281D2F1953F259 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
17:16:40.0876 0x0fd4 ssudmdm - ok
17:16:40.0876 0x0fd4 StateRepository - ok
17:16:40.0892 0x0fd4 stexstor - ok
17:16:40.0892 0x0fd4 stisvc - ok
17:16:40.0892 0x0fd4 storahci - ok
17:16:40.0907 0x0fd4 storflt - ok
17:16:40.0907 0x0fd4 stornvme - ok
17:16:40.0923 0x0fd4 storqosflt - ok
17:16:40.0923 0x0fd4 StorSvc - ok
17:16:40.0923 0x0fd4 storufs - ok
17:16:40.0938 0x0fd4 storvsc - ok
17:16:40.0938 0x0fd4 svsvc - ok
17:16:40.0954 0x0fd4 swenum - ok
17:16:40.0954 0x0fd4 swprv - ok
17:16:40.0954 0x0fd4 Synth3dVsc - ok
17:16:40.0970 0x0fd4 SysMain - ok
17:16:40.0970 0x0fd4 SystemEventsBroker - ok
17:16:40.0985 0x0fd4 TabletInputService - ok
17:16:40.0985 0x0fd4 [ 3C32FF010F869BC184DF71290477384E, 55CFCEC7F026C6E2E96A2FBE846AB513BB12BB0348735274FE1B71AF019C837B ] tap0901 C:\WINDOWS\System32\drivers\tap0901.sys
17:16:41.0001 0x0fd4 tap0901 - ok
17:16:41.0001 0x0fd4 TapiSrv - ok
17:16:41.0017 0x0fd4 Tcpip - ok
17:16:41.0017 0x0fd4 Tcpip6 - ok
17:16:41.0032 0x0fd4 tcpipreg - ok
17:16:41.0032 0x0fd4 tdx - ok
17:16:41.0048 0x0fd4 terminpt - ok
17:16:41.0048 0x0fd4 TermService - ok
17:16:41.0048 0x0fd4 Themes - ok
17:16:41.0063 0x0fd4 TieringEngineService - ok
17:16:41.0063 0x0fd4 tiledatamodelsvc - ok
17:16:41.0079 0x0fd4 TimeBrokerSvc - ok
17:16:41.0079 0x0fd4 TPM - ok
17:16:41.0079 0x0fd4 TrkWks - ok
17:16:41.0095 0x0fd4 TrustedInstaller - ok
17:16:41.0095 0x0fd4 tsusbflt - ok
17:16:41.0110 0x0fd4 TsUsbGD - ok
17:16:41.0110 0x0fd4 tsusbhub - ok
17:16:41.0110 0x0fd4 tunnel - ok
17:16:41.0126 0x0fd4 tzautoupdate - ok
17:16:41.0126 0x0fd4 UASPStor - ok
17:16:41.0142 0x0fd4 [ 209F5CEAAAFE601851E7B40902FC230D, B7BFD753DF9EA1AD6D6BD8FB47F24E79FA84208E7A66C88B934C3A13B087901D ] ucdrv C:\WINDOWS\System32\drivers:ucdrv-x64.sys
17:16:41.0157 0x0fd4 Suspicious file ( Hidden ): C:\WINDOWS\System32\drivers:ucdrv-x64.sys. md5: 209F5CEAAAFE601851E7B40902FC230D, sha256: B7BFD753DF9EA1AD6D6BD8FB47F24E79FA84208E7A66C88B934C3A13B087901D
17:16:41.0157 0x0fd4 ucdrv - detected HiddenFile.Multi.Generic ( 1 )
17:16:41.0157 0x0fd4 Detect skipped due to KSN trusted
17:16:41.0157 0x0fd4 ucdrv - ok
17:16:41.0157 0x0fd4 UcmCx0101 - ok
17:16:41.0157 0x0fd4 UcmTcpciCx0101 - ok
17:16:41.0173 0x0fd4 UcmUcsi - ok
17:16:41.0173 0x0fd4 Ucx01000 - ok
17:16:41.0188 0x0fd4 UdeCx - ok
17:16:41.0188 0x0fd4 udfs - ok
17:16:41.0188 0x0fd4 UEFI - ok
17:16:41.0204 0x0fd4 UevAgentDriver - ok
17:16:41.0204 0x0fd4 UevAgentService - ok
17:16:41.0204 0x0fd4 Ufx01000 - ok
17:16:41.0220 0x0fd4 UfxChipidea - ok
17:16:41.0220 0x0fd4 ufxsynopsys - ok
17:16:41.0235 0x0fd4 UI0Detect - ok
17:16:41.0235 0x0fd4 umbus - ok
17:16:41.0251 0x0fd4 UmPass - ok
17:16:41.0251 0x0fd4 UmRdpService - ok
17:16:41.0251 0x0fd4 UnistoreSvc - ok
17:16:41.0267 0x0fd4 [ 9DC07E73A4ABB9ACF692113B36A5009F, CA7176FC219515D58DCFA66EC61880ECE5617275C9B83701BB74D8B60E733D34 ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys
17:16:41.0282 0x0fd4 UnlockerDriver5 - ok
17:16:41.0282 0x0fd4 upnphost - ok
17:16:41.0298 0x0fd4 UrsChipidea - ok
17:16:41.0298 0x0fd4 UrsCx01000 - ok
17:16:41.0298 0x0fd4 UrsSynopsys - ok
17:16:41.0329 0x0fd4 [ 55020D37C29F05D583A76F20127B4FD7, 9BFB5F16D5C15ADF3ECB8769B66F443250497F6A2F58FA74954EC64EF2F6C33E ] USB28xxBGA C:\WINDOWS\system32\DRIVERS\emBDA64.sys
17:16:41.0360 0x0fd4 USB28xxBGA - ok
17:16:41.0376 0x0fd4 [ D7940283C43E440FCF83AB55B85689C9, C41DD0E5CE66328694047FF468BBBB3D35FBB9CB41A249202A05DB411EFEEFB1 ] USB28xxOEM C:\WINDOWS\system32\DRIVERS\emOEM64.sys
17:16:41.0392 0x0fd4 USB28xxOEM - ok
17:16:41.0392 0x0fd4 usbaudio - ok
17:16:41.0407 0x0fd4 usbccgp - ok
17:16:41.0407 0x0fd4 usbcir - ok
17:16:41.0423 0x0fd4 usbehci - ok
17:16:41.0423 0x0fd4 usbhub - ok
17:16:41.0423 0x0fd4 USBHUB3 - ok
17:16:41.0439 0x0fd4 usbohci - ok
17:16:41.0439 0x0fd4 usbprint - ok
17:16:41.0454 0x0fd4 usbscan - ok
17:16:41.0454 0x0fd4 usbser - ok
17:16:41.0454 0x0fd4 USBSTOR - ok
17:16:41.0470 0x0fd4 usbuhci - ok
17:16:41.0470 0x0fd4 usbvideo - ok
17:16:41.0485 0x0fd4 USBXHCI - ok
17:16:41.0485 0x0fd4 UserDataSvc - ok
17:16:41.0485 0x0fd4 UserManager - ok
17:16:41.0501 0x0fd4 UsoSvc - ok
17:16:41.0501 0x0fd4 VaultSvc - ok
17:16:41.0517 0x0fd4 vdrvroot - ok
17:16:41.0517 0x0fd4 vds - ok
17:16:41.0532 0x0fd4 VerifierExt - ok
17:16:41.0532 0x0fd4 vhdmp - ok
17:16:41.0548 0x0fd4 vhf - ok
17:16:41.0548 0x0fd4 vmbus - ok
17:16:41.0564 0x0fd4 VMBusHID - ok
17:16:41.0564 0x0fd4 vmgid - ok
17:16:41.0579 0x0fd4 vmicguestinterface - ok
17:16:41.0579 0x0fd4 vmicheartbeat - ok
17:16:41.0579 0x0fd4 vmickvpexchange - ok
17:16:41.0595 0x0fd4 vmicrdv - ok
17:16:41.0595 0x0fd4 vmicshutdown - ok
17:16:41.0610 0x0fd4 vmictimesync - ok
17:16:41.0610 0x0fd4 vmicvmsession - ok
17:16:41.0626 0x0fd4 vmicvss - ok
17:16:41.0626 0x0fd4 volmgr - ok
17:16:41.0626 0x0fd4 volmgrx - ok
17:16:41.0642 0x0fd4 volsnap - ok
17:16:41.0642 0x0fd4 volume - ok
17:16:41.0657 0x0fd4 vpci - ok
17:16:41.0657 0x0fd4 vsmraid - ok
17:16:41.0657 0x0fd4 VSS - ok
17:16:41.0673 0x0fd4 VSTXRAID - ok
17:16:41.0673 0x0fd4 vwifibus - ok
17:16:41.0689 0x0fd4 vwififlt - ok
17:16:41.0689 0x0fd4 vwifimp - ok
17:16:41.0689 0x0fd4 W32Time - ok
17:16:41.0704 0x0fd4 WacomPen - ok
17:16:41.0704 0x0fd4 WalletService - ok
17:16:41.0720 0x0fd4 wanarp - ok
17:16:41.0720 0x0fd4 wanarpv6 - ok
17:16:41.0720 0x0fd4 wbengine - ok
17:16:41.0735 0x0fd4 WbioSrvc - ok
17:16:41.0735 0x0fd4 wcifs - ok
17:16:41.0751 0x0fd4 Wcmsvc - ok
17:16:41.0751 0x0fd4 wcncsvc - ok
17:16:41.0767 0x0fd4 wcnfs - ok
17:16:41.0767 0x0fd4 WdBoot - ok
17:16:41.0767 0x0fd4 Wdf01000 - ok
17:16:41.0782 0x0fd4 WdFilter - ok
17:16:41.0782 0x0fd4 WdiServiceHost - ok
17:16:41.0798 0x0fd4 WdiSystemHost - ok
17:16:41.0798 0x0fd4 wdiwifi - ok
17:16:41.0798 0x0fd4 WdNisDrv - ok
17:16:41.0814 0x0fd4 WdNisSvc - ok
17:16:41.0814 0x0fd4 WebClient - ok
17:16:41.0829 0x0fd4 Wecsvc - ok
