Lani2388 | 14.01.2017 17:58 | Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2017.01.14.02
rootkit: v2016.11.20.01
Windows 10 x64 NTFS
Internet Explorer 11.576.14393.0
Sabrina :: SABRINA [administrator]
14.01.2017 15:55:56
mbar-log-2017-01-14 (15-55-56).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 347900
Time elapsed: 1 hour(s), 16 minute(s), 8 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Users\Sabrina\Desktop\GameZone\Battlefield\fff-ea117.exe (RiskWare.Tool.CK) -> Delete on reboot. [02c890eb644460d610977c73679c09f7]
C:\Users\Sabrina\Desktop\GameZone\Call of Duty\Call Of Duty 4 - Modern Warfare\keygen.exe (CrackTool.Agent) -> Delete on reboot. [a6245b20693f270f3d661cb8fc047f81]
Physical Sectors Detected: 0
(No malicious items detected)
(end) Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2017.01.14.02
rootkit: v2016.11.20.01
Windows 10 x64 NTFS
Internet Explorer 11.576.14393.0
Sabrina :: SABRINA [administrator]
14.01.2017 17:19:21
mbar-log-2017-01-14 (17-19-21).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 346999
Time elapsed: 33 minute(s), 53 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) das sind die beiden Mbar sachen
Und hier der Tdsskiller Code:
17:54:09.0246 0x1318 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
17:54:19.0437 0x1318 ============================================================
17:54:19.0437 0x1318 Current date / time: 2017/01/14 17:54:19.0437
17:54:19.0437 0x1318 SystemInfo:
17:54:19.0437 0x1318
17:54:19.0437 0x1318 OS Version: 10.0.14393 ServicePack: 0.0
17:54:19.0437 0x1318 Product type: Workstation
17:54:19.0437 0x1318 ComputerName: SABRINA
17:54:19.0438 0x1318 UserName: Sabrina
17:54:19.0438 0x1318 Windows directory: C:\WINDOWS
17:54:19.0438 0x1318 System windows directory: C:\WINDOWS
17:54:19.0438 0x1318 Running under WOW64
17:54:19.0438 0x1318 Processor architecture: Intel x64
17:54:19.0438 0x1318 Number of processors: 8
17:54:19.0438 0x1318 Page size: 0x1000
17:54:19.0438 0x1318 Boot type: Normal boot
17:54:19.0438 0x1318 CodeIntegrityOptions = 0x00000001
17:54:19.0438 0x1318 ============================================================
17:54:19.0989 0x1318 KLMD registered as C:\WINDOWS\system32\drivers\09562194.sys
17:54:19.0989 0x1318 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.693, osProperties = 0x19
17:54:20.0501 0x1318 System UUID: {DE5ECD0E-3269-E80D-5BD0-312B86A8684D}
17:54:21.0032 0x1318 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:54:21.0045 0x1318 ============================================================
17:54:21.0045 0x1318 \Device\Harddisk0\DR0:
17:54:21.0059 0x1318 MBR partitions:
17:54:21.0059 0x1318 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAF000
17:54:21.0059 0x1318 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xAF800, BlocksNum 0x74575800
17:54:21.0059 0x1318 ============================================================
17:54:21.0115 0x1318 C: <-> \Device\Harddisk0\DR0\Partition2
17:54:21.0115 0x1318 ============================================================
17:54:21.0115 0x1318 Initialize success
17:54:21.0115 0x1318 ============================================================
17:54:53.0478 0x1648 ============================================================
17:54:53.0478 0x1648 Scan started
17:54:53.0478 0x1648 Mode: Manual; SigCheck; TDLFS;
17:54:53.0478 0x1648 ============================================================
17:54:53.0478 0x1648 KSN ping started
17:54:53.0589 0x1648 KSN ping finished: true
17:55:02.0133 0x1648 ================ Scan system memory ========================
17:55:02.0133 0x1648 System memory - ok
17:55:02.0133 0x1648 ================ Scan services =============================
17:55:02.0304 0x1648 1394ohci - ok
17:55:02.0306 0x1648 3ware - ok
17:55:02.0335 0x1648 ACPI - ok
17:55:02.0337 0x1648 AcpiDev - ok
17:55:02.0339 0x1648 acpiex - ok
17:55:02.0341 0x1648 acpipagr - ok