17:16:41.0829 0x0fd4 WEPHOSTSVC - ok
17:16:41.0829 0x0fd4 wercplsupport - ok
17:16:41.0845 0x0fd4 WerSvc - ok
17:16:41.0845 0x0fd4 WFPLWFS - ok
17:16:41.0860 0x0fd4 WiaRpc - ok
17:16:41.0860 0x0fd4 WIMMount - ok
17:16:41.0860 0x0fd4 WinDefend - ok
17:16:41.0876 0x0fd4 WindowsTrustedRT - ok
17:16:41.0876 0x0fd4 WindowsTrustedRTProxy - ok
17:16:41.0892 0x0fd4 WinHttpAutoProxySvc - ok
17:16:41.0892 0x0fd4 WinMad - ok
17:16:41.0907 0x0fd4 Winmgmt - ok
17:16:41.0907 0x0fd4 WinRM - ok
17:16:41.0923 0x0fd4 WINUSB - ok
17:16:41.0923 0x0fd4 WinVerbs - ok
17:16:41.0939 0x0fd4 wisvc - ok
17:16:41.0939 0x0fd4 WlanSvc - ok
17:16:41.0954 0x0fd4 wlidsvc - ok
17:16:41.0954 0x0fd4 WmiAcpi - ok
17:16:41.0970 0x0fd4 wmiApSrv - ok
17:16:41.0970 0x0fd4 WMPNetworkSvc - ok
17:16:41.0985 0x0fd4 Wof - ok
17:16:41.0985 0x0fd4 workfolderssvc - ok
17:16:42.0001 0x0fd4 WPDBusEnum - ok
17:16:42.0001 0x0fd4 WpdUpFltr - ok
17:16:42.0017 0x0fd4 WpnService - ok
17:16:42.0017 0x0fd4 WpnUserService - ok
17:16:42.0032 0x0fd4 ws2ifsl - ok
17:16:42.0032 0x0fd4 wscsvc - ok
17:16:42.0032 0x0fd4 WSearch - ok
17:16:42.0048 0x0fd4 wuauserv - ok
17:16:42.0048 0x0fd4 WudfPf - ok
17:16:42.0064 0x0fd4 WUDFRd - ok
17:16:42.0064 0x0fd4 wudfsvc - ok
17:16:42.0079 0x0fd4 WUDFWpdFs - ok
17:16:42.0079 0x0fd4 WUDFWpdMtp - ok
17:16:42.0095 0x0fd4 WwanSvc - ok
17:16:42.0095 0x0fd4 XblAuthManager - ok
17:16:42.0095 0x0fd4 XblGameSave - ok
17:16:42.0110 0x0fd4 xboxgip - ok
17:16:42.0110 0x0fd4 XboxNetApiSvc - ok
17:16:42.0126 0x0fd4 xinputhid - ok
17:16:42.0142 0x0fd4 ykinw8 - ok
17:16:42.0142 0x0fd4 ================ Scan global ===============================
17:16:42.0157 0x0fd4 [ Global ] - ok
17:16:42.0157 0x0fd4 ================ Scan MBR ==================================
17:16:42.0157 0x0fd4 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:16:42.0251 0x0fd4 \Device\Harddisk0\DR0 - ok
17:16:42.0251 0x0fd4 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
17:16:42.0329 0x0fd4 \Device\Harddisk1\DR1 - ok
17:16:42.0329 0x0fd4 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk4\DR4
17:16:42.0407 0x0fd4 \Device\Harddisk4\DR4 - ok
17:16:42.0407 0x0fd4 ================ Scan VBR ==================================
17:16:42.0407 0x0fd4 [ B75D89CA6D84C3CB1A6CA73A56716F49 ] \Device\Harddisk0\DR0\Partition1
17:16:42.0423 0x0fd4 \Device\Harddisk0\DR0\Partition1 - ok
17:16:42.0423 0x0fd4 [ BF802D8035F06A0BA68F026159CA8763 ] \Device\Harddisk1\DR1\Partition1
17:16:42.0423 0x0fd4 \Device\Harddisk1\DR1\Partition1 - ok
17:16:42.0423 0x0fd4 [ 55D863E4CA2B9A5E1BB7A9B572FDDD70 ] \Device\Harddisk4\DR4\Partition1
17:16:42.0423 0x0fd4 \Device\Harddisk4\DR4\Partition1 - ok
17:16:42.0423 0x0fd4 ================ Scan generic autorun ======================
17:16:42.0610 0x0fd4 [ 5229C2546E151D368A1CE0E451351231, 2E421986933D70789665195A92D2A9022500E9382B2881881B741F0023D6422E ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
17:16:42.0798 0x0fd4 RtHDVCpl - ok
17:16:42.0814 0x0fd4 [ 5677C8C60F4659E8626AC9036EEF38DF, 1C7D3EC3BCB3E34900DD9556A3EBAF449C68585DC8E07682E680790497105B8B ] C:\Program Files\Classic Shell\ClassicStartMenu.exe
17:16:42.0829 0x0fd4 Classic Start Menu - ok
17:16:42.0829 0x0fd4 [ 8943465BEFA91044227D42E84ECB8280, 76D19CE3EB7E6C6573F250543CDC10B3601604535BFB756805AE246FA55AC265 ] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
17:16:42.0845 0x0fd4 NUSB3MON - ok
17:16:42.0860 0x0fd4 [ CD0362AEE36CFE1EF5DF973230742E67, 9F1D8AD4E09D16C39CD6A35CB298456468C1808226FFA8AD65BF9562A6ECC07D ] C:\Program Files (x86)\PDF24\pdf24.exe
17:16:42.0892 0x0fd4 PDFPrint - ok
17:16:42.0892 0x0fd4 [ B69B3F28C5DB496202C88F5A181640AC, 6ECD6DCFE27A043457BA910289849534ED9D173856DAF694687366E1A2C7A135 ] C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
17:16:42.0907 0x0fd4 Avira SystrayStartTrigger - ok
17:16:42.0923 0x0fd4 OneDriveSetup - ok
17:16:42.0923 0x0fd4 OneDriveSetup - ok
17:16:42.0954 0x0fd4 [ 7D0F245088942BCB888A0AC149A6F378, 20B8145FC6988DB195E7E153FB8CA20DDE39CFC540AC5DC9BC1E91497E3ACC92 ] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEJE.EXE
17:16:42.0970 0x0fd4 EPSON Stylus Office BX300F - ok
17:16:43.0079 0x0fd4 [ F73154E180105822A5F9B755BA933737, 1CD775B6CE3736A70EC5FC7A6B77A2FEDA70D59B49A66046CC20B341005501D9 ] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
17:16:43.0189 0x0fd4 DAEMON Tools Lite - ok
17:16:43.0204 0x0fd4 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
17:16:43.0204 0x0fd4 AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.134 ), 0x60000 ( disabled : updated )
17:16:43.0204 0x0fd4 Win FW state via NFP2: enabled ( trusted )
17:16:43.0298 0x0fd4 ============================================================
17:16:43.0298 0x0fd4 Scan finished
17:16:43.0298 0x0fd4 ============================================================
17:16:43.0298 0x00d4 Detected object count: 0
17:16:43.0298 0x00d4 Actual detected object count: 0
17:17:47.0598 0x0380 Deinitialize success Code:
17:26:27.0450 0x0fe4 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
17:26:30.0419 0x0fe4 ============================================================
17:26:30.0419 0x0fe4 Current date / time: 2016/12/22 17:26:30.0419
17:26:30.0419 0x0fe4 SystemInfo:
17:26:30.0419 0x0fe4
17:26:30.0419 0x0fe4 OS Version: 10.0.14393 ServicePack: 0.0
17:26:30.0419 0x0fe4 Product type: Workstation
17:26:30.0419 0x0fe4 ComputerName: SONYDB
17:26:30.0419 0x0fe4 UserName: db
17:26:30.0419 0x0fe4 Windows directory: C:\WINDOWS
17:26:30.0419 0x0fe4 System windows directory: C:\WINDOWS
17:26:30.0419 0x0fe4 Running under WOW64
17:26:30.0419 0x0fe4 Processor architecture: Intel x64
17:26:30.0419 0x0fe4 Number of processors: 4
17:26:30.0419 0x0fe4 Page size: 0x1000
17:26:30.0419 0x0fe4 Boot type: Normal boot
17:26:30.0419 0x0fe4 CodeIntegrityOptions = 0x00000001
17:26:30.0434 0x0fe4 ============================================================