17:55:02.0370 0x1648 AcpiPmi - ok
17:55:02.0372 0x1648 acpitime - ok
17:55:02.0375 0x1648 ADP80XX - ok
17:55:02.0383 0x1648 AFD - ok
17:55:02.0390 0x1648 ahcache - ok
17:55:02.0396 0x1648 AJRouter - ok
17:55:02.0409 0x1648 ALG - ok
17:55:02.0411 0x1648 AmdK8 - ok
17:55:02.0413 0x1648 AmdPPM - ok
17:55:02.0414 0x1648 amdsata - ok
17:55:02.0416 0x1648 amdsbs - ok
17:55:02.0418 0x1648 amdxata - ok
17:55:02.0492 0x1648 [ 809D92855656EFC1D71C980582F7FF8B, 01B551CEC0CFD50CA88EB49AA3F68EEEAE34DFE31E6CA37DA106B3C49CF7FA81 ] AmUStor C:\WINDOWS\system32\drivers\AmUStor.SYS
17:55:02.0515 0x1648 AmUStor - ok
17:55:02.0519 0x1648 AppID - ok
17:55:02.0521 0x1648 AppIDSvc - ok
17:55:02.0542 0x1648 Appinfo - ok
17:55:02.0544 0x1648 applockerfltr - ok
17:55:02.0559 0x1648 AppReadiness - ok
17:55:02.0579 0x1648 AppXSvc - ok
17:55:02.0581 0x1648 arcsas - ok
17:55:02.0583 0x1648 AsyncMac - ok
17:55:02.0637 0x1648 atapi - ok
17:55:02.0639 0x1648 AudioEndpointBuilder - ok
17:55:02.0666 0x1648 Audiosrv - ok
17:55:02.0668 0x1648 AxInstSV - ok
17:55:02.0696 0x1648 b06bdrv - ok
17:55:02.0698 0x1648 BasicDisplay - ok
17:55:02.0700 0x1648 BasicRender - ok
17:55:02.0702 0x1648 bcmfn - ok
17:55:02.0704 0x1648 bcmfn2 - ok
17:55:02.0706 0x1648 BDESVC - ok
17:55:02.0722 0x1648 Beep - ok
17:55:02.0843 0x1648 [ 5B413BEADC23C9D182F7EC09C10441FA, E16E06848492331107C6D682D93D35C5D1A0DC8CAD3816B42203A4BF05932C7E ] BEService C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
17:55:02.0865 0x1648 BEService - ok
17:55:02.0891 0x1648 BFE - ok
17:55:02.0896 0x1648 BITS - ok
17:55:02.0905 0x1648 bowser - ok
17:55:02.0977 0x1648 [ 7487B46E104303E247F68D485C12326F, BAC6A4FFD5B4009B4B673479630FAA2784618438925DFB6489F07BF163188114 ] BRDriver64_1_3_3_E02B25FC C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys
17:55:02.0981 0x1648 BRDriver64_1_3_3_E02B25FC - ok
17:55:03.0006 0x1648 BrokerInfrastructure - ok
17:55:03.0015 0x1648 Browser - ok
17:55:03.0047 0x1648 [ 448917845F097FCE9D4554C3D2001EF3, BDCBEC01579D7CF28963E4E13CDC5B26E4B69CA24FA2CC4D6E24CAE0DDBCB3FE ] BRSptStub C:\ProgramData\BitRaider\BRSptStub.exe
17:55:03.0055 0x1648 BRSptStub - ok
17:55:03.0087 0x1648 BthAvrcpTg - ok
17:55:03.0089 0x1648 BthHFEnum - ok
17:55:03.0090 0x1648 bthhfhid - ok
17:55:03.0100 0x1648 BthHFSrv - ok
17:55:03.0102 0x1648 BTHMODEM - ok
17:55:03.0114 0x1648 bthserv - ok
17:55:03.0121 0x1648 buttonconverter - ok
17:55:03.0122 0x1648 CapImg - ok
17:55:03.0124 0x1648 cdfs - ok
17:55:03.0137 0x1648 CDPSvc - ok
17:55:03.0166 0x1648 CDPUserSvc - ok
17:55:03.0221 0x1648 cdrom - ok
17:55:03.0259 0x1648 CertPropSvc - ok
17:55:03.0261 0x1648 cht4iscsi - ok
17:55:03.0263 0x1648 cht4vbd - ok
17:55:03.0264 0x1648 circlass - ok
17:55:03.0290 0x1648 CLFS - ok
17:55:03.0292 0x1648 ClipSVC - ok
17:55:03.0293 0x1648 clreg - ok
17:55:03.0297 0x1648 CmBatt - ok
17:55:03.0299 0x1648 CNG - ok
17:55:03.0300 0x1648 cnghwassist - ok
17:55:03.0355 0x1648 CompositeBus - ok
17:55:03.0357 0x1648 COMSysApp - ok
17:55:03.0359 0x1648 condrv - ok
17:55:03.0381 0x1648 CoreMessagingRegistrar - ok
17:55:03.0392 0x1648 CryptSvc - ok
17:55:03.0397 0x1648 dam - ok
17:55:03.0408 0x1648 DcomLaunch - ok
17:55:03.0420 0x1648 DcpSvc - ok
17:55:03.0425 0x1648 defragsvc - ok
17:55:03.0434 0x1648 DeviceAssociationService - ok
17:55:03.0436 0x1648 DeviceInstall - ok
17:55:03.0449 0x1648 DevQueryBroker - ok
17:55:03.0475 0x1648 Dfsc - ok
17:55:03.0531 0x1648 [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
17:55:03.0538 0x1648 dg_ssudbus - ok
17:55:03.0564 0x1648 Dhcp - ok
17:55:03.0674 0x1648 diagnosticshub.standardcollector.service - ok
17:55:03.0709 0x1648 DiagTrack - ok
17:55:03.0746 0x1648 disk - ok
17:55:03.0766 0x1648 DmEnrollmentSvc - ok
17:55:03.0767 0x1648 dmvsc - ok
17:55:03.0769 0x1648 dmwappushservice - ok
17:55:03.0814 0x1648 Dnscache - ok
17:55:03.0817 0x1648 dot3svc - ok
17:55:03.0818 0x1648 DPS - ok
17:55:03.0863 0x1648 drmkaud - ok