17:26:30.0497 0x0fe4 KLMD registered as C:\WINDOWS\system32\drivers\06235165.sys
17:26:30.0497 0x0fe4 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.576, osProperties = 0x19
17:26:30.0575 0x0fe4 System UUID: {89ED3A84-A01E-3FFA-4466-86F945B2E9B7}
17:26:30.0841 0x0fe4 Drive \Device\Harddisk0\DR0 - Size: 0x1DCF856000 ( 119.24 Gb ), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:26:30.0903 0x0fe4 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:26:30.0934 0x0fe4 Drive \Device\Harddisk4\DR4 - Size: 0x773C00000 ( 29.81 Gb ), SectorSize: 0x200, Cylinders: 0xF33, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
17:26:30.0934 0x0fe4 ============================================================
17:26:30.0934 0x0fe4 \Device\Harddisk0\DR0:
17:26:30.0934 0x0fe4 MBR partitions:
17:26:30.0934 0x0fe4 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xED9A000
17:26:30.0934 0x0fe4 \Device\Harddisk1\DR1:
17:26:30.0934 0x0fe4 MBR partitions:
17:26:30.0950 0x0fe4 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F00, BlocksNum 0x3A380D41
17:26:30.0950 0x0fe4 \Device\Harddisk4\DR4:
17:26:30.0950 0x0fe4 MBR partitions:
17:26:30.0950 0x0fe4 \Device\Harddisk4\DR4\Partition1: MBR, Type 0xC, StartLBA 0x2000, BlocksNum 0x3B9E000
17:26:30.0950 0x0fe4 ============================================================
17:26:30.0950 0x0fe4 C: <-> \Device\Harddisk0\DR0\Partition1
17:26:30.0966 0x0fe4 D: <-> \Device\Harddisk1\DR1\Partition1
17:26:30.0966 0x0fe4 ============================================================
17:26:30.0966 0x0fe4 Initialize success
17:26:30.0966 0x0fe4 ============================================================
17:26:38.0310 0x11a0 ============================================================
17:26:38.0310 0x11a0 Scan started
17:26:38.0310 0x11a0 Mode: Manual; SigCheck; TDLFS;
17:26:38.0310 0x11a0 ============================================================
17:26:38.0310 0x11a0 KSN ping started
17:26:38.0325 0x11a0 KSN ping finished: false
17:26:39.0185 0x11a0 ================ Scan system memory ========================
17:26:39.0185 0x11a0 System memory - ok
17:26:39.0185 0x11a0 ================ Scan services =============================
17:26:39.0185 0x11a0 [ 970C70F6B2953ED43822D3797855D84C, CB22723678B514277BC6E6DDDD206F3B2377CD889C9D473A47A7056BE597BC6B ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
17:26:39.0263 0x11a0 !SASCORE - ok
17:26:39.0310 0x11a0 1394ohci - ok
17:26:39.0310 0x11a0 3ware - ok
17:26:39.0325 0x11a0 ACPI - ok
17:26:39.0325 0x11a0 AcpiDev - ok
17:26:39.0325 0x11a0 acpiex - ok
17:26:39.0341 0x11a0 acpipagr - ok
17:26:39.0341 0x11a0 AcpiPmi - ok
17:26:39.0357 0x11a0 acpitime - ok
17:26:39.0357 0x11a0 ADP80XX - ok
17:26:39.0357 0x11a0 AFD - ok
17:26:39.0372 0x11a0 ahcache - ok
17:26:39.0372 0x11a0 AJRouter - ok
17:26:39.0388 0x11a0 [ 808820DEF092FA0A6D93BAE3E5D069CD, D1F49B6D99E346242EF6A9C37D2EC9333411FBDB031BE87FE0F8CDFEC545DD89 ] AlcatelOTnet C:\WINDOWS\system32\DRIVERS\AlcatelOTUsbnet.sys
17:26:39.0404 0x11a0 AlcatelOTnet - ok
17:26:39.0419 0x11a0 ALG - ok
17:26:39.0419 0x11a0 [ D7A72B9BA6AB996DADB37BFCB0363D63, A223684978928B59D39DFB49F6658E0CF04ADD15AD8ACFCEC384DBD4D8C8CBCA ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
17:26:39.0450 0x11a0 AMD External Events Utility - ok
17:26:39.0466 0x11a0 AmdK8 - ok
17:26:39.0466 0x11a0 [ 83ADF64C5BEAC0A065D7D2811E9A79CA, C724DC6EC9CB0E93DC034054FFB79284E70502FA155EFF624E112243F6C8D8E8 ] amdkmafd C:\WINDOWS\system32\drivers\amdkmafd.sys
17:26:39.0482 0x11a0 amdkmafd - ok
17:26:39.0482 0x11a0 amdkmdag - ok
17:26:39.0497 0x11a0 [ C14D7E5F24381BC8F333C4EB77892400, 8B8EF49D2398AF39E36EFFE6D1E0489727D5612DEFA43C71E3C7E4C0650010A5 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
17:26:39.0544 0x11a0 amdkmdap - ok
17:26:39.0544 0x11a0 AmdPPM - ok
17:26:39.0560 0x11a0 amdsata - ok
17:26:39.0560 0x11a0 amdsbs - ok
17:26:39.0560 0x11a0 amdxata - ok
17:26:39.0575 0x11a0 AppID - ok
17:26:39.0575 0x11a0 AppIDSvc - ok
17:26:39.0575 0x11a0 Appinfo - ok
17:26:39.0591 0x11a0 applockerfltr - ok
17:26:39.0591 0x11a0 AppMgmt - ok
17:26:39.0591 0x11a0 AppReadiness - ok
17:26:39.0607 0x11a0 AppVClient - ok
17:26:39.0607 0x11a0 AppvStrm - ok
17:26:39.0607 0x11a0 AppvVemgr - ok
17:26:39.0622 0x11a0 AppvVfs - ok
17:26:39.0622 0x11a0 AppXSvc - ok
17:26:39.0622 0x11a0 arcsas - ok
17:26:39.0638 0x11a0 AsyncMac - ok
17:26:39.0638 0x11a0 atapi - ok
17:26:39.0638 0x11a0 athr - ok
17:26:39.0654 0x11a0 AudioEndpointBuilder - ok
17:26:39.0654 0x11a0 Audiosrv - ok
17:26:39.0669 0x11a0 [ 14FCA1D1720A68C2D586940ABBE2DB3C, 274DB01CFD3024357602748FE36882ACE6BB3764A9FB62B2B40F9232B84A9B3E ] Avira.ServiceHost C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
17:26:39.0685 0x11a0 Avira.ServiceHost - ok
17:26:39.0700 0x11a0 AxInstSV - ok
17:26:39.0700 0x11a0 b06bdrv - ok
17:26:39.0700 0x11a0 BasicDisplay - ok
17:26:39.0716 0x11a0 BasicRender - ok
17:26:39.0716 0x11a0 bcmfn - ok
17:26:39.0732 0x11a0 bcmfn2 - ok
17:26:39.0732 0x11a0 BDESVC - ok
17:26:39.0732 0x11a0 Beep - ok
17:26:39.0747 0x11a0 BFE - ok
17:26:39.0747 0x11a0 BITS - ok
17:26:39.0747 0x11a0 bowser - ok
17:26:39.0747 0x11a0 BrokerInfrastructure - ok
17:26:39.0763 0x11a0 Browser - ok
17:26:39.0763 0x11a0 BthAvrcpTg - ok
17:26:39.0763 0x11a0 BthHFEnum - ok
17:26:39.0779 0x11a0 bthhfhid - ok
17:26:39.0794 0x11a0 BthHFSrv - ok
17:26:39.0794 0x11a0 BTHMODEM - ok
17:26:39.0810 0x11a0 bthserv - ok
17:26:39.0810 0x11a0 buttonconverter - ok
17:26:39.0825 0x11a0 CapImg - ok
17:26:39.0825 0x11a0 cdfs - ok
17:26:39.0825 0x11a0 CDPSvc - ok
17:26:39.0841 0x11a0 CDPUserSvc - ok
17:26:39.0841 0x11a0 cdrom - ok
17:26:39.0841 0x11a0 CertPropSvc - ok
17:26:39.0857 0x11a0 cht4iscsi - ok
17:26:39.0857 0x11a0 cht4vbd - ok
17:26:39.0857 0x11a0 circlass - ok
17:26:39.0872 0x11a0 CLFS - ok
17:26:39.0872 0x11a0 ClipSVC - ok
17:26:39.0872 0x11a0 clreg - ok
17:26:39.0888 0x11a0 CmBatt - ok
17:26:39.0888 0x11a0 CNG - ok
17:26:39.0904 0x11a0 cnghwassist - ok
17:26:39.0904 0x11a0 CompositeBus - ok
17:26:39.0919 0x11a0 COMSysApp - ok
17:26:39.0919 0x11a0 condrv - ok
17:26:39.0935 0x11a0 CoreMessagingRegistrar - ok
17:26:39.0935 0x11a0 CryptSvc - ok
17:26:39.0935 0x11a0 CSC - ok
17:26:39.0951 0x11a0 CscService - ok
17:26:39.0951 0x11a0 dam - ok
17:26:39.0966 0x11a0 DcomLaunch - ok
17:26:39.0966 0x11a0 DcpSvc - ok
17:26:39.0966 0x11a0 defragsvc - ok
17:26:39.0966 0x11a0 DeviceAssociationService - ok
17:26:39.0982 0x11a0 DeviceInstall - ok
17:26:39.0982 0x11a0 DevQueryBroker - ok
17:26:39.0982 0x11a0 Dfsc - ok
17:26:39.0997 0x11a0 [ 73BDD44A6088916964945886F9025409, 8E2ECC9AAEF3C6EBA2E61D25F657FDFCC72AB517CC4FD5FFF992E1F9EB942662 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
17:26:40.0013 0x11a0 dg_ssudbus - ok
17:26:40.0013 0x11a0 Dhcp - ok
17:26:40.0013 0x11a0 diagnosticshub.standardcollector.service - ok
17:26:40.0029 0x11a0 DiagTrack - ok
17:26:40.0029 0x11a0 disk - ok
17:26:40.0044 0x11a0 DmEnrollmentSvc - ok
17:26:40.0044 0x11a0 dmvsc - ok
17:26:40.0044 0x11a0 dmwappushservice - ok
17:26:40.0044 0x11a0 Dnscache - ok
17:26:40.0060 0x11a0 dot3svc - ok
17:26:40.0060 0x11a0 DPS - ok
17:26:40.0075 0x11a0 drmkaud - ok
17:26:40.0075 0x11a0 DsmSvc - ok
17:26:40.0075 0x11a0 DsSvc - ok
17:26:40.0091 0x11a0 [ 33F90B202E9DD9B7D489EB59310FDC34, 6ECF6669433E090E9CF6B1875AF18D2C06F8CDB3901D58BF89C3E2202574ABBD ] dtsoftbus01 C:\WINDOWS\System32\drivers\dtsoftbus01.sys
17:26:40.0107 0x11a0 dtsoftbus01 - ok
17:26:40.0107 0x11a0 DXGKrnl - ok
17:26:40.0122 0x11a0 EapHost - ok
17:26:40.0122 0x11a0 ebdrv - ok
17:26:40.0122 0x11a0 EFS - ok
17:26:40.0138 0x11a0 EhStorClass - ok
17:26:40.0138 0x11a0 EhStorTcgDrv - ok
17:26:40.0138 0x11a0 embeddedmode - ok
17:26:40.0154 0x11a0 EntAppSvc - ok
17:26:40.0154 0x11a0 [ 9EAFB3B3B60B8AD958985152A9309ACA, EC58F487D50A125DA3F747670282EA2104580CCAAF709EA494B61C7549576AE6 ] epmntdrv C:\Windows\system32\epmntdrv.sys
17:26:40.0169 0x11a0 epmntdrv - detected UnsignedFile.Multi.Generic ( 1 )
17:26:40.0263 0x11a0 epmntdrv ( UnsignedFile.Multi.Generic ) - warning
17:26:40.0279 0x11a0 ErrDev - ok
17:26:40.0279 0x11a0 [ FB949ED2C93C878A189039F3D7730942, 857AFB9965F14C80C21948C05A44D37948BD206961101DFF087735D6A7CCAA8A ] EuGdiDrv C:\Windows\system32\EuGdiDrv.sys
17:26:40.0294 0x11a0 EuGdiDrv - detected UnsignedFile.Multi.Generic ( 1 )
17:26:40.0294 0x11a0 EuGdiDrv ( UnsignedFile.Multi.Generic ) - warning
17:26:40.0294 0x11a0 Force sending object to P2P due to detect: EuGdiDrv
17:26:40.0294 0x11a0 Object send P2P result: false
17:26:40.0294 0x11a0 EventSystem - ok
17:26:40.0310 0x11a0 [ CA2E486FE6212FFD5FD171AC1A0B17BE, 4534A8496C8044F4DF3573B4021391327BE3BED026BC5CD1A35A5708651A9E1D ] ewusbmbb C:\WINDOWS\system32\DRIVERS\ewusbwwan.sys
17:26:40.0341 0x11a0 ewusbmbb - ok
17:26:40.0357 0x11a0 [ 86F7951BBCEE4A86E79A97306BD14318, 84B52A0392DA53ED71A2C4D483DD93DDF552BF8AC764C7BD47BE0EB58C7C8219 ] ew_hwusbdev C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys
17:26:40.0372 0x11a0 ew_hwusbdev - ok
17:26:40.0372 0x11a0 exfat - ok
17:26:40.0388 0x11a0 fastfat - ok
17:26:40.0388 0x11a0 Fax - ok
17:26:40.0388 0x11a0 fdc - ok
17:26:40.0404 0x11a0 fdPHost - ok
17:26:40.0404 0x11a0 FDResPub - ok
17:26:40.0404 0x11a0 fhsvc - ok
17:26:40.0419 0x11a0 FileCrypt - ok
17:26:40.0419 0x11a0 FileInfo - ok
17:26:40.0419 0x11a0 Filetrace - ok
17:26:40.0435 0x11a0 flpydisk - ok
17:26:40.0435 0x11a0 FltMgr - ok
17:26:40.0435 0x11a0 FontCache - ok
17:26:40.0450 0x11a0 FontCache3.0.0.0 - ok
17:26:40.0482 0x11a0 [ B3A740CF5841D2087F2A8ACBAD9CA9AD, 587D966D8FF6A6704E8367B470B4F6CA5F6A29A25E960C718E9AB51899D53DD1 ] FoxitReaderService C:\Program Files (x86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe
17:26:40.0529 0x11a0 FoxitReaderService - ok
17:26:40.0544 0x11a0 FrameServer - ok
17:26:40.0544 0x11a0 FsDepends - ok
17:26:40.0544 0x11a0 Fs_Rec - ok
17:26:40.0560 0x11a0 fvevol - ok
17:26:40.0560 0x11a0 gencounter - ok
17:26:40.0575 0x11a0 genericusbfn - ok
17:26:40.0575 0x11a0 GPIOClx0101 - ok
17:26:40.0575 0x11a0 gpsvc - ok
17:26:40.0575 0x11a0 GpuEnergyDrv - ok
17:26:40.0591 0x11a0 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:26:40.0607 0x11a0 gupdate - ok
17:26:40.0607 0x11a0 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:26:40.0622 0x11a0 gupdatem - ok
17:26:40.0622 0x11a0 HdAudAddService - ok
17:26:40.0638 0x11a0 HDAudBus - ok
17:26:40.0638 0x11a0 [ B6AC71AAA2B10848F57FC49D55A651AF, 4FAD833654E86F9FAF972AC8AF87FD4A9A765B26B96F096BBD63506B5D521A91 ] HECIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
17:26:40.0654 0x11a0 HECIx64 - ok
17:26:40.0654 0x11a0 HidBatt - ok
17:26:40.0669 0x11a0 HidBth - ok
17:26:40.0669 0x11a0 hidi2c - ok
17:26:40.0669 0x11a0 hidinterrupt - ok
17:26:40.0685 0x11a0 HidIr - ok
17:26:40.0685 0x11a0 hidserv - ok
17:26:40.0685 0x11a0 HidUsb - ok
17:26:40.0701 0x11a0 HomeGroupListener - ok
17:26:40.0701 0x11a0 HomeGroupProvider - ok
17:26:40.0701 0x11a0 HpSAMD - ok
17:26:40.0716 0x11a0 HTTP - ok
17:26:40.0716 0x11a0 [ 1642C62F1FD5E1FF44608283994A7BB8, 4646AA0EF74A2AEE6C17D12206FCFE1E84D6FA712AD95A171F16D11BC9D3F11A ] huawei_enumerator C:\WINDOWS\System32\drivers\ew_jubusenum.sys
17:26:40.0732 0x11a0 huawei_enumerator - ok
17:26:40.0747 0x11a0 HvHost - ok
17:26:40.0747 0x11a0 hvservice - ok
17:26:40.0747 0x11a0 HWDeviceService64.exe - ok
17:26:40.0763 0x11a0 hwpolicy - ok
17:26:40.0763 0x11a0 hyperkbd - ok
17:26:40.0763 0x11a0 i8042prt - ok
17:26:40.0779 0x11a0 iagpio - ok
17:26:40.0779 0x11a0 iai2c - ok
17:26:40.0779 0x11a0 iaLPSS2i_GPIO2 - ok
17:26:40.0794 0x11a0 iaLPSS2i_I2C - ok
17:26:40.0794 0x11a0 iaLPSSi_GPIO - ok
17:26:40.0794 0x11a0 iaLPSSi_I2C - ok
17:26:40.0810 0x11a0 iaStorAV - ok
17:26:40.0810 0x11a0 iaStorV - ok
17:26:40.0810 0x11a0 ibbus - ok
17:26:40.0826 0x11a0 icssvc - ok