17:55:03.0874 0x1648 DsmSvc - ok
17:55:03.0876 0x1648 DsSvc - ok
17:55:03.0888 0x1648 DXGKrnl - ok
17:55:03.0892 0x1648 EapHost - ok
17:55:03.0894 0x1648 EasyAntiCheat - ok
17:55:03.0895 0x1648 ebdrv - ok
17:55:03.0936 0x1648 EFS - ok
17:55:03.0938 0x1648 EhStorClass - ok
17:55:03.0953 0x1648 EhStorTcgDrv - ok
17:55:03.0965 0x1648 embeddedmode - ok
17:55:03.0973 0x1648 EntAppSvc - ok
17:55:03.0975 0x1648 ErrDev - ok
17:55:03.0978 0x1648 EventSystem - ok
17:55:03.0979 0x1648 exfat - ok
17:55:03.0981 0x1648 fastfat - ok
17:55:03.0988 0x1648 Fax - ok
17:55:03.0989 0x1648 fdc - ok
17:55:03.0991 0x1648 fdPHost - ok
17:55:04.0002 0x1648 FDResPub - ok
17:55:04.0050 0x1648 fhsvc - ok
17:55:04.0063 0x1648 FileCrypt - ok
17:55:04.0065 0x1648 FileInfo - ok
17:55:04.0066 0x1648 Filetrace - ok
17:55:04.0068 0x1648 flpydisk - ok
17:55:04.0069 0x1648 FltMgr - ok
17:55:04.0104 0x1648 FontCache - ok
17:55:04.0283 0x1648 FontCache3.0.0.0 - ok
17:55:04.0309 0x1648 FrameServer - ok
17:55:04.0311 0x1648 FsDepends - ok
17:55:04.0314 0x1648 Fs_Rec - ok
17:55:04.0335 0x1648 fvevol - ok
17:55:04.0337 0x1648 gencounter - ok
17:55:04.0355 0x1648 genericusbfn - ok
17:55:04.0356 0x1648 GPIOClx0101 - ok
17:55:04.0358 0x1648 gpsvc - ok
17:55:04.0359 0x1648 GpuEnergyDrv - ok
17:55:04.0432 0x1648 [ C6FF00DA1605982E616C03BE809FFE2D, 4D9C86B9FF2FA291DC320677D28DF00C26834409F7AD94D6C07D2233ED746B19 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:55:04.0437 0x1648 gupdate - ok
17:55:04.0441 0x1648 [ C6FF00DA1605982E616C03BE809FFE2D, 4D9C86B9FF2FA291DC320677D28DF00C26834409F7AD94D6C07D2233ED746B19 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:55:04.0446 0x1648 gupdatem - ok
17:55:04.0466 0x1648 [ 7F79205B4EFA98F0767309479C8C01C6, 4B576903A83F33A8CF31D3887144A3D51C56D1187115C83AC99C0E9F6B4BF128 ] Hamachi C:\WINDOWS\system32\DRIVERS\Hamdrv.sys
17:55:04.0475 0x1648 Hamachi - ok
17:55:04.0497 0x1648 HdAudAddService - ok
17:55:04.0499 0x1648 HDAudBus - ok
17:55:04.0501 0x1648 HidBatt - ok
17:55:04.0502 0x1648 HidBth - ok
17:55:04.0504 0x1648 hidi2c - ok
17:55:04.0534 0x1648 hidinterrupt - ok
17:55:04.0572 0x1648 HidIr - ok
17:55:04.0626 0x1648 hidserv - ok
17:55:04.0656 0x1648 HidUsb - ok
17:55:04.0683 0x1648 HomeGroupListener - ok
17:55:04.0687 0x1648 HomeGroupProvider - ok
17:55:04.0689 0x1648 HpSAMD - ok
17:55:04.0700 0x1648 HTTP - ok
17:55:04.0715 0x1648 HvHost - ok
17:55:04.0733 0x1648 hvservice - ok
17:55:04.0865 0x1648 [ EF558A02D734A1403583E95CCEEC2487, F0D052DAF48A62E4A90D067BFCB5EE9563804DE68D0EA82E0E11C8D16AD19D29 ] HWiNFO32 C:\WINDOWS\SysWoW64\drivers\HWiNFO64A.SYS
17:55:04.0869 0x1648 HWiNFO32 - ok
17:55:04.0872 0x1648 hwpolicy - ok
17:55:04.0896 0x1648 hyperkbd - ok
17:55:04.0939 0x1648 i8042prt - ok
17:55:04.0941 0x1648 iagpio - ok
17:55:04.0942 0x1648 iai2c - ok
17:55:04.0944 0x1648 iaLPSS2i_GPIO2 - ok
17:55:04.0945 0x1648 iaLPSS2i_I2C - ok
17:55:04.0947 0x1648 iaLPSSi_GPIO - ok
17:55:04.0948 0x1648 iaLPSSi_I2C - ok
17:55:05.0039 0x1648 [ 0609694A9C4D6C71319732FA82C6E5C5, 5507D20AB9C86B11564C953C6F535976A0D201295C642EA0CABF435DAD908251 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
17:55:05.0063 0x1648 iaStorA - ok
17:55:05.0066 0x1648 iaStorAV - ok
17:55:05.0067 0x1648 iaStorV - ok
17:55:05.0069 0x1648 ibbus - ok
17:55:05.0095 0x1648 icssvc - ok
17:55:05.0101 0x1648 IKEEXT - ok
17:55:05.0121 0x1648 IndirectKmd - ok
17:55:05.0232 0x1648 [ A8FD69E79BF0468DA0C09983AF960C04, 7F87EB5BDA29D7EE3B20887EFE511CEBD5F11490E2C098DF359F7766BC23D769 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
17:55:05.0304 0x1648 IntcAzAudAddService - ok
17:55:05.0338 0x1648 intelide - ok
17:55:05.0340 0x1648 intelpep - ok
17:55:05.0346 0x1648 intelppm - ok
17:55:05.0438 0x1648 [ CD6FE4D2E29D70D9E2AA587DE5978A15, 03BA3338E0178FCB6FC7792FE4BB2B836CEA8B791D53DD4E273AB48621397DC5 ] IObitUnSvr C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe
17:55:05.0446 0x1648 IObitUnSvr - ok