17:26:40.0826 0x11a0 IKEEXT - ok
17:26:40.0826 0x11a0 [ DD587A55390ED2295BCE6D36AD567DA9, AEB7DCB8EF89BEE8D9649A05FC482B1E4E3F44243D57A2577C862EB69166C48E ] Impcd C:\WINDOWS\System32\drivers\Impcd.sys
17:26:40.0857 0x11a0 Impcd - ok
17:26:40.0857 0x11a0 IndirectKmd - ok
17:26:40.0904 0x11a0 [ 1A6241B70453A6629A83DB942AA6B08C, EF93785E20E18BF36F667E35F89BBF2A17C86F57E2D17D077F5031CE70E9DC9D ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
17:26:40.0966 0x11a0 IntcAzAudAddService - ok
17:26:40.0966 0x11a0 intelide - ok
17:26:40.0966 0x11a0 intelpep - ok
17:26:40.0982 0x11a0 intelppm - ok
17:26:40.0982 0x11a0 iorate - ok
17:26:40.0997 0x11a0 IpFilterDriver - ok
17:26:40.0997 0x11a0 iphlpsvc - ok
17:26:40.0997 0x11a0 IPMIDRV - ok
17:26:40.0997 0x11a0 IPNAT - ok
17:26:41.0013 0x11a0 irda - ok
17:26:41.0013 0x11a0 IRENUM - ok
17:26:41.0013 0x11a0 irmon - ok
17:26:41.0029 0x11a0 isapnp - ok
17:26:41.0029 0x11a0 iScsiPrt - ok
17:26:41.0029 0x11a0 [ 5678EC677028221EC5C815BCD07AB697, 02FD1A0290A9A17823D24A0E55D4AB35C3F939C986AB8BB54C6248287466FE0D ] jrdusbser C:\WINDOWS\system32\DRIVERS\jrdusbser.sys
17:26:41.0060 0x11a0 jrdusbser - ok
17:26:41.0060 0x11a0 Juqokchukity - ok
17:26:41.0060 0x11a0 kbdclass - ok
17:26:41.0060 0x11a0 kbdhid - ok
17:26:41.0076 0x11a0 kdnic - ok
17:26:41.0076 0x11a0 KeyIso - ok
17:26:41.0091 0x11a0 KSecDD - ok
17:26:41.0091 0x11a0 KSecPkg - ok
17:26:41.0091 0x11a0 ksthunk - ok
17:26:41.0091 0x11a0 KtmRm - ok
17:26:41.0107 0x11a0 LanmanServer - ok
17:26:41.0107 0x11a0 LanmanWorkstation - ok
17:26:41.0122 0x11a0 lfsvc - ok
17:26:41.0122 0x11a0 LicenseManager - ok
17:26:41.0122 0x11a0 lltdio - ok
17:26:41.0122 0x11a0 lltdsvc - ok
17:26:41.0138 0x11a0 lmhosts - ok
17:26:41.0138 0x11a0 LSI_SAS - ok
17:26:41.0138 0x11a0 LSI_SAS2i - ok
17:26:41.0154 0x11a0 LSI_SAS3i - ok
17:26:41.0154 0x11a0 LSI_SSS - ok
17:26:41.0154 0x11a0 LSM - ok
17:26:41.0169 0x11a0 luafv - ok
17:26:41.0169 0x11a0 [ A0A527569856B9814E8920F52EBB67F5, 4347277C84B47E4CC048850BDEFB258CFB3B476AA99FD503FD71FBB70FFF5ACF ] LVRS64 C:\WINDOWS\system32\DRIVERS\lvrs64.sys
17:26:41.0201 0x11a0 LVRS64 - ok
17:26:41.0294 0x11a0 [ 415E344294D1C0D04627B29146F68481, B4A1A05BDF07E8F226A98E51F62BE18BE2C046A084C495BD8A95CABC79FD0614 ] LVUVC64 C:\WINDOWS\system32\DRIVERS\lvuvc64.sys
17:26:41.0404 0x11a0 LVUVC64 - ok
17:26:41.0419 0x11a0 MapsBroker - ok
17:26:41.0435 0x11a0 [ 3BEC6134F1E45AEF5E971F69F0D38510, 245D7CEEB6561166EE0472551D39A9D3CFDDA52A6BF2E924AB243CCA7FBC9009 ] MBAMChameleon C:\WINDOWS\system32\drivers\MBAMChameleon.sys
17:26:41.0451 0x11a0 MBAMChameleon - ok
17:26:41.0451 0x11a0 [ 88BD122C3A35DE63D75D382DF75554CE, ABDF59543CAD186A6ED4E66257205D9CF5047732A5DA74A96A28B468B41BC396 ] MBAMProtection C:\WINDOWS\system32\drivers\mbam.sys
17:26:41.0466 0x11a0 MBAMProtection - ok
17:26:41.0560 0x11a0 [ 28E521A6ABA9DE062A3719452816F495, B312A37DA052229DFB19353170CD5828582F8AC6426E857CA7C8ACA0DD91C160 ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
17:26:41.0669 0x11a0 MBAMService - ok
17:26:41.0685 0x11a0 megasas - ok
17:26:41.0685 0x11a0 megasas2i - ok
17:26:41.0685 0x11a0 megasr - ok
17:26:41.0701 0x11a0 MessagingService - ok
17:26:41.0701 0x11a0 mlx4_bus - ok
17:26:41.0716 0x11a0 MMCSS - ok
17:26:41.0716 0x11a0 [ 1CE0621B591913C12BECAA5B50E88BB2, 115068C57570140C9389BD923A4E68236ACEBB4F733DA09D05AEEDAD7317AB46 ] Mobile Partner. RunOuc C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe
17:26:41.0732 0x11a0 Mobile Partner. RunOuc - ok
17:26:41.0747 0x11a0 Modem - ok
17:26:41.0747 0x11a0 monitor - ok
17:26:41.0747 0x11a0 mouclass - ok
17:26:41.0763 0x11a0 mouhid - ok
17:26:41.0763 0x11a0 mountmgr - ok
17:26:41.0763 0x11a0 mpsdrv - ok
17:26:41.0779 0x11a0 MpsSvc - ok
17:26:41.0779 0x11a0 MRxDAV - ok
17:26:41.0779 0x11a0 mrxsmb - ok
17:26:41.0794 0x11a0 mrxsmb10 - ok
17:26:41.0794 0x11a0 mrxsmb20 - ok
17:26:41.0794 0x11a0 MsBridge - ok
17:26:41.0794 0x11a0 MSDTC - ok
17:26:41.0810 0x11a0 Msfs - ok
17:26:41.0810 0x11a0 msgpiowin32 - ok
17:26:41.0826 0x11a0 mshidkmdf - ok
17:26:41.0826 0x11a0 mshidumdf - ok
17:26:41.0826 0x11a0 msisadrv - ok
17:26:41.0841 0x11a0 MSiSCSI - ok
17:26:41.0841 0x11a0 msiserver - ok
17:26:41.0841 0x11a0 MSKSSRV - ok
17:26:41.0841 0x11a0 MsLldp - ok
17:26:41.0857 0x11a0 MSPCLOCK - ok
17:26:41.0857 0x11a0 MSPQM - ok
17:26:41.0857 0x11a0 MsRPC - ok
17:26:41.0872 0x11a0 MsSecFlt - ok
17:26:41.0872 0x11a0 mssmbios - ok
17:26:41.0872 0x11a0 MSTEE - ok
17:26:41.0888 0x11a0 MTConfig - ok
17:26:41.0888 0x11a0 Mup - ok
17:26:41.0888 0x11a0 mvumis - ok
17:26:41.0904 0x11a0 NativeWifiP - ok
17:26:41.0919 0x11a0 [ E0E4A1F81A7D69C595A8A9DDAD084C19, 8F55F3637AE8BFFB0ACE37AFC5122026525137E0B2923899B779C1BD08DF0E22 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
17:26:41.0951 0x11a0 NAUpdate - ok
17:26:41.0951 0x11a0 NcaSvc - ok
17:26:41.0951 0x11a0 NcbService - ok
17:26:41.0966 0x11a0 NcdAutoSetup - ok
17:26:41.0966 0x11a0 ndfltr - ok
17:26:41.0966 0x11a0 NDIS - ok
17:26:41.0982 0x11a0 NdisCap - ok
17:26:41.0982 0x11a0 NdisImPlatform - ok
17:26:41.0982 0x11a0 NdisTapi - ok
17:26:41.0997 0x11a0 Ndisuio - ok
17:26:41.0997 0x11a0 NdisVirtualBus - ok
17:26:41.0997 0x11a0 NdisWan - ok
17:26:42.0013 0x11a0 ndiswanlegacy - ok
17:26:42.0013 0x11a0 ndproxy - ok
17:26:42.0013 0x11a0 Ndu - ok
17:26:42.0029 0x11a0 NetAdapterCx - ok
17:26:42.0029 0x11a0 NetBIOS - ok
17:26:42.0029 0x11a0 NetBT - ok
17:26:42.0044 0x11a0 Netlogon - ok
17:26:42.0044 0x11a0 Netman - ok
17:26:42.0044 0x11a0 netprofm - ok
17:26:42.0044 0x11a0 NetSetupSvc - ok
17:26:42.0060 0x11a0 NetTcpPortSharing - ok
17:26:42.0060 0x11a0 NgcCtnrSvc - ok
17:26:42.0076 0x11a0 NgcSvc - ok
17:26:42.0076 0x11a0 NlaSvc - ok
17:26:42.0076 0x11a0 [ DE7FCC77F4A503AF4CA6A47D49B3713D, 4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6 ] npf C:\WINDOWS\system32\drivers\npf.sys
17:26:42.0091 0x11a0 npf - ok
17:26:42.0091 0x11a0 Npfs - ok
17:26:42.0107 0x11a0 npsvctrig - ok
17:26:42.0107 0x11a0 nsi - ok
17:26:42.0107 0x11a0 nsiproxy - ok
17:26:42.0122 0x11a0 NTFS - ok
17:26:42.0122 0x11a0 Null - ok
17:26:42.0138 0x11a0 [ B01C1E6D7477961D6D1CBDCD44AF3E67, 407BD335FE7C87DFBD9EDE49BDD828263D8C8D25C8216FF04AC70320E74AE8B6 ] nusb3hub C:\WINDOWS\System32\drivers\nusb3hub.sys
17:26:42.0154 0x11a0 nusb3hub - ok
17:26:42.0154 0x11a0 nvraid - ok
17:26:42.0169 0x11a0 nvstor - ok
17:26:42.0169 0x11a0 OneSyncSvc - ok
17:26:42.0185 0x11a0 [ 11E0B35479C895888BA3D7F619DCFFF3, 6ED82C19898101EC00BD64A9F90595C3D20AD2D2902AA8765B740FB3B9312DDF ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:26:42.0201 0x11a0 ose64 - ok
17:26:42.0201 0x11a0 p2pimsvc - ok
17:26:42.0216 0x11a0 p2psvc - ok
17:26:42.0216 0x11a0 Parport - ok
17:26:42.0232 0x11a0 partmgr - ok
17:26:42.0232 0x11a0 PcaSvc - ok
17:26:42.0232 0x11a0 pci - ok
17:26:42.0247 0x11a0 pciide - ok
17:26:42.0247 0x11a0 pcmcia - ok
17:26:42.0247 0x11a0 pcw - ok
17:26:42.0263 0x11a0 pdc - ok
17:26:42.0263 0x11a0 PEAUTH - ok
17:26:42.0263 0x11a0 PeerDistSvc - ok
17:26:42.0279 0x11a0 percsas2i - ok
17:26:42.0279 0x11a0 percsas3i - ok
17:26:42.0294 0x11a0 PerfHost - ok
17:26:42.0310 0x11a0 PhoneSvc - ok
17:26:42.0310 0x11a0 PimIndexMaintenanceSvc - ok
17:26:42.0310 0x11a0 pla - ok
17:26:42.0326 0x11a0 PlugPlay - ok
17:26:42.0326 0x11a0 PnkBstrA - ok
17:26:42.0326 0x11a0 PnkBstrB - ok
17:26:42.0341 0x11a0 PNRPAutoReg - ok
17:26:42.0341 0x11a0 PNRPsvc - ok
17:26:42.0341 0x11a0 PolicyAgent - ok
17:26:42.0357 0x11a0 Power - ok
17:26:42.0357 0x11a0 PptpMiniport - ok
17:26:42.0435 0x11a0 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
17:26:42.0576 0x11a0 PrintNotify - ok
17:26:42.0591 0x11a0 Processor - ok
17:26:42.0591 0x11a0 ProfSvc - ok
17:26:42.0607 0x11a0 Psched - ok
17:26:42.0607 0x11a0 [ C32ECB99AD25E9A04F01C8665DF29EF8, 0489B3DEC6A33E50D8A48A8DAD3F5B923A81F7300E4A71358D90D2879BAC9AA2 ] pwdrvio C:\Windows\system32\pwdrvio.sys
17:26:42.0622 0x11a0 pwdrvio - ok
17:26:42.0638 0x11a0 [ D619356B955EEFA642F5FF72755E8B3C, 1FD54978A77ACD6FBF1236E177ED074894743A9141E4169FE9AFE28680FC93C5 ] pwdspio C:\Windows\system32\pwdspio.sys
17:26:42.0654 0x11a0 pwdspio - ok
17:26:42.0654 0x11a0 QWAVE - ok
17:26:42.0669 0x11a0 QWAVEdrv - ok
17:26:42.0669 0x11a0 RasAcd - ok
17:26:42.0669 0x11a0 RasAgileVpn - ok
17:26:42.0685 0x11a0 RasAuto - ok
17:26:42.0685 0x11a0 Rasl2tp - ok
17:26:42.0685 0x11a0 RasMan - ok
17:26:42.0701 0x11a0 RasPppoe - ok
17:26:42.0701 0x11a0 RasSstp - ok
17:26:42.0701 0x11a0 rdbss - ok
17:26:42.0716 0x11a0 rdpbus - ok
17:26:42.0716 0x11a0 RDPDR - ok
17:26:42.0716 0x11a0 RdpVideoMiniport - ok
17:26:42.0732 0x11a0 rdyboost - ok
17:26:42.0732 0x11a0 ReFSv1 - ok
17:26:42.0747 0x11a0 RemoteAccess - ok
17:26:42.0747 0x11a0 RemoteRegistry - ok
17:26:42.0747 0x11a0 RetailDemo - ok
17:26:42.0763 0x11a0 [ 5CA4ABD888B602551B59BAA26941C167, F6FC0F828153E07EAFFAB6E11556DA23A5F6D9FC063E36947B1AC73E7E7E705E ] rimspci C:\WINDOWS\System32\drivers\rimssne64.sys
17:26:42.0779 0x11a0 rimspci - ok
17:26:42.0779 0x11a0 [ BB6E138AEB351728959DA5E2731D8140, E6656869A03380EB96A31E4E5FF4D565916EB0A7ED334330D2DD039390441D15 ] risdsnpe C:\WINDOWS\System32\drivers\risdsne64.sys
17:26:42.0794 0x11a0 risdsnpe - ok
17:26:42.0810 0x11a0 RmSvc - ok
17:26:42.0810 0x11a0 RpcEptMapper - ok
17:26:42.0810 0x11a0 RpcLocator - ok
17:26:42.0826 0x11a0 RpcSs - ok
17:26:42.0826 0x11a0 rspndr - ok
17:26:42.0841 0x11a0 [ 7421A35C45484B95E83B5E9E107CEFC2, 128BB6A7552B9D57284056FB8946A6FE3C620F7B706F709F896828304A6FCD77 ] RTHDMIAzAudService C:\WINDOWS\system32\drivers\RtHDMIVX.sys
17:26:42.0857 0x11a0 RTHDMIAzAudService - ok
17:26:42.0857 0x11a0 s3cap - ok
17:26:42.0857 0x11a0 SamSs - ok
17:26:42.0873 0x11a0 [ 3289766038DB2CB14D07DC84392138D5, A7790B787690CC1A8B97E4532090C5295350A836A9474DEA74CEB3E81CF26124 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
17:26:42.0873 0x11a0 SASDIFSV - ok
17:26:42.0888 0x11a0 [ 58A38E75F3316A83C23DF6173D41F2B5, B0A8CDA1D164B7534FB41AB80792861384709BF0F914F44553275CF20194F1A1 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
17:26:42.0888 0x11a0 SASKUTIL - ok
17:26:42.0904 0x11a0 sbp2port - ok
17:26:42.0904 0x11a0 SCardSvr - ok
17:26:42.0904 0x11a0 ScDeviceEnum - ok
17:26:42.0919 0x11a0 scfilter - ok
17:26:42.0919 0x11a0 Schedule - ok
17:26:42.0919 0x11a0 scmbus - ok
17:26:42.0935 0x11a0 scmdisk0101 - ok
17:26:42.0935 0x11a0 SCPolicySvc - ok
17:26:42.0935 0x11a0 sdbus - ok
17:26:42.0951 0x11a0 SDRSVC - ok
17:26:42.0951 0x11a0 sdstor - ok
17:26:42.0951 0x11a0 seclogon - ok
17:26:42.0966 0x11a0 SENS - ok
17:26:42.0966 0x11a0 Sense - ok
17:26:42.0966 0x11a0 SensorDataService - ok
17:26:42.0982 0x11a0 SensorService - ok
17:26:42.0982 0x11a0 SensrSvc - ok
17:26:42.0982 0x11a0 SerCx - ok
17:26:42.0997 0x11a0 SerCx2 - ok
17:26:42.0997 0x11a0 Serenum - ok
17:26:42.0997 0x11a0 Serial - ok
17:26:42.0997 0x11a0 sermouse - ok
17:26:43.0013 0x11a0 SessionEnv - ok
17:26:43.0013 0x11a0 [ 70F9C476B62DE4F2823E918A6C181ADE, E1A641418A6CB4FA38BB29B86934838B28D8909B8066E5089D85BF72FD61F4C4 ] SFEP C:\WINDOWS\System32\drivers\SFEP.sys
17:26:43.0029 0x11a0 SFEP - ok
17:26:43.0044 0x11a0 sfloppy - ok
17:26:43.0044 0x11a0 SharedAccess - ok
17:26:43.0044 0x11a0 ShellHWDetection - ok
17:26:43.0060 0x11a0 shpamsvc - ok
17:26:43.0060 0x11a0 SiSRaid2 - ok
17:26:43.0076 0x11a0 SiSRaid4 - ok
17:26:43.0076 0x11a0 [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
17:26:43.0107 0x11a0 SkypeUpdate - ok
17:26:43.0107 0x11a0 smphost - ok
17:26:43.0107 0x11a0 SmsRouter - ok
17:26:43.0122 0x11a0 SNMPTRAP - ok
17:26:43.0122 0x11a0 spaceport - ok
17:26:43.0138 0x11a0 Sparhandy_Germany Silverstone Modem Device Helper - ok
17:26:43.0138 0x11a0 SpbCx - ok
17:26:43.0154 0x11a0 [ 0FFE35F0B0CD5A324BBE22F02569AE3B, F4EE803EEFDB4EAEEDB3024C3516F1F9A202C77F4870D6B74356BBDE32B3B560 ] speedfan C:\Windows\SysWOW64\speedfan.sys