17:55:05.0472 0x1648 iorate - ok
17:55:05.0474 0x1648 IpFilterDriver - ok
17:55:05.0503 0x1648 iphlpsvc - ok
17:55:05.0505 0x1648 IPMIDRV - ok
17:55:05.0530 0x1648 IPNAT - ok
17:55:05.0533 0x1648 irda - ok
17:55:05.0535 0x1648 IRENUM - ok
17:55:05.0540 0x1648 irmon - ok
17:55:05.0542 0x1648 isapnp - ok
17:55:05.0543 0x1648 iScsiPrt - ok
17:55:05.0597 0x1648 kbdclass - ok
17:55:05.0607 0x1648 kbdhid - ok
17:55:05.0617 0x1648 kdnic - ok
17:55:05.0628 0x1648 KeyIso - ok
17:55:05.0629 0x1648 KSecDD - ok
17:55:05.0641 0x1648 KSecPkg - ok
17:55:05.0643 0x1648 ksthunk - ok
17:55:05.0654 0x1648 KtmRm - ok
17:55:05.0659 0x1648 LanmanServer - ok
17:55:05.0669 0x1648 LanmanWorkstation - ok
17:55:05.0671 0x1648 lfsvc - ok
17:55:05.0679 0x1648 LicenseManager - ok
17:55:05.0681 0x1648 lltdio - ok
17:55:05.0682 0x1648 lltdsvc - ok
17:55:05.0686 0x1648 lmhosts - ok
17:55:05.0689 0x1648 LSI_SAS - ok
17:55:05.0690 0x1648 LSI_SAS2i - ok
17:55:05.0701 0x1648 LSI_SAS3i - ok
17:55:05.0703 0x1648 LSI_SSS - ok
17:55:05.0704 0x1648 LSM - ok
17:55:05.0713 0x1648 luafv - ok
17:55:05.0725 0x1648 MapsBroker - ok
17:55:05.0726 0x1648 megasas - ok
17:55:05.0759 0x1648 megasas2i - ok
17:55:05.0761 0x1648 megasr - ok
17:55:05.0812 0x1648 [ C4A4BE9C6EDA9640F272B48FC0AB4F06, 8A9BE9FACDDBEBDF47ACB86D5DDC0DD3E5F90EDE1E93B59F9E92375E5CB2ACD6 ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
17:55:05.0821 0x1648 MEIx64 - ok
17:55:05.0848 0x1648 MessagingService - ok
17:55:05.0878 0x1648 mlx4_bus - ok
17:55:05.0905 0x1648 MMCSS - ok
17:55:05.0906 0x1648 Modem - ok
17:55:05.0913 0x1648 monitor - ok
17:55:05.0915 0x1648 mouclass - ok
17:55:05.0916 0x1648 mouhid - ok
17:55:05.0918 0x1648 mountmgr - ok
17:55:05.0920 0x1648 mpsdrv - ok
17:55:05.0921 0x1648 MpsSvc - ok
17:55:05.0923 0x1648 MRxDAV - ok
17:55:05.0935 0x1648 mrxsmb - ok
17:55:05.0936 0x1648 mrxsmb10 - ok
17:55:05.0944 0x1648 mrxsmb20 - ok
17:55:05.0946 0x1648 MsBridge - ok
17:55:05.0956 0x1648 MSDTC - ok
17:55:05.0966 0x1648 Msfs - ok
17:55:05.0968 0x1648 msgpiowin32 - ok
17:55:05.0970 0x1648 mshidkmdf - ok
17:55:05.0972 0x1648 mshidumdf - ok
17:55:05.0973 0x1648 msisadrv - ok
17:55:05.0985 0x1648 MSiSCSI - ok
17:55:05.0988 0x1648 msiserver - ok
17:55:05.0990 0x1648 MSKSSRV - ok
17:55:05.0995 0x1648 MsLldp - ok
17:55:05.0997 0x1648 MSPCLOCK - ok
17:55:05.0999 0x1648 MSPQM - ok
17:55:06.0000 0x1648 MsRPC - ok
17:55:06.0014 0x1648 mssmbios - ok
17:55:06.0015 0x1648 MSTEE - ok
17:55:06.0017 0x1648 MTConfig - ok
17:55:06.0019 0x1648 Mup - ok
17:55:06.0021 0x1648 mvumis - ok
17:55:06.0037 0x1648 NativeWifiP - ok
17:55:06.0038 0x1648 NcaSvc - ok
17:55:06.0050 0x1648 NcbService - ok
17:55:06.0052 0x1648 NcdAutoSetup - ok
17:55:06.0054 0x1648 ndfltr - ok
17:55:06.0075 0x1648 NDIS - ok
17:55:06.0077 0x1648 NdisCap - ok
17:55:06.0095 0x1648 NdisImPlatform - ok
17:55:06.0121 0x1648 NdisTapi - ok
17:55:06.0123 0x1648 Ndisuio - ok
17:55:06.0126 0x1648 NdisVirtualBus - ok
17:55:06.0128 0x1648 NdisWan - ok
17:55:06.0129 0x1648 ndiswanlegacy - ok
17:55:06.0131 0x1648 ndproxy - ok
17:55:06.0132 0x1648 Ndu - ok
17:55:06.0134 0x1648 NetAdapterCx - ok
17:55:06.0136 0x1648 NetBIOS - ok
17:55:06.0141 0x1648 NetBT - ok
17:55:06.0143 0x1648 Netlogon - ok
17:55:06.0145 0x1648 Netman - ok
17:55:06.0146 0x1648 netprofm - ok
17:55:06.0202 0x1648 NetSetupSvc - ok
17:55:06.0342 0x1648 NetTcpPortSharing - ok
17:55:06.0344 0x1648 NgcCtnrSvc - ok
17:55:06.0354 0x1648 NgcSvc - ok
17:55:06.0355 0x1648 NlaSvc - ok
17:55:06.0357 0x1648 Npfs - ok
17:55:06.0358 0x1648 npsvctrig - ok
17:55:06.0364 0x1648 nsi - ok
17:55:06.0365 0x1648 nsiproxy - ok
17:55:06.0375 0x1648 NTFS - ok
17:55:06.0377 0x1648 Null - ok
17:55:06.0416 0x1648 [ 64DA1993B1973F049C1347DA1B05185E, 2A04E263DB13751D033E2F9B9518820CF4942EEAFA5A32488570EEB699EE2A96 ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
17:55:06.0423 0x1648 NVHDA - ok
17:55:06.0805 0x1648 [ 557A0393BDFED327968A9E695FB4CEBA, 76D39F74439205B5B614B0D99E9E10629738E00250A5E7FFEE50815F69EE70D0 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3f929cc119e3b994\nvlddmkm.sys
17:55:06.0978 0x1648 nvlddmkm - ok
17:55:07.0014 0x1648 nvraid - ok
17:55:07.0030 0x1648 nvstor - ok
17:55:07.0155 0x1648 [ DEF76B479C3525952D0BD71E881E07B0, DC4B13AA97F61542F55F92769F9C8C5EB253BD6EB165EF064107D11158CD412F ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
17:55:07.0159 0x1648 NvStreamKms - ok
17:55:07.0227 0x1648 [ AF5BE3694A76365874B8967331049F2C, F704A0403B63E856EE9ECCE7C913650F5FF928F0872035EE73E1AE1CD54BC046 ] NvStreamNetworkSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
17:55:07.0276 0x1648 NvStreamNetworkSvc - ok
17:55:07.0314 0x1648 [ 77BE9E1AFCE995652A1C4FF4C8A0F839, 4AD981BCC349D413B3CCDC06DC8D6D2C2648D049726D6825E35A9A91D4C072FF ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
17:55:07.0348 0x1648 NvStreamSvc - ok
17:55:07.0402 0x1648 [ 86BB05638CF921AB95E346AD0AB0E300, 84C5E12F69A106E8C8A59A3C032796FB80344E32F6CC283045A9E9D9CB0E470F ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
17:55:07.0406 0x1648 nvvad_WaveExtensible - ok
17:55:07.0431 0x1648 OneSyncSvc - ok
17:55:07.0477 0x1648 p2pimsvc - ok
17:55:07.0484 0x1648 p2psvc - ok
17:55:07.0489 0x1648 Parport - ok
17:55:07.0497 0x1648 partmgr - ok
17:55:07.0525 0x1648 PcaSvc - ok
17:55:07.0554 0x1648 pci - ok
17:55:07.0587 0x1648 pciide - ok
17:55:07.0589 0x1648 pcmcia - ok
17:55:07.0592 0x1648 pcw - ok
17:55:07.0617 0x1648 pdc - ok
17:55:07.0622 0x1648 PEAUTH - ok
17:55:07.0623 0x1648 percsas2i - ok
17:55:07.0624 0x1648 percsas3i - ok
17:55:07.0698 0x1648 PerfHost - ok
17:55:07.0705 0x1648 PhoneSvc - ok
17:55:07.0718 0x1648 PimIndexMaintenanceSvc - ok
17:55:07.0777 0x1648 pla - ok
17:55:07.0785 0x1648 PlugPlay - ok
17:55:07.0788 0x1648 PnkBstrA - ok
17:55:07.0790 0x1648 PNRPAutoReg - ok
17:55:07.0792 0x1648 PNRPsvc - ok
17:55:07.0801 0x1648 PolicyAgent - ok
17:55:07.0810 0x1648 Power - ok
17:55:07.0813 0x1648 PptpMiniport - ok
17:55:07.0949 0x1648 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
17:55:08.0089 0x1648 PrintNotify - ok
17:55:08.0122 0x1648 Processor - ok
17:55:08.0132 0x1648 ProfSvc - ok
17:55:08.0133 0x1648 Psched - ok
17:55:08.0137 0x1648 QWAVE - ok
17:55:08.0147 0x1648 QWAVEdrv - ok
17:55:08.0148 0x1648 RasAcd - ok
17:55:08.0164 0x1648 RasAgileVpn - ok
17:55:08.0173 0x1648 RasAuto - ok
17:55:08.0175 0x1648 Rasl2tp - ok
17:55:08.0183 0x1648 RasMan - ok
17:55:08.0185 0x1648 RasPppoe - ok
17:55:08.0187 0x1648 RasSstp - ok
17:55:08.0189 0x1648 rdbss - ok
17:55:08.0200 0x1648 rdpbus - ok
17:55:08.0201 0x1648 RDPDR - ok
17:55:08.0255 0x1648 RdpVideoMiniport - ok
17:55:08.0256 0x1648 rdyboost - ok
17:55:08.0258 0x1648 ReFSv1 - ok
17:55:08.0281 0x1648 RemoteAccess - ok
17:55:08.0283 0x1648 RemoteRegistry - ok
17:55:08.0291 0x1648 RetailDemo - ok
17:55:08.0318 0x1648 RmSvc - ok
17:55:08.0320 0x1648 RpcEptMapper - ok
17:55:08.0330 0x1648 RpcLocator - ok
17:55:08.0332 0x1648 RpcSs - ok
17:55:08.0334 0x1648 rspndr - ok
17:55:08.0376 0x1648 [ 39FC08BE0FBCBF40A67C22FFB671A96F, B9B942A0AEF03E4E9D4A61C9F042CDC97BAD98912369CD0E0D8B0FFC08D124A3 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
17:55:08.0393 0x1648 rt640x64 - ok
17:55:08.0422 0x1648 s3cap - ok
17:55:08.0436 0x1648 SamSs - ok
17:55:08.0455 0x1648 sbp2port - ok
17:55:08.0472 0x1648 SCardSvr - ok
17:55:08.0489 0x1648 ScDeviceEnum - ok
17:55:08.0497 0x1648 scfilter - ok
17:55:08.0499 0x1648 Schedule - ok
17:55:08.0500 0x1648 scmbus - ok
17:55:08.0502 0x1648 scmdisk0101 - ok
17:55:08.0526 0x1648 SCPolicySvc - ok
17:55:08.0533 0x1648 sdbus - ok
17:55:08.0535 0x1648 SDRSVC - ok
17:55:08.0537 0x1648 sdstor - ok
17:55:08.0540 0x1648 seclogon - ok
17:55:08.0541 0x1648 SENS - ok
17:55:08.0543 0x1648 SensorDataService - ok
17:55:08.0569 0x1648 SensorService - ok
17:55:08.0574 0x1648 SensrSvc - ok