17:26:43.0169 0x11a0 speedfan - ok
17:26:43.0185 0x11a0 Spooler - ok
17:26:43.0185 0x11a0 sppsvc - ok
17:26:43.0185 0x11a0 srv - ok
17:26:43.0201 0x11a0 srv2 - ok
17:26:43.0201 0x11a0 srvnet - ok
17:26:43.0216 0x11a0 SSDPSRV - ok
17:26:43.0216 0x11a0 SstpSvc - ok
17:26:43.0232 0x11a0 [ 5252D7BC56E5E0ED715AEA8FE173A455, 1408B3E98B35A449434718777EE70595F0D306197A428279C6281D2F1953F259 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
17:26:43.0232 0x11a0 ssudmdm - ok
17:26:43.0247 0x11a0 StateRepository - ok
17:26:43.0247 0x11a0 stexstor - ok
17:26:43.0247 0x11a0 stisvc - ok
17:26:43.0263 0x11a0 storahci - ok
17:26:43.0263 0x11a0 storflt - ok
17:26:43.0263 0x11a0 stornvme - ok
17:26:43.0279 0x11a0 storqosflt - ok
17:26:43.0279 0x11a0 StorSvc - ok
17:26:43.0279 0x11a0 storufs - ok
17:26:43.0294 0x11a0 storvsc - ok
17:26:43.0294 0x11a0 svsvc - ok
17:26:43.0294 0x11a0 swenum - ok
17:26:43.0310 0x11a0 swprv - ok
17:26:43.0310 0x11a0 Synth3dVsc - ok
17:26:43.0310 0x11a0 SysMain - ok
17:26:43.0326 0x11a0 SystemEventsBroker - ok
17:26:43.0326 0x11a0 TabletInputService - ok
17:26:43.0326 0x11a0 [ 3C32FF010F869BC184DF71290477384E, 55CFCEC7F026C6E2E96A2FBE846AB513BB12BB0348735274FE1B71AF019C837B ] tap0901 C:\WINDOWS\System32\drivers\tap0901.sys
17:26:43.0341 0x11a0 tap0901 - ok
17:26:43.0357 0x11a0 TapiSrv - ok
17:26:43.0357 0x11a0 Tcpip - ok
17:26:43.0357 0x11a0 Tcpip6 - ok
17:26:43.0373 0x11a0 tcpipreg - ok
17:26:43.0373 0x11a0 tdx - ok
17:26:43.0388 0x11a0 terminpt - ok
17:26:43.0388 0x11a0 TermService - ok
17:26:43.0388 0x11a0 Themes - ok
17:26:43.0404 0x11a0 TieringEngineService - ok
17:26:43.0404 0x11a0 tiledatamodelsvc - ok
17:26:43.0404 0x11a0 TimeBrokerSvc - ok
17:26:43.0419 0x11a0 TPM - ok
17:26:43.0419 0x11a0 TrkWks - ok
17:26:43.0419 0x11a0 TrustedInstaller - ok
17:26:43.0435 0x11a0 tsusbflt - ok
17:26:43.0435 0x11a0 TsUsbGD - ok
17:26:43.0451 0x11a0 tsusbhub - ok
17:26:43.0451 0x11a0 tunnel - ok
17:26:43.0451 0x11a0 tzautoupdate - ok
17:26:43.0466 0x11a0 UASPStor - ok
17:26:43.0466 0x11a0 [ 209F5CEAAAFE601851E7B40902FC230D, B7BFD753DF9EA1AD6D6BD8FB47F24E79FA84208E7A66C88B934C3A13B087901D ] ucdrv C:\WINDOWS\System32\drivers:ucdrv-x64.sys
17:26:43.0482 0x11a0 Suspicious file ( Hidden ): C:\WINDOWS\System32\drivers:ucdrv-x64.sys. md5: 209F5CEAAAFE601851E7B40902FC230D, sha256: B7BFD753DF9EA1AD6D6BD8FB47F24E79FA84208E7A66C88B934C3A13B087901D
17:26:43.0482 0x11a0 ucdrv - detected HiddenFile.Multi.Generic ( 1 )
17:26:43.0482 0x11a0 ucdrv ( HiddenFile.Multi.Generic ) - warning
17:26:43.0482 0x11a0 Force sending object to P2P due to detect: ucdrv
17:26:43.0482 0x11a0 Object send P2P result: false
17:26:43.0482 0x11a0 UcmCx0101 - ok
17:26:43.0497 0x11a0 UcmTcpciCx0101 - ok
17:26:43.0497 0x11a0 UcmUcsi - ok
17:26:43.0497 0x11a0 Ucx01000 - ok
17:26:43.0513 0x11a0 UdeCx - ok
17:26:43.0513 0x11a0 udfs - ok
17:26:43.0513 0x11a0 UEFI - ok
17:26:43.0529 0x11a0 UevAgentDriver - ok
17:26:43.0529 0x11a0 UevAgentService - ok
17:26:43.0529 0x11a0 Ufx01000 - ok
17:26:43.0544 0x11a0 UfxChipidea - ok
17:26:43.0544 0x11a0 ufxsynopsys - ok
17:26:43.0560 0x11a0 UI0Detect - ok
17:26:43.0560 0x11a0 umbus - ok
17:26:43.0560 0x11a0 UmPass - ok
17:26:43.0576 0x11a0 UmRdpService - ok
17:26:43.0576 0x11a0 UnistoreSvc - ok
17:26:43.0591 0x11a0 [ 9DC07E73A4ABB9ACF692113B36A5009F, CA7176FC219515D58DCFA66EC61880ECE5617275C9B83701BB74D8B60E733D34 ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys
17:26:43.0591 0x11a0 UnlockerDriver5 - ok
17:26:43.0607 0x11a0 upnphost - ok
17:26:43.0607 0x11a0 UrsChipidea - ok
17:26:43.0623 0x11a0 UrsCx01000 - ok
17:26:43.0623 0x11a0 UrsSynopsys - ok
17:26:43.0638 0x11a0 [ 55020D37C29F05D583A76F20127B4FD7, 9BFB5F16D5C15ADF3ECB8769B66F443250497F6A2F58FA74954EC64EF2F6C33E ] USB28xxBGA C:\WINDOWS\system32\DRIVERS\emBDA64.sys
17:26:43.0669 0x11a0 USB28xxBGA - ok
17:26:43.0685 0x11a0 [ D7940283C43E440FCF83AB55B85689C9, C41DD0E5CE66328694047FF468BBBB3D35FBB9CB41A249202A05DB411EFEEFB1 ] USB28xxOEM C:\WINDOWS\system32\DRIVERS\emOEM64.sys
17:26:43.0701 0x11a0 USB28xxOEM - ok
17:26:43.0701 0x11a0 usbaudio - ok
17:26:43.0716 0x11a0 usbccgp - ok
17:26:43.0716 0x11a0 usbcir - ok
17:26:43.0716 0x11a0 usbehci - ok
17:26:43.0732 0x11a0 usbhub - ok
17:26:43.0732 0x11a0 USBHUB3 - ok
17:26:43.0732 0x11a0 usbohci - ok
17:26:43.0748 0x11a0 usbprint - ok
17:26:43.0748 0x11a0 usbscan - ok
17:26:43.0748 0x11a0 usbser - ok
17:26:43.0763 0x11a0 USBSTOR - ok
17:26:43.0763 0x11a0 usbuhci - ok
17:26:43.0763 0x11a0 usbvideo - ok
17:26:43.0779 0x11a0 USBXHCI - ok
17:26:43.0779 0x11a0 UserDataSvc - ok
17:26:43.0794 0x11a0 UserManager - ok
17:26:43.0794 0x11a0 UsoSvc - ok
17:26:43.0794 0x11a0 VaultSvc - ok
17:26:43.0810 0x11a0 vdrvroot - ok
17:26:43.0810 0x11a0 vds - ok
17:26:43.0810 0x11a0 VerifierExt - ok
17:26:43.0826 0x11a0 vhdmp - ok
17:26:43.0826 0x11a0 vhf - ok
17:26:43.0826 0x11a0 vmbus - ok
17:26:43.0841 0x11a0 VMBusHID - ok
17:26:43.0841 0x11a0 vmgid - ok
17:26:43.0841 0x11a0 vmicguestinterface - ok
17:26:43.0857 0x11a0 vmicheartbeat - ok
17:26:43.0857 0x11a0 vmickvpexchange - ok
17:26:43.0857 0x11a0 vmicrdv - ok
17:26:43.0873 0x11a0 vmicshutdown - ok
17:26:43.0873 0x11a0 vmictimesync - ok
17:26:43.0873 0x11a0 vmicvmsession - ok
17:26:43.0888 0x11a0 vmicvss - ok
17:26:43.0888 0x11a0 volmgr - ok
17:26:43.0888 0x11a0 volmgrx - ok
17:26:43.0904 0x11a0 volsnap - ok
17:26:43.0904 0x11a0 volume - ok
17:26:43.0904 0x11a0 vpci - ok
17:26:43.0919 0x11a0 vsmraid - ok
17:26:43.0919 0x11a0 VSS - ok
17:26:43.0919 0x11a0 VSTXRAID - ok
17:26:43.0935 0x11a0 vwifibus - ok
17:26:43.0935 0x11a0 vwififlt - ok
17:26:43.0935 0x11a0 vwifimp - ok
17:26:43.0951 0x11a0 W32Time - ok
17:26:43.0951 0x11a0 WacomPen - ok
17:26:43.0966 0x11a0 WalletService - ok
17:26:43.0966 0x11a0 wanarp - ok
17:26:43.0966 0x11a0 wanarpv6 - ok
17:26:43.0966 0x11a0 wbengine - ok
17:26:43.0982 0x11a0 WbioSrvc - ok
17:26:43.0982 0x11a0 wcifs - ok