17:55:08.0576 0x1648 SerCx - ok
17:55:08.0578 0x1648 SerCx2 - ok
17:55:08.0580 0x1648 Serenum - ok
17:55:08.0582 0x1648 Serial - ok
17:55:08.0584 0x1648 sermouse - ok
17:55:08.0591 0x1648 SessionEnv - ok
17:55:08.0593 0x1648 sfloppy - ok
17:55:08.0630 0x1648 SharedAccess - ok
17:55:08.0637 0x1648 ShellHWDetection - ok
17:55:08.0669 0x1648 shpamsvc - ok
17:55:08.0671 0x1648 SiSRaid2 - ok
17:55:08.0673 0x1648 SiSRaid4 - ok
17:55:08.0688 0x1648 smphost - ok
17:55:08.0695 0x1648 SmsRouter - ok
17:55:08.0699 0x1648 SNMPTRAP - ok
17:55:08.0731 0x1648 spaceport - ok
17:55:08.0755 0x1648 SpbCx - ok
17:55:08.0762 0x1648 Spooler - ok
17:55:08.0789 0x1648 sppsvc - ok
17:55:08.0818 0x1648 srv - ok
17:55:08.0826 0x1648 srv2 - ok
17:55:08.0832 0x1648 srvnet - ok
17:55:08.0834 0x1648 SSDPSRV - ok
17:55:08.0842 0x1648 SstpSvc - ok
17:55:08.0886 0x1648 [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
17:55:08.0892 0x1648 ssudmdm - ok
17:55:08.0944 0x1648 StateRepository - ok
17:55:09.0127 0x1648 [ AE4590027FEA1EAC935EF802C09E87E4, 9FD054D95106DE3A604A316B183CA140F2261654405485324CAA1AEA9E7EEA12 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
17:55:09.0148 0x1648 Steam Client Service - ok
17:55:09.0189 0x1648 stexstor - ok
17:55:09.0245 0x1648 stisvc - ok
17:55:09.0251 0x1648 storahci - ok
17:55:09.0253 0x1648 storflt - ok
17:55:09.0255 0x1648 stornvme - ok
17:55:09.0270 0x1648 storqosflt - ok
17:55:09.0272 0x1648 StorSvc - ok
17:55:09.0273 0x1648 storufs - ok
17:55:09.0275 0x1648 storvsc - ok
17:55:09.0292 0x1648 svsvc - ok
17:55:09.0294 0x1648 swenum - ok
17:55:09.0296 0x1648 swprv - ok
17:55:09.0313 0x1648 Synth3dVsc - ok
17:55:09.0318 0x1648 SysMain - ok
17:55:09.0329 0x1648 SystemEventsBroker - ok
17:55:09.0333 0x1648 TabletInputService - ok
17:55:09.0334 0x1648 TapiSrv - ok
17:55:09.0342 0x1648 Tcpip - ok
17:55:09.0343 0x1648 Tcpip6 - ok
17:55:09.0346 0x1648 tcpipreg - ok
17:55:09.0349 0x1648 tdx - ok
17:55:09.0350 0x1648 terminpt - ok
17:55:09.0352 0x1648 TermService - ok
17:55:09.0378 0x1648 Themes - ok
17:55:09.0384 0x1648 TieringEngineService - ok
17:55:09.0385 0x1648 tiledatamodelsvc - ok
17:55:09.0388 0x1648 TimeBrokerSvc - ok
17:55:09.0481 0x1648 [ 17DB352FA977DAAABB6E61A4DED245D9, D428BB4F42F9BCA73A1E74FD7DFBB5322A7A1804FA150B4A783B0EF3BB6CB53E ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
17:55:09.0487 0x1648 TOSHIBA HDD SSD Alert Service - ok
17:55:09.0519 0x1648 TPM - ok
17:55:09.0522 0x1648 TrkWks - ok
17:55:09.0580 0x1648 TrustedInstaller - ok
17:55:09.0583 0x1648 tsusbflt - ok
17:55:09.0585 0x1648 TsUsbGD - ok
17:55:09.0587 0x1648 tunnel - ok
17:55:09.0632 0x1648 tzautoupdate - ok
17:55:09.0639 0x1648 UASPStor - ok
17:55:09.0641 0x1648 UcmCx0101 - ok
17:55:09.0643 0x1648 UcmTcpciCx0101 - ok
17:55:09.0645 0x1648 UcmUcsi - ok
17:55:09.0655 0x1648 Ucx01000 - ok
17:55:09.0657 0x1648 UdeCx - ok
17:55:09.0658 0x1648 udfs - ok
17:55:09.0660 0x1648 UEFI - ok
17:55:09.0672 0x1648 Ufx01000 - ok
17:55:09.0673 0x1648 UfxChipidea - ok
17:55:09.0675 0x1648 ufxsynopsys - ok
17:55:09.0678 0x1648 UI0Detect - ok
17:55:09.0680 0x1648 umbus - ok
17:55:09.0681 0x1648 UmPass - ok
17:55:09.0685 0x1648 UmRdpService - ok
17:55:09.0687 0x1648 UnistoreSvc - ok
17:55:09.0690 0x1648 upnphost - ok
17:55:09.0697 0x1648 UrsChipidea - ok
17:55:09.0698 0x1648 UrsCx01000 - ok
17:55:09.0700 0x1648 UrsSynopsys - ok
17:55:09.0702 0x1648 usbccgp - ok
17:55:09.0704 0x1648 usbcir - ok
17:55:09.0707 0x1648 usbehci - ok
17:55:09.0709 0x1648 usbhub - ok
17:55:09.0711 0x1648 USBHUB3 - ok
17:55:09.0713 0x1648 usbohci - ok
17:55:09.0715 0x1648 usbprint - ok
17:55:09.0717 0x1648 usbser - ok
17:55:09.0718 0x1648 USBSTOR - ok
17:55:09.0720 0x1648 usbuhci - ok
17:55:09.0724 0x1648 USBXHCI - ok
17:55:09.0735 0x1648 UserDataSvc - ok
17:55:09.0784 0x1648 UserManager - ok
17:55:09.0788 0x1648 UsoSvc - ok
17:55:09.0790 0x1648 VaultSvc - ok
17:55:09.0793 0x1648 vdrvroot - ok
17:55:09.0798 0x1648 vds - ok
17:55:09.0801 0x1648 VerifierExt - ok
17:55:09.0812 0x1648 vhdmp - ok
17:55:09.0814 0x1648 vhf - ok
17:55:09.0816 0x1648 vmbus - ok
17:55:09.0818 0x1648 VMBusHID - ok
17:55:09.0820 0x1648 vmgid - ok
17:55:09.0830 0x1648 vmicguestinterface - ok
17:55:09.0831 0x1648 vmicheartbeat - ok
17:55:09.0833 0x1648 vmickvpexchange - ok
17:55:09.0848 0x1648 vmicrdv - ok
17:55:09.0849 0x1648 vmicshutdown - ok
17:55:09.0851 0x1648 vmictimesync - ok
17:55:09.0853 0x1648 vmicvmsession - ok
17:55:09.0855 0x1648 vmicvss - ok
17:55:09.0856 0x1648 volmgr - ok
17:55:09.0858 0x1648 volmgrx - ok
17:55:09.0860 0x1648 volsnap - ok
17:55:09.0862 0x1648 volume - ok
17:55:09.0863 0x1648 vpci - ok
17:55:09.0865 0x1648 vsmraid - ok
17:55:09.0867 0x1648 VSS - ok
17:55:09.0869 0x1648 VSTXRAID - ok
17:55:09.0871 0x1648 vwifibus - ok
17:55:09.0873 0x1648 vwififlt - ok
17:55:09.0880 0x1648 W32Time - ok
17:55:09.0881 0x1648 WacomPen - ok
17:55:09.0883 0x1648 WalletService - ok
17:55:09.0885 0x1648 wanarp - ok
17:55:09.0887 0x1648 wanarpv6 - ok
17:55:09.0891 0x1648 wbengine - ok
17:55:09.0918 0x1648 WbioSrvc - ok
17:55:09.0920 0x1648 wcifs - ok
17:55:09.0922 0x1648 Wcmsvc - ok
17:55:09.0925 0x1648 wcncsvc - ok
17:55:09.0930 0x1648 wcnfs - ok
17:55:09.0931 0x1648 WdBoot - ok
17:55:09.0934 0x1648 Wdf01000 - ok
17:55:09.0935 0x1648 WdFilter - ok
17:55:09.0937 0x1648 WdiServiceHost - ok
17:55:09.0941 0x1648 WdiSystemHost - ok
17:55:09.0943 0x1648 wdiwifi - ok
17:55:09.0944 0x1648 WdNisDrv - ok
17:55:09.0988 0x1648 WdNisSvc - ok
17:55:09.0990 0x1648 WebClient - ok
17:55:09.0992 0x1648 Wecsvc - ok
17:55:09.0994 0x1648 WEPHOSTSVC - ok
17:55:09.0995 0x1648 wercplsupport - ok
17:55:09.0998 0x1648 WerSvc - ok
17:55:10.0000 0x1648 WFPLWFS - ok
17:55:10.0003 0x1648 WiaRpc - ok
17:55:10.0004 0x1648 WIMMount - ok
17:55:10.0007 0x1648 WinDefend - ok
17:55:10.0011 0x1648 WindowsTrustedRT - ok
17:55:10.0013 0x1648 WindowsTrustedRTProxy - ok
17:55:10.0034 0x1648 WinHttpAutoProxySvc - ok
17:55:10.0037 0x1648 WinMad - ok
17:55:10.0102 0x1648 Winmgmt - ok
17:55:10.0134 0x1648 WinRM - ok
17:55:10.0180 0x1648 WINUSB - ok
17:55:10.0182 0x1648 WinVerbs - ok
17:55:10.0216 0x1648 wisvc - ok
17:55:10.0242 0x1648 WlanSvc - ok
17:55:10.0265 0x1648 wlidsvc - ok
17:55:10.0290 0x1648 WmiAcpi - ok
17:55:10.0298 0x1648 wmiApSrv - ok
17:55:10.0326 0x1648 WMPNetworkSvc - ok
17:55:10.0356 0x1648 Wof - ok
17:55:10.0363 0x1648 workfolderssvc - ok
17:55:10.0365 0x1648 WPDBusEnum - ok
17:55:10.0367 0x1648 WpdUpFltr - ok
17:55:10.0369 0x1648 WpnService - ok
17:55:10.0374 0x1648 WpnUserService - ok
17:55:10.0380 0x1648 ws2ifsl - ok
17:55:10.0382 0x1648 wscsvc - ok
17:55:10.0384 0x1648 WSearch - ok
17:55:10.0418 0x1648 wuauserv - ok
17:55:10.0420 0x1648 WudfPf - ok
17:55:10.0423 0x1648 WUDFRd - ok
17:55:10.0445 0x1648 wudfsvc - ok
17:55:10.0447 0x1648 WUDFWpdFs - ok
17:55:10.0450 0x1648 WUDFWpdMtp - ok
17:55:10.0457 0x1648 WwanSvc - ok
17:55:10.0469 0x1648 XblAuthManager - ok
17:55:10.0501 0x1648 XblGameSave - ok
17:55:10.0503 0x1648 xboxgip - ok
17:55:10.0506 0x1648 XboxNetApiSvc - ok
17:55:10.0536 0x1648 xinputhid - ok
17:55:10.0537 0x1648 ================ Scan global ===============================
17:55:10.0634 0x1648 [ Global ] - ok
17:55:10.0634 0x1648 ================ Scan MBR ==================================
17:55:10.0645 0x1648 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:55:10.0902 0x1648 \Device\Harddisk0\DR0 - ok
17:55:10.0902 0x1648 ================ Scan VBR ==================================
17:55:10.0903 0x1648 [ 0AC15D53CCB7A8CA470C09BAD343236F ] \Device\Harddisk0\DR0\Partition1
17:55:10.0904 0x1648 \Device\Harddisk0\DR0\Partition1 - ok
17:55:10.0905 0x1648 [ D3D441D5556714F1515FF3DC1530463E ] \Device\Harddisk0\DR0\Partition2
17:55:10.0905 0x1648 \Device\Harddisk0\DR0\Partition2 - ok
17:55:10.0905 0x1648 ================ Scan generic autorun ======================