17:26:43.0982 0x11a0 Wcmsvc - ok
17:26:43.0998 0x11a0 wcncsvc - ok
17:26:43.0998 0x11a0 wcnfs - ok
17:26:43.0998 0x11a0 WdBoot - ok
17:26:44.0013 0x11a0 Wdf01000 - ok
17:26:44.0013 0x11a0 WdFilter - ok
17:26:44.0013 0x11a0 WdiServiceHost - ok
17:26:44.0029 0x11a0 WdiSystemHost - ok
17:26:44.0029 0x11a0 wdiwifi - ok
17:26:44.0029 0x11a0 WdNisDrv - ok
17:26:44.0044 0x11a0 WdNisSvc - ok
17:26:44.0044 0x11a0 WebClient - ok
17:26:44.0044 0x11a0 Wecsvc - ok
17:26:44.0060 0x11a0 WEPHOSTSVC - ok
17:26:44.0060 0x11a0 wercplsupport - ok
17:26:44.0060 0x11a0 WerSvc - ok
17:26:44.0076 0x11a0 WFPLWFS - ok
17:26:44.0076 0x11a0 WiaRpc - ok
17:26:44.0076 0x11a0 WIMMount - ok
17:26:44.0091 0x11a0 WinDefend - ok
17:26:44.0091 0x11a0 WindowsTrustedRT - ok
17:26:44.0107 0x11a0 WindowsTrustedRTProxy - ok
17:26:44.0107 0x11a0 WinHttpAutoProxySvc - ok
17:26:44.0107 0x11a0 WinMad - ok
17:26:44.0123 0x11a0 Winmgmt - ok
17:26:44.0123 0x11a0 WinRM - ok
17:26:44.0138 0x11a0 WINUSB - ok
17:26:44.0138 0x11a0 WinVerbs - ok
17:26:44.0154 0x11a0 wisvc - ok
17:26:44.0154 0x11a0 WlanSvc - ok
17:26:44.0154 0x11a0 wlidsvc - ok
17:26:44.0169 0x11a0 WmiAcpi - ok
17:26:44.0169 0x11a0 wmiApSrv - ok
17:26:44.0169 0x11a0 WMPNetworkSvc - ok
17:26:44.0185 0x11a0 Wof - ok
17:26:44.0185 0x11a0 workfolderssvc - ok
17:26:44.0201 0x11a0 WPDBusEnum - ok
17:26:44.0201 0x11a0 WpdUpFltr - ok
17:26:44.0201 0x11a0 WpnService - ok
17:26:44.0201 0x11a0 WpnUserService - ok
17:26:44.0216 0x11a0 ws2ifsl - ok
17:26:44.0216 0x11a0 wscsvc - ok
17:26:44.0232 0x11a0 WSearch - ok
17:26:44.0232 0x11a0 wuauserv - ok
17:26:44.0248 0x11a0 WudfPf - ok
17:26:44.0248 0x11a0 WUDFRd - ok
17:26:44.0248 0x11a0 wudfsvc - ok
17:26:44.0263 0x11a0 WUDFWpdFs - ok
17:26:44.0263 0x11a0 WUDFWpdMtp - ok
17:26:44.0263 0x11a0 WwanSvc - ok
17:26:44.0279 0x11a0 XblAuthManager - ok
17:26:44.0279 0x11a0 XblGameSave - ok
17:26:44.0279 0x11a0 xboxgip - ok
17:26:44.0294 0x11a0 XboxNetApiSvc - ok
17:26:44.0294 0x11a0 xinputhid - ok
17:26:44.0310 0x11a0 ykinw8 - ok
17:26:44.0310 0x11a0 ================ Scan global ===============================
17:26:44.0326 0x11a0 [ Global ] - ok
17:26:44.0326 0x11a0 ================ Scan MBR ==================================
17:26:44.0326 0x11a0 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:26:44.0466 0x11a0 \Device\Harddisk0\DR0 - ok
17:26:44.0466 0x11a0 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
17:26:44.0654 0x11a0 \Device\Harddisk1\DR1 - ok
17:26:44.0654 0x11a0 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk4\DR4
17:26:44.0748 0x11a0 \Device\Harddisk4\DR4 - ok
17:26:44.0748 0x11a0 ================ Scan VBR ==================================
17:26:44.0748 0x11a0 [ B75D89CA6D84C3CB1A6CA73A56716F49 ] \Device\Harddisk0\DR0\Partition1
17:26:44.0763 0x11a0 \Device\Harddisk0\DR0\Partition1 - ok
17:26:44.0763 0x11a0 [ BF802D8035F06A0BA68F026159CA8763 ] \Device\Harddisk1\DR1\Partition1
17:26:44.0763 0x11a0 \Device\Harddisk1\DR1\Partition1 - ok
17:26:44.0779 0x11a0 [ 55D863E4CA2B9A5E1BB7A9B572FDDD70 ] \Device\Harddisk4\DR4\Partition1
17:26:44.0779 0x11a0 \Device\Harddisk4\DR4\Partition1 - ok
17:26:44.0779 0x11a0 ================ Scan generic autorun ======================
17:26:44.0966 0x11a0 [ 5229C2546E151D368A1CE0E451351231, 2E421986933D70789665195A92D2A9022500E9382B2881881B741F0023D6422E ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
17:26:45.0138 0x11a0 RtHDVCpl - ok
17:26:45.0154 0x11a0 [ 5677C8C60F4659E8626AC9036EEF38DF, 1C7D3EC3BCB3E34900DD9556A3EBAF449C68585DC8E07682E680790497105B8B ] C:\Program Files\Classic Shell\ClassicStartMenu.exe
17:26:45.0169 0x11a0 Classic Start Menu - ok
17:26:45.0216 0x11a0 [ 8943465BEFA91044227D42E84ECB8280, 76D19CE3EB7E6C6573F250543CDC10B3601604535BFB756805AE246FA55AC265 ] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
17:26:45.0232 0x11a0 NUSB3MON - ok
17:26:45.0248 0x11a0 [ CD0362AEE36CFE1EF5DF973230742E67, 9F1D8AD4E09D16C39CD6A35CB298456468C1808226FFA8AD65BF9562A6ECC07D ] C:\Program Files (x86)\PDF24\pdf24.exe
17:26:45.0279 0x11a0 PDFPrint - ok
17:26:45.0279 0x11a0 [ B69B3F28C5DB496202C88F5A181640AC, 6ECD6DCFE27A043457BA910289849534ED9D173856DAF694687366E1A2C7A135 ] C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
17:26:45.0294 0x11a0 Avira SystrayStartTrigger - ok
17:26:45.0326 0x11a0 OneDriveSetup - ok
17:26:45.0326 0x11a0 OneDriveSetup - ok
17:26:45.0341 0x11a0 [ 7D0F245088942BCB888A0AC149A6F378, 20B8145FC6988DB195E7E153FB8CA20DDE39CFC540AC5DC9BC1E91497E3ACC92 ] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEJE.EXE
17:26:45.0373 0x11a0 EPSON Stylus Office BX300F - ok
17:26:45.0451 0x11a0 [ F73154E180105822A5F9B755BA933737, 1CD775B6CE3736A70EC5FC7A6B77A2FEDA70D59B49A66046CC20B341005501D9 ] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
17:26:45.0529 0x11a0 DAEMON Tools Lite - ok
17:26:45.0560 0x11a0 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
17:26:45.0560 0x11a0 AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.134 ), 0x60000 ( disabled : updated )
17:26:45.0560 0x11a0 Win FW state via NFP2: enabled ( trusted )
17:26:45.0576 0x11a0 ============================================================
17:26:45.0576 0x11a0 Scan finished
17:26:45.0576 0x11a0 ============================================================
17:26:45.0576 0x1028 Detected object count: 3
17:26:45.0576 0x1028 Actual detected object count: 3
17:26:50.0685 0x1028 epmntdrv ( UnsignedFile.Multi.Generic ) - skipped by user
17:26:50.0685 0x1028 epmntdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:26:50.0701 0x1028 EuGdiDrv ( UnsignedFile.Multi.Generic ) - skipped by user
17:26:50.0701 0x1028 EuGdiDrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:26:50.0701 0x1028 ucdrv ( HiddenFile.Multi.Generic ) - skipped by user
17:26:50.0701 0x1028 ucdrv ( HiddenFile.Multi.Generic ) - User select action: Skip
17:27:03.0983 0x1754 Deinitialize success |