17:55:11.0003 0x1648 [ C8AC55CCB8AB33713522B4CAAFAC0F59, CCEA638F90395F5C1C9DA892227FF4F3A7BC7567DEF8A7B63AFE2A487DADA88A ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
17:55:11.0034 0x1648 NvBackend - ok
17:55:11.0036 0x1648 WindowsDefender - ok
17:55:11.0066 0x1648 [ B936172D47C3319B4D25AF109CE539E7, B409C2827CF0282D485F1E3F7B2AF81872182028D2E2A39E0F5530EF9860D5BD ] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
17:55:11.0077 0x1648 TosSENotify - ok
17:55:11.0078 0x1648 BlueStacks Agent - ok
17:55:11.0222 0x1648 [ 8D8D9C8486CB29D01000BFFFE132780A, E1DD85E8CF029FA2F294A2E162838C0D5F11795338C4DE585FD3A0E58894F7C6 ] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
17:55:11.0249 0x1648 Wondershare Helper Compact.exe - ok
17:55:11.0296 0x1648 RoccatIsku - ok
17:55:11.0399 0x1648 [ 14E9A77F1D135704FF87A43EAFF5675E, 4EA434DFC2D5907B3D73C5AC8D1C5E1F192896870C1FB1616557A94217402539 ] C:\Program Files (x86)\ROCCAT\Isku FX Keyboard\IskuFXMonitor.exe
17:55:11.0430 0x1648 RoccatIskuFX - detected UnsignedFile.Multi.Generic ( 1 )
17:55:11.0794 0x1648 RoccatIskuFX ( UnsignedFile.Multi.Generic ) - warning
17:55:11.0794 0x1648 Force sending object to P2P due to detect: C:\Program Files (x86)\ROCCAT\Isku FX Keyboard\IskuFXMonitor.exe
17:55:12.0010 0x1648 Object send P2P result: true
17:55:12.0361 0x1648 Discord - ok
17:55:12.0390 0x1648 OneDriveSetup - ok
17:55:12.0391 0x1648 OneDriveSetup - ok
17:55:12.0510 0x1648 [ D961BA20D31E2660AA8FDF81DCFD032B, A899082B1B6CC0F1F75D0D57B6C8AFFD1D1EE981C63652F9DF26BD71C624251F ] C:\Program Files (x86)\Steam\steam.exe
17:55:12.0549 0x1648 Steam - ok
17:55:12.0628 0x1648 [ 92B29E6BE97F5B2C5894904D1447BBFE, C8BF1ABDC9EDE0264ED7A818F61BB84BA2D42F160FDEA45DE6ED6EF816A6425E ] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
17:55:12.0645 0x1648 GoogleChromeAutoLaunch_80ECDFDFF1FFCF1D06BB588B1CF0C0D7 - ok
17:55:12.0863 0x1648 [ 0C2D8CBA28E12D170FC5343F03E6D20C, 73A66AEF5D89E69E6B19172328AC043542FD7628DD44A569B23625261A0B56FB ] C:\Users\Sabrina\AppData\Roaming\Spotify\SpotifyWebHelper.exe
17:55:12.0883 0x1648 Spotify Web Helper - ok
17:55:13.0011 0x1648 [ C654101E928F9C1EC19A3C3AA78D4482, 925C51A2B1DD082EA5F7035CDAD481F6017DD943B005042703CCE1D5F9572AF2 ] C:\Users\Sabrina\AppData\Roaming\Spotify\Spotify.exe
17:55:13.0097 0x1648 Spotify - ok
17:55:13.0187 0x1648 [ 72C4380EE0D19B7B76196B488E2DFD39, 066E21A906F954D8054CA8601BA2663998AA9018AE47A8A8DB398111E973F7EF ] C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe
17:55:13.0247 0x1648 TSMApplication - detected UnsignedFile.Multi.Generic ( 1 )
17:55:13.0513 0x1648 TSMApplication ( UnsignedFile.Multi.Generic ) - warning
17:55:13.0513 0x1648 Force sending object to P2P due to detect: C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe
17:55:13.0874 0x1648 Object send P2P result: true
17:55:14.0375 0x1648 [ 44348495F9D6ED21F4EFB3FF80677D99, 05B76248764B2BF7F9229626D7EFAFF96B724D38A82969EBE376CBE879E30450 ] C:\Users\Sabrina\AppData\Local\Microsoft\OneDrive\OneDrive.exe
17:55:14.0399 0x1648 OneDrive - ok
17:55:14.0400 0x1648 Waiting for KSN requests completion. In queue: 32
17:55:15.0407 0x1648 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x61100 ( enabled : updated )
17:55:15.0409 0x1648 Win FW state via NFP2: enabled ( trusted )
17:55:15.0554 0x1648 ============================================================
17:55:15.0554 0x1648 Scan finished
17:55:15.0554 0x1648 ============================================================
17:55:15.0558 0x0340 Detected object count: 2
17:55:15.0558 0x0340 Actual detected object count: 2
17:55:28.0556 0x0340 RoccatIskuFX ( UnsignedFile.Multi.Generic ) - skipped by user
17:55:28.0556 0x0340 RoccatIskuFX ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:55:28.0556 0x0340 TSMApplication ( UnsignedFile.Multi.Generic ) - skipped by user
17:55:28.0556 0x0340 TSMApplication ( UnsignedFile.Multi.Generic ) - User select action: Skip |